Skip to content

Updated 03:00

Determinate Secure Packages CVE Remediation Dashboard

Every CVE (Common Vulnerabilities and Exposures record) in Determinate Secure Packages has a fix deadline determined by our service-level agreement (SLA). See how Determinate Secure Packages stays ahead of CVEs.

Fixed within SLA

933

last 30 days

Fixed within SLA

44

last 7 days

Open

82

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Currently tracked CVEs

Every dot is one currently tracked CVE, with a color and shape indicating its current status, and placed in the row that corresponds to its severity and the position on the x-axis that corresponds to the day of its SLA deadline. The vertically aligned dotted purple lines indicate SLA dates for the corresponding severity.

Severity
Status

1015 of 1015 tracked CVEs shown.

Critical7-day SLA (100)+7dHigh15-day SLA (416)+15dMedium45-day SLA (446)+45dLow90-day SLA (53)+90dAug 1Oct 1Nov 1Dec 1Aug 1Sep 1Oct 1Nov 1Dec 1SeveritySLA deadlineTodayCVE-2026-14679 · Open · CVE-2026-14679: PostgreSQL stack buffer overflow via OUT parameter count in argument name matching; 0x0/0x1 writesCVE-2026-14671 · Open · CVE-2026-14671: PostgreSQL refint type confusion enables arbitrary code execution as DB OS user; affects <18.5/17.11/16.15/15.19/14.24CVE-2026-6471 · Open · CVE-2026-6471: PostgreSQL logical decoding auth flaw lets REPLICATION users dlopen arbitrary files, execute codeCVE-2026-16238 · Open · CVE-2026-16238: PostgreSQL 18.0-18.4 pg_restore_attribute_stats type confusion enables OS-level code execution via range/multirangeCVE-2026-14677 · Open · CVE-2026-14677: PostgreSQL 32-bit pltcl/plperl integer wraparound enables OOB write and RCE (pre-18.5/17.11/16.15/15.19/14.24)CVE-2026-64117 · Open · CVE-2026-64117: mac80211 use-after-free: fast-RX reads RX status after mesh forwarding reuses skb->cbCVE-2026-14668 · Open · CVE-2026-14668: PostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory data (pre-18.5/17.11/16.15/15.19/14.24)CVE-2026-14680 · Open · CVE-2026-14680: Type confusion in PostgreSQL 'internal' arguments enables arbitrary code execution by any user via functionsCVE-2026-19385 · Open · CVE-2026-19385: pg_dump heap overflow on long transform lists enables RCE; PostgreSQL <18.5/17.11/16.15/15.19/14.24CVE-2026-14669 · Open · CVE-2026-14669: Heap overflow in PostgreSQL to_char(timestamptz) enables code execution via long timezone abbreviationCVE-2026-15742 · Open · CVE-2026-15742: PostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein; affects versions before 18.5/17.11/16.15/15.19/14.24CVE-2026-18408 · Open · CVE-2026-18408: Restore-time code execution via psql \restrict/\unrestrict in PostgreSQL pg_dump/pg_dumpall/pg_restoreCVE-2026-14670 · Open · CVE-2026-14670: Heap buffer overflow in PostgreSQL plperl tied hash return enables function owner OS code executionCVE-2026-14664 · Open · CVE-2026-14664: PostgreSQL regexp heap overflow permits RCE via invalid encoding; pre-18.5/17.11/16.15/15.19/14.24 affectedCVE-2026-15741 · Open · CVE-2026-15741: PostgreSQL EXTRACT() deparse SQL injection lets object owners run superuser SQL; affects pg_dump and psqlCVE-2026-16239 · Open · CVE-2026-16239: PostgreSQL portal/cursor type confusion enables arbitrary OS-level code execution; before 18.5/17.11/16.15/15.19/14.24.CVE-2026-6464 · Open · CVE-2026-6464: psql COPY FROM STDIN may execute data rows as commands on early failureCVE-2026-14662 · Open · CVE-2026-14662: PostgreSQL tsvector/tsquery integer wraparound causes OOB write RCE; affects <18.5/17.11/16.15/15.19/14.24CVE-2026-14669 · Open · CVE-2026-14669: PostgreSQL to_char(timestamptz) heap overflow via long POSIX timezone allows OS-user RCECVE-2026-15742 · Open · CVE-2026-15742: PostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein/levenshtein_less_equal extreme inputsCVE-2026-14662 · Open · CVE-2026-14662: PostgreSQL tsvector/tsquery integer wraparound enables unprivileged OOB write and potential RCECVE-2026-15741 · Open · CVE-2026-15741: PostgreSQL EXTRACT() deparse SQL injection lets object owners escalate to superuser via deparse consumersCVE-2026-18408 · Open · CVE-2026-18408: PostgreSQL pg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict expansion; CVE-2025-8714 bypassCVE-2026-14671 · Open · CVE-2026-14671: PostgreSQL refint type confusion allows arbitrary code execution as DB OS user (pre-18.5/17.11/16.15/15.19/14.24)CVE-2026-16238 · Open · CVE-2026-16238: pg_restore_attribute_stats type confusion lets object creators execute OS code in PostgreSQL 18 before 18.5CVE-2026-6464 · Open · CVE-2026-6464: Security: psql COPY FROM STDIN may execute data rows as commands on failureCVE-2026-6471 · Open · CVE-2026-6471: Logical decoding lacks authorization, REPLICATION users can dlopen arbitrary files, execute code as server accountCVE-2026-19385 · Open · CVE-2026-19385: PostgreSQL pg_dump heap buffer overflow via crafted long transform lists enables OS user RCECVE-2026-14668 · Open · CVE-2026-14668: Type confusion in PostgreSQL ctid selectivity estimator enables memory disclosure via crafted non-ctid inputCVE-2026-16239 · Open · CVE-2026-16239: PostgreSQL portal/cursor type confusion permits arbitrary code execution as database OS user pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14670 · Open · CVE-2026-14670: PostgreSQL plperl tied-hash return heap overflow enables OS code execution; affects pre 18.5/17.11/16.15/15.19/14.24CVE-2026-14679 · Open · CVE-2026-14679: PostgreSQL stack buffer overflow in argument name matching via OUT parameter countCVE-2026-14664 · Open · CVE-2026-14664: PostgreSQL regexp heap overflow enables OS-level RCE via invalid-encoding text; pre-18.5/17.11/16.15/15.19/14.24 affectedCVE-2026-14677 · Open · CVE-2026-14677: PostgreSQL pltcl/plperl 32-bit integer wraparound causes OOB write, potential RCE; pre-18.5 affectedCVE-2026-14680 · Open · CVE-2026-14680: PostgreSQL 'internal' type confusion enables arbitrary OS code execution by any userCVE-2026-76038 · Fixed within SLA · CVE-2026-76038: Chrome V8 type confusion allows sandboxed RCE via crafted HTML pre-151.0.7922.169CVE-2026-76040 · Fixed within SLA · CVE-2026-76040: High-severity Chrome Mac Browser use-after-free pre-151.0.7922.169 allows RCE outside sandbox via crafted HTMLCVE-2026-76047 · Fixed within SLA · CVE-2026-76047: V8 type confusion in Chrome pre-151.0.7922.169 enables sandboxed RCE via crafted HTMLCVE-2026-76043 · Fixed within SLA · CVE-2026-76043: Incorrect calculation in V8 allows sandboxed RCE via crafted HTML in Chrome <151.0.7922.169CVE-2026-76046 · Fixed within SLA · CVE-2026-76046: Chrome Android ANGLE buffer overflow before 151.0.7922.169 enables out-of-sandbox RCECVE-2026-64117 · Fixed within SLA · CVE-2026-64117: Use-after-free in ieee80211_prepare_and_rx_handle from mesh skb->cb reuse during fast-RXCVE-2026-76044 · Fixed within SLA · CVE-2026-76044: Chrome <151.0.7922.169 USB race leads to sandbox escape RCE from crafted HTMLCVE-2026-76037 · Fixed within SLA · CVE-2026-76037: Chrome Windows CredentialProvider link-following bug allows local arbitrary code execution outside sandbox pre-151.0.7922.169CVE-2026-76045 · Fixed within SLA · CVE-2026-76045: Use-after-free in Chrome WebGL pre-151.0.7922.169 allows sandboxed RCE via crafted HTML pageCVE-2026-76034 · Fixed within SLA · CVE-2026-76034: Critical WebGL buffer overflow in Chrome <151.0.7922.169 enables sandbox-escape RCE via crafted HTMLCVE-2026-16241 · Open · CVE-2026-16241: Server-admin triggered PostgreSQL ECPG integer underflow DoS via malformed bytea; pre-18.5/17.11/16.15/15.19/14.24CVE-2026-6469 · Open · CVE-2026-6469: PostgreSQL ALTER TABLE ALTER TYPE reassigns stats ownership, enabling unauthorized DROP/ALTER; pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14673 · Open · CVE-2026-14673: PostgreSQL amcheck untrusted search_path enables privilege escalation via expression indexes; affects <18.5/16.15/15.19/14.24CVE-2026-16241 · Open · CVE-2026-16241: PostgreSQL ECPG integer underflow: client DoS via missing bytea prefix; pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14673 · Open · CVE-2026-14673: PostgreSQL amcheck untrusted search_path permits arbitrary function execution via expression indexes in versions before 18.5/16.15/15.19/14.24CVE-2026-6469 · Open · CVE-2026-6469: PostgreSQL ALTER TABLE ALTER TYPE misassigns stats ownership, allowing unauthorized DROP/ALTERCVE-2026-76042 · Fixed within SLA · CVE-2026-76042: Chrome GPU uninitialized resource allows memory read outside sandbox post-renderer compromise (pre-151.0.7922.169)CVE-2026-6470 · Open · CVE-2026-6470: PostgreSQL DDL missing auth enables DoS on type ALTER/DROP via range/expression dependenciesCVE-2026-14678 · Open · CVE-2026-14678: PostgreSQL pg_trgm picksplit buffer over-read enabling memory inference; affects pre-18.5/17.11/16.15/15.19/14.24CVE-2026-0864 · Open · CVE-2026-0864: ConfigParser write() allows key/value injection via CR in attacker-controlled multiline valuesCVE-2026-14672 · Open · CVE-2026-14672: SCRAM auth iteration-count discrepancy enables user enumeration with non-default scram_iterations; affects PostgreSQL 16–18 pre 18.5/17.11/16.15CVE-2026-14663 · Open · CVE-2026-14663: PostgreSQL pgcrypto vuln: disabled ciphers allow cleartext recovery, wrong-key decryption bypasses MDCCVE-2026-14666 · Open · CVE-2026-14666: PostgreSQL stale RLS policies after role or ownership changes due to plan reuseCVE-2026-18024 · Open · CVE-2026-18024: PostgreSQL ascii() buffer over-read leaks up to 3 bytes via crafted text; affects <18.5/17.11/16.15/15.19/14.24CVE-2026-6470 · Open · CVE-2026-6470: PostgreSQL DDL lacks auth for range subtype/expressions, enabling DoS on type ALTER/DROPCVE-2026-14678 · Open · CVE-2026-14678: PostgreSQL pg_trgm picksplit heap buffer over-read may leak memory via split choicesCVE-2026-14663 · Open · CVE-2026-14663: PostgreSQL pgcrypto disabled OpenSSL ciphers leak plaintext; wrong-key decryption bypasses MDCCVE-2026-0864 · Open · CVE-2026-0864: configparser CR in multiline values allows injected keys/values via attacker-controlled inputCVE-2026-14672 · Open · CVE-2026-14672: PostgreSQL 16–18: SCRAM iteration-count discrepancy enables unauthenticated user enumerationCVE-2026-14666 · Open · CVE-2026-14666: PostgreSQL RLS cache invalidation bug allows unauthorized access after role/ownership changes via plan reuseCVE-2026-18024 · Open · CVE-2026-18024: PostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24CVE-2026-17572 · Fixed within SLA · CVE-2026-17572: HDF5 <=2.1.1 SOHM list-index deserialization heap overflow via crafted file, causing crashCVE-2026-17573 · Fixed within SLA · CVE-2026-17573: HDF5 h5repack double free on crafted file with oversized chunk sizeCVE-2026-76039 · Fixed within SLA · CVE-2026-76039: Chrome Android Core reference resolution bug leaks sensitive data via crafted HTML (pre-151.0.7922.169)CVE-2026-17573 · Fixed within SLA · CVE-2026-17573: HDF5 h5repack double free when parsing oversized chunk size in crafted fileCVE-2026-76033 · Fixed within SLA · CVE-2026-76033: CORS implementation flaw lets compromised renderer bypass Chrome site isolation (pre-151.0.7922.169)CVE-2026-76041 · Fixed within SLA · CVE-2026-76041: High-severity Skia info leak in Chrome <151.0.7922.169 allows origin policy bypass via crafted HTMLCVE-2026-17572 · Fixed within SLA · CVE-2026-17572: Heap-based buffer overflow in HDF5 <=2.1.1 SOHM list-index deserialization (DoS)CVE-2026-17574 · Fixed within SLA · CVE-2026-17574: HDF5 NULL pointer dereference on reading attribute with invalid variable-length datatype fieldCVE-2026-76036 · Fixed within SLA · CVE-2026-76036: Chrome Android Dawn buffer overflow enables remote code execution outside sandbox pre-151.0.7922.169 via crafted HTMLCVE-2026-14672 · Open · CVE-2026-14672: PostgreSQL 16–18 SCRAM iteration-count leak allows unauthenticated user enumeration when non-default scram_iterationsCVE-2026-6470 · Open · CVE-2026-6470: Privilege check bypass in PostgreSQL DDL enables DoS via type dependencies (pre-18.5/17.11/16.15/15.19/14.24)CVE-2026-14678 · Open · CVE-2026-14678: PostgreSQL pg_trgm picksplit buffer over-read leaks memory via split choices; pre-18.5/17.11/16.15/15.19/14.24CVE-2026-0864 · Open · CVE-2026-0864: Attacker-controlled CR in configparser multiline values injects unexpected configuration keys and valuesCVE-2026-18024 · Open · CVE-2026-18024: PostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24CVE-2026-14663 · Open · CVE-2026-14663: PostgreSQL pgcrypto disabled-cipher bug allows cleartext recovery; wrong-key decrypt bypasses MDCCVE-2026-14666 · Open · CVE-2026-14666: PostgreSQL: Stale RLS from role/ownership changes enables unauthorized reads/writes via plan reuseCVE-2026-76039 · Fixed within SLA · CVE-2026-76039: Chrome Android Core reference resolution bug leaks sensitive data via crafted HTML pre-151.0.7922.169CVE-2026-76041 · Fixed within SLA · CVE-2026-76041: High-severity Skia info leak in Chrome <151.0.7922.169 enables origin policy bypass via crafted HTML pageCVE-2026-17572 · Fixed within SLA · CVE-2026-17572: Heap overflow in HDF5 SOHM list-index deserialization triggers DoS with crafted file through 2.1.1CVE-2026-76033 · Fixed within SLA · CVE-2026-76033: Chrome <151.0.7922.169 CORS flaw enables compromised renderer to bypass site isolation via crafted HTMLCVE-2026-17573 · Fixed within SLA · CVE-2026-17573: Double free vulnerability in HDF5 h5repack triggered by crafted file oversized chunk sizeCVE-2026-17574 · Fixed within SLA · CVE-2026-17574: NULL pointer dereference when reading crafted HDF5 attribute with invalid variable-length datatypeCVE-2026-18408 · Open · CVE-2026-18408: pg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict; affects pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14664 · Open · CVE-2026-14664: PostgreSQL regexp heap overflow enables arbitrary code execution via invalid encoding input affects pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14679 · Open · CVE-2026-14679: PostgreSQL stack buffer overflow in OUT parameter name matching with limited 0/1-byte writesCVE-2026-15742 · Open · CVE-2026-15742: Integer wraparound RCE in PostgreSQL fuzzystrmatch via levenshtein/less_equal before 18.5/17.11/16.15/15.19/14.24CVE-2026-19385 · Open · CVE-2026-19385: PostgreSQL pg_dump heap buffer overflow in transform lists enables RCE; versions <18.5/17.11/16.15/15.19/14.24CVE-2026-6464 · Open · CVE-2026-6464: psql COPY FROM STDIN pre-input error executes data lines as commandsCVE-2026-14677 · Open · CVE-2026-14677: PostgreSQL 32-bit pltcl/plperl integer wraparound causes undersized allocation, OOB write, RCECVE-2026-14680 · Open · CVE-2026-14680: PostgreSQL 'internal' type confusion lets any user execute arbitrary code; affects <18.5,17.11,16.15,15.19,14.24CVE-2026-14669 · Open · CVE-2026-14669: Heap buffer overflow in PostgreSQL to_char(timestamptz) via long timezone abbreviation enables RCECVE-2026-14671 · Open · CVE-2026-14671: PostgreSQL refint type confusion allows arbitrary OS code execution; no CVE; affects pre-18.5/17.11/16.15/15.19/14.24CVE-2026-14670 · Open · CVE-2026-14670: PostgreSQL plperl tied-hash return heap overflow enables RCE as database OS userCVE-2026-14662 · Open · CVE-2026-14662: PostgreSQL tsvector/tsquery integer wraparound allows OOB write, potential RCE by unprivileged usersCVE-2026-16239 · Open · CVE-2026-16239: Type confusion in PostgreSQL portal/cursor lifecycle enables OS-level code execution; pre-18.5, 17.11, 16.15, 15.19, 14.24CVE-2026-6471 · Open · CVE-2026-6471: PostgreSQL logical decoding auth flaw lets REPLICATION users execute arbitrary code as server OS accountCVE-2026-14668 · Open · CVE-2026-14668: PostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory-derived values via non-ctid inputCVE-2026-16238 · Open · CVE-2026-16238: PostgreSQL 18<18.5 pg_restore_attribute_stats type confusion allows RCE as database OS userCVE-2026-15741 · Open · CVE-2026-15741: SQL injection in PostgreSQL EXTRACT() deparse allows superuser execution via hostile object definitionsCVE-2026-76040 · Fixed within SLA · CVE-2026-76040: Chrome Mac <151.0.7922.169 Browser use-after-free enables remote sandbox-escape RCE via crafted HTMLCVE-2026-76034 · Fixed within SLA · CVE-2026-76034: Buffer overflow in Chrome WebGL before 151.0.7922.169 enables RCE outside sandbox via crafted HTML page.CVE-2026-76038 · Fixed within SLA · CVE-2026-76038: Google Chrome <151.0.7922.169 V8 type confusion allows sandboxed RCE via crafted HTMLCVE-2026-76045 · Fixed within SLA · CVE-2026-76045: WebGL use-after-free in Chrome <151.0.7922.169 enables sandbox RCE via crafted HTMLCVE-2026-76037 · Fixed within SLA · CVE-2026-76037: Chrome CredentialProvider link-following on Windows allows local sandbox escape pre-151.0.7922.169CVE-2026-76047 · Fixed within SLA · CVE-2026-76047: V8 type confusion enables remote code execution within Chrome sandbox pre-151.0.7922.169CVE-2026-64117 · Fixed within SLA · CVE-2026-64117: Use-after-free from skb->cb reuse in mac80211 mesh fast-RX rate handlingCVE-2026-76044 · Fixed within SLA · CVE-2026-76044: Chrome <151.0.7922.169 USB race enables code execution outside sandbox via crafted HTMLCVE-2026-76046 · Fixed within SLA · CVE-2026-76046: ANGLE buffer overflow in Chrome Android <151.0.7922.169 enables sandbox escape remote code executionCVE-2026-76043 · Fixed within SLA · CVE-2026-76043: V8 miscalculation enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.169CVE-2026-14673 · Open · CVE-2026-14673: PostgreSQL amcheck EXECUTE privilege allows arbitrary function execution as expression index ownersCVE-2026-6469 · Open · CVE-2026-6469: PostgreSQL ALTER TABLE ALTER TYPE misassigns stats ownership, enabling unauthorized DROP/ALTER STATISTICSCVE-2026-16241 · Open · CVE-2026-16241: PostgreSQL ECPG integer underflow enables DoS via bytea without prefix; client memory overwriteCVE-2026-76042 · Fixed within SLA · CVE-2026-76042: Chrome pre-151.0.7922.169 GPU uninitialized resource leaks memory outside sandbox via crafted HTMLCVE-2026-76036 · Fixed within SLA · CVE-2026-76036: Critical Dawn buffer overflow allows remote code execution outside sandbox on Android Chrome <151.0.7922.169CVE-2026-64123 · Fixed within SLA · CVE-2026-64123: HSR RTM_DELLINK frees nodes without RCU, causing generic-netlink reader use-after-freeCVE-2026-64283 · Fixed within SLA · CVE-2026-64283: KVM guest_memfd uses signed offset/size; sum overflow bypasses memslot binding file-size checkCVE-2026-64146 · Fixed within SLA · CVE-2026-64146: ERoFS inode xattr init: metabuf/folio ref leak on error paths after erofs_read_metabufCVE-2026-64159 · Fixed within SLA · CVE-2026-64159: netfs_release_folio zero_point misupdate when i_size > remote_i_size causes short readsCVE-2026-64154 · Fixed within SLA · CVE-2026-64154: Reference leak in drm/msm/adreno a6xx_gpu_init from of_parse_phandle early-return pathsCVE-2026-64160 · Fixed within SLA · CVE-2026-64160: Linux kernel netfs potential tearing in remote_i_size/zero_point risking i_size_seqcount corruptionCVE-2026-19556 · Fixed within SLA · CVE-2026-19556: Use-after-free in Chrome V8 pre-151.0.7922.137 allows sandboxed remote code executionCVE-2026-19559 · Fixed within SLA · CVE-2026-19559: Chrome <151.0.7922.137 HTML use-after-free enables sandboxed RCE via crafted pageCVE-2026-19557 · Fixed within SLA · CVE-2026-19557: High-severity TabStrip use-after-free enables sandbox escape via HTML on Chrome Mac <151.0.7922.137CVE-2026-19560 · Fixed within SLA · CVE-2026-19560: Chrome <151.0.7922.137 Blink use-after-free allows sandboxed remote code execution via crafted HTMLCVE-2026-19558 · Fixed within SLA · CVE-2026-19558: Use-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed arbitrary code executionCVE-2026-19556 · Fixed within SLA · CVE-2026-19556: High-severity V8 use-after-free in Chrome <151.0.7922.137 enables sandboxed RCE via crafted HTMLCVE-2026-19557 · Fixed within SLA · CVE-2026-19557: Google Chrome Mac TabStrip use-after-free enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.137)CVE-2026-19559 · Fixed within SLA · CVE-2026-19559: Chrome <151.0.7922.137 HTML use-after-free enables sandboxed remote code execution via crafted pageCVE-2026-19558 · Fixed within SLA · CVE-2026-19558: Use-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed code execution via malicious extensionCVE-2026-19560 · Fixed within SLA · CVE-2026-19560: Blink use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.137CVE-2026-64283 · Fixed within SLA · CVE-2026-64283: KVM guest_memfd memslot offset+size signed overflow bypasses i_size bound checkCVE-2026-64123 · Fixed within SLA · CVE-2026-64123: HSR RCU readers race with RTM_DELLINK node frees, causing use-after-freeCVE-2026-64160 · Fixed within SLA · CVE-2026-64160: Linux kernel netfs potential tearing and i_size_seqcount corruption updating remote_i_size/zero_point without i_lockCVE-2026-64160 · Fixed within SLA · CVE-2026-64160: Netfs: Tearing in remote_i_size/zero_point may corrupt i_size_seqcountCVE-2026-64146 · Fixed within SLA · CVE-2026-64146: EROFS xattr inode init leaks folio reference when metabuf not dropped on errorsCVE-2026-64154 · Fixed within SLA · CVE-2026-64154: drm/msm/adreno: missing of_node_put causes node reference leak in a6xx_gpu_init()CVE-2026-64159 · Fixed within SLA · CVE-2026-64159: Netfs zero_point misupdated with i_size > remote_i_size, causing short reads on EOFCVE-2026-73433 · Fixed within SLA · CVE-2026-73433: Heap OOB read/write and leak via FUJIFILM strd underflow in GStreamer avidemuxCVE-2026-64146 · Fixed within SLA · CVE-2026-64146: ERoFS inode xattr init error paths leak metabuf, causing folio reference leakCVE-2026-73434 · Fixed within SLA · CVE-2026-73434: GStreamer gst-plugins-good avidemux vprp parser OOB read via crafted AVI causes DoSCVE-2026-64154 · Fixed within SLA · CVE-2026-64154: Reference leak in a6xx_gpu_init() due to missed of_node_put on early error pathsCVE-2026-64159 · Fixed within SLA · CVE-2026-64159: netfs_release_folio zero_point update uses i_size not remote_i_size, causing EOF short readsCVE-2026-64283 · Fixed within SLA · CVE-2026-64283: KVM guest_memfd offset+size treated signed, letting negative sum bypass file size checkCVE-2026-64255 · Fixed within SLA · CVE-2026-64255: Linux iwlwifi BA handlers use ffs on zero sta_mask, causing out-of-bounds accessCVE-2026-19147 · Fixed within SLA · CVE-2026-19147: High severity use-after-free in Aura allows sandbox escape on Chrome Linux <151.0.7922.109CVE-2026-19142 · Fixed within SLA · CVE-2026-19142: Use-after-free in Chrome Views pre-151.0.7922.109 allows remote heap corruption via crafted HTMLCVE-2026-19144 · Fixed within SLA · CVE-2026-19144: Use-after-free in Chrome HTML before 151.0.7922.109 enables remote heap corruptionCVE-2026-64210 · Fixed within SLA · CVE-2026-64210: mlx5e XSK race: unlocked ICOSQ IRQ trigger during NAPI affinity change causes CQE errorsCVE-2026-19142 · Fixed within SLA · CVE-2026-19142: Chrome Views use-after-free before 151.0.7922.109 allows heap corruption via crafted HTML and gesturesCVE-2026-64210 · Fixed within SLA · CVE-2026-64210: mlx5e XSK: Unprotected ICOSQ IRQ trigger races with NAPI and CPU affinity changesCVE-2026-19147 · Fixed within SLA · CVE-2026-19147: Aura use-after-free in Chrome Linux pre-151.0.7922.109 enables sandbox escape via HTML from compromised rendererCVE-2026-19144 · Fixed within SLA · CVE-2026-19144: Use-after-free in Chrome HTML enables remote heap corruption before 151.0.7922.109CVE-2026-19142 · Fixed within SLA · CVE-2026-19142: Chrome pre-151.0.7922.109 Views UAF enables remote heap corruption via crafted HTML page, requires UI gesturesCVE-2026-64210 · Fixed within SLA · CVE-2026-64210: mlx5e XSK: Unprotected ICOSQ IRQ triggering races with NAPI, causing ICOSQ CQE errorsCVE-2026-19147 · Fixed within SLA · CVE-2026-19147: Use-after-free in Aura allows sandbox escape after renderer compromise in Chrome Linux <151.0.7922.109CVE-2026-19144 · Fixed within SLA · CVE-2026-19144: Chrome pre-151.0.7922.109 HTML use-after-free allows remote heap corruption via crafted pageCVE-2026-64212 · Fixed within SLA · CVE-2026-64212: iwlwifi mld: Potential NULL pointer dereference in iwl_mld_remove_link storing link->fw_idCVE-2026-64213 · Fixed within SLA · CVE-2026-64213: lm90_alert lacks hwmon_lock; race with sysfs re-enables alert, causing interrupt stormCVE-2026-64190 · Fixed within SLA · CVE-2026-64190: Mode change race memsetting team->ops leads to NULL deref in team_xmitCVE-2026-64216 · Fixed within SLA · CVE-2026-64216: UAF in netfs_unlock_abandoned_read_pages and netfs_unlock_read_folio after request progress clearedCVE-2026-19158 · Fixed within SLA · CVE-2026-19158: Chrome Views use-after-free on Windows <151.0.7922.109 allows heap corruption via HTML and UI gesturesCVE-2026-19177 · Fixed within SLA · CVE-2026-19177: Chrome UI input validation flaw enables sandbox escape from renderer via crafted HTML pre-151.0.7922.109CVE-2026-19159 · Fixed within SLA · CVE-2026-19159: Chrome Views use-after-free enables remote heap corruption via crafted HTML requiring user gestures before 151.0.7922.109CVE-2026-19154 · Fixed within SLA · CVE-2026-19154: Skia use-after-free in Chrome for Android pre-151.0.7922.109 enables sandbox escape via crafted HTMLCVE-2026-19148 · Fixed within SLA · CVE-2026-19148: Chrome Linux GPU out-of-bounds write allows sandbox escape via crafted HTML pre-151.0.7922.109 High severityCVE-2026-19150 · Fixed within SLA · CVE-2026-19150: V8 inappropriate implementation allows remote sandboxed RCE via crafted HTML in Chrome <151.0.7922.109CVE-2026-66036 · Fixed within SLA · CVE-2026-66036: FFmpeg <=8.1.2 vf_hqdn3d heap out-of-bounds write with -reinit_filter 0 and growing framesCVE-2026-19141 · Fixed within SLA · CVE-2026-19141: Chrome Android <151.0.7922.109 use-after-free in Resources enables sandbox escape via crafted HTMLCVE-2026-19139 · Fixed within SLA · CVE-2026-19139: Race in Chrome Windows CredentialProvider pre-151.0.7922.109 enables local privilege escalation via malicious fileCVE-2026-19153 · Fixed within SLA · CVE-2026-19153: Google Chrome Workers input validation flaw allows site isolation bypass before 151.0.7922.109CVE-2026-19174 · Fixed within SLA · CVE-2026-19174: V8 integer overflow enables sandboxed arbitrary code execution in Chrome <151.0.7922.109 via crafted HTMLCVE-2026-19176 · Fixed within SLA · CVE-2026-19176: Skia use-after-free in Chrome <151.0.7922.109 enables sandboxed RCE via crafted HTMLCVE-2026-19173 · Fixed within SLA · CVE-2026-19173: Skia out-of-bounds write enables sandbox escape from compromised renderer in Chrome <151.0.7922.109CVE-2026-19152 · Fixed within SLA · CVE-2026-19152: Chrome <151.0.7922.109 Navigation policy flaw allows renderer sandbox escape via crafted HTMLCVE-2026-19137 · Fixed within SLA · CVE-2026-19137: Critical Chrome Android WebGL use-after-free enables sandbox escape after renderer compromise (pre-151.0.7922.109)CVE-2026-65706 · Fixed within SLA · CVE-2026-65706: FFmpeg 3.0–8.1.2 vf_swaprect OOB write on NV12 odd-width frames causes heap corruptionCVE-2026-19145 · Fixed within SLA · CVE-2026-19145: Chrome Translate use-after-free enables sandbox RCE via crafted HTML (pre-151.0.7922.109)CVE-2026-19138 · Fixed within SLA · CVE-2026-19138: Chrome pre-151.0.7922.109 CrashReporting heap overflow allows sandbox escape from compromised rendererCVE-2026-19156 · Fixed within SLA · CVE-2026-19156: Chrome Base heap buffer overflow pre-151.0.7922.109 via crafted malicious extensionCVE-2026-19169 · Fixed within SLA · CVE-2026-19169: Chrome pre-151.0.7922.109 Contextual Tasks input validation flaw allows remote privilege escalation via crafted HTMLCVE-2026-19143 · Fixed within SLA · CVE-2026-19143: Android Chrome <151 WebAPKs: input validation flaw enables local sandbox escape via malicious fileCVE-2026-19162 · Fixed within SLA · CVE-2026-19162: Chrome V8 out-of-bounds write before 151.0.7922.109 enables sandboxed RCE via crafted HTMLCVE-2026-19140 · Fixed within SLA · CVE-2026-19140: Chrome <151.0.7922.109 GPU use-after-free enables sandbox escape via crafted HTMLCVE-2026-65703 · Fixed within SLA · CVE-2026-65703: FFmpeg 2.7–8.1.2 TDSC decoder OOB write on frame dimension changes enables RCECVE-2026-19168 · Fixed within SLA · CVE-2026-19168: Chrome V8 sandbox arbitrary code execution via crafted HTML pre-151.0.7922.109CVE-2026-19155 · Fixed within SLA · CVE-2026-19155: Use-after-free in Chrome Payments enables sandbox escape via crafted HTML (pre-151.0.7922.109)CVE-2026-19165 · Fixed within SLA · CVE-2026-19165: Use-after-free in Chrome Extensions pre-151.0.7922.109 enables sandboxed arbitrary code executionCVE-2026-66037 · Fixed within SLA · CVE-2026-66037: FFmpeg ≤8.1.2 IAMF demuxer OOM via crafted count_label during format probingCVE-2026-19163 · Fixed within SLA · CVE-2026-19163: Chrome Windows pre-151.0.7922.109 Media use-after-free enables sandbox escape via crafted HTMLCVE-2026-65705 · Fixed within SLA · CVE-2026-65705: FFmpeg 3.4-8.1.2 vf_floodfill OOB write on dynamic frames with -reinit_filter 0CVE-2026-19151 · Fixed within SLA · CVE-2026-19151: Chrome V8 use-after-free enables sandboxed RCE via crafted HTML pre-151.0.7922.109CVE-2026-66040 · Fixed within SLA · CVE-2026-66040: Heap OOB write in FFmpeg PNG/APNG encoders <=8.1.2 via malicious eXIf chunk, RCECVE-2026-65704 · Fixed within SLA · CVE-2026-65704: FFmpeg <=8.1.2 OOB write via crafted ffconcat (-safe 0) in TY demuxerCVE-2026-66038 · Fixed within SLA · CVE-2026-66038: FFmpeg <=8.1.2 LCL/ZLIB decoder info leak via short zlib decompressionCVE-2026-19172 · Fixed within SLA · CVE-2026-19172: Use-after-free in Chrome Views enables sandbox escape from compromised renderer via crafted HTMLCVE-2026-66039 · Fixed within SLA · CVE-2026-66039: FFmpeg ≤8.1.2 MACE6 signed integer overflow leads to heap OOB write via CAFCVE-2026-66041 · Fixed within SLA · CVE-2026-66041: FFmpeg 7.0–8.1.2 vf_quirc heap OOB write via mismatched PGS/SUP frame dimensionsCVE-2026-19146 · Fixed within SLA · CVE-2026-19146: Chrome Android <151.0.7922.109 GPU uninitialized use leaks memory via crafted HTMLCVE-2026-43174 · Fixed within SLA · CVE-2026-43174: io_uring zcrx post-open error handling prematurely frees ctx; page pools may persistCVE-2026-43174 · Fixed within SLA · CVE-2026-43174CVE-2026-19157 · Fixed within SLA · CVE-2026-19157: ANGLE out-of-bounds write in Chrome Android pre-151.0.7922.109 enables remote sandbox escapeCVE-2026-19171 · Fixed within SLA · CVE-2026-19171: Use-after-free in Chrome Media on Windows pre-151.0.7922.109 enables remote sandbox escape via crafted HTMLCVE-2026-19166 · Fixed within SLA · CVE-2026-19166: Google Chrome WebAuthn use-after-free allows remote sandbox escape via crafted HTML (pre-151.0.7922.109)CVE-2026-19149 · Fixed within SLA · CVE-2026-19149: Critical use-after-free in Google Chrome Aura on Linux <151.0.7922.109 enables remote sandbox escapeCVE-2026-19175 · Fixed within SLA · CVE-2026-19175: Use-after-free in Chrome Payments allows remote sandbox escape via crafted HTML pre-151.0.7922.109CVE-2026-19170 · Fixed within SLA · CVE-2026-19170: Critical WebGL use-after-free allows remote sandbox escape in Android Chrome <151.0.7922.109CVE-2026-19164 · Fixed within SLA · CVE-2026-19164: Insufficient Chrome Codecs input validation enables remote sandbox escape via crafted HTML (pre-151.0.7922.109)CVE-2026-19167 · Fixed within SLA · CVE-2026-19167: Chrome GPU integer overflow allowed cross-origin data leak via crafted page (pre-151.0.7922.109)CVE-2026-19161 · Fixed within SLA · CVE-2026-19161: Skia uninitialized use in Chrome <151.0.7922.109 enables cross-origin data leak after renderer compromiseCVE-2026-19160 · Fixed within SLA · CVE-2026-19160: Uninitialized use in Skia allows cross-origin data leak in Chrome before 151.0.7922.109 after renderer compromiseCVE-2026-19159 · Fixed within SLA · CVE-2026-19159: Use-after-free in Google Chrome Views pre-151.0.7922.109 allows heap corruption via crafted HTML, user gesturesCVE-2026-19172 · Fixed within SLA · CVE-2026-19172: Critical use-after-free in Chrome Views enables sandbox escape from compromised renderer via crafted HTML.CVE-2026-17653 · Fixed within SLA · CVE-2026-17653: Critical Skia use-after-free enables sandbox escape after renderer compromise via crafted HTML, Chrome <151.0.7922.72CVE-2026-19150 · Fixed within SLA · CVE-2026-19150: Google Chrome V8 pre-151.0.7922.109 allows remote sandboxed RCE via crafted HTML (High severity)CVE-2026-19173 · Fixed within SLA · CVE-2026-19173: Out-of-bounds write in Chrome Skia pre-151.0.7922.109 enables sandbox escape via crafted HTMLCVE-2026-19155 · Fixed within SLA · CVE-2026-19155: Use-after-free in Google Chrome Payments enables sandbox escape via crafted HTML from compromised renderer pre-151.0.7922.109CVE-2026-19168 · Fixed within SLA · CVE-2026-19168: Chrome V8 <151.0.7922.109 allows remote sandboxed RCE via crafted HTMLCVE-2026-19153 · Fixed within SLA · CVE-2026-19153: Chrome Workers input validation flaw enables site isolation bypass after renderer compromiseCVE-2026-19177 · Fixed within SLA · CVE-2026-19177: Insufficient UI input validation in Chrome <151.0.7922.109 enables renderer sandbox escape via crafted HTML pageCVE-2026-19162 · Fixed within SLA · CVE-2026-19162: Chrome V8 out-of-bounds write allows sandboxed RCE via crafted HTML pre-151.0.7922.109CVE-2026-19165 · Fixed within SLA · CVE-2026-19165: Chrome Extensions UAF pre-151.0.7922.109 enables sandbox arbitrary code via malicious extensionCVE-2026-19137 · Fixed within SLA · CVE-2026-19137: Critical WebGL use-after-free enables sandbox escape in Android Chrome <151.0.7922.109CVE-2026-19163 · Fixed within SLA · CVE-2026-19163: Use-after-free in Chrome Media on Windows pre-151.0.7922.109 enables renderer sandbox escape via crafted HTMLCVE-2026-17654 · Fixed within SLA · CVE-2026-17654: Race condition in Chrome Updater on Mac enabled local OS-level privilege escalation pre-151.0.7922.72CVE-2026-19158 · Fixed within SLA · CVE-2026-19158: Chrome Windows Views use-after-free pre-151.0.7922.109 allows remote heap corruption exploit via crafted HTML and gesturesCVE-2026-17660 · Fixed within SLA · CVE-2026-17660: Chrome <151.0.7922.72 Network input validation enables renderer sandbox escape via crafted HTMLCVE-2026-19174 · Fixed within SLA · CVE-2026-19174: V8 integer overflow enables sandboxed remote code execution via crafted HTML in Chrome <151.0.7922.109CVE-2026-66041 · Fixed within SLA · CVE-2026-66041: FFmpeg vf_quirc heap out-of-bounds write via crafted PGS/SUP with mismatched frame dimensionsCVE-2026-65704 · Fixed within SLA · CVE-2026-65704: FFmpeg <=8.1.2 OOB write processing ffconcat -safe 0 via TY demuxerCVE-2026-19176 · Fixed within SLA · CVE-2026-19176: Skia use-after-free in Chrome <151.0.7922.109 enables renderer RCE via crafted HTMLCVE-2026-19152 · Fixed within SLA · CVE-2026-19152: Chrome pre-151.0.7922.109 navigation policy flaw enables sandbox escape from compromised rendererCVE-2026-19169 · Fixed within SLA · CVE-2026-19169: Insufficient validation in Chrome Contextual Tasks allows remote privilege escalation via crafted HTMLCVE-2026-19139 · Fixed within SLA · CVE-2026-19139: Google Chrome Windows CredentialProvider race enables local privilege escalation via malicious file pre-151.0.7922.109CVE-2026-17650 · Fixed within SLA · CVE-2026-17650: Google Chrome Compositing use after free enables sandbox escape from compromised renderer before 151.0.7922.72CVE-2026-19140 · Fixed within SLA · CVE-2026-19140: Pre-151.0.7922.109 Chrome GPU use-after-free enables sandbox escape via crafted HTML from compromised rendererCVE-2026-19143 · Fixed within SLA · CVE-2026-19143: Chrome Android WebAPKs insufficient input validation enables local sandbox escape via malicious fileCVE-2026-17658 · Fixed within SLA · CVE-2026-17658: High-severity V8 use-after-free allows remote sandboxed code execution via crafted HTML in Chrome <151.0.7922.72CVE-2026-19154 · Fixed within SLA · CVE-2026-19154: Critical Skia use-after-free enables renderer sandbox escape in Chrome Android <151.0.7922.109CVE-2026-66040 · Fixed within SLA · CVE-2026-66040: FFmpeg ≤8.1.2 PNG/APNG encoder eXIf handling causes heap OOB write, crash/RCECVE-2026-65703 · Fixed within SLA · CVE-2026-65703: FFmpeg 2.7–8.1.2 TDSC decoder out-of-bounds write via crafted AVI frame dimension changesCVE-2026-19151 · Fixed within SLA · CVE-2026-19151: V8 use-after-free enables sandboxed RCE in Chrome <151.0.7922.109 via crafted HTMLCVE-2026-66036 · Fixed within SLA · CVE-2026-66036: FFmpeg <=8.1.2 vf_hqdn3d heap OOB write on resolution increase with -reinit_filter 0 disabledCVE-2026-19156 · Fixed within SLA · CVE-2026-19156: High severity Chrome Base heap buffer overflow pre-151.0.7922.109 via malicious extensionCVE-2026-19141 · Fixed within SLA · CVE-2026-19141: Use-after-free in Chrome Android Resources pre-151.0.7922.109 enables sandbox escape via crafted HTMLCVE-2026-19145 · Fixed within SLA · CVE-2026-19145: Google Chrome Translate use-after-free allows sandbox RCE via crafted HTML pre-151.0.7922.109CVE-2026-19148 · Fixed within SLA · CVE-2026-19148: Chrome Linux GPU OOB write enables sandbox escape via crafted HTML pre-151.0.7922.109CVE-2026-17657 · Fixed within SLA · CVE-2026-17657: Chrome Navigation use-after-free pre-151.0.7922.72 allows sandbox escape via crafted HTMLCVE-2026-66039 · Fixed within SLA · CVE-2026-66039: FFmpeg ≤8.1.2 MACE6 CAF signed integer overflow causes heap OOB write, RCE riskCVE-2026-19138 · Fixed within SLA · CVE-2026-19138: Pre-151.0.7922.109 Chrome CrashReporting heap overflow enables sandbox escape via crafted HTMLCVE-2026-66037 · Fixed within SLA · CVE-2026-66037: FFmpeg ≤8.1.2 IAMF demuxer OOM via crafted count_label causing massive allocation during probingCVE-2026-65706 · Fixed within SLA · CVE-2026-65706: FFmpeg 3.0–8.1.2 vf_swaprect OOB write with odd-width NV12 frames causes heap corruptionCVE-2026-65705 · Fixed within SLA · CVE-2026-65705: FFmpeg 3.4–8.1.2 OOB write in vf_floodfill with -reinit_filter 0CVE-2026-66038 · Fixed within SLA · CVE-2026-66038: FFmpeg ≤8.1.2 LCL/ZLIB decoder information disclosure: short inflate leaks uninitialized heapCVE-2026-19177 · Fixed within SLA · CVE-2026-19177: Google Chrome UI input validation flaw enables sandbox escape post-renderer compromise, pre-151.0.7922.109CVE-2026-19148 · Fixed within SLA · CVE-2026-19148: Chrome Linux GPU OOB write allows sandbox escape via crafted HTML (pre-151.0.7922.109)CVE-2026-19163 · Fixed within SLA · CVE-2026-19163: Google Chrome Windows Media use-after-free enables sandbox escape via crafted HTML (pre-151.0.7922.109)CVE-2026-19172 · Fixed within SLA · CVE-2026-19172: Critical Chrome Views use-after-free enables sandbox escape via crafted HTML (pre-151.0.7922.109)CVE-2026-19173 · Fixed within SLA · CVE-2026-19173: Skia OOB write in Chrome <151.0.7922.109 enables sandbox escape via crafted HTMLCVE-2026-19176 · Fixed within SLA · CVE-2026-19176: Skia use-after-free in Chrome <151.0.7922.109 allows sandboxed RCE via crafted HTMLCVE-2026-19137 · Fixed within SLA · CVE-2026-19137: WebGL use-after-free allows sandbox escape post-renderer-compromise in Chrome Android <151.0.7922.109CVE-2026-19156 · Fixed within SLA · CVE-2026-19156: High-severity Google Chrome Base heap buffer overflow pre-151.0.7922.109 via malicious extensionCVE-2026-19168 · Fixed within SLA · CVE-2026-19168: V8 vulnerability allows sandbox RCE via crafted HTML in Chrome <151.0.7922.109CVE-2026-19140 · Fixed within SLA · CVE-2026-19140: Chrome GPU use-after-free <151.0.7922.109 allows sandbox escape from compromised renderer via HTMLCVE-2026-19143 · Fixed within SLA · CVE-2026-19143: Chrome Android WebAPK input validation flaw enables local sandbox escape via malicious fileCVE-2026-19155 · Fixed within SLA · CVE-2026-19155: Use-after-free in Chrome Payments (<151.0.7922.109) enables sandbox escape from compromised rendererCVE-2026-19145 · Fixed within SLA · CVE-2026-19145: Chrome <151.0.7922.109 Translate use-after-free allows sandboxed RCE via crafted HTMLCVE-2026-19169 · Fixed within SLA · CVE-2026-19169: Chrome <151.0.7922.109 Contextual Tasks input validation flaw allows remote privilege escalation via crafted HTMLCVE-2026-19141 · Fixed within SLA · CVE-2026-19141: Chrome Android pre-151.0.7922.109 Resources use-after-free enables sandbox escape from compromised renderer via crafted HTML pageCVE-2026-19153 · Fixed within SLA · CVE-2026-19153: Pre-151.0.7922.109 Chrome Workers input validation flaw enabled site isolation bypass via crafted HTMLCVE-2026-19139 · Fixed within SLA · CVE-2026-19139: Windows Chrome CredentialProvider race allows local privilege escalation via malicious file pre-151.0.7922.109CVE-2026-19159 · Fixed within SLA · CVE-2026-19159: Use-after-free in Chrome Views before 151.0.7922.109 enables remote heap corruption via crafted HTML, UI gesturesCVE-2026-19174 · Fixed within SLA · CVE-2026-19174: Chrome V8 integer overflow allows sandbox RCE via crafted HTML pre-151.0.7922.109CVE-2026-65706 · Fixed within SLA · CVE-2026-65706: FFmpeg 3.0-8.1.2 vf_swaprect OOB write on odd-width NV12 frames causing heap corruptionCVE-2026-19165 · Fixed within SLA · CVE-2026-19165: Use-after-free in Chrome Extensions allows sandboxed code execution via crafted extension pre-151.0.7922.109CVE-2026-19162 · Fixed within SLA · CVE-2026-19162: Out-of-bounds write in Chrome V8 pre-151.0.7922.109 allows sandbox RCE via HTMLCVE-2026-19152 · Fixed within SLA · CVE-2026-19152: Insufficient navigation policy in Chrome <151.0.7922.109 allows renderer sandbox escape via crafted HTMLCVE-2026-19154 · Fixed within SLA · CVE-2026-19154: Critical use-after-free in Skia enables sandbox escape in Chrome Android <151.0.7922.109 via HTMLCVE-2026-19151 · Fixed within SLA · CVE-2026-19151: Chrome V8 use-after-free enables sandboxed RCE via crafted HTML, high severity (pre-151.0.7922.109)CVE-2026-19158 · Fixed within SLA · CVE-2026-19158: Windows Chrome pre-151.0.7922.109 Views use-after-free allows heap corruption via crafted HTMLCVE-2026-65705 · Fixed within SLA · CVE-2026-65705: FFmpeg 3.4-8.1.2 vf_floodfill OOB write with -reinit_filter 0, heap corruptionCVE-2026-19150 · Fixed within SLA · CVE-2026-19150: V8 in Chrome <151.0.7922.109 allows sandboxed RCE via crafted HTML pageCVE-2026-66039 · Fixed within SLA · CVE-2026-66039: FFmpeg <=8.1.2 MACE6 CAF bytes_per_packet integer overflow causes heap OOB write, RCECVE-2026-65703 · Fixed within SLA · CVE-2026-65703: FFmpeg 2.7–8.1.2 TDSC decoder OOB write causing heap corruption and potential RCECVE-2026-19138 · Fixed within SLA · CVE-2026-19138: Chrome CrashReporting heap overflow enables sandbox escape with renderer compromise (pre-151.0.7922.109)CVE-2026-66038 · Fixed within SLA · CVE-2026-66038: FFmpeg up to 8.1.2 LCL/ZLIB decoder leaks uninitialized heap; short inflate enables ASLR bypassCVE-2026-66036 · Fixed within SLA · CVE-2026-66036: FFmpeg ≤8.1.2 vf_hqdn3d heap OOB write when -reinit_filter 0 and resolution increasesCVE-2026-66037 · Fixed within SLA · CVE-2026-66037: FFmpeg ≤8.1.2 IAMF demuxer uncontrolled allocation from 17-byte input via count_labelCVE-2026-66040 · Fixed within SLA · CVE-2026-66040: Heap out-of-bounds write in FFmpeg PNG/APNG encoder eXIf handling (≤8.1.2)CVE-2026-66041 · Fixed within SLA · CVE-2026-66041: FFmpeg 7.0–8.1.2 vf_quirc heap OOB write via crafted PGS/SUP subtitles mismatched dimensionsCVE-2026-65704 · Fixed within SLA · CVE-2026-65704: FFmpeg <=8.1.2 heap corruption via TY demuxer OOB write using crafted ffconcat with -safe 0CVE-2026-4046 · Fixed within SLA · CVE-2026-4046CVE-2026-5928 · Fixed within SLA · CVE-2026-5928CVE-2026-19164 · Fixed within SLA · CVE-2026-19164: Chrome pre-151.0.7922.109 Codecs validation flaw allows remote sandbox escape via crafted HTML, high severityCVE-2026-19166 · Fixed within SLA · CVE-2026-19166: High-severity WebAuthn use-after-free in Google Chrome <151.0.7922.109 enables remote sandbox escape via crafted HTML pageCVE-2026-19175 · Fixed within SLA · CVE-2026-19175: Use-after-free in Google Chrome Payments enables sandbox escape via crafted HTML (pre-151.0.7922.109)CVE-2026-19170 · Fixed within SLA · CVE-2026-19170: WebGL use-after-free in Chrome Android enables remote sandbox escape pre-151.0.7922.109CVE-2026-17655 · Fixed within SLA · CVE-2026-17655: ANGLE input validation flaw in Chrome <151.0.7922.72 enables remote sandbox escape via crafted HTMLCVE-2026-19171 · Fixed within SLA · CVE-2026-19171: Use-after-free in Chrome Media on Windows enables remote sandbox escape (pre-151.0.7922.109)CVE-2026-17656 · Fixed within SLA · CVE-2026-17656: Critical Chrome Ozone use-after-free enables remote sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17652 · Fixed within SLA · CVE-2026-17652: Critical use-after-free in Chrome Views enables sandbox escape from compromised renderer prior to 151.0.7922.72CVE-2026-19157 · Fixed within SLA · CVE-2026-19157: Critical OOB write in ANGLE on Chrome Android before 151.0.7922.109 enabling sandbox escape via HTMLCVE-2026-19149 · Fixed within SLA · CVE-2026-19149: Aura UAF enables remote sandbox escape via crafted HTML in Chrome Linux <151.0.7922.109CVE-2026-19170 · Fixed within SLA · CVE-2026-19170: Use-after-free in Chrome Android WebGL enables remote sandbox escape (pre-151.0.7922.109)CVE-2026-19157 · Fixed within SLA · CVE-2026-19157: Critical ANGLE out-of-bounds write enables sandbox escape via crafted HTML in Chrome Android <151.0.7922.109CVE-2026-19166 · Fixed within SLA · CVE-2026-19166: Use-after-free in Chrome WebAuthn pre-151.0.7922.109 allows remote sandbox escape via HTMLCVE-2026-19149 · Fixed within SLA · CVE-2026-19149: Critical UAF in Chrome Aura on Linux enables remote sandbox escape via crafted HTML pre-151.0.7922.109CVE-2026-19164 · Fixed within SLA · CVE-2026-19164: Insufficient input validation in Chrome Codecs pre-151.0.7922.109 allows remote sandbox escape via HTMLCVE-2026-19175 · Fixed within SLA · CVE-2026-19175: Use-after-free in Chrome Payments allows remote sandbox escape via crafted HTML (pre-151.0.7922.109)CVE-2026-19171 · Fixed within SLA · CVE-2026-19171: Chrome Windows <151.0.7922.109 Media use-after-free enables remote sandbox escape via HTMLCVE-2026-5450 · Fixed within SLA · CVE-2026-5450CVE-2026-19160 · Fixed within SLA · CVE-2026-19160: Skia uninitialized use leaks cross-origin data in Chrome <151.0.7922.109 via crafted HTMLCVE-2026-19161 · Fixed within SLA · CVE-2026-19161: Chrome <151.0.7922.109 Skia uninitialized use leaks cross-origin data via crafted HTMLCVE-2026-19167 · Fixed within SLA · CVE-2026-19167: Chrome GPU integer overflow allowed compromised renderer to leak cross-origin data pre-151.0.7922.109CVE-2026-19167 · Fixed within SLA · CVE-2026-19167: Chrome <151.0.7922.109 GPU integer overflow leaks cross-origin data; requires renderer compromiseCVE-2026-19161 · Fixed within SLA · CVE-2026-19161: Skia uninitialized use in Chrome <151.0.7922.109 leaks cross-origin data after renderer compromise via crafted HTMLCVE-2026-19160 · Fixed within SLA · CVE-2026-19160: Chrome <151.0.7922.109 Skia uninitialized use leaks cross-origin data post-renderer compromiseCVE-2026-17659 · Fixed within SLA · CVE-2026-17659: Chrome pre-151.0.7922.72 SiteIsolation bug let compromised renderer bypass isolation via crafted HTMLCVE-2026-19146 · Fixed within SLA · CVE-2026-19146: Chrome Android GPU uninitialized-use pre-151.0.7922.109 lets compromised renderer leak memory via crafted HTMLCVE-2026-52972 · Fixed within SLA · CVE-2026-52972: Linux kernel af_alg AEAD AD length overflow when checking TX buffer sizeCVE-2026-19146 · Fixed within SLA · CVE-2026-19146: Uninitialized GPU use in Chrome Android leaks process memory via crafted HTML (pre-151.0.7922.109)CVE-2026-17657 · Fixed within SLA · CVE-2026-17657: Chrome Navigation use-after-free allowed sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17654 · Fixed within SLA · CVE-2026-17654: Critical race in Chrome Updater on Mac pre-151.0.7922.72 enables local privilege escalationCVE-2026-17653 · Fixed within SLA · CVE-2026-17653: Critical Skia use-after-free in Google Chrome <151.0.7922.72 enables sandbox escape via crafted HTMLCVE-2026-17660 · Fixed within SLA · CVE-2026-17660: Insufficient input validation in Chrome Network enables sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17650 · Fixed within SLA · CVE-2026-17650: Chrome Compositing use-after-free pre-151.0.7922.72 enables sandbox escape via crafted HTMLCVE-2026-17658 · Fixed within SLA · CVE-2026-17658: V8 use-after-free in Chrome <151.0.7922.72 allows sandboxed remote code execution via crafted HTML pageCVE-2026-17658 · Fixed within SLA · CVE-2026-17658: High severity V8 use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72CVE-2026-17653 · Fixed within SLA · CVE-2026-17653: Skia use-after-free enables sandbox escape via crafted HTML in Chrome <151.0.7922.72CVE-2026-17654 · Fixed within SLA · CVE-2026-17654: Race in macOS Chrome Updater allows local privilege escalation before 151.0.7922.72 via malicious fileCVE-2026-17650 · Fixed within SLA · CVE-2026-17650: Use-after-free in Chrome Compositing allows sandbox escape from compromised renderer via HTML (pre-151.0.7922.72)CVE-2026-17660 · Fixed within SLA · CVE-2026-17660: Chrome Network input validation flaw enables sandbox escape from compromised renderer via HTMLCVE-2026-17657 · Fixed within SLA · CVE-2026-17657: Chrome <151.0.7922.72 Navigation use-after-free enables sandbox escape via crafted HTMLCVE-2026-17652 · Fixed within SLA · CVE-2026-17652: Chrome <151.0.7922.72: Views use-after-free enables sandbox escape via crafted HTMLCVE-2026-17656 · Fixed within SLA · CVE-2026-17656: Critical use-after-free in Chrome Ozone pre-151.0.7922.72 enables remote crafted-HTML sandbox escapeCVE-2026-17655 · Fixed within SLA · CVE-2026-17655: Critical ANGLE input validation flaw enables remote sandbox escape via crafted HTML in Chrome <151.0.7922.72CVE-2026-17656 · Fixed within SLA · CVE-2026-17656: Critical Chrome Ozone use-after-free enables remote sandbox escape via crafted HTML before 151.0.7922.72CVE-2026-17655 · Fixed within SLA · CVE-2026-17655: Critical ANGLE input validation flaw enables sandbox escape via crafted HTML (Chrome <151.0.7922.72)CVE-2026-17652 · Fixed within SLA · CVE-2026-17652: Use-after-free in Views enables sandbox escape on Chrome before 151.0.7922.72 via crafted HTMLCVE-2026-17659 · Fixed within SLA · CVE-2026-17659: Chrome pre-151.0.7922.72 SiteIsolation flaw allows compromised renderer to bypass isolation via crafted HTMLCVE-2026-17659 · Fixed within SLA · CVE-2026-17659: Site Isolation bypass in Chrome <151.0.7922.72 via crafted HTML after renderer compromiseCVE-2026-45897 · Fixed within SLA · CVE-2026-45897: Concurrent nft_counter dump-and-reset race can double-subtract, underrunning netfilter counter totalsCVE-2026-17770 · Fixed within SLA · CVE-2026-17770: Chrome Mac Media out-of-bounds read allows sandbox escape after renderer compromise pre-151.0.7922.72CVE-2026-17788 · Fixed within SLA · CVE-2026-17788: Blink cross-origin data leak via crafted HTML in Chrome before 151.0.7922.72CVE-2026-17789 · Fixed within SLA · CVE-2026-17789: Chrome iOS pre-151.0.7922.72: Untrusted input validation flaw enables remote navigation restrictions bypassCVE-2026-17761 · Fixed within SLA · CVE-2026-17761: Chrome iOS <151.0.7922.72 UXSS from insufficient validation of untrusted network inputCVE-2026-17787 · Fixed within SLA · CVE-2026-17787: Chrome DevTools SOP bypass via crafted HTML before 151.0.7922.72; remote attacker, MediumCVE-2026-17767 · Fixed within SLA · CVE-2026-17767: Android Chrome WebView untrusted input validation flaw leaks cross-origin data via compromised renderer pre-151.0.7922.72CVE-2026-17782 · Fixed within SLA · CVE-2026-17782: Chrome iOS prior to 151.0.7922.72 Omnibox spoofing via crafted HTML (incorrect security UI)CVE-2026-17798 · Fixed within SLA · CVE-2026-17798: Chrome Cast pre-151.0.7922.72 allows remote cross-origin data leak via crafted HTMLCVE-2026-17776 · Fixed within SLA · CVE-2026-17776: Receiver policy bypass in Chrome pre-151.0.7922.72 enables sandbox escape from compromised renderer via crafted HTMLCVE-2026-17769 · Fixed within SLA · CVE-2026-17769: Insufficient untrusted input validation in Chrome Cast enables cross-origin data leak via crafted HTML (pre-151.0.7922.72)CVE-2026-17771 · Fixed within SLA · CVE-2026-17771: Skia uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17783 · Fixed within SLA · CVE-2026-17783: Pre-151.0.7922.72 Chrome Loader leaks cross-origin data via crafted HTMLCVE-2026-17792 · Fixed within SLA · CVE-2026-17792: Credential Management UI spoofing via crafted HTML in Chrome prior to 151.0.7922.72CVE-2026-17797 · Fixed within SLA · CVE-2026-17797: Chrome pre-151.0.7922.72 CSS implementation enables UXSS script/HTML injection via crafted pageCVE-2026-17795 · Fixed within SLA · CVE-2026-17795: GetUserMedia flaw leaks cross-origin data via crafted page after renderer compromise in Chrome <151.0.7922.72CVE-2026-17775 · Fixed within SLA · CVE-2026-17775: PresentationAPI in Chrome <151.0.7922.72 leaked cross-origin data via crafted HTML pageCVE-2026-17791 · Fixed within SLA · CVE-2026-17791: Insufficient input validation in Chrome Payments pre-151.0.7922.72 enables UI spoofing from compromised rendererCVE-2026-17780 · Fixed within SLA · CVE-2026-17780: Chrome Isolated Web Apps allowed remote bypass of navigation restrictions via crafted HTML pre-151.0.7922.72CVE-2026-17785 · Fixed within SLA · CVE-2026-17785: ANGLE uninitialized use in Chrome <151.0.7922.72 enables cross-origin data leak via crafted HTML pageCVE-2026-17779 · Fixed within SLA · CVE-2026-17779: Google Chrome Site Isolation bypass before 151.0.7922.72 via crafted HTML pageCVE-2026-17754 · Fixed within SLA · CVE-2026-17754: Blink same-origin policy bypass in Chrome before 151.0.7922.72 via crafted HTMLCVE-2026-17802 · Fixed within SLA · CVE-2026-17802: Chrome Android GPU side-channel leaks cross-origin data via crafted HTML page pre-151.0.7922.72CVE-2026-18018 · Fixed within SLA · CVE-2026-18018: Windows Chrome Updater vulnerability enables local UI spoofing via malicious file (pre-151.0.7922.72)CVE-2026-17762 · Fixed within SLA · CVE-2026-17762: Chrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML pageCVE-2026-17777 · Fixed within SLA · CVE-2026-17777: Chrome Autofill flaw pre-151.0.7922.72 enables remote cross-origin data leak via crafted HTMLCVE-2026-17773 · Fixed within SLA · CVE-2026-17773: Google Chrome Cast input validation flaw leaks cross-origin data via crafted HTMLCVE-2026-67217 · Fixed within SLA · CVE-2026-67217: cJSON ≤1.7.19 JSON Patch non-atomic; failed replace/move deletes target membersCVE-2026-17772 · Fixed within SLA · CVE-2026-17772: WebGL out-of-bounds read in Chrome pre-151.0.7922.72 allows remote memory disclosureCVE-2026-17764 · Fixed within SLA · CVE-2026-17764: FedCM SOP bypass in Chrome prior to 151.0.7922.72 via crafted HTML pageCVE-2026-17756 · Fixed within SLA · CVE-2026-17756: Chrome pre-151.0.7922.72 Presentation policy flaw enables remote navigation bypass via crafted HTMLCVE-2026-17755 · Fixed within SLA · CVE-2026-17755: Google Chrome pre-151 Extensions UI security flaw enables malicious extension-based UI spoofingCVE-2026-17761 · Fixed within SLA · CVE-2026-17761: Chrome iOS <151.0.7922.72: Insufficient input validation enables UXSS script/HTML injection via malicious trafficCVE-2026-18018 · Fixed within SLA · CVE-2026-18018: Windows Chrome Updater bug allows local UI spoofing via malicious file pre-151.0.7922.72CVE-2026-17791 · Fixed within SLA · CVE-2026-17791: Chrome Payments insufficient input validation allows UI spoofing via compromised renderer prior to 151.0.7922.72CVE-2026-17802 · Fixed within SLA · CVE-2026-17802: Android Chrome <151.0.7922.72 GPU side-channel leaks cross-origin data via crafted HTMLCVE-2026-17779 · Fixed within SLA · CVE-2026-17779: Chrome prior to 151.0.7922.72: Remote Site Isolation bypass via crafted HTML pageCVE-2026-17795 · Fixed within SLA · CVE-2026-17795: GetUserMedia cross-origin data leak in Chrome before 151.0.7922.72 via compromised renderer using crafted HTML pageCVE-2026-17780 · Fixed within SLA · CVE-2026-17780: Chrome Isolated Web Apps navigation restriction bypass via crafted HTML (pre-151.0.7922.72)CVE-2026-17773 · Fixed within SLA · CVE-2026-17773: Chrome Cast insufficient input validation allowed cross-origin data leak via crafted HTML (pre-151.0.7922.72)CVE-2026-17776 · Fixed within SLA · CVE-2026-17776: Chrome <151.0.7922.72 Receiver policy bypass allows sandbox escape via crafted HTMLCVE-2026-17770 · Fixed within SLA · CVE-2026-17770: Chrome macOS Media out-of-bounds read enables sandbox escape after renderer compromise (pre-151.0.7922.72)CVE-2026-17797 · Fixed within SLA · CVE-2026-17797: Google Chrome pre-151.0.7922.72 CSS bug allows remote UXSS via crafted HTMLCVE-2026-17756 · Fixed within SLA · CVE-2026-17756: Chrome before 151.0.7922.72 Presentation policy flaw allowed remote navigation bypass via crafted HTMLCVE-2026-17782 · Fixed within SLA · CVE-2026-17782: Chrome iOS <151.0.7922.72: Omnibox URL spoofing via crafted HTML pageCVE-2026-17792 · Fixed within SLA · CVE-2026-17792: Google Chrome Credential Management vulnerability enables remote UI spoofing via crafted HTML pre-151.0.7922.72CVE-2026-17798 · Fixed within SLA · CVE-2026-17798: Chrome Cast prior to 151.0.7922.72 cross-origin data leak via crafted HTML pageCVE-2026-17769 · Fixed within SLA · CVE-2026-17769: Chrome Cast insufficient input validation leaks cross-origin data via crafted HTML (pre-151.0.7922.72)CVE-2026-17772 · Fixed within SLA · CVE-2026-17772: Chrome WebGL out-of-bounds read pre-151.0.7922.72 enables remote memory disclosure via crafted HTML pageCVE-2026-17775 · Fixed within SLA · CVE-2026-17775: Chrome <151.0.7922.72 PresentationAPI vulnerability allows cross-origin data leak via crafted HTMLCVE-2026-17785 · Fixed within SLA · CVE-2026-17785: Uninitialized use in ANGLE allowed cross-origin data leak in Chrome <151.0.7922.72 via crafted HTML pageCVE-2026-17783 · Fixed within SLA · CVE-2026-17783: Chrome pre-151.0.7922.72 Loader bug leaks cross-origin data via crafted HTML pageCVE-2026-17787 · Fixed within SLA · CVE-2026-17787: Inappropriate DevTools implementation enables same-origin policy bypass before Chrome 151.0.7922.72 via crafted HTMLCVE-2026-17755 · Fixed within SLA · CVE-2026-17755: Chrome Extensions security UI bug allowed spoofing via malicious extension before 151.0.7922.72CVE-2026-17762 · Fixed within SLA · CVE-2026-17762: iOS Chrome pre-151.0.7922.72 cross-origin data leak via crafted HTMLCVE-2026-17777 · Fixed within SLA · CVE-2026-17777: Chrome Autofill pre-151.0.7922.72 cross-origin data leak via crafted HTML pageCVE-2026-17789 · Fixed within SLA · CVE-2026-17789: Chrome iOS pre-151.0.7922.72 input validation flaw enables remote navigation restriction bypassCVE-2026-17754 · Fixed within SLA · CVE-2026-17754: Blink same-origin policy bypass via crafted HTML in Chrome before 151.0.7922.72CVE-2026-66011 · Fixed within SLA · CVE-2026-66011: ImageMagick <7.1.2-27 magick CLI memory leak on malformed options causes DoSCVE-2026-17764 · Fixed within SLA · CVE-2026-17764: FedCM in Chrome <151.0.7922.72 allows remote same-origin policy bypass via crafted HTMLCVE-2026-17788 · Fixed within SLA · CVE-2026-17788: Blink vulnerability allowed cross-origin data leak via crafted HTML in Chrome <151.0.7922.72CVE-2026-17767 · Fixed within SLA · CVE-2026-17767: Android Chrome WebView <151.0.7922.72: insufficient input validation enables cross-origin data leakCVE-2026-67217 · Fixed within SLA · CVE-2026-67217: cJSON <=1.7.19 JSON Patch non-atomic; failed replace/move deletes target membersCVE-2026-17771 · Fixed within SLA · CVE-2026-17771: Uninitialized Skia use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17791 · Fixed within SLA · CVE-2026-17791: Chrome Payments input validation bug enables UI spoofing by compromised renderer pre-151.0.7922.72CVE-2026-17792 · Fixed within SLA · CVE-2026-17792: Chrome Credential Management UI spoofing via crafted HTML by remote attacker pre-151.0.7922.72CVE-2026-17798 · Fixed within SLA · CVE-2026-17798: Google Chrome Cast pre-151.0.7922.72 remote cross-origin data leak via crafted HTMLCVE-2026-17767 · Fixed within SLA · CVE-2026-17767: Insufficient WebView input validation in Android Chrome leaks cross-origin data after renderer compromiseCVE-2026-67217 · Fixed within SLA · CVE-2026-67217: cJSON ≤1.7.19: non-atomic JSON Patch lets failed replace/move delete target membersCVE-2026-17780 · Fixed within SLA · CVE-2026-17780: Isolated Web Apps in Chrome <151.0.7922.72 allow remote bypass of navigation restrictions via crafted HTMLCVE-2026-17797 · Fixed within SLA · CVE-2026-17797: Google Chrome CSS bug enabled remote script/HTML injection (UXSS) before 151.0.7922.72CVE-2026-17761 · Fixed within SLA · CVE-2026-17761: Chrome iOS <151.0.7922.72 UXSS via insufficient validation of untrusted network inputCVE-2026-17795 · Fixed within SLA · CVE-2026-17795: GetUserMedia allows cross-origin data leak in Chrome prior to 151.0.7922.72 via compromised rendererCVE-2026-17773 · Fixed within SLA · CVE-2026-17773: Chrome Cast insufficient input validation (<151.0.7922.72) leaks cross-origin data via crafted HTMLCVE-2026-17789 · Fixed within SLA · CVE-2026-17789: Chrome iOS <151.0.7922.72 insufficient input validation enables remote navigation restriction bypassCVE-2026-17764 · Fixed within SLA · CVE-2026-17764: Chrome FedCM same-origin policy bypass by remote attacker via crafted HTML prior to 151.0.7922.72CVE-2026-17775 · Fixed within SLA · CVE-2026-17775: Inappropriate PresentationAPI implementation leaks cross-origin data in Chrome before 151.0.7922.72CVE-2026-17769 · Fixed within SLA · CVE-2026-17769: Chrome Cast input validation flaw leaks cross-origin data via crafted HTML (pre-151.0.7922.72) (Medium severity)CVE-2026-17770 · Fixed within SLA · CVE-2026-17770: Chrome Mac pre-151.0.7922.72 Media OOB read enables sandbox escape after renderer compromiseCVE-2026-17802 · Fixed within SLA · CVE-2026-17802: Chrome Android GPU side-channel lets remote attackers leak cross-origin data before 151.0.7922.72CVE-2026-17762 · Fixed within SLA · CVE-2026-17762: Google Chrome on iOS before 151.0.7922.72 leaks cross-origin data via crafted HTML pageCVE-2026-17787 · Fixed within SLA · CVE-2026-17787: Chrome DevTools same-origin policy bypass via crafted HTML before 151.0.7922.72CVE-2026-17776 · Fixed within SLA · CVE-2026-17776: Policy bypass in Chrome Receiver enables sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17785 · Fixed within SLA · CVE-2026-17785: ANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17788 · Fixed within SLA · CVE-2026-17788: Blink cross-origin data leak via crafted HTML in Chrome before 151.0.7922.72CVE-2026-17756 · Fixed within SLA · CVE-2026-17756: Insufficient policy enforcement in Chrome Presentation pre-151.0.7922.72 allows remote navigation bypass via crafted HTMLCVE-2026-17782 · Fixed within SLA · CVE-2026-17782: Incorrect security UI allows Omnibox spoofing via crafted HTML on Chrome iOS <151.0.7922.72CVE-2026-17779 · Fixed within SLA · CVE-2026-17779: Remote Site Isolation bypass in Google Chrome <151.0.7922.72 via crafted HTML pageCVE-2026-18018 · Fixed within SLA · CVE-2026-18018: Windows Chrome Updater allows local UI spoofing via malicious file before 151.0.7922.72CVE-2026-17754 · Fixed within SLA · CVE-2026-17754: Blink SOP bypass via crafted HTML in Chrome before 151.0.7922.72CVE-2026-17783 · Fixed within SLA · CVE-2026-17783: Google Chrome Loader before 151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17755 · Fixed within SLA · CVE-2026-17755: Chrome pre-151.0.7922.72 Extensions security UI flaw enables UI spoofing via crafted extensionCVE-2026-17772 · Fixed within SLA · CVE-2026-17772: Chrome <151.0.7922.72 WebGL out-of-bounds read allows remote memory disclosure via crafted HTMLCVE-2026-17777 · Fixed within SLA · CVE-2026-17777: Google Chrome Autofill cross-origin data leak via crafted HTML page pre-151.0.7922.72CVE-2026-17771 · Fixed within SLA · CVE-2026-17771: Skia uninitialized use enables cross-origin data leak via crafted HTML in Chrome <151.0.7922.72CVE-2026-66011 · Fixed within SLA · CVE-2026-66011: ImageMagick <7.1.2-27 magick CLI memory leak on invalid options enables memory exhaustionCVE-2026-17774 · Fixed within SLA · CVE-2026-17774: Insufficient input validation in Chrome Variations pre-151.0.7922.72 allows heap corruption by privileged network attackerCVE-2026-17894 · Fixed within SLA · CVE-2026-17894: Chrome Linux Views use-after-free allows remote heap corruption via crafted HTML, prior to 151.0.7922.72CVE-2026-17784 · Fixed within SLA · CVE-2026-17784: Chrome Mac Audio use-after-free enables sandbox escape pre-151.0.7922.72 via crafted HTMLCVE-2026-17786 · Fixed within SLA · CVE-2026-17786: Insufficient DevTools input validation in Chrome allows privilege escalation via crafted extension (<151.0.7922.72)CVE-2026-67215 · Fixed within SLA · CVE-2026-67215: cJSON <=1.7.19: Untrusted JSON Patch via cJSONUtils_ApplyPatches triggers uncontrolled recursion and stack exhaustion DoSCVE-2026-17894 · Fixed within SLA · CVE-2026-17894: Google Chrome Linux pre-151.0.7922.72 Views use-after-free enables remote heap corruption via crafted HTMLCVE-2026-67216 · Fixed within SLA · CVE-2026-67216: cJSON 1.7.19 and earlier: cJSON_Compare exponential complexity allows DoS via nested JSONCVE-2026-17784 · Fixed within SLA · CVE-2026-17784: Chrome Mac Audio use-after-free permits sandbox escape after renderer compromise via crafted HTML (pre-151.0.7922.72)CVE-2026-17786 · Fixed within SLA · CVE-2026-17786: Insufficient DevTools input validation enables privilege escalation via malicious Chrome extension (pre-151.0.7922.72)CVE-2026-17774 · Fixed within SLA · CVE-2026-17774: Pre-151.0.7922.72 Chrome Variations input validation flaw enables heap corruption via privileged network attackerCVE-2026-67216 · Fixed within SLA · CVE-2026-67216: cJSON <=1.7.19 cJSON_Compare exponential time on deep nested equal objects causes DoSCVE-2026-67215 · Fixed within SLA · CVE-2026-67215: cJSON through 1.7.19: Untrusted RFC 6902 patch triggers recursion, stack exhaustion DoSCVE-2026-17894 · Fixed within SLA · CVE-2026-17894: Use-after-free in Views on Linux Chrome <151.0.7922.72 allows remote heap corruption via crafted HTMLCVE-2026-67216 · Fixed within SLA · CVE-2026-67216: cJSON <=1.7.19: cJSON_Compare exponential-time recursion causes DoS on deeply nested JSONCVE-2026-67215 · Fixed within SLA · CVE-2026-67215: cJSON <=1.7.19 DoS: stack exhaustion from uncontrolled recursion applying RFC6902 JSON PatchCVE-2026-17774 · Fixed within SLA · CVE-2026-17774: Insufficient input validation in Chrome Variations enables heap corruption by privileged network attackerCVE-2026-17784 · Fixed within SLA · CVE-2026-17784: Chrome Mac Audio use-after-free enables sandbox escape after renderer compromise via crafted HTML (pre-151.0.7922.72)CVE-2026-17786 · Fixed within SLA · CVE-2026-17786: Insufficient validation in Chrome DevTools allows extension-based privilege escalation pre-151.0.7922.72CVE-2026-18015 · Fixed within SLA · CVE-2026-18015: Pre-151.0.7922.72 Chrome for Mac Tint flaw enabled remote sandbox escape via HTMLCVE-2026-17768 · Fixed within SLA · CVE-2026-17768: WebSockets input validation flaw enables sandbox escape from compromised renderer in Chrome <151.0.7922.72CVE-2026-18015 · Fixed within SLA · CVE-2026-18015: Tint implementation flaw in Chrome Mac before 151.0.7922.72 allows sandbox escape via crafted HTMLCVE-2026-17768 · Fixed within SLA · CVE-2026-17768: Chrome <151.0.7922.72 WebSocket input validation bug enables sandbox escape from compromised rendererCVE-2026-17768 · Fixed within SLA · CVE-2026-17768: Chrome WebSockets input validation flaw enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72)CVE-2026-18015 · Fixed within SLA · CVE-2026-18015: Tint implementation flaw in Google Chrome on Mac <151.0.7922.72 enabling sandbox escape via crafted HTMLCVE-2026-17877 · Fixed within SLA · CVE-2026-17877: Chrome Chromoting on Linux <151.0.7922.72 allows OS-level privilege escalation via network trafficCVE-2026-63806 · Fixed within SLA · CVE-2026-63806: Guest-triggered kernel BUG via unaligned ioeventfd datamatch on KVM page-split MMIOCVE-2026-63803 · Fixed within SLA · CVE-2026-63803: Use-after-free from PPP protocol timers when HDLC state is freed during detachCVE-2026-53396 · Fixed within SLA · CVE-2026-53396: Linux nfsd4_create_file ignores ACL conversion errors; leaks posix_acl allocationsCVE-2026-63807 · Fixed within SLA · CVE-2026-63807: KVM: Missing memslot bounds check causes OOB lpage_info access during hugepage recoveryCVE-2026-53389 · Fixed within SLA · CVE-2026-53389: Use-after-free in TCP-AO del_async due to dangling current_key/rnext_key on LISTEN socketsCVE-2026-63796 · Fixed within SLA · CVE-2026-63796: OCFS2 accepts oversized group bitmap descriptors causing OOB bitmap access and use-after-freeCVE-2026-63802 · Fixed within SLA · CVE-2026-63802: Use-after-free in blk-cgroup __blkcg_rstat_flush via llist_del_all during concurrent blkg releasesCVE-2026-53394 · Fixed within SLA · CVE-2026-53394: nfsd memory leak: pre-allocated openowner overwritten during unconfirmed owner retry raceCVE-2026-63805 · Fixed within SLA · CVE-2026-63805: Linux nx crypto: kernel oops from wrong ctx type passed to nx_crypto_ctx_exitCVE-2026-63794 · Fixed within SLA · CVE-2026-63794: KVM SVM unbounded destination offset causes page overflow and memcpy overrun in sev_dbg_crypt ENCRYPTCVE-2026-53392 · Fixed within SLA · CVE-2026-53392: NFSv4/flexfiles accepts zero fh_count, causing ZERO_SIZE_PTR and KASAN null dereferenceCVE-2026-63804 · Fixed within SLA · CVE-2026-63804: gfs2: use-after-free in gfs2_qd_dealloc when superblock freed before RCU callbacks finishCVE-2026-63797 · Fixed within SLA · CVE-2026-63797: rpmsg char: callbacks use freed eptdev after probe failure due to stale privCVE-2026-53390 · Fixed within SLA · CVE-2026-53390: ksmbd: OOB read in smb_check_perm_dacl due to ACE/SID length mismatchCVE-2026-53395 · Fixed within SLA · CVE-2026-53395: Dead ACL conflict guard in nfsd4_create leaks posix_acls, causing unbounded slab exhaustionCVE-2026-53397 · Fixed within SLA · CVE-2026-53397: nfsd: posix_acl memory leak when SETACL decode fails; pc_release didn't free ACLsCVE-2026-63799 · Fixed within SLA · CVE-2026-63799: sched/mmcid: OOB clear_bit from MM_CID_UNSET during per-CPU CID fixupCVE-2026-63801 · Fixed within SLA · CVE-2026-63801: TIPC decrypt async completion UAF from missing netns ref when crypto_aead_decrypt offloadedCVE-2026-53402 · Fixed within SLA · CVE-2026-53402: fbcon_do_set_font err_out misses hi_font rollback, enabling OOB read/memory leakCVE-2026-53391 · Fixed within SLA · CVE-2026-53391: NFSv4/pNFS: zero-length r_addr triggers NULL pointer dereference in nfs4_decode_mp_ds_addrCVE-2026-53400 · Fixed within SLA · CVE-2026-53400: i2c core adapter registration race causes i2c_get_adapter to access uninitialized device, NULL/UAFCVE-2026-53401 · Fixed within SLA · CVE-2026-53401: fbdev omap2 omapfb_mmap race with OMAPFB_SETUP_PLANE leads to use-after-freeCVE-2026-53368 · Fixed within SLA · CVE-2026-53368: f2fs: Race reading nat_entry flags causes incorrect inode dentry mark and fsck inconsistency after checkpointCVE-2026-17877 · Fixed within SLA · CVE-2026-17877: Linux Chrome Chromoting pre-151.0.7922.72 allows local privilege escalation via network trafficCVE-2026-63805 · Fixed within SLA · CVE-2026-63805: Type mismatch in nx_crypto_ctx_exit triggers kernel oops via nx_crypto_ctx_shash_exitCVE-2026-53392 · Fixed within SLA · CVE-2026-53392: NFSv4 flexfiles ff_layout_alloc_lseg accepts zero fh_count, causing NULL pointer dereferenceCVE-2026-53401 · Fixed within SLA · CVE-2026-53401: fbdev omap2: omapfb_mmap use-after-free race with OMAPFB_SETUP_PLANE mapping freed memoryCVE-2026-53402 · Fixed within SLA · CVE-2026-53402: fbcon_do_set_font error rollback misses hi_font state restore, causing out-of-bounds font readsCVE-2026-17778 · Fixed within SLA · CVE-2026-17778: Use-after-free in Chrome Extensions pre-151.0.7922.72 enables sandboxed arbitrary code executionCVE-2026-17950 · Fixed within SLA · CVE-2026-17950: Chrome Mac Safe Browsing bug pre-151.0.7922.72 allows RCE via malicious fileCVE-2026-17881 · Fixed within SLA · CVE-2026-17881: WebXR integer overflow in Chrome <151.0.7922.72 enables sandboxed remote code execution via crafted HTML pageCVE-2026-17888 · Fixed within SLA · CVE-2026-17888: Chrome pre-151.0.7922.72 WebUI input validation flaw enables sandbox escape via malicious network trafficCVE-2026-17951 · Fixed within SLA · CVE-2026-17951: Google Chrome WebRTC heap buffer overflow enables remote out-of-bounds read via crafted HTML pre-151.0.7922.72CVE-2026-17971 · Fixed within SLA · CVE-2026-17971: Chrome <151.0.7922.72 Frame implementation allows remote OOB memory access via crafted HTMLCVE-2026-17920 · Fixed within SLA · CVE-2026-17920: Chrome V8 use-after-free enables sandboxed code execution via malicious extension pre-151.0.7922.72CVE-2026-17868 · Fixed within SLA · CVE-2026-17868: Chrome USB policy enforcement bug (<151.0.7922.72) allows remote privilege escalation via crafted HTMLCVE-2026-17744 · Fixed within SLA · CVE-2026-17744: Chrome Linux File Input vulnerability enables remote sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17861 · Fixed within SLA · CVE-2026-17861: Insufficient input validation in Chrome Updater allows local privilege escalation via malicious file (pre-151.0.7922.72)CVE-2026-18012 · Fixed within SLA · CVE-2026-18012: Chrome <151.0.7922.72: PDFium use-after-free enables sandboxed code execution via crafted PDFCVE-2026-17887 · Fixed within SLA · CVE-2026-17887: Chrome <151.0.7922.72 TabStrip use-after-free enables heap corruption via crafted HTML and UI gesturesCVE-2026-17836 · Fixed within SLA · CVE-2026-17836: Chrome <151.0.7922.72 V8 use-after-free enables sandboxed remote code execution via crafted HTMLCVE-2026-17993 · Fixed within SLA · CVE-2026-17993: Race in Chrome Updater on Windows allows local privilege escalation pre-151.0.7922.72CVE-2026-17979 · Fixed within SLA · CVE-2026-17979: V8 race condition in Chrome <151.0.7922.72 enables remote code execution in sandbox via crafted HTMLCVE-2026-17967 · Fixed within SLA · CVE-2026-17967: Use-after-free in Chrome iOS pre-151.0.7922.72 enables remote heap corruption via crafted HTMLCVE-2026-18017 · Fixed within SLA · CVE-2026-18017: Chrome <151.0.7922.72 Dawn use-after-free enables sandboxed RCE via crafted HTML, low severityCVE-2026-17922 · Fixed within SLA · CVE-2026-17922: Chrome Enterprise <151.0.7922.72 inappropriate implementation enables remote code execution via crafted HTMLCVE-2026-17918 · Fixed within SLA · CVE-2026-17918: Use-after-free in Chrome Sync allows sandboxed code execution via crafted HTML pre-151.0.7922.72CVE-2026-17899 · Fixed within SLA · CVE-2026-17899: Insufficient DevTools policy enforcement enables Chrome extension privilege escalation before 151.0.7922.72CVE-2026-17952 · Fixed within SLA · CVE-2026-17952: Chrome V8 pre-151.0.7922.72 allows sandbox code execution via malicious extensionCVE-2026-17863 · Fixed within SLA · CVE-2026-17863: Chrome Windows pre-151.0.7922.72: Local privilege escalation via malicious fileCVE-2026-17995 · Fixed within SLA · CVE-2026-17995: Remote out-of-bounds memory read in Chrome Dawn via crafted HTML before 151.0.7922.72CVE-2026-17969 · Fixed within SLA · CVE-2026-17969: Google Chrome Passwords prior to 151.0.7922.72 allows remote sandbox RCE via crafted HTMLCVE-2026-17867 · Fixed within SLA · CVE-2026-17867: Insufficient input validation in Chrome Dawn allows remote sandbox escape via crafted HTML pageCVE-2026-17989 · Fixed within SLA · CVE-2026-17989: Chrome <151.0.7922.72 V8 type confusion allows sandboxed code execution via crafted HTMLCVE-2026-17948 · Fixed within SLA · CVE-2026-17948: Chrome V8 type confusion enables sandboxed code execution via malicious extension (pre-151.0.7922.72)CVE-2026-17930 · Fixed within SLA · CVE-2026-17930: Pre-151.0.7922.72 Chrome Extensions untrusted input validation flaw allows renderer privilege escalation via HTMLCVE-2026-17896 · Fixed within SLA · CVE-2026-17896: Use-after-free in Chrome DevTools allows sandboxed RCE via crafted HTML (pre-151.0.7922.72)CVE-2026-17884 · Fixed within SLA · CVE-2026-17884: Chrome WebRTC lifecycle bug pre-151.0.7922.72 allows remote heap corruption via crafted HTMLCVE-2026-17811 · Fixed within SLA · CVE-2026-17811: Use-after-free in Chrome ANGLE on Windows allows sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17935 · Fixed within SLA · CVE-2026-17935: Heap buffer overflow in Chrome Codecs enables sandboxed RCE via crafted HTML (pre-151.0.7922.72)CVE-2026-17916 · Fixed within SLA · CVE-2026-17916: Insufficient Settings policy enforcement allows compromised renderer privilege escalation in Chrome <151.0.7922.72 via crafted HTML.CVE-2026-17956 · Fixed within SLA · CVE-2026-17956: Chrome pre-151.0.7922.72 Scheduling flaw enables sandbox RCE via crafted HTMLCVE-2026-17898 · Fixed within SLA · CVE-2026-17898: Chrome DevTools use-after-free enables sandboxed code execution via malicious extension pre-151.0.7922.72CVE-2026-17877 · Fixed within SLA · CVE-2026-17877: Chromoting on Linux before 151.0.7922.72 enables OS-level privilege escalation via malicious network trafficCVE-2026-17886 · Fixed within SLA · CVE-2026-17886: Use-after-free in Chrome Enterprise pre-151.0.7922.72 enables remote heap corruption via HTMLCVE-2026-17862 · Fixed within SLA · CVE-2026-17862: Chrome Windows Tracing use-after-free allows local privilege escalation via malicious file (pre-151.0.7922.72)CVE-2026-17875 · Fixed within SLA · CVE-2026-17875: PDFium use-after-free enables sandboxed RCE via crafted PDF in Chrome <151.0.7922.72CVE-2026-17864 · Fixed within SLA · CVE-2026-17864: Chrome Mac Updater pre-151.0.7922.72 local OS-level privilege escalation via malicious fileCVE-2026-17869 · Fixed within SLA · CVE-2026-17869: Chrome <151.0.7922.72 WebXR out-of-bounds read enables remote memory disclosureCVE-2026-17751 · Fixed within SLA · CVE-2026-17751: Google Chrome AdFilter sandbox RCE via crafted HTML before 151.0.7922.72CVE-2026-17816 · Fixed within SLA · CVE-2026-17816: Android Chrome Speech policy enforcement bug enables compromised renderer privilege escalation via crafted HTMLCVE-2026-17722 · Fixed within SLA · CVE-2026-17722: WebView lifecycle bug in Android Chrome pre-151.0.7922.72 allowed renderer-compromised sandbox escapeCVE-2026-17663 · Fixed within SLA · CVE-2026-17663: Chrome Android GPU input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17750 · Fixed within SLA · CVE-2026-17750: Chrome pre-151.0.7922.72 ANGLE use-after-free allows remote sandbox escape via crafted HTMLCVE-2026-17725 · Fixed within SLA · CVE-2026-17725: V8 type confusion in Chrome <151.0.7922.72 allows sandboxed RCE via crafted HTMLCVE-2026-17678 · Fixed within SLA · CVE-2026-17678: Chrome ANGLE out-of-bounds read enables renderer sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17807 · Fixed within SLA · CVE-2026-17807: Chrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72CVE-2026-17712 · Fixed within SLA · CVE-2026-17712: Chrome Mac Skia race pre-151.0.7922.72 enables sandboxed remote code execution via crafted HTMLCVE-2026-17752 · Fixed within SLA · CVE-2026-17752: Use-after-free in Chrome Views on Mac pre-151.0.7922.72 enables remote heap corruption via crafted HTMLCVE-2026-17686 · Fixed within SLA · CVE-2026-17686: Chrome Passwords untrusted input validation flaw allows site isolation bypass pre-151.0.7922.72CVE-2026-17665 · Fixed within SLA · CVE-2026-17665: High-severity Chrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72CVE-2026-17741 · Fixed within SLA · CVE-2026-17741: WebView untrusted input validation flaw enables sandbox escape in Chrome Android prior to 151.0.7922.72CVE-2026-5928 · Fixed within SLA · CVE-2026-5928: glibc ≤ 2.43 ungetwc wrong buffer causes under-read with overlapping encodings, data leak/crashCVE-2026-17698 · Fixed within SLA · CVE-2026-17698: Chrome on Android UI input validation flaw pre-151.0.7922.72 allows local cross-origin data leakCVE-2026-17699 · Fixed within SLA · CVE-2026-17699: Use-after-free in Chrome Views enables local attacker sandbox escape via malicious file (pre-151.0.7922.72)CVE-2026-17705 · Fixed within SLA · CVE-2026-17705: High-severity Chrome <151.0.7922.72 libxml integer overflow allows sandboxed RCE via crafted HTMLCVE-2026-17694 · Fixed within SLA · CVE-2026-17694: Google Chrome prior to 151.0.7922.72 DOM use-after-free enables sandboxed RCE via crafted HTMLCVE-2026-17677 · Fixed within SLA · CVE-2026-17677: Remote sandbox escape via crafted HTML in Chrome Android ANGLE pre-151.0.7922.72CVE-2026-17719 · Fixed within SLA · CVE-2026-17719: High-severity use-after-free in Input enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72CVE-2026-4046 · Fixed within SLA · CVE-2026-4046: glibc <=2.43 iconv assertion failure on IBM1390/IBM1399 may allow remote crashCVE-2026-17685 · Fixed within SLA · CVE-2026-17685: Chrome Autofill use-after-free enables sandboxed RCE via crafted HTML (pre-151.0.7922.72)CVE-2026-53401 · Fixed within SLA · CVE-2026-53401: fbdev omap2: omapfb_mmap race with OMAPFB_SETUP_PLANE causes use-after-freeCVE-2026-53005 · Fixed within SLA · CVE-2026-53005: SOCKMAP hides inflight fds from AF_UNIX GC causing leaks, UAF, and incorrect SCM countsCVE-2026-17937 · Fixed within SLA · CVE-2026-17937: Chrome DevTools untrusted input allows remote bypass of navigation restrictions via crafted HTMLCVE-2026-63798 · Fixed within SLA · CVE-2026-63798: imgpdc irqchip resource leak and dangling chained handlers cause use-after-free, kernel crashesCVE-2026-53403 · Fixed within SLA · CVE-2026-53403: fbdev: fb_videomode_to_var NULL deref when new modelist omits current modeCVE-2026-53393 · Fixed within SLA · CVE-2026-53393: nfsd fails to reset write verifier on deferred writeback errors, causing COMMIT data lossCVE-2026-62363 · Fixed within SLA · CVE-2026-62363: Heap buffer overwrite in ImageMagick fx operation via crafted argument before 7.1.2-27CVE-2026-62946 · Fixed within SLA · CVE-2026-62946: ImageMagick JNX parsing integer overflow on 32-bit platforms causes heap buffer overwriteCVE-2026-64685 · Fixed within SLA · CVE-2026-64685: Crafted image triggers heap buffer over-read in ImageMagick BGR decoder pre-7.1.2-27CVE-2026-17937 · Fixed within SLA · CVE-2026-17937: Chrome DevTools insufficient input validation lets remote attackers bypass navigation restrictions via crafted HTML pre-151.0.7922.72CVE-2026-47143 · Fixed within SLA · CVE-2026-47143: Pre-5.0.8/6.0.0-alpha8 Capstone reduced x86 NULL deref on 3DNow! 0F 0F remote crashCVE-2026-62946 · Fixed within SLA · CVE-2026-62946: Large JNX files on 32-bit ImageMagick cause integer overflow and heap buffer overwriteCVE-2026-64685 · Fixed within SLA · CVE-2026-64685: Heap buffer over-read in ImageMagick BGR decoder due to missing EOF checks (<7.1.2-27)CVE-2026-53377 · Fixed within SLA · CVE-2026-53377: MSM DRM recover_worker skips recovery when idle, leaving hung GPU state and repeated timeoutsCVE-2026-62363 · Fixed within SLA · CVE-2026-62363: ImageMagick <7.1.2-27 heap buffer overwrite in fx operation via crafted argumentCVE-2026-17986 · Fixed within SLA · CVE-2026-17986: Chrome pre-151.0.7922.72 Bluetooth policy bug allows same-origin policy bypass via crafted HTML from compromised rendererCVE-2026-17790 · Fixed within SLA · CVE-2026-17790: Chrome Windows ANGLE uninitialized use leaks process memory via crafted HTML pre-151.0.7922.72CVE-2026-17977 · Fixed within SLA · CVE-2026-17977: Google Chrome prior to 151.0.7922.72 CSS policy bypass leaks cross-origin data via crafted HTML pageCVE-2026-17981 · Fixed within SLA · CVE-2026-17981: Chrome Blink flaw lets remote attacker leak cross-origin data via crafted HTML pre-151.0.7922.72CVE-2026-17970 · Fixed within SLA · CVE-2026-17970: Chrome <151.0.7922.72 Passwords lacks input validation, enabling UI spoofing by privileged network attackerCVE-2026-17931 · Fixed within SLA · CVE-2026-17931: Chrome DevTools navigation restriction bypass via crafted HTML page (pre-151.0.7922.72)CVE-2026-17963 · Fixed within SLA · CVE-2026-17963: Chrome <151.0.7922.72 SVG bug allows cross-origin data leak via crafted HTMLCVE-2026-17844 · Fixed within SLA · CVE-2026-17844: Pre-151.0.7922.72 Chrome Cast input validation allowed local attacker to leak cross-origin dataCVE-2026-17975 · Fixed within SLA · CVE-2026-17975: Chrome Mac IME pre-151.0.7922.72 flaw allows remote process memory disclosure via crafted HTMLCVE-2026-17907 · Fixed within SLA · CVE-2026-17907: Chrome pre-151.0.7922.72 Network component side-channel leaks cross-origin data via crafted HTMLCVE-2026-17960 · Fixed within SLA · CVE-2026-17960: Insufficient policy enforcement enables no-referrer bypass via crafted HTML in Chrome iOS <151.0.7922.72CVE-2026-17927 · Fixed within SLA · CVE-2026-17927: Chrome DevTools insufficient policy enforcement pre-151.0.7922.72 enables cross-origin data leak via malicious extensionCVE-2026-17919 · Fixed within SLA · CVE-2026-17919: Chrome Mac pre-151.0.7922.72 Enterprise policy enforcement flaw allows local privilege escalation with physical accessCVE-2026-17974 · Fixed within SLA · CVE-2026-17974: Chrome <151.0.7922.72 DevTools policy flaw lets local attacker bypass navigation restrictions via crafted HTMLCVE-2026-17914 · Fixed within SLA · CVE-2026-17914: Skia side-channel leak in Chrome exposes process memory via crafted HTML (pre-151.0.7922.72)CVE-2026-17747 · Fixed within SLA · CVE-2026-17747: Insufficient input validation in Chrome Android Payments enables UI spoofing via compromised rendererCVE-2026-17866 · Fixed within SLA · CVE-2026-17866: Type confusion in Tab allows sandbox escape post-renderer compromise in Chrome Android <151.0.7922.72CVE-2026-17968 · Fixed within SLA · CVE-2026-17968: WebXR uninitialized use leaks process memory in Chrome Android before 151.0.7922.72CVE-2026-17982 · Fixed within SLA · CVE-2026-17982: Insufficient input validation in Chrome Cast allowed same-origin policy bypass via crafted HTML pre-151.0.7922.72CVE-2026-18010 · Fixed within SLA · CVE-2026-18010: Chrome Passwords pre-151.0.7922.72 enables remote UI spoofing via malicious network trafficCVE-2026-17934 · Fixed within SLA · CVE-2026-17934: Chrome DevTools insufficient validation of untrusted input enabled navigation restriction bypass via crafted HTML pre-151.0.7922.72CVE-2026-17928 · Fixed within SLA · CVE-2026-17928: Chrome <151.0.7922.72 DataTransfer bug leaks cross-origin data via crafted HTMLCVE-2026-17822 · Fixed within SLA · CVE-2026-17822: Chrome iOS race condition allows remote UI spoofing via crafted HTML pre-151.0.7922.72CVE-2026-17994 · Fixed within SLA · CVE-2026-17994: Remote attacker could bypass navigation restrictions via Media in Chrome Android <151.0.7922.72CVE-2026-17882 · Fixed within SLA · CVE-2026-17882: Chrome <151.0.7922.72 extension policy flaw allows site isolation bypass via malicious extensionCVE-2026-17823 · Fixed within SLA · CVE-2026-17823: Chrome <151.0.7922.72 WebXR policy enforcement flaw enables same-origin policy bypassCVE-2026-18007 · Fixed within SLA · CVE-2026-18007: Input implementation flaw in Chrome Android <151.0.7922.72 enables remote UI spoofing via crafted HTMLCVE-2026-17983 · Fixed within SLA · CVE-2026-17983: UI spoofing in Chrome Global Media Controls via crafted HTML before 151.0.7922.72CVE-2026-17966 · Fixed within SLA · CVE-2026-17966: Mac Chrome Views bug allowed local process memory disclosure via crafted HTML prior to 151.0.7922.72CVE-2026-17873 · Fixed within SLA · CVE-2026-17873: iOS Chrome <151.0.7922.72: insufficient policy enforcement enables HTML-based discretionary access control bypassCVE-2026-17976 · Fixed within SLA · CVE-2026-17976: Chrome Extensions policy flaw allows DAC bypass via crafted domains (pre-151.0.7922.72)CVE-2026-17998 · Fixed within SLA · CVE-2026-17998: Chrome <151.0.7922.72: Incorrect Extensions security UI enables malicious extension UI spoofingCVE-2026-17874 · Fixed within SLA · CVE-2026-17874: Chrome for iOS before 151.0.7922.72 allows UI spoofing via crafted HTMLCVE-2026-17854 · Fixed within SLA · CVE-2026-17854: Chrome <151.0.7922.72 WebMCP policy flaw enables remote same-origin policy bypass via crafted HTMLCVE-2026-17827 · Fixed within SLA · CVE-2026-17827: Chrome CSS bug before 151.0.7922.72 enables UXSS via crafted HTML pageCVE-2026-18006 · Fixed within SLA · CVE-2026-18006: Google Lens in Chrome <151.0.7922.72 enables UI spoofing via crafted HTML after renderer compromiseCVE-2026-18014 · Fixed within SLA · CVE-2026-18014: Insufficient input validation in Chrome DevTools pre-151.0.7922.72 allows navigation bypass via malicious fileCVE-2026-17821 · Fixed within SLA · CVE-2026-17821: Chrome before 151.0.7922.72 extension policy flaw enables bypass of navigation restrictionsCVE-2026-17949 · Fixed within SLA · CVE-2026-17949: Uninitialized GPU use in Chrome Android pre-151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-18016 · Fixed within SLA · CVE-2026-18016: Chrome iOS <151.0.7922.72: Insufficient policy enforcement allows remote UI spoofing via crafted HTMLCVE-2026-18001 · Fixed within SLA · CVE-2026-18001: Pre-151.0.7922.72 Chrome WebGL bug exposes process memory via crafted HTMLCVE-2026-17830 · Fixed within SLA · CVE-2026-17830: Chrome for iOS <151.0.7922.72 navigation restriction bypass via crafted HTML by remote attackerCVE-2026-17858 · Fixed within SLA · CVE-2026-17858: Chrome WebNN uninitialized use on Windows <151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17883 · Fixed within SLA · CVE-2026-17883: Remote attacker could bypass same-origin policy in Headless Chrome <151.0.7922.72 via crafted HTMLCVE-2026-17937 · Fixed within SLA · CVE-2026-17937: DevTools input validation flaw allowed remote attacker to bypass navigation via crafted HTML before 151.0.7922.72CVE-2026-17985 · Fixed within SLA · CVE-2026-17985: Google Chrome pre-151 Speech policy bug enables remote site isolation bypass via crafted HTMLCVE-2026-17852 · Fixed within SLA · CVE-2026-17852: Chrome Media Router pre-151.0.7922.72 Same-Origin Policy bypass via crafted HTML by remote attackerCVE-2026-17955 · Fixed within SLA · CVE-2026-17955: Insufficient input validation in Chrome Payments allows UI spoofing via crafted HTML (pre-151.0.7922.72)CVE-2026-17923 · Fixed within SLA · CVE-2026-17923: Google Chrome Enterprise pre-151.0.7922.72 policy flaw lets remote attackers bypass navigation restrictions via crafted domainsCVE-2026-17925 · Fixed within SLA · CVE-2026-17925: Chrome Android Cast before 151.0.7922.72 allows same-origin policy bypass via crafted HTMLCVE-2026-17841 · Fixed within SLA · CVE-2026-17841: Chrome iOS race allows remote UI spoofing via crafted HTML before 151.0.7922.72CVE-2026-17818 · Fixed within SLA · CVE-2026-17818: Remote UXSS via crafted HTML in Chrome <151.0.7922.72 Network componentCVE-2026-17840 · Fixed within SLA · CVE-2026-17840: Google Chrome Passwords UI flaw enables domain spoofing via crafted HTML (pre-151.0.7922.72)CVE-2026-17933 · Fixed within SLA · CVE-2026-17933: Chrome DOMStorage vulnerability allowed remote cross-origin data leak via crafted HTML page pre-151.0.7922.72CVE-2026-17943 · Fixed within SLA · CVE-2026-17943: Google Chrome <151.0.7922.72 parser flaw allows CSP bypass via crafted HTML pageCVE-2026-17897 · Fixed within SLA · CVE-2026-17897: Inappropriate ORB implementation in Chrome pre-151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17912 · Fixed within SLA · CVE-2026-17912: Remote attacker bypasses navigation restrictions in iOS Chrome pre-151.0.7922.72 via crafted HTMLCVE-2026-17996 · Fixed within SLA · CVE-2026-17996: Chrome Mac pre-151.0.7922.72 local attacker bypasses navigation restrictions via malicious fileCVE-2026-17942 · Fixed within SLA · CVE-2026-17942: Cross-origin data leak via SVG side-channel in Google Chrome before 151.0.7922.72 using crafted HTMLCVE-2026-17961 · Fixed within SLA · CVE-2026-17961: Chrome Android pre-151.0.7922.72 Session bug allows remote bypass of navigation restrictions via crafted HTMLCVE-2026-17909 · Fixed within SLA · CVE-2026-17909: Insufficient untrusted input validation in Chrome Isolated Web Apps allows cross-origin data leak via networkCVE-2026-17917 · Fixed within SLA · CVE-2026-17917: iOS Chrome pre-151.0.7922.72 policy enforcement flaw lets remote bypass DAC via crafted HTMLCVE-2026-18008 · Fixed within SLA · CVE-2026-18008: Google Chrome Settings bug before 151.0.7922.72 allowed remote UI spoofing via malicious trafficCVE-2026-18004 · Fixed within SLA · CVE-2026-18004: Insufficient Speech API policy in Chrome <151.0.7922.72 enables compromised renderer cross-origin data leakCVE-2026-17973 · Fixed within SLA · CVE-2026-17973: Google Chrome Mac Views flaw allows local memory disclosure via crafted HTML pre-151.0.7922.72CVE-2026-18019 · Fixed within SLA · CVE-2026-18019: Side-channel leak in Chrome Media exposes cross-origin data via crafted HTML (pre-151.0.7922.72)CVE-2026-17900 · Fixed within SLA · CVE-2026-17900: Remote cross-origin data leak in Chrome Enterprise Windows <151.0.7922.72 via malicious fileCVE-2026-17972 · Fixed within SLA · CVE-2026-17972: Chrome iOS pre-151.0.7922.72 permits UI spoofing via crafted HTML pageCVE-2026-17992 · Fixed within SLA · CVE-2026-17992: Skia uninitialized use in Chrome Windows leaks process memory via crafted HTML (pre-151.0.7922.72)CVE-2026-17889 · Fixed within SLA · CVE-2026-17889: WebXR uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via HTMLCVE-2026-18013 · Fixed within SLA · CVE-2026-18013: Google Chrome for iOS prior to 151.0.7922.72 UI spoofing via crafted HTML pageCVE-2026-17999 · Fixed within SLA · CVE-2026-17999: Chrome Android pre-151.0.7922.72 PIP race enables remote domain spoofing via crafted HTMLCVE-2026-18009 · Fixed within SLA · CVE-2026-18009: Chrome Passwords pre-151.0.7922.72 untrusted input validation flaw enables remote UI spoofing via malicious network trafficCVE-2026-17857 · Fixed within SLA · CVE-2026-17857: Chrome Network cross-origin data leak via crafted HTML before 151.0.7922.72CVE-2026-17929 · Fixed within SLA · CVE-2026-17929: Pre-151.0.7922.72 Chrome DevTools insufficient input validation lets remote attackers bypass navigation via malicious fileCVE-2026-17946 · Fixed within SLA · CVE-2026-17946: Chrome <151.0.7922.72 Dawn uninitialized use leaks process memory via crafted HTML when renderer compromisedCVE-2026-17903 · Fixed within SLA · CVE-2026-17903: Chromecast in Chrome pre-151.0.7922.72 allows LAN script/HTML injection into privileged pageCVE-2026-17921 · Fixed within SLA · CVE-2026-17921: Chrome pre-151.0.7922.72 navigation input validation flaw enables renderer-based navigation restriction bypassCVE-2026-18005 · Fixed within SLA · CVE-2026-18005: Google Chrome WebXR info disclosure from process memory via crafted HTML pre-151.0.7922.72CVE-2026-17962 · Fixed within SLA · CVE-2026-17962: Blink UXSS in Chrome <151.0.7922.72 allows remote script/HTML injection via crafted pageCVE-2026-17911 · Fixed within SLA · CVE-2026-17911: Insufficient SVG policy enforcement in Google Chrome <151.0.7922.72 enables cross-origin data leak via crafted HTMLCVE-2026-18003 · Fixed within SLA · CVE-2026-18003: UI spoofing vulnerability in Chrome iOS <151.0.7922.72 via crafted HTMLCVE-2026-17978 · Fixed within SLA · CVE-2026-17978: Chrome WebCodecs side-channel exposes sensitive process memory via crafted HTML (pre-151.0.7922.72)CVE-2026-17878 · Fixed within SLA · CVE-2026-17878: Chrome <151.0.7922.72 CSS bug enables UXSS via crafted HTML pageCVE-2026-17853 · Fixed within SLA · CVE-2026-17853: Chrome <151.0.7922.72 DevTools: compromised renderer injects script/HTML into privileged pagesCVE-2026-17799 · Fixed within SLA · CVE-2026-17799: Chrome Safe Browsing input validation bug pre-151.0.7922.72 enables DAC bypass via malicious fileCVE-2026-17731 · Fixed within SLA · CVE-2026-17731: Android Chrome Autofill prior to 151.0.7922.72 leaks cross-origin data via crafted pageCVE-2026-17829 · Fixed within SLA · CVE-2026-17829: Chrome Passwords vulnerability pre-151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17944 · Fixed within SLA · CVE-2026-17944: Chrome for iOS <151.0.7922.72 allows navigation restriction bypass via crafted HTMLCVE-2026-17904 · Fixed within SLA · CVE-2026-17904: Android Chrome <151.0.7922.72 NFC policy flaw leaks cross-origin data via crafted HTMLCVE-2026-17936 · Fixed within SLA · CVE-2026-17936: Chrome DevTools vulnerability before 151.0.7922.72 enables bypass of navigation restrictions via crafted HTML with gesturesCVE-2026-17964 · Fixed within SLA · CVE-2026-17964: Incorrect security UI on Chrome Android pre-151.0.7922.72 enables domain spoofing via crafted HTMLCVE-2026-17945 · Fixed within SLA · CVE-2026-17945: Insufficient Navigation input validation in Chrome <151.0.7922.72 allows UI spoofing post-renderer compromiseCVE-2026-17965 · Fixed within SLA · CVE-2026-17965: Chrome iOS <151.0.7922.72: Incorrect security UI allows remote HTML UI spoofingCVE-2026-17941 · Fixed within SLA · CVE-2026-17941: Omnibox URL spoofing in Chrome for iOS before 151.0.7922.72 via crafted HTMLCVE-2026-17850 · Fixed within SLA · CVE-2026-17850: Chrome Permissions bug pre-151.0.7922.72 enables same-origin policy bypass via crafted HTMLCVE-2026-17906 · Fixed within SLA · CVE-2026-17906: Google Chrome <151.0.7922.72 Bluetooth input validation bug allows renderer sandbox escape via HTMLCVE-2026-17954 · Fixed within SLA · CVE-2026-17954: Policy bypass in Chrome MHTML before 151.0.7922.72 leaks cross-origin dataCVE-2026-17745 · Fixed within SLA · CVE-2026-17745: Skia out-of-bounds read enables sandbox escape after renderer compromise, Chrome <151.0.7922.72CVE-2026-17915 · Fixed within SLA · CVE-2026-17915: Android Chrome WebView UI spoofing vulnerability before 151.0.7922.72 via crafted HTMLCVE-2026-17988 · Fixed within SLA · CVE-2026-17988: Chrome <151.0.7922.72 Navigation input validation flaw lets compromised renderer bypass restrictions via crafted HTMLCVE-2026-17892 · Fixed within SLA · CVE-2026-17892: WebXR vulnerability leaks Chrome process memory via crafted HTML (pre-151.0.7922.72)CVE-2026-17846 · Fixed within SLA · CVE-2026-17846: Chrome Windows Media bug pre-151.0.7922.72 allows compromised renderer to bypass same-origin policy via crafted HTMLCVE-2026-17959 · Fixed within SLA · CVE-2026-17959: Chrome Network vulnerability leaked cross-origin data via crafted HTML page pre-151.0.7922.72CVE-2026-17958 · Fixed within SLA · CVE-2026-17958: Google Chrome pre-151.0.7922.72 Views flaw enables remote UI spoofing via crafted HTMLCVE-2026-17932 · Fixed within SLA · CVE-2026-17932: Chrome Windows DataTransfer use-after-free leaks process memory via crafted HTML pre-151.0.7922.72CVE-2026-17926 · Fixed within SLA · CVE-2026-17926: Chrome DevTools insufficient input validation enables navigation bypass via crafted HTML and user gesturesCVE-2026-17939 · Fixed within SLA · CVE-2026-17939: Insufficient untrusted input validation in Chrome Passwords enables UI spoofing via network traffic (pre-151.0.7922.72)CVE-2026-17859 · Fixed within SLA · CVE-2026-17859: Google Chrome <151.0.7922.72 favicon implementation leaks cross-origin data via crafted HTML pageCVE-2026-17938 · Fixed within SLA · CVE-2026-17938: Chrome Android pre-151.0.7922.72 FullScreen flaw enables remote UI spoofing via crafted HTMLCVE-2026-17953 · Fixed within SLA · CVE-2026-17953: Android Chrome WebView policy enforcement bug allows navigation bypass via crafted HTML before 151.0.7922.72CVE-2026-17759 · Fixed within SLA · CVE-2026-17759: Chrome <151.0.7922.72 Codecs uninitialized use leaks memory via crafted HTMLCVE-2026-17814 · Fixed within SLA · CVE-2026-17814: iOS Chrome input validation flaw bypasses navigation restrictions via crafted HTML, pre-151.0.7922.72CVE-2026-17891 · Fixed within SLA · CVE-2026-17891: <151.0.7922.72 Chrome Android ANGLE use-after-free allows sandbox escape via crafted HTMLCVE-2026-17895 · Fixed within SLA · CVE-2026-17895: Chrome pre-151.0.7922.72 DataTransfer flaw leaks cross-origin data via crafted page/UI gesturesCVE-2026-17890 · Fixed within SLA · CVE-2026-17890: Chrome DevTools insufficient input validation enables sandbox escape via crafted HTML from compromised rendererCVE-2026-17815 · Fixed within SLA · CVE-2026-17815: Chrome GuestView insufficient policy enforcement enables cross-origin data leak pre-151.0.7922.72CVE-2026-17794 · Fixed within SLA · CVE-2026-17794: Insufficient input validation enables Chrome Android pre-151.0.7922.72 Omnibox spoofing via crafted HTML after renderer compromiseCVE-2026-17872 · Fixed within SLA · CVE-2026-17872: Cryptographic flaw in WebAppInstalls allows local sandbox escape via crafted HTML in Android Chrome pre-151.0.7922.72CVE-2026-17905 · Fixed within SLA · CVE-2026-17905: Chrome SurfaceCapture bug before 151.0.7922.72 lets remote attacker leak cross-origin data via crafted HTMLCVE-2026-17876 · Fixed within SLA · CVE-2026-17876: Pre-151.0.7922.72 Chrome Payments bug leaks cross-origin data via crafted HTMLCVE-2026-17908 · Fixed within SLA · CVE-2026-17908: Pre-151.0.7922.72 Windows Chrome Printing input validation bug allows sandbox escape via crafted HTML post-renderer compromiseCVE-2026-17910 · Fixed within SLA · CVE-2026-17910: Android Chrome NFC policy enforcement flaw allows remote cross-origin data leak pre-151.0.7922.72CVE-2026-17825 · Fixed within SLA · CVE-2026-17825: Chrome Android <151.0.7922.72 Passwords policy bug allows discretionary access control bypass via crafted HTMLCVE-2026-17843 · Fixed within SLA · CVE-2026-17843: Chrome CSS flaw before 151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17845 · Fixed within SLA · CVE-2026-17845: Chrome <151.0.7922.72 CSS UXSS allows remote script/HTML injection via crafted pageCVE-2026-17901 · Fixed within SLA · CVE-2026-17901: Chrome Android Sharing input validation flaw pre-151.0.7922.72 enables remote navigation bypassCVE-2026-17849 · Fixed within SLA · CVE-2026-17849: Chrome iOS <151.0.7922.72 Omnibox spoofing via malicious network trafficCVE-2026-17893 · Fixed within SLA · CVE-2026-17893: Insufficient input validation in Chrome Mac Updater allows sandbox escape from compromised rendererCVE-2026-17810 · Fixed within SLA · CVE-2026-17810: Chrome Dawn uninitialized use leaks cross-origin data via crafted HTML, pre-151.0.7922.72CVE-2026-17879 · Fixed within SLA · CVE-2026-17879: Chrome Autofill cross-origin data leak via crafted HTML (pre-151.0.7922.72)CVE-2026-17796 · Fixed within SLA · CVE-2026-17796: Google Chrome WebXR side-channel leak exposes process memory via crafted HTML (pre-151.0.7922.72)CVE-2026-17870 · Fixed within SLA · CVE-2026-17870: Chrome Cast pre-151.0.7922.72 insufficient input validation leaks cross-origin data on LANCVE-2026-17880 · Fixed within SLA · CVE-2026-17880: Chrome Autofill cross-origin data leak via crafted HTML page prior to 151.0.7922.72CVE-2026-17737 · Fixed within SLA · CVE-2026-17737: Android Chrome Bluetooth use-after-free enables sandbox escape by compromised renderer via crafted HTML pre-151.0.7922.72CVE-2026-17703 · Fixed within SLA · CVE-2026-17703: Chrome iOS <151.0.7922.72 policy enforcement bug allows navigation restriction bypass via crafted HTML remote attackerCVE-2026-17851 · Fixed within SLA · CVE-2026-17851: Pre-151.0.7922.72 Chrome Autofill side-channel leak enables cross-origin exfiltration via compromised rendererCVE-2026-17885 · Fixed within SLA · CVE-2026-17885: Chrome Paint cross-origin data leak via crafted HTML before 151.0.7922.72CVE-2026-17700 · Fixed within SLA · CVE-2026-17700: Chrome pre-151.0.7922.72 Actor input validation flaw leaks cross-origin data via compromised rendererCVE-2026-17808 · Fixed within SLA · CVE-2026-17808: WebGL uninitialized use leaks cross-origin data in Chrome Android before 151.0.7922.72 via crafted HTMLCVE-2026-17838 · Fixed within SLA · CVE-2026-17838: Chrome iOS pre-151.0.7922.72 incorrect security UI enables domain spoofing via crafted HTMLCVE-2026-17820 · Fixed within SLA · CVE-2026-17820: Chrome pre-151.0.7922.72 Autofill policy flaw leaked cross-origin data via crafted pagesCVE-2026-17871 · Fixed within SLA · CVE-2026-17871: Pre-151.0.7922.72 Chrome Passwords cross-origin data leak via crafted page, UI gesturesCVE-2026-17760 · Fixed within SLA · CVE-2026-17760: Chrome pre-151.0.7922.72 NoStatePrefetch side-channel allowed remote cross-origin data leaks via crafted HTMLCVE-2026-17800 · Fixed within SLA · CVE-2026-17800: Pre-151.0.7922.72 Chrome MediaRecording bug leaks process memory via crafted HTMLCVE-2026-17805 · Fixed within SLA · CVE-2026-17805: Insufficient Glic policy enforcement in Chrome Android <151.0.7922.72 allows remote navigation bypass via HTMLCVE-2026-17839 · Fixed within SLA · CVE-2026-17839: UI spoofing vulnerability in Chrome for iOS before 151.0.7922.72 via crafted HTMLCVE-2026-17793 · Fixed within SLA · CVE-2026-17793: Remote UI spoofing via crafted HTML in Chrome Android Messages pre-151.0.7922.72CVE-2026-17765 · Fixed within SLA · CVE-2026-17765: Google Chrome WebProtect bug pre-151.0.7922.72 lets compromised renderer leak cross-origin data via crafted HTMLCVE-2026-17781 · Fixed within SLA · CVE-2026-17781: Chrome prior to 151.0.7922.72 extension flaw allows malicious extensions to leak cross-origin dataCVE-2026-17835 · Fixed within SLA · CVE-2026-17835: Chrome for iOS <151.0.7922.72 allows remote UI spoofing via crafted HTMLCVE-2026-17831 · Fixed within SLA · CVE-2026-17831: Insufficient validation of untrusted input in Chrome Passwords allows UI spoofing by compromised rendererCVE-2026-17763 · Fixed within SLA · CVE-2026-17763: Chrome <151.0.7922.72 GPU bug allows cross-origin data leak after renderer compromise via crafted HTMLCVE-2026-17693 · Fixed within SLA · CVE-2026-17693: Google Chrome <151.0.7922.72 FileSystem policy flaw enables remote cross-origin data leak via crafted pageCVE-2026-17683 · Fixed within SLA · CVE-2026-17683: ANGLE implementation flaw leaks process memory via crafted HTML in Chrome <151.0.7922.72CVE-2026-17824 · Fixed within SLA · CVE-2026-17824: Insufficient ServiceWorker policy enforcement enabled same-origin policy bypass in Google Chrome pre-151.0.7922.72 via crafted HTMLCVE-2026-17828 · Fixed within SLA · CVE-2026-17828: Google Chrome for iOS <151.0.7922.72 allows UI spoofing via crafted HTMLCVE-2026-17842 · Fixed within SLA · CVE-2026-17842: Chrome iOS <151.0.7922.72 SOP bypass via crafted HTML requiring specific user gesturesCVE-2026-17730 · Fixed within SLA · CVE-2026-17730: Chrome <151 Autofill side-channel allowed cross-origin data leak via crafted page and UI gesturesCVE-2026-17806 · Fixed within SLA · CVE-2026-17806: Google Chrome Extensions pre-151.0.7922.72 input validation flaw enables renderer sandbox escapeCVE-2026-17742 · Fixed within SLA · CVE-2026-17742: Chrome Payments insufficient policy enforcement allows cross-origin data leak via crafted HTML pageCVE-2026-17809 · Fixed within SLA · CVE-2026-17809: Chrome Extensions input validation bug enables sandbox escape via crafted HTML after renderer compromise (<151.0.7922.72)CVE-2026-17817 · Fixed within SLA · CVE-2026-17817: Pre-151.0.7922.72 Chrome ReportingAndNEL cross-origin data leak via crafted HTML pageCVE-2026-17813 · Fixed within SLA · CVE-2026-17813: Policy enforcement flaw allows navigation bypass in Chrome for iOS <151.0.7922.72CVE-2026-17833 · Fixed within SLA · CVE-2026-17833: Google Chrome Passwords pre-151.0.7922.72 cross-origin data leak via crafted HTMLCVE-2026-17819 · Fixed within SLA · CVE-2026-17819: Google Chrome <151.0.7922.72 WebAppInstalls vulnerability allows remote UI spoofing via crafted HTMLCVE-2026-17740 · Fixed within SLA · CVE-2026-17740: ANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17812 · Fixed within SLA · CVE-2026-17812: Chrome <151.0.7922.72 DigitalCredentials flaw enables remote UI spoofing via crafted HTML pageCVE-2026-17753 · Fixed within SLA · CVE-2026-17753: Chrome Autofill vulnerability pre-151.0.7922.72: remote cross-origin data leak via crafted HTMLCVE-2026-17757 · Fixed within SLA · CVE-2026-17757: Chrome Skia uninitialized use allows cross-origin data leak via crafted HTML (pre-151.0.7922.72)CVE-2026-17736 · Fixed within SLA · CVE-2026-17736: Android Chrome <151 WebView input validation bug lets compromised renderer escape sandbox via HTMLCVE-2026-17739 · Fixed within SLA · CVE-2026-17739: Insufficient policy enforcement allows UXSS via malicious extensions in Chrome pre-151.0.7922.72CVE-2026-17707 · Fixed within SLA · CVE-2026-17707: Chrome Windows pre-151.0.7922.72 Media uninitialized use info leak via crafted HTML requiring renderer compromiseCVE-2026-17746 · Fixed within SLA · CVE-2026-17746: Chrome Mac GPU use-after-free allows sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72)CVE-2026-17714 · Fixed within SLA · CVE-2026-17714: High-severity ANGLE uninitialized use in Chrome pre-151.0.7922.72 enables remote memory disclosure via crafted HTMLCVE-2026-17733 · Fixed within SLA · CVE-2026-17733: Chrome Android QUIC flaw enabled remote cross-origin data leak via crafted HTML (pre-151.0.7922.72)CVE-2026-17679 · Fixed within SLA · CVE-2026-17679: Pre-151.0.7922.72 Chrome Print Preview validation flaw leaks cross-origin data via renderer compromiseCVE-2026-17667 · Fixed within SLA · CVE-2026-17667: Remote cross-origin data leak via crafted HTML exploiting ANGLE uninitialized use in Chrome <151.0.7922.72CVE-2026-17689 · Fixed within SLA · CVE-2026-17689: High-severity ANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLCVE-2026-17690 · Fixed within SLA · CVE-2026-17690: Chrome Android PDF input validation flaw allows local cross-origin data leak via crafted HTMLCVE-2026-17696 · Fixed within SLA · CVE-2026-17696: Chrome Media side-channel allows remote cross-origin data leak via crafted HTML (pre-151.0.7922.72)CVE-2026-52972 · Fixed within SLA · CVE-2026-52972: Linux kernel af_alg AEAD AD length arithmetic overflow during TX buffer size checkCVE-2026-17668 · Fixed within SLA · CVE-2026-17668: Chrome <151.0.7922.72 ANGLE uninitialized use leaks cross-origin data via crafted HTMLCVE-2026-63800 · Fixed within SLA · CVE-2026-63800: Use-after-free in pNFS pnfs_update_layout() tracepoint after freeing lo with pnfs_put_layout_hdrCVE-2026-53399 · Fixed within SLA · CVE-2026-53399: Use-after-free via IDR leak and uninitialized delayed_work on nfsd layout setlease failureCVE-2026-53398 · Fixed within SLA · CVE-2026-53398: NFSD: SECINFO_NO_NAME decode leaves stale sin_exp; exp_put called after truncated XDRCVE-2026-63795 · Fixed within SLA · CVE-2026-63795: 9p p9_client_walk error drops oldfid reference when clone=false, causing UAF/refcount underflowCVE-2026-53399 · Fixed within SLA · CVE-2026-53399: nfsd setlease failure frees layout stid without idr_remove, causing IDR dangling pointer dereferenceCVE-2026-17804 · Fixed within SLA · CVE-2026-17804: Use-after-free in Chrome Media enables sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17947 · Fixed within SLA · CVE-2026-17947: Chrome <151.0.7922.72 WebSockets use-after-free allows remote sandbox escape via crafted HTMLCVE-2026-17856 · Fixed within SLA · CVE-2026-17856: Chrome Mac pre-151.0.7922.72 network flaw enables sandbox escape via crafted HTML after renderer compromiseCVE-2026-17727 · Fixed within SLA · CVE-2026-17727: Chrome Android <151.0.7922.72 WebGL out-of-bounds write enables remote sandbox escape via crafted HTMLCVE-2026-17671 · Fixed within SLA · CVE-2026-17671: Chrome ANGLE input validation bug allows sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17990 · Fixed within SLA · CVE-2026-17990: Chrome WebAuthn input validation flaw allows sandbox escape via PDF (pre-151.0.7922.72)CVE-2026-17855 · Fixed within SLA · CVE-2026-17855: DevTools race on Mac Chrome pre-151.0.7922.72 enables sandbox escape from compromised rendererCVE-2026-17991 · Fixed within SLA · CVE-2026-17991: Chrome <151.0.7922.72 AI input validation bug enables sandbox escape from compromised renderer via crafted HTMLCVE-2026-17837 · Fixed within SLA · CVE-2026-17837: Chrome DevTools untrusted input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72)CVE-2026-17848 · Fixed within SLA · CVE-2026-17848: Integer overflow in Google Chrome Codecs enables remote sandbox escape via crafted video pre-151.0.7922.72CVE-2026-17803 · Fixed within SLA · CVE-2026-17803: Chrome pre-151 Save to Drive input validation bug enabling renderer sandbox escape via crafted PDFCVE-2026-17801 · Fixed within SLA · CVE-2026-17801: ANGLE out-of-bounds read/write allows remote attacker sandbox escape via crafted HTML in Chrome <151.0.7922.72CVE-2026-18002 · Fixed within SLA · CVE-2026-18002: Chrome Google Lens insufficient input validation allows renderer sandbox escape via crafted HTMLCVE-2026-17924 · Fixed within SLA · CVE-2026-17924: Chrome pre-151.0.7922.72 DNS use-after-free enables sandbox escape from compromised renderer via HTMLCVE-2026-17721 · Fixed within SLA · CVE-2026-17721: ANGLE out-of-bounds write allows remote sandbox escape via crafted HTML in Chrome <151.0.7922.72 High severityCVE-2026-17865 · Fixed within SLA · CVE-2026-17865: Google Chrome Mac Crypto bug allows sandbox escape from compromised renderer via crafted HTML pre-151.0.7922.72CVE-2026-17709 · Fixed within SLA · CVE-2026-17709: Chrome Mac pre-151.0.7922.72 Downloads race allows sandbox escape after renderer compromiseCVE-2026-17987 · Fixed within SLA · CVE-2026-17987: Chrome Notifications validation flaw enables sandbox escape via crafted PDF after renderer compromise (pre-151)CVE-2026-17692 · Fixed within SLA · CVE-2026-17692: Use-after-free in DataTransfer enables sandbox escape via crafted HTML in Chrome <151.0.7922.72 on WindowsCVE-2026-17940 · Fixed within SLA · CVE-2026-17940: Chrome Android PiP input validation bug enables sandbox escape post-renderer compromise via crafted HTMLCVE-2026-17834 · Fixed within SLA · CVE-2026-17834: Chrome Passwords validation flaw enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72)CVE-2026-17847 · Fixed within SLA · CVE-2026-17847: ANGLE input validation flaw allows sandbox escape via crafted HTML in Chrome <151.0.7922.72CVE-2026-17680 · Fixed within SLA · CVE-2026-17680: Chrome on ChromeOS Color heap buffer overflow enables sandbox escape via HTML, renderer compromise pre-151.0.7922.72CVE-2026-17726 · Fixed within SLA · CVE-2026-17726: WebGL integer overflow allows sandbox escape in Chrome Android before 151.0.7922.72 via crafted HTMLCVE-2026-17676 · Fixed within SLA · CVE-2026-17676: ANGLE bug enables post-renderer-compromise sandbox escape via crafted HTML in Chrome Android <151.0.7922.72CVE-2026-17832 · Fixed within SLA · CVE-2026-17832: Use-after-free in ANGLE allows sandbox escape in Google Chrome pre-151.0.7922.72 via crafted HTMLCVE-2026-17718 · Fixed within SLA · CVE-2026-17718: Use-after-free in ANGLE allows remote sandbox escape via crafted HTML on Chrome <151.0.7922.72CVE-2026-17687 · Fixed within SLA · CVE-2026-17687: ANGLE type confusion in Chrome <151.0.7922.72 enables sandbox escape via crafted HTML after renderer compromiseCVE-2026-17697 · Fixed within SLA · CVE-2026-17697: Chrome ANGLE type confusion enabling sandbox escape via crafted HTML in versions <151.0.7922.72CVE-2026-17717 · Fixed within SLA · CVE-2026-17717: High severity ANGLE integer overflow in Chrome <151.0.7922.72 enables remote sandbox escape via crafted HTMLCVE-2026-17758 · Fixed within SLA · CVE-2026-17758: Dawn heap buffer overflow in Chrome <151.0.7922.72 enables potential remote sandbox escape via crafted HTMLCVE-2026-17666 · Fixed within SLA · CVE-2026-17666: Chrome Enterprise <151.0.7922.72 crypto bug allows discretionary access control bypass via network MITMCVE-2026-17681 · Fixed within SLA · CVE-2026-17681: Chrome Android WebAuthn input validation flaw enables renderer-compromised sandbox escape via crafted HTML pre-151.0.7922.72CVE-2026-17711 · Fixed within SLA · CVE-2026-17711: Chrome Mac <151.0.7922.72 Downloads race allows sandbox escape after renderer compromise via crafted HTML pageCVE-2026-17710 · Fixed within SLA · CVE-2026-17710: Google Chrome Mac <151.0.7922.72 MHTML flaw enables sandbox escape from compromised renderer via crafted HTMLCVE-2026-17672 · Fixed within SLA · CVE-2026-17672: Chromecast input validation flaw enables sandbox escape via crafted HTML (Chrome <151.0.7922.72)CVE-2026-17695 · Fixed within SLA · CVE-2026-17695: Chrome Mac ANGLE flaw allows remote sandbox escape via crafted HTML pre-151.0.7922.72CVE-2026-17708 · Fixed within SLA · CVE-2026-17708: Google Chrome Audio use-after-free enables sandbox escape from compromised renderer via crafted HTML pre-151.0.7922.72CVE-2026-17670 · Fixed within SLA · CVE-2026-17670: Use-after-free in Chrome Views allows sandbox escape via crafted HTML from compromised rendererCVE-2026-17691 · Fixed within SLA · CVE-2026-17691: Out-of-bounds write in ANGLE enables remote sandbox escape in Chrome Windows pre-151.0.7922.72CVE-2026-17682 · Fixed within SLA · CVE-2026-17682: ANGLE integer overflow in Chrome <151.0.7922.72 enables post-renderer sandbox escapeCVE-2026-17684 · Fixed within SLA · CVE-2026-17684: Chrome for iOS <151.0.7922.72: Insufficient input validation enables renderer sandbox escape via crafted HTMLCVE-2026-17704 · Fixed within SLA · CVE-2026-17704: Chrome <151.0.7922.72 ANGLE use-after-free enables sandbox escape via crafted HTMLCVE-2026-17669 · Fixed within SLA · CVE-2026-17669: iOS Chrome <151.0.7922.72 allows remote sandbox escape via crafted HTML pageCVE-2026-17688 · Fixed within SLA · CVE-2026-17688: Chrome <151.0.7922.72 Input use-after-free allows renderer sandbox escape via crafted HTMLCVE-2026-5450 · Fixed within SLA · CVE-2026-5450: glibc scanf %mc width >1024 triggers 1-byte heap overflow in v2.7-2.43CVE-2026-17673 · Fixed within SLA · CVE-2026-17673: Pre-151.0.7922.72 Chrome QUIC integer overflow enables sandbox escape from compromised renderer via crafted HTMLCVE-2026-17651 · Fixed within SLA · CVE-2026-17651: Insufficient input validation in Chrome Android Dawn allows remote sandbox escape via crafted HTMLCVE-2026-17675 · Fixed within SLA · CVE-2026-17675: ANGLE out-of-bounds write enables sandbox escape via crafted HTML in Chrome <151.0.7922.72CVE-2026-17720 · Fixed within SLA · CVE-2026-17720: High-severity Chrome Passwords policy flaw leaks cross-origin data via compromised renderer (pre-151.0.7922.72)CVE-2026-17984 · Fixed within SLA · CVE-2026-17984: Chrome Android <151.0.7922.72 cross-origin data leak via crafted HTML, local attackerCVE-2026-17997 · Fixed within SLA · CVE-2026-17997: Chrome Passwords <151.0.7922.72 cross-origin data leak via renderer-compromised crafted HTMLCVE-2026-18000 · Fixed within SLA · CVE-2026-18000: Chrome Android USB policy flaw prior to 151.0.7922.72 leaks cross-origin data via compromised rendererCVE-2026-17902 · Fixed within SLA · CVE-2026-17902: Chrome Linux Editing component leaks cross-origin data via crafted HTML prior to 151.0.7922.72CVE-2026-17980 · Fixed within SLA · CVE-2026-17980: Chrome Android <151.0.7922.72 UI flaw enables cross-origin data leak via crafted pageCVE-2026-17957 · Fixed within SLA · CVE-2026-17957: Low-severity CORS flaw in Chrome <151.0.7922.72 enables cross-origin leak via compromised rendererCVE-2026-18011 · Fixed within SLA · CVE-2026-18011: Chrome for iOS <151.0.7922.72 exposes process memory to local physical attackerCVE-2026-17860 · Fixed within SLA · CVE-2026-17860: Android Chrome <151.0.7922.72: Omnibox spoofing via malicious local file; insufficient input validationCVE-2026-17826 · Fixed within SLA · CVE-2026-17826: Chrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML and UI gestures Medium severityCVE-2026-17715 · Fixed within SLA · CVE-2026-17715: Chrome Passwords before 151.0.7922.72: cross-origin data leak via crafted HTML, UI gesturesCVE-2026-17732 · Fixed within SLA · CVE-2026-17732: Pre-151.0.7922.72 Chrome SVG flaw leaks cross-origin data via crafted HTMLCVE-2026-17766 · Fixed within SLA · CVE-2026-17766: Android Chrome Clipboard validation flaw prior to 151.0.7922.72 leaks cross-origin data locallyCVE-2026-17702 · Fixed within SLA · CVE-2026-17702: Chrome <151.0.7922.72 Skia cross-origin data leak via crafted HTML with compromised rendererCVE-2026-64831 · Fixed within SLA · CVE-2026-64831: FFmpeg 8.0-8.1.2 Vulkan HEVC decoder stack buffer overflow enables remote code executionCVE-2026-64834 · Fixed within SLA · CVE-2026-64834: FFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS in rtp_asf_fix_headerCVE-2026-64830 · Fixed within SLA · CVE-2026-64830: FFmpeg 2.1-8.1.2 VobSub demuxer heap overflow from .sub/.idx with excessive stream IDsCVE-2026-64835 · Fixed within SLA · CVE-2026-64835: FFmpeg ADX decoder OOB read/write on mid-stream extradata channel change (v4.4–8.1.2)CVE-2026-64832 · Fixed within SLA · CVE-2026-64832: FFmpeg 4.4–8.1.2 NVDEC double-free enables memory corruption via crafted video filesCVE-2026-64833 · Fixed within SLA · CVE-2026-64833: FFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_sizeCVE-2026-64834 · Fixed within SLA · CVE-2026-64834: FFmpeg RTP/ASF demuxer infinite loop DoS via undersized chunk in rtp_asf_fix_headerCVE-2026-64830 · Fixed within SLA · CVE-2026-64830: FFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via excessive subtitle stream IDs (RCE)CVE-2026-64831 · Fixed within SLA · CVE-2026-64831: FFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack overflow via crafted bitstream enabling RCECVE-2026-64835 · Fixed within SLA · CVE-2026-64835: FFmpeg 4.4–8.1.2 ADX decoder OOB on mid-stream channel layout changeCVE-2026-64833 · Fixed within SLA · CVE-2026-64833: FFmpeg S/PDIF muxer out-of-bounds read via crafted DTS core_size during remuxingCVE-2026-64832 · Fixed within SLA · CVE-2026-64832: FFmpeg 4.4–8.1.2 NVDEC double-free causes memory corruption with crafted videosCVE-2026-64834 · Fixed within SLA · CVE-2026-64834: FFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS on crafted streamCVE-2026-64831 · Fixed within SLA · CVE-2026-64831: FFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack buffer overflow via oversized vps_num_hrd_parameters causing RCECVE-2026-64835 · Fixed within SLA · CVE-2026-64835: FFmpeg 4.4–8.1.2 ADX decoder OOB read/write on mid-stream channel layout changeCVE-2026-64830 · Fixed within SLA · CVE-2026-64830: FFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via crafted .sub/.idx stream IDsCVE-2026-64833 · Fixed within SLA · CVE-2026-64833: FFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_sizeCVE-2026-64832 · Fixed within SLA · CVE-2026-64832: FFmpeg 4.4–8.1.2 NVDEC nvdec.c double-free allows memory corruption via crafted videoCVE-2026-50243 · Fixed within SLA · CVE-2026-50243: Unbound respip with response-ip/RPZ ignores DNSSEC; rewrites BOGUS A/AAAA to operator IP as INSECURECVE-2026-55717 · Fixed within SLA · CVE-2026-55717: Unbound 1.10.0–1.25.1 crash: serve-expired with respip/RPZ CNAME causes NULL dereference DoSCVE-2026-50045 · Fixed within SLA · CVE-2026-50045: Unbound 1.22.0–1.25.1 exceeds max-global-quota on deeply nested DNSSEC query, bypassing amplification limitsCVE-2026-55991 · Fixed within SLA · CVE-2026-55991: Unbound 1.22–1.25.1 DoQ: unauth client aborts process via libngtcp2 assertion failureCVE-2026-56444 · Fixed within SLA · CVE-2026-56444: Unbound 1.20.0–1.25.1 serve-expired misconfig causes discard-timeout counter leak, silently dropping duplicate clientsCVE-2026-56416 · Fixed within SLA · CVE-2026-56416: NLnet Labs Unbound ≤1.25.1 heap overflow canonicalizing RRSIG-covered multi-dname RDATA missing second nameCVE-2026-55990 · Fixed within SLA · CVE-2026-55990: Unbound 1.7.0–1.25.1 DNSCrypt DoS from misconfigured extra certs, crafted UDPCVE-2026-53106 · Fixed within SLA · CVE-2026-53106: Deleting BPF local storage in NMI/reentrant contexts may deadlock via RCU deferralCVE-2026-53108 · Fixed within SLA · CVE-2026-53108: powerpc/64s: munmap race with PMD migration entries hits VM_BUG_ON in pmdp_huge_get_and_clear_fullCVE-2026-52863 · Fixed within SLA · CVE-2026-52863: Unbound 1.25.0–1.25.1 shallow view-name copy causes memory corruption with subqueries under jostleCVE-2026-50248 · Fixed within SLA · CVE-2026-50248: Unbound 1.7.0-1.25.1 accepts bogus primary hostname for XFR, enabling RPZ takeoverCVE-2026-50251 · Fixed within SLA · CVE-2026-50251: Unbound ≤1.25.1 DoS: 0.0.0.0/::0 glue triggers unwanted-reply-threshold cache flush loopCVE-2026-53104 · Fixed within SLA · CVE-2026-53104: mt76 WiFi driver memory leak from RX queue page_pools on device destroyCVE-2026-53107 · Fixed within SLA · CVE-2026-53107: libertas wifi: URBs killed in interrupt context causing sleep-in-atomic bug on TX pathCVE-2026-44621 · Fixed within SLA · CVE-2026-44621: libunbound <=1.25.1 terminates when unwanted-reply-threshold triggers; libworker_alloc_cleanup missing allowlistCVE-2026-50046 · Fixed within SLA · CVE-2026-50046: Use-after-free in Unbound DoT TLS server name causes crash during handshakeCVE-2026-53113 · Fixed within SLA · CVE-2026-53113: ath11k EMA/MBSSID beacon template memory leak on parameter setup error pathsCVE-2026-53108 · Fixed within SLA · CVE-2026-53108: powerpc/64s race between move_pages PMD migration and munmap hits VM_BUG_ON in pmdp_huge_get_and_clear_fullCVE-2026-44621 · Fixed within SLA · CVE-2026-44621: libunbound up to 1.25.1 crash: unwanted-reply-threshold triggers disallowed libworker_alloc_cleanup callCVE-2026-56444 · Fixed within SLA · CVE-2026-56444: Unbound 1.20–1.25.1 counter not decremented in serve-expired discard-timeout; clients droppedCVE-2026-50045 · Fixed within SLA · CVE-2026-50045: Unbound 1.22.0–1.25.1 bypasses max-global-quota via deeply nested DNSSEC query amplificationCVE-2026-55991 · Fixed within SLA · CVE-2026-55991: Unbound 1.22-1.25.1 DoQ remote crash: libngtcp2 assert via -1 application error on STREAM_DATA_BLOCKEDCVE-2026-53113 · Fixed within SLA · CVE-2026-53113: Linux wifi ath11k: memory leaks in beacon template setup error paths (EMA/MBSSID)CVE-2026-50248 · Fixed within SLA · CVE-2026-50248: Unbound 1.7.0–1.25.1 accepts BOGUS XFR primary hostname, enabling spoofed zone/RPZ takeoverCVE-2026-56416 · Fixed within SLA · CVE-2026-56416: Unbound ≤1.25.1 heap overflow processing absent second name in multi-dname RDATA (SOA) during DNSSEC validationCVE-2026-55717 · Fixed within SLA · CVE-2026-55717: Remote Unbound 1.10.0–1.25.1 crash DoS with serve-expired + respip CNAME override, NULL derefCVE-2026-50243 · Fixed within SLA · CVE-2026-50243: Unbound respip/RPZ ignores DNSSEC status, rewriting BOGUS A/AAAA to INSECURE spoofable redirectsCVE-2026-53124 · Fixed within SLA · CVE-2026-53124: Partial IO fetch leaves canceled flags set, blocking ublk io_uring cancel completionCVE-2026-50046 · Fixed within SLA · CVE-2026-50046: Unbound DoT TLS server name dangling pointer during handshake triggers crash/DoS (1.15–1.25.1)CVE-2026-55990 · Fixed within SLA · CVE-2026-55990: Unbound 1.7.0–1.25.1 DNSCrypt cert/key count mismatch causes unauthenticated UDP-triggered crashCVE-2026-53106 · Fixed within SLA · CVE-2026-53106: Linux kernel: Deadlock deleting BPF local storage in NMI due to RCU deferralCVE-2026-50251 · Fixed within SLA · CVE-2026-50251: Unbound <=1.25.1: 0.0.0.0/::0 glue triggers unwanted-reply threshold DoS cache flushesCVE-2026-52863 · Fixed within SLA · CVE-2026-52863: Unbound 1.25.0–1.25.1 respip/dns64 shallow view-name copy corrupts memory under pressureCVE-2026-50243 · Fixed within SLA · CVE-2026-50243: Unbound ≤1.25.1 respip before validator ignores DNSSEC, rewriting BOGUS A/AAAA INSECURE, enabling poisoning.CVE-2026-55990 · Fixed within SLA · CVE-2026-55990: Unbound 1.7.0–1.25.1 DNSCrypt DoS from cert/secret mismatch; 0xdb-triggered UDP crashCVE-2026-55991 · Fixed within SLA · CVE-2026-55991: Unauthenticated DoQ client crashes Unbound 1.22–1.25.1 via libngtcp2 assertion from -1 errorCVE-2026-55717 · Fixed within SLA · CVE-2026-55717: Unbound 1.10.0–1.25.1 DoS: serve-expired with respip/RPZ CNAME triggers NULL pointer crashCVE-2026-56444 · Fixed within SLA · CVE-2026-56444: Unbound 1.20–1.25 misconfigured serve-expired discard-timeout fails counter decrement, drops duplicate clientsCVE-2026-52863 · Fixed within SLA · CVE-2026-52863: Unbound 1.25.0–1.25.1 subquery shallow view-name copy risks memory corruption with respip/dns64CVE-2026-56416 · Fixed within SLA · CVE-2026-56416: Unbound ≤1.25.1 heap overflow canonicalizing RRSIG-covered PX/RP/MINFO/SOA with missing second nameCVE-2026-53108 · Fixed within SLA · CVE-2026-53108: PowerPC64: PMD migration/munmap race causes VM_BUG_ON in pmdp_huge_get_and_clear_fullCVE-2026-50251 · Fixed within SLA · CVE-2026-50251: Unbound ≤1.25.1 DoS: 0.0.0.0/::0 glue with unwanted-reply-threshold triggers endless cache flushesCVE-2026-44621 · Fixed within SLA · CVE-2026-44621: libunbound <=1.25.1 aborts when unwanted-reply-threshold invokes disallowed libworker_alloc_cleanupCVE-2026-50046 · Fixed within SLA · CVE-2026-50046: Unbound DoT TLS handshake use-after-free leads to daemon crash (1.15.0–1.25.1)CVE-2026-50248 · Fixed within SLA · CVE-2026-50248: Unbound 1.7.0–1.25.1 accepts bogus RPZ primary, enabling spoofed XFR and policy takeoverCVE-2026-50045 · Fixed within SLA · CVE-2026-50045: Unbound 1.22–1.25.1 upstream packets per query exceed max-global-quota for deep DNSSEC namesCVE-2026-53124 · Fixed within SLA · CVE-2026-53124: ublk I/O cancellation may never complete due to stale per-IO canceled flag after partial fetchCVE-2026-53106 · Fixed within SLA · CVE-2026-53106: BPF local storage deletion in NMI or reentrant contexts may deadlock via RCU freeingCVE-2026-53113 · Fixed within SLA · CVE-2026-53113: ath11k: memory leaks in beacon template setup error paths (EMA/MBSSID)CVE-2026-53109 · Fixed within SLA · CVE-2026-53109: powerpc/pgtable-frag: pte_frag_destroy leaves folio active, causing bad page state on exitCVE-2026-55973 · Fixed within SLA · CVE-2026-55973: Unbound 1.23-1.25.1 EDNS Report-Channel flaw crashes daemon when dns-error-reporting enabled via crafted responseCVE-2026-40691 · Fixed within SLA · CVE-2026-40691: Unbound 1.9.0–1.25.1 DNSCrypt TCP reply heap overflow causes DoS when DNSCrypt enabledCVE-2026-44690 · Fixed within SLA · CVE-2026-44690: Unbound DNS 1.7.0–1.25.1 RRSIG.Labels/aggressive NSEC bug enables sibling zone cache poisoningCVE-2026-53091 · Fixed within SLA · CVE-2026-53091: GSO headers not in skb->head during qdisc init, risking tso_build_hdr memcpy misuseCVE-2026-53092 · Fixed within SLA · CVE-2026-53092: BPF verifier miscomputes delta when src==dst, causing linked reg verifier-vs-runtime mismatchCVE-2026-32665 · Fixed within SLA · CVE-2026-32665: Unbound downstream DoQ initial streams bypass quic-size, enabling remote memory DoS (1.22.0–1.25.1)CVE-2026-53089 · Fixed within SLA · CVE-2026-53089: Offloaded BPF map/prog info query triggers UAF via get_net during netns teardownCVE-2026-53330 · Fixed within SLA · CVE-2026-53330: AMD DRM: Out-of-bounds read in dp_get_eq_aux_rd_interval with 8 LTTPR repeatersCVE-2026-53118 · Fixed within SLA · CVE-2026-53118: Linux vdpa: Unlocked driver_override access during __driver_attach() match() causes UAFCVE-2026-53090 · Fixed within SLA · CVE-2026-53090: BPF verifier fails to simulate ld_{abs,ind} subprog failure path causing unsafe returnsCVE-2026-55973 · Fixed within SLA · CVE-2026-55973: Unbound 1.23–1.25.1 dns-error-reporting Report-Channel parsing bug allows remote DoSCVE-2026-53091 · Fixed within SLA · CVE-2026-53091: qdisc_pkt_len_segs_init fails to pull GSO headers, risking memcpy issues in TSO driversCVE-2026-40691 · Fixed within SLA · CVE-2026-40691: Heap overflow in Unbound DNSCrypt TCP reply path enables DoS (1.9.0–1.25.1)CVE-2026-53090 · Fixed within SLA · CVE-2026-53090: BPF verifier misses ld_{abs,ind} failure path analysis in subprograms, mishandling abnormal exitsCVE-2026-53089 · Fixed within SLA · CVE-2026-53089: Use-after-free when querying offloaded BPF map/prog due to netns teardown raceCVE-2026-44690 · Fixed within SLA · CVE-2026-44690: Unbound 1.7–1.25.1 RRSIG.Labels/aggressive NSEC flaw enables cross-sibling DNS cache poisoningCVE-2026-32665 · Fixed within SLA · CVE-2026-32665: Unbound 1.22–1.25.1: first DoQ streams bypass per-stream quic-size, enabling memory DoSCVE-2026-55973 · Fixed within SLA · CVE-2026-55973: Unbound 1.23–1.25.1 EDNS Report-Channel length bug causes stack overwrite, crash with dns-error-reportingCVE-2026-40691 · Fixed within SLA · CVE-2026-40691: Unbound 1.9.0–1.25.1 DNSCrypt TCP path overflow causes heap corruption and DoSCVE-2026-32665 · Fixed within SLA · CVE-2026-32665: Unbound downstream DoQ initial streams bypass quic-size, causing remote memory-accounting DoS (v1.22–1.25.1)CVE-2026-44690 · Fixed within SLA · CVE-2026-44690: Unbound 1.7.0–1.25.1 RRSIG.Labels validation bug enables NSEC sibling zone cache poisoningCVE-2026-53091 · Fixed within SLA · CVE-2026-53091: GSO headers not pulled in qdisc_pkt_len_segs_init risk TSO memcpy crash, security issueCVE-2026-53090 · Fixed within SLA · CVE-2026-53090: BPF verifier omits ld_{abs,ind} failure path analysis in BTF subprogramsCVE-2026-53089 · Fixed within SLA · CVE-2026-53089: Use-after-free when filling offloaded BPF map/prog info due to netns teardown raceCVE-2026-55708 · Fixed within SLA · CVE-2026-55708: Unbound control-created view local-zone tree lacks defaults; protected names resolve publiclyCVE-2026-44687 · Fixed within SLA · CVE-2026-44687: Unbound harden-below-nxdomain off-by-one bypasses stub/forward zones via parent secure NXDOMAINCVE-2026-42955 · Fixed within SLA · CVE-2026-42955: Unbound 1.16.2–1.25.1 ghost domain vuln extends A/AAAA glue TTL window, CVE-2026-40622 variantCVE-2026-46582 · Fixed within SLA · CVE-2026-46582: Unbound 1.6.0–1.25.1 cache poisoning via DNSSEC wildcard replay on serve-expired pathCVE-2026-41637 · Fixed within SLA · CVE-2026-41637: Unbound 1.22.0-1.25.1 DoQ termination miscount inflates waiting replies, causing query dropsCVE-2026-54478 · Fixed within SLA · CVE-2026-54478: Unbound 1.18–1.25.1 proxy-protocol miscomputes DNS cookie, enabling off-path spoofed replaysCVE-2026-54478 · Fixed within SLA · CVE-2026-54478: Unbound 1.18–1.25 PROXYv2 computes DNS cookie from proxy IP, enabling off-path UDP spoofingCVE-2026-55708 · Fixed within SLA · CVE-2026-55708: Unbound unbound-control view_local_data(s) omits default-protected zones; protected queries leak to public DNSCVE-2026-44687 · Fixed within SLA · CVE-2026-44687: Unbound 1.13.2-1.25.1: harden-below-nxdomain off-by-one shadows stub/forward zones under DNSSECCVE-2026-42955 · Fixed within SLA · CVE-2026-42955: Unbound 1.16.2–1.25.1 A/AAAA glue ghost domain TTL extension via cache overwriteCVE-2026-46582 · Fixed within SLA · CVE-2026-46582: Unbound 1.6.0–1.25.1 DNSSEC wildcard replay causes cache poisoning on serve-expiredCVE-2026-41637 · Fixed within SLA · CVE-2026-41637: Unbound 1.22–1.25.1 DoQ termination miscount inflates waiters, causing service degradation and silent dropsCVE-2026-54478 · Fixed within SLA · CVE-2026-54478: Unbound PROXYv2 server cookie keyed to proxy, enabling off-path UDP cookie replayCVE-2026-42955 · Fixed within SLA · CVE-2026-42955: Unbound 1.16.2–1.25.1 A/AAAA glue bug extends ghost-domain window; CVE-2026-40622 variantCVE-2026-55708 · Fixed within SLA · CVE-2026-55708: Unbound 1.6.0–1.25.1: unbound-control creates view local zones without defaults; protected queries leakCVE-2026-44687 · Fixed within SLA · CVE-2026-44687: Unbound 1.13.2–1.25.1 harden-below-nxdomain off-by-one returns parent NXDOMAIN, shadowing stub/forward zonesCVE-2026-46582 · Fixed within SLA · CVE-2026-46582: DNSSEC wildcard replay cache poisoning in Unbound 1.6.0–1.25.1 serve-expired pathCVE-2026-41637 · Fixed within SLA · CVE-2026-41637: Unbound 1.22–1.25.1 DoQ termination misaccounting inflates waiters, causing silent query dropsCVE-2026-50252 · Fixed within SLA · CVE-2026-50252: Unbound 1.4.22–1.25.1 SO_REUSEPORT thread partitioning leaks source port entropy, enabling DNS cache poisoningCVE-2026-50252 · Fixed within SLA · CVE-2026-50252: Unbound 1.4.22–1.25.1 SO_REUSEPORT per-thread port partitioning leaks entropy, enabling DNS cache poisoningCVE-2026-50252 · Fixed within SLA · CVE-2026-50252: Unbound 1.4.22–1.25.1 SO_REUSEPORT per-thread port partition leaks entropy, enabling DNS cache poisoningCVE-2026-53102 · Fixed within SLA · CVE-2026-53102: Linux mt76 skb memory leak when mt76_connac_mcu_alloc_sta_req fails in wed_update/key_tlvCVE-2026-53365 · Fixed within SLA · CVE-2026-53365: vsock/virtio zerocopy multi-skb sends miss completion tracking, leaking pinned pages, no notificationCVE-2026-53103 · Fixed within SLA · CVE-2026-53103: Deadlock during station removal: mt7925_roc_abort_sync vs roc_work holding dev->mt76.mutexCVE-2026-53102 · Fixed within SLA · CVE-2026-53102: Linux mt76 WiFi driver leaks skb on error path before mt76_mcu_skb_send_msgCVE-2026-53102 · Fixed within SLA · CVE-2026-53102: mt76 wifi driver memory leak on sta_wed_update/sta_key_tlv failures after skb allocationCVE-2026-53078 · Fixed within SLA · CVE-2026-53078: BPF sock_ops dst==src macro bug causes OOB read and kernel pointer leakCVE-2026-53078 · Fixed within SLA · CVE-2026-53078: Same-register dst/src in BPF sock_ops leaves dst unzeroed, causing OOB read and leakCVE-2026-53362 · Fixed within SLA · CVE-2026-53362: Unprivileged IPv6 UDP fraggap misaccounting overflows skb in paged allocation using MSG_SPLICE_PAGESCVE-2026-53366 · Fixed within SLA · CVE-2026-53366: Linux kernel IPv4 __ip_append_data paged allocation miscalculates fraggap, causing undersized linear area, overstated pagedlenCVE-2026-53361 · Fixed within SLA · CVE-2026-53361: af_unix race: unix_gc may run with gc_in_progress false, breaking MSG_PEEK safetyCVE-2026-53359 · Fixed within SLA · CVE-2026-53359: KVM x86 shadow paging UAF due to child page role mismatch after PDE changeCVE-2026-53361 · Fixed within SLA · CVE-2026-53361: af_unix race: unix_gc may run with gc_in_progress=false, breaking MSG_PEEK handlingCVE-2026-53362 · Fixed within SLA · CVE-2026-53362: IPv6 paged path fraggap misaccounting overflows skb via UDPv6 MSG_MORE/MSG_SPLICE_PAGESCVE-2026-53078 · Fixed within SLA · CVE-2026-53078: BPF sock_ops GET_SK/GET_FIELD miss zeroing when dst==src, causing OOB read and leakCVE-2026-53359 · Fixed within SLA · CVE-2026-53359: KVM x86 UAF: role mismatch reuses shadow page after PDE split 2MB→4KB; rmap not removedCVE-2026-53366 · Fixed within SLA · CVE-2026-53366: IPv4 __ip_append_data paged allocation misaccounts fraggap causing undersized linear area, overstated pagedlenCVE-2026-53027 · Fixed within SLA · CVE-2026-53027: Missing run load for vcn0 across segments in ntfs3 attr_data_get_block_locked causes SPARSE_LCN WARN_ONCVE-2026-53017 · Fixed within SLA · CVE-2026-53017: f2fs data loss when fsync of new file races with checkpoint due to nat flagsCVE-2026-53027 · Fixed within SLA · CVE-2026-53027: ntfs3 attr_data_get_block_locked() misses vcn0 run load across segments, triggers WARN_ONCVE-2026-53017 · Fixed within SLA · CVE-2026-53017: Linux f2fs data loss when new-file fsync races with checkpoint nat_entry flagsCVE-2026-53025 · Fixed within SLA · CVE-2026-53025: Linux kernel Greybus raw cdev close use-after-free after bundle disconnect causes refcount underflowCVE-2026-53024 · Fixed within SLA · CVE-2026-53024: Linux Greybus raw: use-after-free on write after disconnect triggers kernel panicCVE-2026-53025 · Fixed within SLA · CVE-2026-53025: Use-after-free in Greybus raw cdev on close after bundle disconnect causes panicCVE-2026-53024 · Fixed within SLA · CVE-2026-53024: Greybus raw: use-after-free on write after disconnect causes kernel panicCVE-2026-38753 · Fixed within SLA · CVE-2026-38753: BusyBox 1.38.0 awk_sub() use-after-free in editors/awk.c enables DoS via crafted AWK scriptCVE-2026-38755 · Fixed within SLA · CVE-2026-38755: Heap overflow in BusyBox 1.38.0 shell/ash.c evalcommand() enables DoS via crafted inputCVE-2026-38754 · Fixed within SLA · CVE-2026-38754: Heap overflow in BusyBox 1.38.0 shell/ash.c ifsbreakup() enabling DoS via crafted inputCVE-2026-53018 · Fixed within SLA · CVE-2026-53018: f2fs GC reads already updated page causing VM_BUG_ON in folio_end_readCVE-2026-53017 · Fixed within SLA · CVE-2026-53017: F2FS data loss from incorrect nat_entry flag use in fsync-checkpoint raceCVE-2026-52994 · Fixed within SLA · CVE-2026-52994: vsock/virtio MSG_ZEROCOPY misaccounts pinned pages; last skb skips RLIMIT_MEMLOCK enforcementCVE-2026-53027 · Fixed within SLA · CVE-2026-53027: NTFS3: Missing vcn0 run load causes SPARSE_LCN and WARN_ON in attr_data_get_block_lockedCVE-2026-53024 · Fixed within SLA · CVE-2026-53024: Greybus gb_raw use-after-free on write after disconnect triggers kernel panicCVE-2026-52972 · Fixed within SLA · CVE-2026-52972: Arithmetic overflow in af_alg AEAD AD length leads to TX buffer size miscalculationCVE-2026-52965 · Fixed within SLA · CVE-2026-52965: drm/ttm: Infinite LRU walk restoring bulk_move after ttm_bo_swapout() swapout failureCVE-2026-53008 · Fixed within SLA · CVE-2026-53008: Linux kernel ice driver TX timestamp ring cleanup race causes NULL dereferenceCVE-2026-53007 · Fixed within SLA · CVE-2026-53007: Potential NULL dereference in ice_set_ringparam error path due to uncleared ICE_TX_RING_FLAGS_TXTIMECVE-2026-52949 · Fixed within SLA · CVE-2026-52949: Linux kernel drm/ttm ttm_bo_shrink() infinite LRU walk on backup failureCVE-2026-52965 · Fixed within SLA · CVE-2026-52965: drm/ttm: Infinite LRU loop on ttm_bo_swapout when swapout failsCVE-2026-53008 · Fixed within SLA · CVE-2026-53008: ice: race between ice_free_tx_tstamp_ring and ice_tx_map causes NULL derefCVE-2026-52949 · Fixed within SLA · CVE-2026-52949: DRM/TTM ttm_bo_shrink() infinite LRU walk on backup failureCVE-2026-53007 · Fixed within SLA · CVE-2026-53007: ice: Potential NULL dereference in ice_set_ringparam() error path with TXTIME flag setCVE-2026-52960 · Fixed within SLA · CVE-2026-52960: ceph: Missing folio_put for writeback-ineligible folios removed from batch causes reference leakCVE-2026-52988 · Fixed within SLA · CVE-2026-52988: Netfilter nf_tables: netlink dump race from non-RCU hook list joins during commitCVE-2026-53009 · Fixed within SLA · CVE-2026-53009: Linux ice driver double-free of skb during tx ring cleanup after TSO/CSUM failureCVE-2026-52956 · Fixed within SLA · CVE-2026-52956: libceph __ceph_x_decrypt out-of-bounds read when hdr->magic accessed without header-size checkCVE-2026-57432 · Fixed within SLA · CVE-2026-57432: Perl <=5.43.10 pack/unpack integer overflow in S_measure_struct enables out-of-bounds heap readCVE-2026-52956 · Fixed within SLA · CVE-2026-52956: libceph __ceph_x_decrypt() OOB read if buffer smaller than ceph_x_encrypt_headerCVE-2026-53009 · Fixed within SLA · CVE-2026-53009: ice driver double-free of tx_buf skb after tso/csum failure and interface downCVE-2026-52960 · Fixed within SLA · CVE-2026-52960: Ceph writeback path leaks folio references for folios not suitable for writebackCVE-2026-52988 · Fixed within SLA · CVE-2026-52988: nf_tables hook list update RCU race breaks netlink dump traversal during ruleset updatesCVE-2026-53005 · Fixed within SLA · CVE-2026-53005: SOCKMAP redirect hides inflight FDs from AF_UNIX GC, causing leaks and use-after-freeCVE-2026-57432 · Fixed within SLA · CVE-2026-57432: Perl ≤5.43.10 pack/unpack S_measure_struct overflow allows out-of-bounds heap read via large repeat countsCVE-2026-46314 · Fixed within SLA · CVE-2026-46314: drm/v3d infinite loop via empty multisync extension; userspace self-referential chain DoSCVE-2026-53292 · Fixed within SLA · CVE-2026-53292: Phonet: pn_socket_autobind BUG_ON on EINVAL bind causes user-triggerable kernel panicCVE-2026-53226 · Fixed within SLA · CVE-2026-53226: Rockchip GPIO: generic IRQ chips leaked on remove, causing potential UAF and crashesCVE-2026-46092 · Fixed within SLA · CVE-2026-46092: rtw88 8821CE probe crash due to NULL pci_upstream_bridge on root busCVE-2026-45901 · Fixed within SLA · CVE-2026-45901: nf_tables reset commit_mutex causes circular lock dependency with nft reset, ipset list, iptables-nft -m setCVE-2026-46092 · Fixed within SLA · CVE-2026-46092: rtw88 8821CE probe crash when pci_upstream_bridge() returns NULL on root busCVE-2026-45901 · Fixed within SLA · CVE-2026-45901: nf_tables reset commit_mutex causes circular lock with ipset list and iptables-nft '-m set'CVE-2026-46017 · Fixed within SLA · CVE-2026-46017: Deferred split queue race during migration makes dst visible early, triggering WARN and folio lossCVE-2026-46032 · Fixed within SLA · CVE-2026-46032: KVM nSVM ignores L1 CR3 restore failure on nested #VMEXIT, corrupting vCPU stateCVE-2026-46008 · Fixed within SLA · CVE-2026-46008: mm/damon: damos_walk and kdamond exit race causes deadlock with infinite request waitCVE-2026-46017 · Fixed within SLA · CVE-2026-46017: Deferred split queue race during folio migration marks dst partially mapped, triggers WARNCVE-2026-46008 · Fixed within SLA · CVE-2026-46008: damos_walk vs kdamond_fn exit race leads unhandled requests and indefinite wait deadlockCVE-2026-46032 · Fixed within SLA · CVE-2026-46032: KVM nSVM: Ignored CR3 load failure on nested #VMEXIT causes corrupted vCPU stateCVE-2026-45961 · Fixed within SLA · CVE-2026-45961: Linux GFS2 gfs2_fill_super error-path memory leaks: kthreads and quota bitmap on RW transitionCVE-2026-45963 · Fixed within SLA · CVE-2026-45963: Unloading snd_soc_nau8821 while jdet_work pending triggers kernel crashCVE-2026-45963 · Fixed within SLA · CVE-2026-45963: ASoC nau8821: Unloading driver with pending jdet_work causes kernel crashCVE-2026-45961 · Fixed within SLA · CVE-2026-45961: gfs2_fill_super leaks kernel threads and quota bitmap on read-write transition failureCVE-2020-18781 · Fixed within SLA · CVE-2020-18781: Heap buffer overflow in audiofile 0.3.6 FilePOSIX::read triggers DoS via crafted WAV (sfconvert)CVE-1999-0656 · Fixed within SLA · CVE-1999-0656CVE-2022-38096 · Fixed within SLA · CVE-2022-38096CVE-2010-4563 · Fixed within SLA · CVE-2010-4563CVE-2022-48833 · Fixed within SLA · CVE-2022-48833CVE-2021-3669 · Fixed within SLA · CVE-2021-3669CVE-2007-4998 · Fixed within SLA · CVE-2007-4998CVE-2022-4543 · Fixed within SLA · CVE-2022-4543CVE-2025-46394 · Fixed within SLA · CVE-2025-46394

  • Fixed within SLA (933)
  • Open (82)
  • Overdue (0)
  • Missed SLA (0)
  • Today
  • SLA deadline for a CVE published today

About Determinate Secure Packages

Every fix on this page is one you didn't have to make. Determinate Secure Packages watches the packages you depend on, patches them within the SLA, and ships the builds to you.

Determinate Secure Packages overview

What you get, how it fits your Nix setup, and how to start.

determinate.systems (opens in a new tab)

Documentation

How the SLA works, which packages we cover, and how to use them.

docs.determinate.systems (opens in a new tab)

Supply chain security

Control over the code, dependencies, builds, and environments behind every system you run.

determinate.systems (opens in a new tab)

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems

Vulnerability databases

The databases the dashboard draws on. Every CVE here is one of theirs.