← All tracked CVEs
Updated 04:00
High severity
High15d SLAOur service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Open | PostgreSQL refint type confusion enables arbitrary code execution as DB OS user; affects <18.5/17.11/16.15/15.19/14.24 | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | PostgreSQL stack buffer overflow via OUT parameter count in argument name matching; 0x0/0x1 writes | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Fixed within SLA | Use-after-free in ieee80211_prepare_and_rx_handle from mesh skb->cb reuse during fast-RX | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 27, 2026 | 2 days | |
| Fixed within SLA | Use-after-free from skb->cb reuse in mac80211 mesh fast-RX rate handling | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 27, 2026 | 3 days | |
| Fixed within SLA | V8 type confusion enables remote code execution within Chrome sandbox pre-151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | ANGLE buffer overflow in Chrome Android <151.0.7922.169 enables sandbox escape remote code execution | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | WebGL use-after-free in Chrome <151.0.7922.169 enables sandbox RCE via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Chrome <151.0.7922.169 USB race enables code execution outside sandbox via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | V8 miscalculation enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Chrome Mac <151.0.7922.169 Browser use-after-free enables remote sandbox-escape RCE via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Google Chrome <151.0.7922.169 V8 type confusion allows sandboxed RCE via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Chrome CredentialProvider link-following on Windows allows local sandbox escape pre-151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Buffer overflow in Chrome WebGL before 151.0.7922.169 enables RCE outside sandbox via crafted HTML page. | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | V8 type confusion in Chrome pre-151.0.7922.169 enables sandboxed RCE via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Chrome Android ANGLE buffer overflow before 151.0.7922.169 enables out-of-sandbox RCE | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Use-after-free in Chrome WebGL pre-151.0.7922.169 allows sandboxed RCE via crafted HTML page | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Chrome <151.0.7922.169 USB race leads to sandbox escape RCE from crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Incorrect calculation in V8 allows sandboxed RCE via crafted HTML in Chrome <151.0.7922.169 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High-severity Chrome Mac Browser use-after-free pre-151.0.7922.169 allows RCE outside sandbox via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Chrome V8 type confusion allows sandboxed RCE via crafted HTML pre-151.0.7922.169 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Chrome Windows CredentialProvider link-following bug allows local arbitrary code execution outside sandbox pre-151.0.7922.169 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Critical WebGL buffer overflow in Chrome <151.0.7922.169 enables sandbox-escape RCE via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | KVM guest_memfd memslot offset+size signed overflow bypasses i_size bound check | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 25, 2026 | 7 days | |
| Fixed within SLA | HSR RCU readers race with RTM_DELLINK node frees, causing use-after-free | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 25, 2026 | 7 days | |
| Fixed within SLA | KVM guest_memfd uses signed offset/size; sum overflow bypasses memslot binding file-size check | secure-packages-26.05 | Aug 19, 2026 | Sep 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | HSR RTM_DELLINK frees nodes without RCU, causing generic-netlink reader use-after-free | secure-packages-26.05 | Aug 19, 2026 | Sep 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Blink use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.137 | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Chrome <151.0.7922.137 HTML use-after-free enables sandboxed remote code execution via crafted page | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Use-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed code execution via malicious extension | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Google Chrome Mac TabStrip use-after-free enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.137) | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High-severity V8 use-after-free in Chrome <151.0.7922.137 enables sandboxed RCE via crafted HTML | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Chrome <151.0.7922.137 Blink use-after-free allows sandboxed remote code execution via crafted HTML | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Chrome <151.0.7922.137 HTML use-after-free enables sandboxed RCE via crafted page | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Use-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed arbitrary code execution | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High-severity TabStrip use-after-free enables sandbox escape via HTML on Chrome Mac <151.0.7922.137 | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Use-after-free in Chrome V8 pre-151.0.7922.137 allows sandboxed remote code execution | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | KVM guest_memfd offset+size treated signed, letting negative sum bypass file size check | secure-packages-25.11 | Aug 17, 2026 | Sep 1, 2026 | Aug 18, 2026 | 1 day | |
| Fixed within SLA | FFmpeg 7.0–8.1.2 vf_quirc heap OOB write via crafted PGS/SUP subtitles mismatched dimensions | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | Heap out-of-bounds write in FFmpeg PNG/APNG encoder eXIf handling (≤8.1.2) | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | FFmpeg <=8.1.2 MACE6 CAF bytes_per_packet integer overflow causes heap OOB write, RCE | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | FFmpeg up to 8.1.2 LCL/ZLIB decoder leaks uninitialized heap; short inflate enables ASLR bypass | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | FFmpeg ≤8.1.2 IAMF demuxer uncontrolled allocation from 17-byte input via count_label | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | FFmpeg ≤8.1.2 vf_hqdn3d heap OOB write when -reinit_filter 0 and resolution increases | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | FFmpeg 3.0-8.1.2 vf_swaprect OOB write on odd-width NV12 frames causing heap corruption | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | FFmpeg 3.4-8.1.2 vf_floodfill OOB write with -reinit_filter 0, heap corruption | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | FFmpeg <=8.1.2 heap corruption via TY demuxer OOB write using crafted ffconcat with -safe 0 | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | FFmpeg 2.7–8.1.2 TDSC decoder OOB write causing heap corruption and potential RCE | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | mlx5e XSK race: unlocked ICOSQ IRQ trigger during NAPI affinity change causes CQE errors | secure-packages-rolling | Aug 12, 2026 | Aug 27, 2026 | Aug 15, 2026 | 2 days | |
| Fixed within SLA | mlx5e XSK: Unprotected ICOSQ IRQ trigger races with NAPI and CPU affinity changes | secure-packages-26.05 | Aug 12, 2026 | Aug 27, 2026 | Aug 15, 2026 | 2 days | |
| Fixed within SLA | Linux iwlwifi BA handlers use ffs on zero sta_mask, causing out-of-bounds access | secure-packages-25.11 | Aug 14, 2026 | Aug 29, 2026 | Aug 15, 2026 | same day |