← All tracked CVEs
Updated 05:00
High severity
High15d SLAOur service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | FFmpeg 7.0–8.1.2 vf_quirc heap OOB write via mismatched PGS/SUP frame dimensions | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | Heap OOB write in FFmpeg PNG/APNG encoders <=8.1.2 via malicious eXIf chunk, RCE | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | FFmpeg ≤8.1.2 MACE6 signed integer overflow leads to heap OOB write via CAF | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | FFmpeg <=8.1.2 LCL/ZLIB decoder info leak via short zlib decompression | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | FFmpeg ≤8.1.2 IAMF demuxer OOM via crafted count_label during format probing | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | FFmpeg <=8.1.2 vf_hqdn3d heap out-of-bounds write with -reinit_filter 0 and growing frames | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | FFmpeg 3.0–8.1.2 vf_swaprect OOB write on NV12 odd-width frames causes heap corruption | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | FFmpeg 3.4-8.1.2 vf_floodfill OOB write on dynamic frames with -reinit_filter 0 | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | FFmpeg <=8.1.2 OOB write via crafted ffconcat (-safe 0) in TY demuxer | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | FFmpeg 2.7–8.1.2 TDSC decoder OOB write on frame dimension changes enables RCE | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High severity use-after-free in Aura allows sandbox escape on Chrome Linux <151.0.7922.109 | secure-packages-rolling | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | Use-after-free in Chrome HTML before 151.0.7922.109 enables remote heap corruption | secure-packages-rolling | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | Use-after-free in Chrome Views pre-151.0.7922.109 allows remote heap corruption via crafted HTML | secure-packages-rolling | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | Aura use-after-free in Chrome Linux pre-151.0.7922.109 enables sandbox escape via HTML from compromised renderer | secure-packages-26.05 | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | Use-after-free in Chrome HTML enables remote heap corruption before 151.0.7922.109 | secure-packages-26.05 | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | Chrome Views use-after-free before 151.0.7922.109 allows heap corruption via crafted HTML and gestures | secure-packages-26.05 | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | mlx5e XSK: Unprotected ICOSQ IRQ triggering races with NAPI, causing ICOSQ CQE errors | secure-packages-25.11 | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | Type mismatch in nx_crypto_ctx_exit triggers kernel oops via nx_crypto_ctx_shash_exit | secure-packages-25.11 | Aug 4, 2026 | Aug 19, 2026 | Aug 14, 2026 | 10 days | |
| Fixed within SLA | fbdev omap2: omapfb_mmap use-after-free race with OMAPFB_SETUP_PLANE mapping freed memory | secure-packages-25.11 | Aug 4, 2026 | Aug 19, 2026 | Aug 14, 2026 | 10 days | |
| Fixed within SLA | f2fs: Race reading nat_entry flags causes incorrect inode dentry mark and fsck inconsistency after checkpoint | secure-packages-25.11 | Aug 4, 2026 | Aug 19, 2026 | Aug 14, 2026 | 10 days | |
| Fixed within SLA | FFmpeg vf_quirc heap out-of-bounds write via crafted PGS/SUP with mismatched frame dimensions | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg ≤8.1.2 PNG/APNG encoder eXIf handling causes heap OOB write, crash/RCE | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg ≤8.1.2 MACE6 CAF signed integer overflow causes heap OOB write, RCE risk | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg ≤8.1.2 LCL/ZLIB decoder information disclosure: short inflate leaks uninitialized heap | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg ≤8.1.2 IAMF demuxer OOM via crafted count_label causing massive allocation during probing | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg <=8.1.2 vf_hqdn3d heap OOB write on resolution increase with -reinit_filter 0 disabled | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg 3.0–8.1.2 vf_swaprect OOB write with odd-width NV12 frames causes heap corruption | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg 3.4–8.1.2 OOB write in vf_floodfill with -reinit_filter 0 | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg <=8.1.2 OOB write processing ffconcat -safe 0 via TY demuxer | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | FFmpeg 2.7–8.1.2 TDSC decoder out-of-bounds write via crafted AVI frame dimension changes | secure-packages-25.11 | Aug 10, 2026 | Aug 25, 2026 | Aug 14, 2026 | 4 days | |
| Fixed within SLA | fbdev omap2: omapfb_mmap race with OMAPFB_SETUP_PLANE causes use-after-free | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | fbdev omap2 omapfb_mmap race with OMAPFB_SETUP_PLANE leads to use-after-free | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | Use-after-free in Aura allows sandbox escape after renderer compromise in Chrome Linux <151.0.7922.109 | secure-packages-25.11 | Aug 12, 2026 | Aug 27, 2026 | Aug 12, 2026 | same day | |
| Fixed within SLA | Chrome pre-151.0.7922.109 HTML use-after-free allows remote heap corruption via crafted page | secure-packages-25.11 | Aug 12, 2026 | Aug 27, 2026 | Aug 12, 2026 | same day | |
| Fixed within SLA | Chrome pre-151.0.7922.109 Views UAF enables remote heap corruption via crafted HTML page, requires UI gestures | secure-packages-25.11 | Aug 12, 2026 | Aug 27, 2026 | Aug 12, 2026 | same day | |
| Fixed within SLA | cJSON <=1.7.19 cJSON_Compare exponential time on deep nested equal objects causes DoS | secure-packages-rolling | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | cJSON through 1.7.19: Untrusted RFC 6902 patch triggers recursion, stack exhaustion DoS | secure-packages-rolling | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | cJSON 1.7.19 and earlier: cJSON_Compare exponential complexity allows DoS via nested JSON | secure-packages-26.05 | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | cJSON <=1.7.19: Untrusted JSON Patch via cJSONUtils_ApplyPatches triggers uncontrolled recursion and stack exhaustion DoS | secure-packages-26.05 | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | cJSON <=1.7.19: cJSON_Compare exponential-time recursion causes DoS on deeply nested JSON | secure-packages-25.11 | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | cJSON <=1.7.19 DoS: stack exhaustion from uncontrolled recursion applying RFC6902 JSON Patch | secure-packages-25.11 | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | glibc ≤ 2.43 ungetwc wrong buffer causes under-read with overlapping encodings, data leak/crash | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | glibc <=2.43 iconv assertion failure on IBM1390/IBM1399 may allow remote crash | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 12, 2026 | 1 day | ||
| Fixed within SLA | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 12, 2026 | 1 day | ||
| Fixed within SLA | Chrome UI input validation flaw enables sandbox escape from renderer via crafted HTML pre-151.0.7922.109 | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Skia use-after-free in Chrome <151.0.7922.109 enables sandboxed RCE via crafted HTML | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | V8 integer overflow enables sandboxed arbitrary code execution in Chrome <151.0.7922.109 via crafted HTML | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Skia out-of-bounds write enables sandbox escape from compromised renderer in Chrome <151.0.7922.109 | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Use-after-free in Chrome Views enables sandbox escape from compromised renderer via crafted HTML | secure-packages-26.05 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day |