← All tracked CVEs
Updated 07:00
High severity
High15d SLAOur service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Skia use-after-free enables sandbox escape via crafted HTML in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Use-after-free in Chrome Compositing allows sandbox escape from compromised renderer via HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | FFmpeg ADX decoder OOB read/write on mid-stream extradata channel change (v4.4–8.1.2) | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | FFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS in rtp_asf_fix_header | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | FFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_size | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | FFmpeg 4.4–8.1.2 NVDEC double-free enables memory corruption via crafted video files | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | FFmpeg 8.0-8.1.2 Vulkan HEVC decoder stack buffer overflow enables remote code execution | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | FFmpeg 2.1-8.1.2 VobSub demuxer heap overflow from .sub/.idx with excessive stream IDs | secure-packages-rolling | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | Use-after-free when querying offloaded BPF map/prog due to netns teardown race | secure-packages-rolling | Jul 27, 2026 | Aug 11, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Use-after-free when filling offloaded BPF map/prog info due to netns teardown race | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | GSO headers not in skb->head during qdisc init, risking tso_build_hdr memcpy misuse | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | fbcon_do_set_font error rollback misses hi_font state restore, causing out-of-bounds font reads | secure-packages-25.11 | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | NFSv4 flexfiles ff_layout_alloc_lseg accepts zero fh_count, causing NULL pointer dereference | secure-packages-25.11 | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | KVM: Missing memslot bounds check causes OOB lpage_info access during hugepage recovery | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Guest-triggered kernel BUG via unaligned ioeventfd datamatch on KVM page-split MMIO | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Linux nx crypto: kernel oops from wrong ctx type passed to nx_crypto_ctx_exit | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | gfs2: use-after-free in gfs2_qd_dealloc when superblock freed before RCU callbacks finish | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Use-after-free from PPP protocol timers when HDLC state is freed during detach | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Use-after-free in blk-cgroup __blkcg_rstat_flush via llist_del_all during concurrent blkg releases | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | TIPC decrypt async completion UAF from missing netns ref when crypto_aead_decrypt offloaded | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | sched/mmcid: OOB clear_bit from MM_CID_UNSET during per-CPU CID fixup | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | rpmsg char: callbacks use freed eptdev after probe failure due to stale priv | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | OCFS2 accepts oversized group bitmap descriptors causing OOB bitmap access and use-after-free | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | KVM SVM unbounded destination offset causes page overflow and memcpy overrun in sev_dbg_crypt ENCRYPT | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | fbcon_do_set_font err_out misses hi_font rollback, enabling OOB read/memory leak | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | i2c core adapter registration race causes i2c_get_adapter to access uninitialized device, NULL/UAF | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | nfsd: posix_acl memory leak when SETACL decode fails; pc_release didn't free ACLs | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Linux nfsd4_create_file ignores ACL conversion errors; leaks posix_acl allocations | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Dead ACL conflict guard in nfsd4_create leaks posix_acls, causing unbounded slab exhaustion | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | nfsd memory leak: pre-allocated openowner overwritten during unconfirmed owner retry race | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | NFSv4/flexfiles accepts zero fh_count, causing ZERO_SIZE_PTR and KASAN null dereference | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | NFSv4/pNFS: zero-length r_addr triggers NULL pointer dereference in nfs4_decode_mp_ds_addr | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | ksmbd: OOB read in smb_check_perm_dacl due to ACE/SID length mismatch | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Use-after-free in TCP-AO del_async due to dangling current_key/rnext_key on LISTEN sockets | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Linux kernel IPv4 __ip_append_data paged allocation miscalculates fraggap, causing undersized linear area, overstated pagedlen | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | Unprivileged IPv6 UDP fraggap misaccounting overflows skb in paged allocation using MSG_SPLICE_PAGES | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | af_unix race: unix_gc may run with gc_in_progress false, breaking MSG_PEEK safety | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | KVM x86 shadow paging UAF due to child page role mismatch after PDE change | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | qdisc_pkt_len_segs_init fails to pull GSO headers, risking memcpy issues in TSO drivers | secure-packages-rolling | Jul 27, 2026 | Aug 11, 2026 | Aug 7, 2026 | 11 days | |
| Fixed within SLA | BPF verifier misses ld_{abs,ind} failure path analysis in subprograms, mishandling abnormal exits | secure-packages-rolling | Jul 27, 2026 | Aug 11, 2026 | Aug 7, 2026 | 11 days | |
| Fixed within SLA | Same-register dst/src in BPF sock_ops leaves dst unzeroed, causing OOB read and leak | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | GSO headers not pulled in qdisc_pkt_len_segs_init risk TSO memcpy crash, security issue | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Aug 7, 2026 | 11 days | |
| Fixed within SLA | BPF verifier omits ld_{abs,ind} failure path analysis in BTF subprograms | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Aug 7, 2026 | 11 days | |
| Fixed within SLA | BPF sock_ops GET_SK/GET_FIELD miss zeroing when dst==src, causing OOB read and leak | secure-packages-26.05 | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | SOCKMAP hides inflight fds from AF_UNIX GC causing leaks, UAF, and incorrect SCM counts | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 7, 2026 | 3 days | |
| Fixed within SLA | Chrome Chromoting on Linux <151.0.7922.72 allows OS-level privilege escalation via network traffic | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 5, 2026 | 1 day | |
| Fixed within SLA | Chromoting on Linux before 151.0.7922.72 enables OS-level privilege escalation via malicious network traffic | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 5, 2026 | 1 day | |
| Fixed within SLA | Use-after-free in Views on Linux Chrome <151.0.7922.72 allows remote heap corruption via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Aug 20, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Linux Chrome Chromoting pre-151.0.7922.72 allows local privilege escalation via network traffic | secure-packages-25.11 | Aug 4, 2026 | Aug 19, 2026 | Aug 5, 2026 | 1 day | |
| Fixed within SLA | Insufficient validation in Chrome DevTools allows extension-based privilege escalation pre-151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Aug 20, 2026 | Aug 5, 2026 | same day |