Skip to content
← All tracked CVEs

Updated 07:00

High severity

High15d SLA

Our service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLASkia use-after-free enables sandbox escape via crafted HTML in Chrome <151.0.7922.72secure-packages-26.05Aug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAUse-after-free in Chrome Compositing allows sandbox escape from compromised renderer via HTML (pre-151.0.7922.72)secure-packages-26.05Aug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAFFmpeg ADX decoder OOB read/write on mid-stream extradata channel change (v4.4–8.1.2)secure-packages-rollingJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAFFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS in rtp_asf_fix_headersecure-packages-rollingJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAFFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_sizesecure-packages-rollingJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAFFmpeg 4.4–8.1.2 NVDEC double-free enables memory corruption via crafted video filessecure-packages-rollingJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAFFmpeg 8.0-8.1.2 Vulkan HEVC decoder stack buffer overflow enables remote code executionsecure-packages-rollingJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAFFmpeg 2.1-8.1.2 VobSub demuxer heap overflow from .sub/.idx with excessive stream IDssecure-packages-rollingJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAUse-after-free when querying offloaded BPF map/prog due to netns teardown racesecure-packages-rollingJul 27, 2026Aug 11, 2026Aug 11, 202615 days
Fixed within SLAUse-after-free when filling offloaded BPF map/prog info due to netns teardown racesecure-packages-26.05Jul 27, 2026Aug 11, 2026Aug 11, 202615 days
Fixed within SLAGSO headers not in skb->head during qdisc init, risking tso_build_hdr memcpy misusesecure-packages-25.11Jul 27, 2026Aug 11, 2026Aug 11, 202615 days
Fixed within SLAfbcon_do_set_font error rollback misses hi_font state restore, causing out-of-bounds font readssecure-packages-25.11Aug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLANFSv4 flexfiles ff_layout_alloc_lseg accepts zero fh_count, causing NULL pointer dereferencesecure-packages-25.11Aug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAKVM: Missing memslot bounds check causes OOB lpage_info access during hugepage recoverysecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAGuest-triggered kernel BUG via unaligned ioeventfd datamatch on KVM page-split MMIOsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLALinux nx crypto: kernel oops from wrong ctx type passed to nx_crypto_ctx_exitsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAgfs2: use-after-free in gfs2_qd_dealloc when superblock freed before RCU callbacks finishsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAUse-after-free from PPP protocol timers when HDLC state is freed during detachsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAUse-after-free in blk-cgroup __blkcg_rstat_flush via llist_del_all during concurrent blkg releasessecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLATIPC decrypt async completion UAF from missing netns ref when crypto_aead_decrypt offloadedsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAsched/mmcid: OOB clear_bit from MM_CID_UNSET during per-CPU CID fixupsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLArpmsg char: callbacks use freed eptdev after probe failure due to stale privsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAOCFS2 accepts oversized group bitmap descriptors causing OOB bitmap access and use-after-freesecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAKVM SVM unbounded destination offset causes page overflow and memcpy overrun in sev_dbg_crypt ENCRYPTsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAfbcon_do_set_font err_out misses hi_font rollback, enabling OOB read/memory leaksecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAi2c core adapter registration race causes i2c_get_adapter to access uninitialized device, NULL/UAFsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAnfsd: posix_acl memory leak when SETACL decode fails; pc_release didn't free ACLssecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLALinux nfsd4_create_file ignores ACL conversion errors; leaks posix_acl allocationssecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLADead ACL conflict guard in nfsd4_create leaks posix_acls, causing unbounded slab exhaustionsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAnfsd memory leak: pre-allocated openowner overwritten during unconfirmed owner retry racesecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLANFSv4/flexfiles accepts zero fh_count, causing ZERO_SIZE_PTR and KASAN null dereferencesecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLANFSv4/pNFS: zero-length r_addr triggers NULL pointer dereference in nfs4_decode_mp_ds_addrsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAksmbd: OOB read in smb_check_perm_dacl due to ACE/SID length mismatchsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAUse-after-free in TCP-AO del_async due to dangling current_key/rnext_key on LISTEN socketssecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLALinux kernel IPv4 __ip_append_data paged allocation miscalculates fraggap, causing undersized linear area, overstated pagedlensecure-packages-rollingJul 23, 2026Aug 7, 2026Aug 7, 202615 days
Fixed within SLAUnprivileged IPv6 UDP fraggap misaccounting overflows skb in paged allocation using MSG_SPLICE_PAGESsecure-packages-rollingJul 23, 2026Aug 7, 2026Aug 7, 202615 days
Fixed within SLAaf_unix race: unix_gc may run with gc_in_progress false, breaking MSG_PEEK safetysecure-packages-rollingJul 23, 2026Aug 7, 2026Aug 7, 202615 days
Fixed within SLAKVM x86 shadow paging UAF due to child page role mismatch after PDE changesecure-packages-rollingJul 23, 2026Aug 7, 2026Aug 7, 202615 days
Fixed within SLAqdisc_pkt_len_segs_init fails to pull GSO headers, risking memcpy issues in TSO driverssecure-packages-rollingJul 27, 2026Aug 11, 2026Aug 7, 202611 days
Fixed within SLABPF verifier misses ld_{abs,ind} failure path analysis in subprograms, mishandling abnormal exitssecure-packages-rollingJul 27, 2026Aug 11, 2026Aug 7, 202611 days
Fixed within SLASame-register dst/src in BPF sock_ops leaves dst unzeroed, causing OOB read and leaksecure-packages-rollingJul 23, 2026Aug 7, 2026Aug 7, 202615 days
Fixed within SLAGSO headers not pulled in qdisc_pkt_len_segs_init risk TSO memcpy crash, security issuesecure-packages-26.05Jul 27, 2026Aug 11, 2026Aug 7, 202611 days
Fixed within SLABPF verifier omits ld_{abs,ind} failure path analysis in BTF subprogramssecure-packages-26.05Jul 27, 2026Aug 11, 2026Aug 7, 202611 days
Fixed within SLABPF sock_ops GET_SK/GET_FIELD miss zeroing when dst==src, causing OOB read and leaksecure-packages-26.05Jul 23, 2026Aug 7, 2026Aug 7, 202615 days
Fixed within SLASOCKMAP hides inflight fds from AF_UNIX GC causing leaks, UAF, and incorrect SCM countssecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 7, 20263 days
Fixed within SLAChrome Chromoting on Linux <151.0.7922.72 allows OS-level privilege escalation via network trafficsecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 5, 20261 day
Fixed within SLAChromoting on Linux before 151.0.7922.72 enables OS-level privilege escalation via malicious network trafficsecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 5, 20261 day
Fixed within SLAUse-after-free in Views on Linux Chrome <151.0.7922.72 allows remote heap corruption via crafted HTMLsecure-packages-25.11Aug 5, 2026Aug 20, 2026Aug 5, 2026same day
Fixed within SLALinux Chrome Chromoting pre-151.0.7922.72 allows local privilege escalation via network trafficsecure-packages-25.11Aug 4, 2026Aug 19, 2026Aug 5, 20261 day
Fixed within SLAInsufficient validation in Chrome DevTools allows extension-based privilege escalation pre-151.0.7922.72secure-packages-25.11Aug 5, 2026Aug 20, 2026Aug 5, 2026same day