← All tracked CVEs
Updated 09:00
High severity
High15d SLAOur service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Google Chrome AdFilter sandbox RCE via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome pre-151.0.7922.72 ANGLE use-after-free allows remote sandbox escape via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Linux File Input vulnerability enables remote sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | WebView untrusted input validation flaw enables sandbox escape in Chrome Android prior to 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | V8 type confusion in Chrome <151.0.7922.72 allows sandboxed RCE via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | WebView lifecycle bug in Android Chrome pre-151.0.7922.72 allowed renderer-compromised sandbox escape | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High-severity use-after-free in Input enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Mac Skia race pre-151.0.7922.72 enables sandboxed remote code execution via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High-severity Chrome <151.0.7922.72 libxml integer overflow allows sandboxed RCE via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Use-after-free in Chrome Views enables local attacker sandbox escape via malicious file (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome on Android UI input validation flaw pre-151.0.7922.72 allows local cross-origin data leak | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Google Chrome prior to 151.0.7922.72 DOM use-after-free enables sandboxed RCE via crafted HTML | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Passwords untrusted input validation flaw allows site isolation bypass pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Autofill use-after-free enables sandboxed RCE via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome ANGLE out-of-bounds read enables renderer sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Remote sandbox escape via crafted HTML in Chrome Android ANGLE pre-151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High-severity Chrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72 | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Chrome Android GPU input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72) | secure-packages-26.05 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | FFmpeg 4.4–8.1.2 ADX decoder OOB on mid-stream channel layout change | secure-packages-26.05 | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | FFmpeg RTP/ASF demuxer infinite loop DoS via undersized chunk in rtp_asf_fix_header | secure-packages-26.05 | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | FFmpeg S/PDIF muxer out-of-bounds read via crafted DTS core_size during remuxing | secure-packages-26.05 | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | FFmpeg 4.4–8.1.2 NVDEC double-free causes memory corruption with crafted videos | secure-packages-26.05 | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | FFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack overflow via crafted bitstream enabling RCE | secure-packages-26.05 | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | FFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via excessive subtitle stream IDs (RCE) | secure-packages-26.05 | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | IPv4 __ip_append_data paged allocation misaccounts fraggap causing undersized linear area, overstated pagedlen | secure-packages-26.05 | Jul 23, 2026 | Aug 7, 2026 | Aug 4, 2026 | 12 days | |
| Fixed within SLA | IPv6 paged path fraggap misaccounting overflows skb via UDPv6 MSG_MORE/MSG_SPLICE_PAGES | secure-packages-26.05 | Jul 23, 2026 | Aug 7, 2026 | Aug 4, 2026 | 12 days | |
| Fixed within SLA | af_unix race: unix_gc may run with gc_in_progress=false, breaking MSG_PEEK handling | secure-packages-26.05 | Jul 23, 2026 | Aug 7, 2026 | Aug 4, 2026 | 12 days | |
| Fixed within SLA | KVM x86 UAF: role mismatch reuses shadow page after PDE split 2MB→4KB; rmap not removed | secure-packages-26.05 | Jul 23, 2026 | Aug 7, 2026 | Aug 4, 2026 | 12 days | |
| Fixed within SLA | Heap overflow in BusyBox 1.38.0 shell/ash.c evalcommand() enables DoS via crafted input | secure-packages-26.05 | Aug 4, 2026 | Aug 4, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Heap overflow in BusyBox 1.38.0 shell/ash.c ifsbreakup() enabling DoS via crafted input | secure-packages-26.05 | Aug 4, 2026 | Aug 4, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | BusyBox 1.38.0 awk_sub() use-after-free in editors/awk.c enables DoS via crafted AWK script | secure-packages-26.05 | Aug 4, 2026 | Aug 4, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Linux kernel Greybus raw cdev close use-after-free after bundle disconnect causes refcount underflow | secure-packages-rolling | Jul 20, 2026 | Aug 4, 2026 | Jul 30, 2026 | 10 days | |
| Fixed within SLA | Greybus raw: use-after-free on write after disconnect causes kernel panic | secure-packages-rolling | Jul 20, 2026 | Aug 4, 2026 | Jul 30, 2026 | 10 days | |
| Fixed within SLA | ice driver double-free of tx_buf skb after tso/csum failure and interface down | secure-packages-rolling | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | SOCKMAP redirect hides inflight FDs from AF_UNIX GC, causing leaks and use-after-free | secure-packages-rolling | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | nf_tables hook list update RCU race breaks netlink dump traversal during ruleset updates | secure-packages-rolling | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | Ceph writeback path leaks folio references for folios not suitable for writeback | secure-packages-rolling | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | libceph __ceph_x_decrypt() OOB read if buffer smaller than ceph_x_encrypt_header | secure-packages-rolling | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | Use-after-free in Greybus raw cdev on close after bundle disconnect causes panic | secure-packages-26.05 | Jul 20, 2026 | Aug 4, 2026 | Jul 30, 2026 | 10 days | |
| Fixed within SLA | Linux Greybus raw: use-after-free on write after disconnect triggers kernel panic | secure-packages-26.05 | Jul 20, 2026 | Aug 4, 2026 | Jul 30, 2026 | 10 days | |
| Fixed within SLA | Linux ice driver double-free of skb during tx ring cleanup after TSO/CSUM failure | secure-packages-26.05 | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | Netfilter nf_tables: netlink dump race from non-RCU hook list joins during commit | secure-packages-26.05 | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | ceph: Missing folio_put for writeback-ineligible folios removed from batch causes reference leak | secure-packages-26.05 | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | libceph __ceph_x_decrypt out-of-bounds read when hdr->magic accessed without header-size check | secure-packages-26.05 | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | powerpc/pgtable-frag: pte_frag_destroy leaves folio active, causing bad page state on exit | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | BPF verifier miscomputes delta when src==dst, causing linked reg verifier-vs-runtime mismatch | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | Offloaded BPF map/prog info query triggers UAF via get_net during netns teardown | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | AMD DRM: Out-of-bounds read in dp_get_eq_aux_rd_interval with 8 LTTPR repeaters | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | Linux vdpa: Unlocked driver_override access during __driver_attach() match() causes UAF | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | BPF verifier fails to simulate ld_{abs,ind} subprog failure path causing unsafe returns | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days |