Skip to content
← All tracked CVEs

Updated 09:00

High severity

High15d SLA

Our service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLAGoogle Chrome AdFilter sandbox RCE via crafted HTML before 151.0.7922.72secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAChrome pre-151.0.7922.72 ANGLE use-after-free allows remote sandbox escape via crafted HTMLsecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAChrome Linux File Input vulnerability enables remote sandbox escape via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAWebView untrusted input validation flaw enables sandbox escape in Chrome Android prior to 151.0.7922.72secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAV8 type confusion in Chrome <151.0.7922.72 allows sandboxed RCE via crafted HTMLsecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAWebView lifecycle bug in Android Chrome pre-151.0.7922.72 allowed renderer-compromised sandbox escapesecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHigh-severity use-after-free in Input enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAChrome Mac Skia race pre-151.0.7922.72 enables sandboxed remote code execution via crafted HTMLsecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHigh-severity Chrome <151.0.7922.72 libxml integer overflow allows sandboxed RCE via crafted HTMLsecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAUse-after-free in Chrome Views enables local attacker sandbox escape via malicious file (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAChrome on Android UI input validation flaw pre-151.0.7922.72 allows local cross-origin data leaksecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAGoogle Chrome prior to 151.0.7922.72 DOM use-after-free enables sandboxed RCE via crafted HTMLsecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAChrome Passwords untrusted input validation flaw allows site isolation bypass pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAChrome Autofill use-after-free enables sandboxed RCE via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAChrome ANGLE out-of-bounds read enables renderer sandbox escape via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLARemote sandbox escape via crafted HTML in Chrome Android ANGLE pre-151.0.7922.72secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHigh-severity Chrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAChrome Android GPU input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72)secure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAFFmpeg 4.4–8.1.2 ADX decoder OOB on mid-stream channel layout changesecure-packages-26.05Jul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAFFmpeg RTP/ASF demuxer infinite loop DoS via undersized chunk in rtp_asf_fix_headersecure-packages-26.05Jul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAFFmpeg S/PDIF muxer out-of-bounds read via crafted DTS core_size during remuxingsecure-packages-26.05Jul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAFFmpeg 4.4–8.1.2 NVDEC double-free causes memory corruption with crafted videossecure-packages-26.05Jul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAFFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack overflow via crafted bitstream enabling RCEsecure-packages-26.05Jul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAFFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via excessive subtitle stream IDs (RCE)secure-packages-26.05Jul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAIPv4 __ip_append_data paged allocation misaccounts fraggap causing undersized linear area, overstated pagedlensecure-packages-26.05Jul 23, 2026Aug 7, 2026Aug 4, 202612 days
Fixed within SLAIPv6 paged path fraggap misaccounting overflows skb via UDPv6 MSG_MORE/MSG_SPLICE_PAGESsecure-packages-26.05Jul 23, 2026Aug 7, 2026Aug 4, 202612 days
Fixed within SLAaf_unix race: unix_gc may run with gc_in_progress=false, breaking MSG_PEEK handlingsecure-packages-26.05Jul 23, 2026Aug 7, 2026Aug 4, 202612 days
Fixed within SLAKVM x86 UAF: role mismatch reuses shadow page after PDE split 2MB→4KB; rmap not removedsecure-packages-26.05Jul 23, 2026Aug 7, 2026Aug 4, 202612 days
Fixed within SLAHeap overflow in BusyBox 1.38.0 shell/ash.c evalcommand() enables DoS via crafted inputsecure-packages-26.05Aug 4, 2026Aug 4, 2026Aug 4, 2026same day
Fixed within SLAHeap overflow in BusyBox 1.38.0 shell/ash.c ifsbreakup() enabling DoS via crafted inputsecure-packages-26.05Aug 4, 2026Aug 4, 2026Aug 4, 2026same day
Fixed within SLABusyBox 1.38.0 awk_sub() use-after-free in editors/awk.c enables DoS via crafted AWK scriptsecure-packages-26.05Aug 4, 2026Aug 4, 2026Aug 4, 2026same day
Fixed within SLALinux kernel Greybus raw cdev close use-after-free after bundle disconnect causes refcount underflowsecure-packages-rollingJul 20, 2026Aug 4, 2026Jul 30, 202610 days
Fixed within SLAGreybus raw: use-after-free on write after disconnect causes kernel panicsecure-packages-rollingJul 20, 2026Aug 4, 2026Jul 30, 202610 days
Fixed within SLAice driver double-free of tx_buf skb after tso/csum failure and interface downsecure-packages-rollingJul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLASOCKMAP redirect hides inflight FDs from AF_UNIX GC, causing leaks and use-after-freesecure-packages-rollingJul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLAnf_tables hook list update RCU race breaks netlink dump traversal during ruleset updatessecure-packages-rollingJul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLACeph writeback path leaks folio references for folios not suitable for writebacksecure-packages-rollingJul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLAlibceph __ceph_x_decrypt() OOB read if buffer smaller than ceph_x_encrypt_headersecure-packages-rollingJul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLAUse-after-free in Greybus raw cdev on close after bundle disconnect causes panicsecure-packages-26.05Jul 20, 2026Aug 4, 2026Jul 30, 202610 days
Fixed within SLALinux Greybus raw: use-after-free on write after disconnect triggers kernel panicsecure-packages-26.05Jul 20, 2026Aug 4, 2026Jul 30, 202610 days
Fixed within SLALinux ice driver double-free of skb during tx ring cleanup after TSO/CSUM failuresecure-packages-26.05Jul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLANetfilter nf_tables: netlink dump race from non-RCU hook list joins during commitsecure-packages-26.05Jul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLAceph: Missing folio_put for writeback-ineligible folios removed from batch causes reference leaksecure-packages-26.05Jul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLAlibceph __ceph_x_decrypt out-of-bounds read when hdr->magic accessed without header-size checksecure-packages-26.05Jul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLApowerpc/pgtable-frag: pte_frag_destroy leaves folio active, causing bad page state on exitsecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLABPF verifier miscomputes delta when src==dst, causing linked reg verifier-vs-runtime mismatchsecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLAOffloaded BPF map/prog info query triggers UAF via get_net during netns teardownsecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLAAMD DRM: Out-of-bounds read in dp_get_eq_aux_rd_interval with 8 LTTPR repeaterssecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLALinux vdpa: Unlocked driver_override access during __driver_attach() match() causes UAFsecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLABPF verifier fails to simulate ld_{abs,ind} subprog failure path causing unsafe returnssecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 30, 20263 days