Skip to content
← All tracked CVEs

Updated 09:00

High severity

High15d SLA

Our service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLABPF sock_ops dst==src macro bug causes OOB read and kernel pointer leaksecure-packages-25.11Jul 23, 2026Aug 7, 2026Jul 30, 20267 days
Fixed within SLAGreybus gb_raw use-after-free on write after disconnect triggers kernel panicsecure-packages-25.11Jul 17, 2026Aug 1, 2026Jul 30, 202613 days
Fixed within SLAPerl ≤5.43.10 pack/unpack S_measure_struct overflow allows out-of-bounds heap read via large repeat countssecure-packages-rollingJul 16, 2026Jul 31, 2026Jul 29, 202613 days
Fixed within SLAUnbound 1.23–1.25.1 dns-error-reporting Report-Channel parsing bug allows remote DoSsecure-packages-rollingJul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.7–1.25.1 RRSIG.Labels/aggressive NSEC flaw enables cross-sibling DNS cache poisoningsecure-packages-rollingJul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAHeap overflow in Unbound DNSCrypt TCP reply path enables DoS (1.9.0–1.25.1)secure-packages-rollingJul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.22–1.25.1: first DoQ streams bypass per-stream quic-size, enabling memory DoSsecure-packages-rollingJul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAPerl <=5.43.10 pack/unpack integer overflow in S_measure_struct enables out-of-bounds heap readsecure-packages-26.05Jul 16, 2026Jul 31, 2026Jul 29, 202613 days
Fixed within SLAUnbound 1.23–1.25.1 EDNS Report-Channel length bug causes stack overwrite, crash with dns-error-reportingsecure-packages-26.05Jul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.7.0–1.25.1 RRSIG.Labels validation bug enables NSEC sibling zone cache poisoningsecure-packages-26.05Jul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.9.0–1.25.1 DNSCrypt TCP path overflow causes heap corruption and DoSsecure-packages-26.05Jul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound downstream DoQ initial streams bypass quic-size, causing remote memory-accounting DoS (v1.22–1.25.1)secure-packages-26.05Jul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.23-1.25.1 EDNS Report-Channel flaw crashes daemon when dns-error-reporting enabled via crafted responsesecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.9.0–1.25.1 DNSCrypt TCP reply heap overflow causes DoS when DNSCrypt enabledsecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound DNS 1.7.0–1.25.1 RRSIG.Labels/aggressive NSEC bug enables sibling zone cache poisoningsecure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 29, 20262 days
Fixed within SLAUnbound downstream DoQ initial streams bypass quic-size, enabling remote memory DoS (1.22.0–1.25.1)secure-packages-25.11Jul 27, 2026Aug 11, 2026Jul 29, 20262 days