← All tracked CVEs
Updated 09:00
High severity
High15d SLAOur service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | BPF sock_ops dst==src macro bug causes OOB read and kernel pointer leak | secure-packages-25.11 | Jul 23, 2026 | Aug 7, 2026 | Jul 30, 2026 | 7 days | |
| Fixed within SLA | Greybus gb_raw use-after-free on write after disconnect triggers kernel panic | secure-packages-25.11 | Jul 17, 2026 | Aug 1, 2026 | Jul 30, 2026 | 13 days | |
| Fixed within SLA | Perl ≤5.43.10 pack/unpack S_measure_struct overflow allows out-of-bounds heap read via large repeat counts | secure-packages-rolling | Jul 16, 2026 | Jul 31, 2026 | Jul 29, 2026 | 13 days | |
| Fixed within SLA | Unbound 1.23–1.25.1 dns-error-reporting Report-Channel parsing bug allows remote DoS | secure-packages-rolling | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.7–1.25.1 RRSIG.Labels/aggressive NSEC flaw enables cross-sibling DNS cache poisoning | secure-packages-rolling | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Heap overflow in Unbound DNSCrypt TCP reply path enables DoS (1.9.0–1.25.1) | secure-packages-rolling | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.22–1.25.1: first DoQ streams bypass per-stream quic-size, enabling memory DoS | secure-packages-rolling | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Perl <=5.43.10 pack/unpack integer overflow in S_measure_struct enables out-of-bounds heap read | secure-packages-26.05 | Jul 16, 2026 | Jul 31, 2026 | Jul 29, 2026 | 13 days | |
| Fixed within SLA | Unbound 1.23–1.25.1 EDNS Report-Channel length bug causes stack overwrite, crash with dns-error-reporting | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.7.0–1.25.1 RRSIG.Labels validation bug enables NSEC sibling zone cache poisoning | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.9.0–1.25.1 DNSCrypt TCP path overflow causes heap corruption and DoS | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound downstream DoQ initial streams bypass quic-size, causing remote memory-accounting DoS (v1.22–1.25.1) | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.23-1.25.1 EDNS Report-Channel flaw crashes daemon when dns-error-reporting enabled via crafted response | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.9.0–1.25.1 DNSCrypt TCP reply heap overflow causes DoS when DNSCrypt enabled | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound DNS 1.7.0–1.25.1 RRSIG.Labels/aggressive NSEC bug enables sibling zone cache poisoning | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound downstream DoQ initial streams bypass quic-size, enabling remote memory DoS (1.22.0–1.25.1) | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days |