← All tracked CVEs
Updated 05:00
Medium severity
Medium45d SLAOur service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Open | PostgreSQL: Stale RLS from role/ownership changes enables unauthorized reads/writes via plan reuse | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | — | — | |
| Open | PostgreSQL pgcrypto disabled-cipher bug allows cleartext recovery; wrong-key decrypt bypasses MDC | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | — | — | |
| Open | PostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24 | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | — | — | |
| Open | PostgreSQL pg_trgm picksplit buffer over-read leaks memory via split choices; pre-18.5/17.11/16.15/15.19/14.24 | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | — | — | |
| Open | Attacker-controlled CR in configparser multiline values injects unexpected configuration keys and values | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | — | — | |
| Open | Privilege check bypass in PostgreSQL DDL enables DoS via type dependencies (pre-18.5/17.11/16.15/15.19/14.24) | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | — | — | |
| Open | PostgreSQL 16–18 SCRAM iteration-count leak allows unauthenticated user enumeration when non-default scram_iterations | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | — | — | |
| Open | PostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24 | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL RLS cache invalidation bug allows unauthorized access after role/ownership changes via plan reuse | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | configparser CR in multiline values allows injected keys/values via attacker-controlled input | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL 16–18: SCRAM iteration-count discrepancy enables unauthenticated user enumeration | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL pgcrypto disabled OpenSSL ciphers leak plaintext; wrong-key decryption bypasses MDC | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL pg_trgm picksplit heap buffer over-read may leak memory via split choices | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL DDL lacks auth for range subtype/expressions, enabling DoS on type ALTER/DROP | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL stale RLS policies after role or ownership changes due to plan reuse | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL ascii() buffer over-read leaks up to 3 bytes via crafted text; affects <18.5/17.11/16.15/15.19/14.24 | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL pgcrypto vuln: disabled ciphers allow cleartext recovery, wrong-key decryption bypasses MDC | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | SCRAM auth iteration-count discrepancy enables user enumeration with non-default scram_iterations; affects PostgreSQL 16–18 pre 18.5/17.11/16.15 | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | ConfigParser write() allows key/value injection via CR in attacker-controlled multiline values | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL pg_trgm picksplit buffer over-read enabling memory inference; affects pre-18.5/17.11/16.15/15.19/14.24 | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | PostgreSQL DDL missing auth enables DoS on type ALTER/DROP via range/expression dependencies | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Fixed within SLA | HDF5 h5repack double free on crafted file with oversized chunk size | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | HDF5 <=2.1.1 SOHM list-index deserialization heap overflow via crafted file, causing crash | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | HDF5 NULL pointer dereference on reading attribute with invalid variable-length datatype field | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | HDF5 h5repack double free when parsing oversized chunk size in crafted file | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Heap-based buffer overflow in HDF5 <=2.1.1 SOHM list-index deserialization (DoS) | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | NULL pointer dereference when reading crafted HDF5 attribute with invalid variable-length datatype | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Double free vulnerability in HDF5 h5repack triggered by crafted file oversized chunk size | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Heap overflow in HDF5 SOHM list-index deserialization triggers DoS with crafted file through 2.1.1 | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | High-severity Skia info leak in Chrome <151.0.7922.169 enables origin policy bypass via crafted HTML page | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Chrome Android Core reference resolution bug leaks sensitive data via crafted HTML pre-151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Chrome <151.0.7922.169 CORS flaw enables compromised renderer to bypass site isolation via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High-severity Skia info leak in Chrome <151.0.7922.169 allows origin policy bypass via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Chrome Android Core reference resolution bug leaks sensitive data via crafted HTML (pre-151.0.7922.169) | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | CORS implementation flaw lets compromised renderer bypass Chrome site isolation (pre-151.0.7922.169) | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Netfs zero_point misupdated with i_size > remote_i_size, causing short reads on EOF | secure-packages-rolling | Aug 18, 2026 | Oct 2, 2026 | Aug 25, 2026 | 6 days | |
| Fixed within SLA | drm/msm/adreno: missing of_node_put causes node reference leak in a6xx_gpu_init() | secure-packages-rolling | Aug 18, 2026 | Oct 2, 2026 | Aug 25, 2026 | 6 days | |
| Fixed within SLA | EROFS xattr inode init leaks folio reference when metabuf not dropped on errors | secure-packages-rolling | Aug 18, 2026 | Oct 2, 2026 | Aug 25, 2026 | 6 days | |
| Fixed within SLA | GStreamer gst-plugins-good avidemux vprp parser OOB read via crafted AVI causes DoS | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Heap OOB read/write and leak via FUJIFILM strd underflow in GStreamer avidemux | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | netfs_release_folio zero_point misupdate when i_size > remote_i_size causes short reads | secure-packages-26.05 | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Reference leak in drm/msm/adreno a6xx_gpu_init from of_parse_phandle early-return paths | secure-packages-26.05 | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | ERoFS inode xattr init: metabuf/folio ref leak on error paths after erofs_read_metabuf | secure-packages-26.05 | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | netfs_release_folio zero_point update uses i_size not remote_i_size, causing EOF short reads | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Reference leak in a6xx_gpu_init() due to missed of_node_put on early error paths | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | ERoFS inode xattr init error paths leak metabuf, causing folio reference leak | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Arithmetic overflow in af_alg AEAD AD length leads to TX buffer size miscalculation | secure-packages-25.11 | Jul 16, 2026 | Aug 30, 2026 | Aug 17, 2026 | 32 days | |
| Fixed within SLA | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days |