← All tracked CVEs
Updated 04:00
Medium severity
Medium45d SLAOur service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | ath11k EMA/MBSSID beacon template memory leak on parameter setup error paths | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | powerpc/64s: munmap race with PMD migration entries hits VM_BUG_ON in pmdp_huge_get_and_clear_full | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | libertas wifi: URBs killed in interrupt context causing sleep-in-atomic bug on TX path | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | Deleting BPF local storage in NMI/reentrant contexts may deadlock via RCU deferral | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | mt76 WiFi driver memory leak from RX queue page_pools on device destroy | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | Deadlock during station removal: mt7925_roc_abort_sync vs roc_work holding dev->mt76.mutex | secure-packages-25.11 | Jul 23, 2026 | Sep 6, 2026 | Aug 15, 2026 | 22 days | |
| Fixed within SLA | Linux mt76 skb memory leak when mt76_connac_mcu_alloc_sta_req fails in wed_update/key_tlv | secure-packages-25.11 | Jul 23, 2026 | Sep 6, 2026 | Aug 15, 2026 | 22 days | |
| Fixed within SLA | f2fs GC reads already updated page causing VM_BUG_ON in folio_end_read | secure-packages-25.11 | Jul 17, 2026 | Aug 31, 2026 | Aug 15, 2026 | 28 days | |
| Fixed within SLA | F2FS data loss from incorrect nat_entry flag use in fsync-checkpoint race | secure-packages-25.11 | Jul 17, 2026 | Aug 31, 2026 | Aug 15, 2026 | 28 days | |
| Fixed within SLA | vsock/virtio MSG_ZEROCOPY misaccounts pinned pages; last skb skips RLIMIT_MEMLOCK enforcement | secure-packages-25.11 | Jul 17, 2026 | Aug 31, 2026 | Aug 15, 2026 | 28 days | |
| Fixed within SLA | lm90_alert lacks hwmon_lock; race with sysfs re-enables alert, causing interrupt storm | secure-packages-25.11 | Aug 12, 2026 | Sep 26, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | iwlwifi mld: Potential NULL pointer dereference in iwl_mld_remove_link storing link->fw_id | secure-packages-25.11 | Aug 12, 2026 | Sep 26, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | Mode change race memsetting team->ops leads to NULL deref in team_xmit | secure-packages-25.11 | Aug 12, 2026 | Sep 26, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | MSM DRM recover_worker skips recovery when idle, leaving hung GPU state and repeated timeouts | secure-packages-25.11 | Aug 4, 2026 | Sep 18, 2026 | Aug 14, 2026 | 10 days | |
| Fixed within SLA | ath11k: memory leaks in beacon template setup error paths (EMA/MBSSID) | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Aug 12, 2026 | 16 days | |
| Fixed within SLA | BPF local storage deletion in NMI or reentrant contexts may deadlock via RCU freeing | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Aug 12, 2026 | 16 days | |
| Fixed within SLA | mt76 wifi driver memory leak on sta_wed_update/sta_key_tlv failures after skb allocation | secure-packages-26.05 | Jul 23, 2026 | Sep 6, 2026 | Aug 12, 2026 | 20 days | |
| Fixed within SLA | Linux f2fs data loss when new-file fsync races with checkpoint nat_entry flags | secure-packages-26.05 | Jul 20, 2026 | Sep 3, 2026 | Aug 12, 2026 | 23 days | |
| Fixed within SLA | Linux kernel af_alg AEAD AD length arithmetic overflow during TX buffer size check | secure-packages-26.05 | Aug 4, 2026 | Sep 18, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | drm/ttm: Infinite LRU walk restoring bulk_move after ttm_bo_swapout() swapout failure | secure-packages-26.05 | Jul 16, 2026 | Aug 30, 2026 | Aug 12, 2026 | 27 days | |
| Fixed within SLA | io_uring zcrx post-open error handling prematurely frees ctx; page pools may persist | secure-packages-26.05 | Aug 11, 2026 | Sep 25, 2026 | Aug 12, 2026 | 1 day | |
| Fixed within SLA | Linux wifi ath11k: memory leaks in beacon template setup error paths (EMA/MBSSID) | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Aug 12, 2026 | 16 days | |
| Fixed within SLA | Linux kernel: Deadlock deleting BPF local storage in NMI due to RCU deferral | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Aug 12, 2026 | 16 days | |
| Fixed within SLA | Linux mt76 WiFi driver leaks skb on error path before mt76_mcu_skb_send_msg | secure-packages-rolling | Jul 23, 2026 | Sep 6, 2026 | Aug 12, 2026 | 20 days | |
| Fixed within SLA | f2fs data loss when fsync of new file races with checkpoint due to nat flags | secure-packages-rolling | Jul 20, 2026 | Sep 3, 2026 | Aug 12, 2026 | 23 days | |
| Fixed within SLA | Linux kernel af_alg AEAD AD length overflow when checking TX buffer size | secure-packages-rolling | Aug 10, 2026 | Sep 24, 2026 | Aug 12, 2026 | 2 days | |
| Fixed within SLA | drm/ttm: Infinite LRU loop on ttm_bo_swapout when swapout fails | secure-packages-rolling | Jul 16, 2026 | Aug 30, 2026 | Aug 12, 2026 | 27 days | |
| Fixed within SLA | secure-packages-rolling | Aug 11, 2026 | Sep 25, 2026 | Aug 12, 2026 | 1 day | ||
| Fixed within SLA | ImageMagick <7.1.2-27 magick CLI memory leak on invalid options enables memory exhaustion | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | Heap buffer over-read in ImageMagick BGR decoder due to missing EOF checks (<7.1.2-27) | secure-packages-25.11 | Aug 4, 2026 | Sep 18, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | Large JNX files on 32-bit ImageMagick cause integer overflow and heap buffer overwrite | secure-packages-25.11 | Aug 4, 2026 | Sep 18, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | ImageMagick <7.1.2-27 heap buffer overwrite in fx operation via crafted argument | secure-packages-25.11 | Aug 4, 2026 | Sep 18, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | Pre-5.0.8/6.0.0-alpha8 Capstone reduced x86 NULL deref on 3DNow! 0F 0F remote crash | secure-packages-25.11 | Aug 4, 2026 | Sep 18, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | cJSON <=1.7.19 JSON Patch non-atomic; failed replace/move deletes target members | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | cJSON ≤1.7.19 JSON Patch non-atomic; failed replace/move deletes target members | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | cJSON ≤1.7.19: non-atomic JSON Patch lets failed replace/move delete target members | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | Chrome Android <151.0.7922.109 GPU uninitialized use leaks memory via crafted HTML | secure-packages-26.05 | Aug 11, 2026 | Sep 25, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Chrome Android GPU uninitialized-use pre-151.0.7922.109 lets compromised renderer leak memory via crafted HTML | secure-packages-25.11 | Aug 10, 2026 | Sep 24, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Uninitialized GPU use in Chrome Android leaks process memory via crafted HTML (pre-151.0.7922.109) | secure-packages-rolling | Aug 10, 2026 | Sep 24, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Chrome pre-151.0.7922.72 SiteIsolation bug let compromised renderer bypass isolation via crafted HTML | secure-packages-25.11 | Aug 10, 2026 | Sep 24, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Windows Chrome Updater bug allows local UI spoofing via malicious file pre-151.0.7922.72 | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Android Chrome <151.0.7922.72 GPU side-channel leaks cross-origin data via crafted HTML | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Chrome Cast prior to 151.0.7922.72 cross-origin data leak via crafted HTML page | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Google Chrome pre-151.0.7922.72 CSS bug allows remote UXSS via crafted HTML | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | GetUserMedia cross-origin data leak in Chrome before 151.0.7922.72 via compromised renderer using crafted HTML page | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Google Chrome Credential Management vulnerability enables remote UI spoofing via crafted HTML pre-151.0.7922.72 | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days |