Skip to content
← All tracked CVEs

Updated 06:00

Medium severity

Medium45d SLA

Our service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLAFedCM SOP bypass in Chrome prior to 151.0.7922.72 via crafted HTML pagesecure-packages-26.05Aug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAChrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML pagesecure-packages-26.05Aug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAChrome iOS <151.0.7922.72 UXSS from insufficient validation of untrusted network inputsecure-packages-26.05Aug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAChrome pre-151.0.7922.72 Presentation policy flaw enables remote navigation bypass via crafted HTMLsecure-packages-26.05Aug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAGoogle Chrome pre-151 Extensions UI security flaw enables malicious extension-based UI spoofingsecure-packages-26.05Aug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLABlink same-origin policy bypass in Chrome before 151.0.7922.72 via crafted HTMLsecure-packages-26.05Aug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLASite Isolation bypass in Chrome <151.0.7922.72 via crafted HTML after renderer compromisesecure-packages-26.05Aug 7, 2026Sep 21, 2026Aug 11, 20264 days
Fixed within SLAPartial IO fetch leaves canceled flags set, blocking ublk io_uring cancel completionsecure-packages-rollingJul 27, 2026Sep 10, 2026Aug 11, 202615 days
Fixed within SLApowerpc/64s race between move_pages PMD migration and munmap hits VM_BUG_ON in pmdp_huge_get_and_clear_fullsecure-packages-rollingJul 27, 2026Sep 10, 2026Aug 11, 202615 days
Fixed within SLAice: race between ice_free_tx_tstamp_ring and ice_tx_map causes NULL derefsecure-packages-rollingJul 16, 2026Aug 30, 2026Aug 11, 202626 days
Fixed within SLAice: Potential NULL dereference in ice_set_ringparam() error path with TXTIME flag setsecure-packages-rollingJul 16, 2026Aug 30, 2026Aug 11, 202626 days
Fixed within SLAublk I/O cancellation may never complete due to stale per-IO canceled flag after partial fetchsecure-packages-26.05Jul 27, 2026Sep 10, 2026Aug 11, 202615 days
Fixed within SLAPowerPC64: PMD migration/munmap race causes VM_BUG_ON in pmdp_huge_get_and_clear_fullsecure-packages-26.05Jul 27, 2026Sep 10, 2026Aug 11, 202615 days
Fixed within SLALinux kernel ice driver TX timestamp ring cleanup race causes NULL dereferencesecure-packages-26.05Jul 16, 2026Aug 30, 2026Aug 11, 202626 days
Fixed within SLAPotential NULL dereference in ice_set_ringparam error path due to uncleared ICE_TX_RING_FLAGS_TXTIMEsecure-packages-26.05Jul 16, 2026Aug 30, 2026Aug 11, 202626 days
Fixed within SLAvsock/virtio zerocopy multi-skb sends miss completion tracking, leaking pinned pages, no notificationsecure-packages-25.11Jul 23, 2026Sep 6, 2026Aug 10, 202618 days
Fixed within SLAPhonet: pn_socket_autobind BUG_ON on EINVAL bind causes user-triggerable kernel panicsecure-packages-25.11Jul 9, 2026Aug 23, 2026Aug 10, 202632 days
Fixed within SLARockchip GPIO: generic IRQ chips leaked on remove, causing potential UAF and crashessecure-packages-25.11Jul 6, 2026Aug 20, 2026Aug 10, 202635 days
Fixed within SLANTFS3: Missing vcn0 run load causes SPARSE_LCN and WARN_ON in attr_data_get_block_lockedsecure-packages-25.11Jul 17, 2026Aug 31, 2026Aug 10, 202624 days
Fixed within SLAdrm/v3d infinite loop via empty multisync extension; userspace self-referential chain DoSsecure-packages-25.11Jul 9, 2026Aug 23, 2026Aug 10, 202632 days
Fixed within SLAImageMagick <7.1.2-27 magick CLI memory leak on malformed options causes DoSsecure-packages-rollingAug 5, 2026Sep 19, 2026Aug 10, 20265 days
Fixed within SLACrafted image triggers heap buffer over-read in ImageMagick BGR decoder pre-7.1.2-27secure-packages-rollingAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAimgpdc irqchip resource leak and dangling chained handlers cause use-after-free, kernel crashessecure-packages-rollingAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAImageMagick JNX parsing integer overflow on 32-bit platforms causes heap buffer overwritesecure-packages-rollingAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAHeap buffer overwrite in ImageMagick fx operation via crafted argument before 7.1.2-27secure-packages-rollingAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAfbdev: fb_videomode_to_var NULL deref when new modelist omits current modesecure-packages-rollingAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAnfsd fails to reset write verifier on deferred writeback errors, causing COMMIT data losssecure-packages-rollingAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAMissing run load for vcn0 across segments in ntfs3 attr_data_get_block_locked causes SPARSE_LCN WARN_ONsecure-packages-rollingJul 20, 2026Sep 3, 2026Aug 7, 202618 days
Fixed within SLADRM/TTM ttm_bo_shrink() infinite LRU walk on backup failuresecure-packages-rollingJul 16, 2026Aug 30, 2026Aug 7, 202622 days
Fixed within SLArtw88 8821CE probe crash when pci_upstream_bridge() returns NULL on root bussecure-packages-rollingJun 27, 2026Aug 11, 2026Aug 7, 202641 days
Fixed within SLAnf_tables reset commit_mutex causes circular lock with ipset list and iptables-nft '-m set'secure-packages-rollingJun 26, 2026Aug 10, 2026Aug 7, 202643 days
Fixed within SLAntfs3 attr_data_get_block_locked() misses vcn0 run load across segments, triggers WARN_ONsecure-packages-26.05Jul 20, 2026Sep 3, 2026Aug 7, 202618 days
Fixed within SLALinux kernel drm/ttm ttm_bo_shrink() infinite LRU walk on backup failuresecure-packages-26.05Jul 16, 2026Aug 30, 2026Aug 7, 202622 days
Fixed within SLArtw88 8821CE probe crash due to NULL pci_upstream_bridge on root bussecure-packages-26.05Jun 28, 2026Aug 12, 2026Aug 7, 202640 days
Fixed within SLAnf_tables reset commit_mutex causes circular lock dependency with nft reset, ipset list, iptables-nft -m setsecure-packages-26.05Jun 28, 2026Aug 12, 2026Aug 7, 202640 days
Fixed within SLAConcurrent nft_counter dump-and-reset race can double-subtract, underrunning netfilter counter totalssecure-packages-26.05Aug 7, 2026Sep 21, 2026Aug 7, 2026same day
Fixed within SLAChrome DevTools untrusted input allows remote bypass of navigation restrictions via crafted HTMLsecure-packages-rollingAug 4, 2026Sep 18, 2026Aug 5, 20261 day
Fixed within SLAWindows Chrome Updater allows local UI spoofing via malicious file before 151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome DevTools insufficient input validation lets remote attackers bypass navigation restrictions via crafted HTML pre-151.0.7922.72secure-packages-25.11Aug 4, 2026Sep 18, 2026Aug 5, 20261 day
Fixed within SLAChrome Android GPU side-channel lets remote attackers leak cross-origin data before 151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAGoogle Chrome Cast pre-151.0.7922.72 remote cross-origin data leak via crafted HTMLsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAGoogle Chrome CSS bug enabled remote script/HTML injection (UXSS) before 151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAGetUserMedia allows cross-origin data leak in Chrome prior to 151.0.7922.72 via compromised renderersecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome Credential Management UI spoofing via crafted HTML by remote attacker pre-151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome Payments input validation bug enables UI spoofing by compromised renderer pre-151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome iOS <151.0.7922.72 insufficient input validation enables remote navigation restriction bypasssecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLABlink cross-origin data leak via crafted HTML in Chrome before 151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAChrome DevTools same-origin policy bypass via crafted HTML before 151.0.7922.72secure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAGoogle Chrome Loader before 151.0.7922.72 leaks cross-origin data via crafted HTMLsecure-packages-25.11Aug 5, 2026Sep 19, 2026Aug 5, 2026same day