← All tracked CVEs
Updated 06:00
Medium severity
Medium45d SLAOur service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | FedCM SOP bypass in Chrome prior to 151.0.7922.72 via crafted HTML page | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Chrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML page | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Chrome iOS <151.0.7922.72 UXSS from insufficient validation of untrusted network input | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Chrome pre-151.0.7922.72 Presentation policy flaw enables remote navigation bypass via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Google Chrome pre-151 Extensions UI security flaw enables malicious extension-based UI spoofing | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Blink same-origin policy bypass in Chrome before 151.0.7922.72 via crafted HTML | secure-packages-26.05 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Site Isolation bypass in Chrome <151.0.7922.72 via crafted HTML after renderer compromise | secure-packages-26.05 | Aug 7, 2026 | Sep 21, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Partial IO fetch leaves canceled flags set, blocking ublk io_uring cancel completion | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | powerpc/64s race between move_pages PMD migration and munmap hits VM_BUG_ON in pmdp_huge_get_and_clear_full | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | ice: race between ice_free_tx_tstamp_ring and ice_tx_map causes NULL deref | secure-packages-rolling | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | ice: Potential NULL dereference in ice_set_ringparam() error path with TXTIME flag set | secure-packages-rolling | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | ublk I/O cancellation may never complete due to stale per-IO canceled flag after partial fetch | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | PowerPC64: PMD migration/munmap race causes VM_BUG_ON in pmdp_huge_get_and_clear_full | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Linux kernel ice driver TX timestamp ring cleanup race causes NULL dereference | secure-packages-26.05 | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | Potential NULL dereference in ice_set_ringparam error path due to uncleared ICE_TX_RING_FLAGS_TXTIME | secure-packages-26.05 | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | vsock/virtio zerocopy multi-skb sends miss completion tracking, leaking pinned pages, no notification | secure-packages-25.11 | Jul 23, 2026 | Sep 6, 2026 | Aug 10, 2026 | 18 days | |
| Fixed within SLA | Phonet: pn_socket_autobind BUG_ON on EINVAL bind causes user-triggerable kernel panic | secure-packages-25.11 | Jul 9, 2026 | Aug 23, 2026 | Aug 10, 2026 | 32 days | |
| Fixed within SLA | Rockchip GPIO: generic IRQ chips leaked on remove, causing potential UAF and crashes | secure-packages-25.11 | Jul 6, 2026 | Aug 20, 2026 | Aug 10, 2026 | 35 days | |
| Fixed within SLA | NTFS3: Missing vcn0 run load causes SPARSE_LCN and WARN_ON in attr_data_get_block_locked | secure-packages-25.11 | Jul 17, 2026 | Aug 31, 2026 | Aug 10, 2026 | 24 days | |
| Fixed within SLA | drm/v3d infinite loop via empty multisync extension; userspace self-referential chain DoS | secure-packages-25.11 | Jul 9, 2026 | Aug 23, 2026 | Aug 10, 2026 | 32 days | |
| Fixed within SLA | ImageMagick <7.1.2-27 magick CLI memory leak on malformed options causes DoS | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 10, 2026 | 5 days | |
| Fixed within SLA | Crafted image triggers heap buffer over-read in ImageMagick BGR decoder pre-7.1.2-27 | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | imgpdc irqchip resource leak and dangling chained handlers cause use-after-free, kernel crashes | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | ImageMagick JNX parsing integer overflow on 32-bit platforms causes heap buffer overwrite | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Heap buffer overwrite in ImageMagick fx operation via crafted argument before 7.1.2-27 | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | fbdev: fb_videomode_to_var NULL deref when new modelist omits current mode | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | nfsd fails to reset write verifier on deferred writeback errors, causing COMMIT data loss | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Missing run load for vcn0 across segments in ntfs3 attr_data_get_block_locked causes SPARSE_LCN WARN_ON | secure-packages-rolling | Jul 20, 2026 | Sep 3, 2026 | Aug 7, 2026 | 18 days | |
| Fixed within SLA | DRM/TTM ttm_bo_shrink() infinite LRU walk on backup failure | secure-packages-rolling | Jul 16, 2026 | Aug 30, 2026 | Aug 7, 2026 | 22 days | |
| Fixed within SLA | rtw88 8821CE probe crash when pci_upstream_bridge() returns NULL on root bus | secure-packages-rolling | Jun 27, 2026 | Aug 11, 2026 | Aug 7, 2026 | 41 days | |
| Fixed within SLA | nf_tables reset commit_mutex causes circular lock with ipset list and iptables-nft '-m set' | secure-packages-rolling | Jun 26, 2026 | Aug 10, 2026 | Aug 7, 2026 | 43 days | |
| Fixed within SLA | ntfs3 attr_data_get_block_locked() misses vcn0 run load across segments, triggers WARN_ON | secure-packages-26.05 | Jul 20, 2026 | Sep 3, 2026 | Aug 7, 2026 | 18 days | |
| Fixed within SLA | Linux kernel drm/ttm ttm_bo_shrink() infinite LRU walk on backup failure | secure-packages-26.05 | Jul 16, 2026 | Aug 30, 2026 | Aug 7, 2026 | 22 days | |
| Fixed within SLA | rtw88 8821CE probe crash due to NULL pci_upstream_bridge on root bus | secure-packages-26.05 | Jun 28, 2026 | Aug 12, 2026 | Aug 7, 2026 | 40 days | |
| Fixed within SLA | nf_tables reset commit_mutex causes circular lock dependency with nft reset, ipset list, iptables-nft -m set | secure-packages-26.05 | Jun 28, 2026 | Aug 12, 2026 | Aug 7, 2026 | 40 days | |
| Fixed within SLA | Concurrent nft_counter dump-and-reset race can double-subtract, underrunning netfilter counter totals | secure-packages-26.05 | Aug 7, 2026 | Sep 21, 2026 | Aug 7, 2026 | same day | |
| Fixed within SLA | Chrome DevTools untrusted input allows remote bypass of navigation restrictions via crafted HTML | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 5, 2026 | 1 day | |
| Fixed within SLA | Windows Chrome Updater allows local UI spoofing via malicious file before 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome DevTools insufficient input validation lets remote attackers bypass navigation restrictions via crafted HTML pre-151.0.7922.72 | secure-packages-25.11 | Aug 4, 2026 | Sep 18, 2026 | Aug 5, 2026 | 1 day | |
| Fixed within SLA | Chrome Android GPU side-channel lets remote attackers leak cross-origin data before 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Google Chrome Cast pre-151.0.7922.72 remote cross-origin data leak via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Google Chrome CSS bug enabled remote script/HTML injection (UXSS) before 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | GetUserMedia allows cross-origin data leak in Chrome prior to 151.0.7922.72 via compromised renderer | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome Credential Management UI spoofing via crafted HTML by remote attacker pre-151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome Payments input validation bug enables UI spoofing by compromised renderer pre-151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome iOS <151.0.7922.72 insufficient input validation enables remote navigation restriction bypass | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Blink cross-origin data leak via crafted HTML in Chrome before 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Chrome DevTools same-origin policy bypass via crafted HTML before 151.0.7922.72 | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | ANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Google Chrome Loader before 151.0.7922.72 leaks cross-origin data via crafted HTML | secure-packages-25.11 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day |