← All tracked CVEs
Updated 10:00
Medium severity
Medium45d SLAOur service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Deferred split queue race during migration makes dst visible early, triggering WARN and folio loss | secure-packages-rolling | Jun 19, 2026 | Aug 3, 2026 | Jul 30, 2026 | 41 days | |
| Fixed within SLA | mm/damon: damos_walk and kdamond exit race causes deadlock with infinite request wait | secure-packages-rolling | Jun 19, 2026 | Aug 3, 2026 | Jul 30, 2026 | 41 days | |
| Fixed within SLA | ASoC nau8821: Unloading driver with pending jdet_work causes kernel crash | secure-packages-rolling | Jun 17, 2026 | Aug 1, 2026 | Jul 30, 2026 | 43 days | |
| Fixed within SLA | gfs2_fill_super leaks kernel threads and quota bitmap on read-write transition failure | secure-packages-rolling | Jun 17, 2026 | Aug 1, 2026 | Jul 30, 2026 | 43 days | |
| Fixed within SLA | KVM nSVM: Ignored CR3 load failure on nested #VMEXIT causes corrupted vCPU state | secure-packages-26.05 | Jun 19, 2026 | Aug 3, 2026 | Jul 30, 2026 | 42 days | |
| Fixed within SLA | Deferred split queue race during folio migration marks dst partially mapped, triggers WARN | secure-packages-26.05 | Jun 19, 2026 | Aug 3, 2026 | Jul 30, 2026 | 42 days | |
| Fixed within SLA | damos_walk vs kdamond_fn exit race leads unhandled requests and indefinite wait deadlock | secure-packages-26.05 | Jun 19, 2026 | Aug 3, 2026 | Jul 30, 2026 | 42 days | |
| Fixed within SLA | Unloading snd_soc_nau8821 while jdet_work pending triggers kernel crash | secure-packages-26.05 | Jun 17, 2026 | Aug 1, 2026 | Jul 30, 2026 | 43 days | |
| Fixed within SLA | Linux GFS2 gfs2_fill_super error-path memory leaks: kthreads and quota bitmap on RW transition | secure-packages-26.05 | Jun 17, 2026 | Aug 1, 2026 | Jul 30, 2026 | 43 days | |
| Fixed within SLA | Unbound 1.20–1.25.1 counter not decremented in serve-expired discard-timeout; clients dropped | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound ≤1.25.1 heap overflow processing absent second name in multi-dname RDATA (SOA) during DNSSEC validation | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.22-1.25.1 DoQ remote crash: libngtcp2 assert via -1 application error on STREAM_DATA_BLOCKED | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.7.0–1.25.1 DNSCrypt cert/key count mismatch causes unauthenticated UDP-triggered crash | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Remote Unbound 1.10.0–1.25.1 crash DoS with serve-expired + respip CNAME override, NULL deref | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.25.0–1.25.1 respip/dns64 shallow view-name copy corrupts memory under pressure | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound <=1.25.1: 0.0.0.0/::0 glue triggers unwanted-reply threshold DoS cache flushes | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.7.0–1.25.1 accepts BOGUS XFR primary hostname, enabling spoofed zone/RPZ takeover | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound respip/RPZ ignores DNSSEC status, rewriting BOGUS A/AAAA to INSECURE spoofable redirects | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound DoT TLS server name dangling pointer during handshake triggers crash/DoS (1.15–1.25.1) | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.22.0–1.25.1 bypasses max-global-quota via deeply nested DNSSEC query amplification | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | libunbound up to 1.25.1 crash: unwanted-reply-threshold triggers disallowed libworker_alloc_cleanup call | secure-packages-rolling | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Heap buffer overflow in audiofile 0.3.6 FilePOSIX::read triggers DoS via crafted WAV (sfconvert) | secure-packages-rolling | Jun 15, 2026 | Jul 30, 2026 | Jul 29, 2026 | 44 days | |
| Fixed within SLA | Unbound 1.20–1.25 misconfigured serve-expired discard-timeout fails counter decrement, drops duplicate clients | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound ≤1.25.1 heap overflow canonicalizing RRSIG-covered PX/RP/MINFO/SOA with missing second name | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unauthenticated DoQ client crashes Unbound 1.22–1.25.1 via libngtcp2 assertion from -1 error | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.7.0–1.25.1 DNSCrypt DoS from cert/secret mismatch; 0xdb-triggered UDP crash | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.10.0–1.25.1 DoS: serve-expired with respip/RPZ CNAME triggers NULL pointer crash | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.25.0–1.25.1 subquery shallow view-name copy risks memory corruption with respip/dns64 | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound ≤1.25.1 DoS: 0.0.0.0/::0 glue with unwanted-reply-threshold triggers endless cache flushes | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.7.0–1.25.1 accepts bogus RPZ primary, enabling spoofed XFR and policy takeover | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound ≤1.25.1 respip before validator ignores DNSSEC, rewriting BOGUS A/AAAA INSECURE, enabling poisoning. | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound DoT TLS handshake use-after-free leads to daemon crash (1.15.0–1.25.1) | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.22–1.25.1 upstream packets per query exceed max-global-quota for deep DNSSEC names | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | libunbound <=1.25.1 aborts when unwanted-reply-threshold invokes disallowed libworker_alloc_cleanup | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound respip with response-ip/RPZ ignores DNSSEC; rewrites BOGUS A/AAAA to operator IP as INSECURE | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.10.0–1.25.1 crash: serve-expired with respip/RPZ CNAME causes NULL dereference DoS | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.22.0–1.25.1 exceeds max-global-quota on deeply nested DNSSEC query, bypassing amplification limits | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.22–1.25.1 DoQ: unauth client aborts process via libngtcp2 assertion failure | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.20.0–1.25.1 serve-expired misconfig causes discard-timeout counter leak, silently dropping duplicate clients | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | NLnet Labs Unbound ≤1.25.1 heap overflow canonicalizing RRSIG-covered multi-dname RDATA missing second name | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.7.0–1.25.1 DNSCrypt DoS from misconfigured extra certs, crafted UDP | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.25.0–1.25.1 shallow view-name copy causes memory corruption with subqueries under jostle | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.7.0-1.25.1 accepts bogus primary hostname for XFR, enabling RPZ takeover | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound ≤1.25.1 DoS: 0.0.0.0/::0 glue triggers unwanted-reply-threshold cache flush loop | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | libunbound <=1.25.1 terminates when unwanted-reply-threshold triggers; libworker_alloc_cleanup missing allowlist | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Use-after-free in Unbound DoT TLS server name causes crash during handshake | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days |