Skip to content
← All tracked CVEs

Updated 03:00

last 30 days

933 fixed within SLA

CVEStatusSeveritySummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLAHighUse-after-free in ieee80211_prepare_and_rx_handle from mesh skb->cb reuse during fast-RXsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 27, 20262 days
Fixed within SLAHighUse-after-free from skb->cb reuse in mac80211 mesh fast-RX rate handlingsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 27, 20263 days
Fixed within SLAMediumHDF5 h5repack double free on crafted file with oversized chunk sizesecure-packages-25.11Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumHDF5 <=2.1.1 SOHM list-index deserialization heap overflow via crafted file, causing crashsecure-packages-25.11Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumHDF5 NULL pointer dereference on reading attribute with invalid variable-length datatype fieldsecure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumHDF5 h5repack double free when parsing oversized chunk size in crafted filesecure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumHeap-based buffer overflow in HDF5 <=2.1.1 SOHM list-index deserialization (DoS)secure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumNULL pointer dereference when reading crafted HDF5 attribute with invalid variable-length datatypesecure-packages-rollingAug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLAMediumDouble free vulnerability in HDF5 h5repack triggered by crafted file oversized chunk sizesecure-packages-rollingAug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLAMediumHeap overflow in HDF5 SOHM list-index deserialization triggers DoS with crafted file through 2.1.1secure-packages-rollingAug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLAHighV8 type confusion enables remote code execution within Chrome sandbox pre-151.0.7922.169secure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighANGLE buffer overflow in Chrome Android <151.0.7922.169 enables sandbox escape remote code executionsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighWebGL use-after-free in Chrome <151.0.7922.169 enables sandbox RCE via crafted HTMLsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighChrome <151.0.7922.169 USB race enables code execution outside sandbox via crafted HTMLsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighV8 miscalculation enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.169secure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLALowChrome pre-151.0.7922.169 GPU uninitialized resource leaks memory outside sandbox via crafted HTMLsecure-packages-rollingAug 24, 2026Nov 22, 2026Aug 25, 20261 day
Fixed within SLAMediumHigh-severity Skia info leak in Chrome <151.0.7922.169 enables origin policy bypass via crafted HTML pagesecure-packages-rollingAug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAHighChrome Mac <151.0.7922.169 Browser use-after-free enables remote sandbox-escape RCE via crafted HTMLsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAMediumChrome Android Core reference resolution bug leaks sensitive data via crafted HTML pre-151.0.7922.169secure-packages-rollingAug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAHighGoogle Chrome <151.0.7922.169 V8 type confusion allows sandboxed RCE via crafted HTMLsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighChrome CredentialProvider link-following on Windows allows local sandbox escape pre-151.0.7922.169secure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLACriticalCritical Dawn buffer overflow allows remote code execution outside sandbox on Android Chrome <151.0.7922.169secure-packages-rollingAug 24, 2026Aug 31, 2026Aug 25, 20261 day
Fixed within SLAHighBuffer overflow in Chrome WebGL before 151.0.7922.169 enables RCE outside sandbox via crafted HTML page.secure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAMediumChrome <151.0.7922.169 CORS flaw enables compromised renderer to bypass site isolation via crafted HTMLsecure-packages-rollingAug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAHighV8 type confusion in Chrome pre-151.0.7922.169 enables sandboxed RCE via crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighChrome Android ANGLE buffer overflow before 151.0.7922.169 enables out-of-sandbox RCEsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighUse-after-free in Chrome WebGL pre-151.0.7922.169 allows sandboxed RCE via crafted HTML pagesecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighChrome <151.0.7922.169 USB race leads to sandbox escape RCE from crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighIncorrect calculation in V8 allows sandboxed RCE via crafted HTML in Chrome <151.0.7922.169secure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLALowChrome GPU uninitialized resource allows memory read outside sandbox post-renderer compromise (pre-151.0.7922.169)secure-packages-26.05Aug 25, 2026Nov 23, 2026Aug 25, 2026same day
Fixed within SLAMediumHigh-severity Skia info leak in Chrome <151.0.7922.169 allows origin policy bypass via crafted HTMLsecure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLAHighHigh-severity Chrome Mac Browser use-after-free pre-151.0.7922.169 allows RCE outside sandbox via crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAMediumChrome Android Core reference resolution bug leaks sensitive data via crafted HTML (pre-151.0.7922.169)secure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLAHighChrome V8 type confusion allows sandboxed RCE via crafted HTML pre-151.0.7922.169secure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighChrome Windows CredentialProvider link-following bug allows local arbitrary code execution outside sandbox pre-151.0.7922.169secure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLACriticalChrome Android Dawn buffer overflow enables remote code execution outside sandbox pre-151.0.7922.169 via crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 1, 2026Aug 25, 2026same day
Fixed within SLAHighCritical WebGL buffer overflow in Chrome <151.0.7922.169 enables sandbox-escape RCE via crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAMediumCORS implementation flaw lets compromised renderer bypass Chrome site isolation (pre-151.0.7922.169)secure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLAHighKVM guest_memfd memslot offset+size signed overflow bypasses i_size bound checksecure-packages-rollingAug 18, 2026Sep 2, 2026Aug 25, 20267 days
Fixed within SLACriticalLinux kernel netfs potential tearing and i_size_seqcount corruption updating remote_i_size/zero_point without i_locksecure-packages-rollingAug 18, 2026Aug 25, 2026Aug 25, 20266 days
Fixed within SLAMediumNetfs zero_point misupdated with i_size > remote_i_size, causing short reads on EOFsecure-packages-rollingAug 18, 2026Oct 2, 2026Aug 25, 20266 days
Fixed within SLAMediumdrm/msm/adreno: missing of_node_put causes node reference leak in a6xx_gpu_init()secure-packages-rollingAug 18, 2026Oct 2, 2026Aug 25, 20266 days
Fixed within SLAMediumEROFS xattr inode init leaks folio reference when metabuf not dropped on errorssecure-packages-rollingAug 18, 2026Oct 2, 2026Aug 25, 20266 days
Fixed within SLAHighHSR RCU readers race with RTM_DELLINK node frees, causing use-after-freesecure-packages-rollingAug 18, 2026Sep 2, 2026Aug 25, 20267 days
Fixed within SLAMediumGStreamer gst-plugins-good avidemux vprp parser OOB read via crafted AVI causes DoSsecure-packages-25.11Aug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAMediumHeap OOB read/write and leak via FUJIFILM strd underflow in GStreamer avidemuxsecure-packages-25.11Aug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAHighKVM guest_memfd uses signed offset/size; sum overflow bypasses memslot binding file-size checksecure-packages-26.05Aug 19, 2026Sep 3, 2026Aug 19, 2026same day
Fixed within SLACriticalLinux kernel netfs potential tearing in remote_i_size/zero_point risking i_size_seqcount corruptionsecure-packages-26.05Aug 19, 2026Aug 26, 2026Aug 19, 2026same day
Fixed within SLAMediumnetfs_release_folio zero_point misupdate when i_size > remote_i_size causes short readssecure-packages-26.05Aug 19, 2026Oct 3, 2026Aug 19, 2026same day
Fixed within SLAMediumReference leak in drm/msm/adreno a6xx_gpu_init from of_parse_phandle early-return pathssecure-packages-26.05Aug 19, 2026Oct 3, 2026Aug 19, 2026same day