← All tracked CVEs
Updated 03:00
last 30 days
933 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | High | Use-after-free in ieee80211_prepare_and_rx_handle from mesh skb->cb reuse during fast-RX | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 27, 2026 | 2 days | |
| Fixed within SLA | High | Use-after-free from skb->cb reuse in mac80211 mesh fast-RX rate handling | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 27, 2026 | 3 days | |
| Fixed within SLA | Medium | HDF5 h5repack double free on crafted file with oversized chunk size | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | HDF5 <=2.1.1 SOHM list-index deserialization heap overflow via crafted file, causing crash | secure-packages-25.11 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | HDF5 NULL pointer dereference on reading attribute with invalid variable-length datatype field | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | HDF5 h5repack double free when parsing oversized chunk size in crafted file | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | Heap-based buffer overflow in HDF5 <=2.1.1 SOHM list-index deserialization (DoS) | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | NULL pointer dereference when reading crafted HDF5 attribute with invalid variable-length datatype | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | Double free vulnerability in HDF5 h5repack triggered by crafted file oversized chunk size | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | Heap overflow in HDF5 SOHM list-index deserialization triggers DoS with crafted file through 2.1.1 | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | High | V8 type confusion enables remote code execution within Chrome sandbox pre-151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | ANGLE buffer overflow in Chrome Android <151.0.7922.169 enables sandbox escape remote code execution | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | WebGL use-after-free in Chrome <151.0.7922.169 enables sandbox RCE via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | Chrome <151.0.7922.169 USB race enables code execution outside sandbox via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | V8 miscalculation enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Low | Chrome pre-151.0.7922.169 GPU uninitialized resource leaks memory outside sandbox via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Nov 22, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Medium | High-severity Skia info leak in Chrome <151.0.7922.169 enables origin policy bypass via crafted HTML page | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | Chrome Mac <151.0.7922.169 Browser use-after-free enables remote sandbox-escape RCE via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Medium | Chrome Android Core reference resolution bug leaks sensitive data via crafted HTML pre-151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | Google Chrome <151.0.7922.169 V8 type confusion allows sandboxed RCE via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | Chrome CredentialProvider link-following on Windows allows local sandbox escape pre-151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Critical | Critical Dawn buffer overflow allows remote code execution outside sandbox on Android Chrome <151.0.7922.169 | secure-packages-rolling | Aug 24, 2026 | Aug 31, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | Buffer overflow in Chrome WebGL before 151.0.7922.169 enables RCE outside sandbox via crafted HTML page. | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.169 CORS flaw enables compromised renderer to bypass site isolation via crafted HTML | secure-packages-rolling | Aug 24, 2026 | Oct 8, 2026 | Aug 25, 2026 | 1 day | |
| Fixed within SLA | High | V8 type confusion in Chrome pre-151.0.7922.169 enables sandboxed RCE via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Chrome Android ANGLE buffer overflow before 151.0.7922.169 enables out-of-sandbox RCE | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome WebGL pre-151.0.7922.169 allows sandboxed RCE via crafted HTML page | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.169 USB race leads to sandbox escape RCE from crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Incorrect calculation in V8 allows sandboxed RCE via crafted HTML in Chrome <151.0.7922.169 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Low | Chrome GPU uninitialized resource allows memory read outside sandbox post-renderer compromise (pre-151.0.7922.169) | secure-packages-26.05 | Aug 25, 2026 | Nov 23, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Medium | High-severity Skia info leak in Chrome <151.0.7922.169 allows origin policy bypass via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | High-severity Chrome Mac Browser use-after-free pre-151.0.7922.169 allows RCE outside sandbox via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android Core reference resolution bug leaks sensitive data via crafted HTML (pre-151.0.7922.169) | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 type confusion allows sandboxed RCE via crafted HTML pre-151.0.7922.169 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Chrome Windows CredentialProvider link-following bug allows local arbitrary code execution outside sandbox pre-151.0.7922.169 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Android Dawn buffer overflow enables remote code execution outside sandbox pre-151.0.7922.169 via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 1, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Critical WebGL buffer overflow in Chrome <151.0.7922.169 enables sandbox-escape RCE via crafted HTML | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Medium | CORS implementation flaw lets compromised renderer bypass Chrome site isolation (pre-151.0.7922.169) | secure-packages-26.05 | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | KVM guest_memfd memslot offset+size signed overflow bypasses i_size bound check | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 25, 2026 | 7 days | |
| Fixed within SLA | Critical | Linux kernel netfs potential tearing and i_size_seqcount corruption updating remote_i_size/zero_point without i_lock | secure-packages-rolling | Aug 18, 2026 | Aug 25, 2026 | Aug 25, 2026 | 6 days | |
| Fixed within SLA | Medium | Netfs zero_point misupdated with i_size > remote_i_size, causing short reads on EOF | secure-packages-rolling | Aug 18, 2026 | Oct 2, 2026 | Aug 25, 2026 | 6 days | |
| Fixed within SLA | Medium | drm/msm/adreno: missing of_node_put causes node reference leak in a6xx_gpu_init() | secure-packages-rolling | Aug 18, 2026 | Oct 2, 2026 | Aug 25, 2026 | 6 days | |
| Fixed within SLA | Medium | EROFS xattr inode init leaks folio reference when metabuf not dropped on errors | secure-packages-rolling | Aug 18, 2026 | Oct 2, 2026 | Aug 25, 2026 | 6 days | |
| Fixed within SLA | High | HSR RCU readers race with RTM_DELLINK node frees, causing use-after-free | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 25, 2026 | 7 days | |
| Fixed within SLA | Medium | GStreamer gst-plugins-good avidemux vprp parser OOB read via crafted AVI causes DoS | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Medium | Heap OOB read/write and leak via FUJIFILM strd underflow in GStreamer avidemux | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | KVM guest_memfd uses signed offset/size; sum overflow bypasses memslot binding file-size check | secure-packages-26.05 | Aug 19, 2026 | Sep 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Critical | Linux kernel netfs potential tearing in remote_i_size/zero_point risking i_size_seqcount corruption | secure-packages-26.05 | Aug 19, 2026 | Aug 26, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Medium | netfs_release_folio zero_point misupdate when i_size > remote_i_size causes short reads | secure-packages-26.05 | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Medium | Reference leak in drm/msm/adreno a6xx_gpu_init from of_parse_phandle early-return paths | secure-packages-26.05 | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day |