← All tracked CVEs
Updated 03:00
last 30 days
933 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | ERoFS inode xattr init: metabuf/folio ref leak on error paths after erofs_read_metabuf | secure-packages-26.05 | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | High | HSR RTM_DELLINK frees nodes without RCU, causing generic-netlink reader use-after-free | secure-packages-26.05 | Aug 19, 2026 | Sep 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Critical | Netfs: Tearing in remote_i_size/zero_point may corrupt i_size_seqcount | secure-packages-25.11 | Aug 18, 2026 | Aug 25, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Medium | netfs_release_folio zero_point update uses i_size not remote_i_size, causing EOF short reads | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Medium | Reference leak in a6xx_gpu_init() due to missed of_node_put on early error paths | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Medium | ERoFS inode xattr init error paths leak metabuf, causing folio reference leak | secure-packages-25.11 | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Blink use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.137 | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Chrome <151.0.7922.137 HTML use-after-free enables sandboxed remote code execution via crafted page | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed code execution via malicious extension | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Google Chrome Mac TabStrip use-after-free enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.137) | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | High-severity V8 use-after-free in Chrome <151.0.7922.137 enables sandboxed RCE via crafted HTML | secure-packages-25.11 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Chrome <151.0.7922.137 Blink use-after-free allows sandboxed remote code execution via crafted HTML | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Chrome <151.0.7922.137 HTML use-after-free enables sandboxed RCE via crafted page | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed arbitrary code execution | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | High-severity TabStrip use-after-free enables sandbox escape via HTML on Chrome Mac <151.0.7922.137 | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome V8 pre-151.0.7922.137 allows sandboxed remote code execution | secure-packages-rolling | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | KVM guest_memfd offset+size treated signed, letting negative sum bypass file size check | secure-packages-25.11 | Aug 17, 2026 | Sep 1, 2026 | Aug 18, 2026 | 1 day | |
| Fixed within SLA | High | FFmpeg 7.0–8.1.2 vf_quirc heap OOB write via crafted PGS/SUP subtitles mismatched dimensions | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | Heap out-of-bounds write in FFmpeg PNG/APNG encoder eXIf handling (≤8.1.2) | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg <=8.1.2 MACE6 CAF bytes_per_packet integer overflow causes heap OOB write, RCE | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg up to 8.1.2 LCL/ZLIB decoder leaks uninitialized heap; short inflate enables ASLR bypass | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg ≤8.1.2 IAMF demuxer uncontrolled allocation from 17-byte input via count_label | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg ≤8.1.2 vf_hqdn3d heap OOB write when -reinit_filter 0 and resolution increases | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg 3.0-8.1.2 vf_swaprect OOB write on odd-width NV12 frames causing heap corruption | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg 3.4-8.1.2 vf_floodfill OOB write with -reinit_filter 0, heap corruption | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg <=8.1.2 heap corruption via TY demuxer OOB write using crafted ffconcat with -safe 0 | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg 2.7–8.1.2 TDSC decoder OOB write causing heap corruption and potential RCE | secure-packages-rolling | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | Critical | UAF in netfs_unlock_abandoned_read_pages and netfs_unlock_read_folio after request progress cleared | secure-packages-25.11 | Aug 12, 2026 | Aug 19, 2026 | Aug 18, 2026 | 6 days | |
| Fixed within SLA | Low | secure-packages-rolling | Jun 15, 2026 | Sep 13, 2026 | Aug 18, 2026 | 63 days | ||
| Fixed within SLA | Medium | Arithmetic overflow in af_alg AEAD AD length leads to TX buffer size miscalculation | secure-packages-25.11 | Jul 16, 2026 | Aug 30, 2026 | Aug 17, 2026 | 32 days | |
| Fixed within SLA | Medium | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | secure-packages-25.11 | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | High | mlx5e XSK race: unlocked ICOSQ IRQ trigger during NAPI affinity change causes CQE errors | secure-packages-rolling | Aug 12, 2026 | Aug 27, 2026 | Aug 15, 2026 | 2 days | |
| Fixed within SLA | High | mlx5e XSK: Unprotected ICOSQ IRQ trigger races with NAPI and CPU affinity changes | secure-packages-26.05 | Aug 12, 2026 | Aug 27, 2026 | Aug 15, 2026 | 2 days | |
| Fixed within SLA | High | Linux iwlwifi BA handlers use ffs on zero sta_mask, causing out-of-bounds access | secure-packages-25.11 | Aug 14, 2026 | Aug 29, 2026 | Aug 15, 2026 | same day | |
| Fixed within SLA | Medium | ath11k EMA/MBSSID beacon template memory leak on parameter setup error paths | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | Medium | powerpc/64s: munmap race with PMD migration entries hits VM_BUG_ON in pmdp_huge_get_and_clear_full | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | Medium | libertas wifi: URBs killed in interrupt context causing sleep-in-atomic bug on TX path | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | Medium | Deleting BPF local storage in NMI/reentrant contexts may deadlock via RCU deferral | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | Medium | mt76 WiFi driver memory leak from RX queue page_pools on device destroy | secure-packages-25.11 | Jul 27, 2026 | Sep 10, 2026 | Aug 15, 2026 | 18 days | |
| Fixed within SLA | Medium | Deadlock during station removal: mt7925_roc_abort_sync vs roc_work holding dev->mt76.mutex | secure-packages-25.11 | Jul 23, 2026 | Sep 6, 2026 | Aug 15, 2026 | 22 days | |
| Fixed within SLA | Medium | Linux mt76 skb memory leak when mt76_connac_mcu_alloc_sta_req fails in wed_update/key_tlv | secure-packages-25.11 | Jul 23, 2026 | Sep 6, 2026 | Aug 15, 2026 | 22 days | |
| Fixed within SLA | Medium | f2fs GC reads already updated page causing VM_BUG_ON in folio_end_read | secure-packages-25.11 | Jul 17, 2026 | Aug 31, 2026 | Aug 15, 2026 | 28 days | |
| Fixed within SLA | Medium | F2FS data loss from incorrect nat_entry flag use in fsync-checkpoint race | secure-packages-25.11 | Jul 17, 2026 | Aug 31, 2026 | Aug 15, 2026 | 28 days | |
| Fixed within SLA | Medium | vsock/virtio MSG_ZEROCOPY misaccounts pinned pages; last skb skips RLIMIT_MEMLOCK enforcement | secure-packages-25.11 | Jul 17, 2026 | Aug 31, 2026 | Aug 15, 2026 | 28 days |