Posts of last 24 hours
CVE-2026-64507 | Linux Kernel up to 7.2-rc1 BPF JIT bugs.c allocation of resources (EUVD-2026-48851)
A vulnerability was found in Linux Kernel up to 6.6.144/6.12.96/6.18.38/7.1.3/7.2-rc1. It has been rated as problematic. This issue affects some unknown processing of the file bugs.c of the component BPF JIT. This manipulation causes allocation of resources.
The identification of this vulnerability is CVE-2026-64507. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/383300
A vulnerability was found in Linux Kernel up to 7.2-rc2. It has been declared as very critical. This vulnerability affects the function __bmc150_accel_fifo_flush of the component BMC150 Accelerometer Driver. The manipulation results in stack-based buffer overflow.
This vulnerability was named CVE-2026-64504. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/383299
A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services. As part of the Open Defense Initiative, Depthfirst researcher Yuhang Wu used the automated analysis […]
The post GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations appeared first on Cyber Security News.
https://cybersecuritynews.com/gitlab-vulnerabilities-enable-code-execution/
A vulnerability was found in Linux Kernel up to 7.2-rc2. It has been classified as critical. This affects the function lpc32xx_adc_probe of the file drivers/iio/adc/lpc32xx_adc.c of the component Lpc32xx Adc. The manipulation leads to uninitialized pointer.
This vulnerability is uniquely identified as CVE-2026-64500. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/383298
A vulnerability was found in Linux Kernel up to 7.1.3 and classified as very critical. Affected by this issue is the function iio_hw_buf_release of the component hw-consumer. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2026-64498. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/383297
A vulnerability has been found in Linux Kernel up to 6.18.38/7.1.3 and classified as critical. Affected by this vulnerability is the function handle_tpr_below_threshold of the component KVM. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2026-64513. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/383296
A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.1.3. Affected is an unknown function of the component rtw89. Such manipulation leads to state issue.
This vulnerability is traded as CVE-2026-64506. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/383295
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.1.3. This impacts the function cpc_write of the file drivers/acpi/cppc_acpi.c of the component Cppc. This manipulation of the argument access_width causes out-of-bounds read.
This vulnerability appears as CVE-2026-64512. The attack requires local access. There is no available exploit.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/383294
A vulnerability classified as very critical was found in Linux Kernel up to 7.1.3. This affects the function FIELD_GET of the file linux/bitfield.h of the component scd30. The manipulation results in integer overflow.
This vulnerability is reported as CVE-2026-64497. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
https://vuldb.com/vuln/383293
A vulnerability described as critical has been identified in Linux Kernel up to 7.1.3. The affected element is the function bmg160_get_filter/bmg160_set_filter of the file drivers/iio/gyro/bmg160_core.c of the component Bmg160. Executing a manipulation of the argument bw_bits can lead to out-of-bounds read.
This vulnerability is registered as CVE-2026-64495. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/383291