Posts of last 24 hours
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.38/7.1.3/7.2-rc1. The impacted element is the function tascam_disconnect of the component ALSA usx2y. The manipulation results in use after free.
This vulnerability is known as CVE-2026-64491. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.
https://vuldb.com/vuln/383281
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.2-rc2. The affected element is the function rtw_cfg80211_set_wpa_ie of the component rtl8723bs. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-64446. An attack has to be approached locally. There is no exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/383280
A vulnerability classified as problematic was found in Linux Kernel up to 7.1.3. Impacted is the function snd_dualsense_ih_match of the component ALSA USB Audio. Executing a manipulation can lead to null pointer dereference.
This vulnerability appears as CVE-2026-64478. The attack requires local access. There is no available exploit.
Upgrading the affected component is advised.
https://vuldb.com/vuln/383279
A vulnerability classified as critical has been found in Linux Kernel up to 6.12.95/6.18.38/7.1.3/7.2-rc1. This issue affects the function cpu_to_node of the component resctrl. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-64477. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/383278
A vulnerability described as very critical has been identified in Linux Kernel up to 7.1.3. This vulnerability affects the function snd_ctl_new1 of the component ALSA. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-64484. The attack needs to be performed locally. There is not any exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/383277
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.12.96/6.18.38/7.1.3. This affects the function cs35l41_remove_dsp of the component Alsa Hda Cs35l41. This manipulation causes privilege escalation.
This vulnerability is registered as CVE-2026-64481. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/383276
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3. Affected by this issue is the function snd_gf1_pcm_volume_control of the component ALSA. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-64482. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/383275
A vulnerability identified as very critical has been detected in Linux Kernel up to 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3. Affected by this vulnerability is the function snd_ctl_new1 of the file ice1712.c/ice1724.c/aureon.c of the component ALSA ice1712 driver. The manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2026-64480. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/383274
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.6.144/6.12.95/6.18.38/7.1.3. Affected is the function snd_seq_event_dup of the component ALSA. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is tracked as CVE-2026-64479. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/383273
A vulnerability was found in Linux Kernel up to 6.6.144/6.12.95/6.18.38/7.1.3. It has been rated as problematic. This impacts the function vfio_mig_get_next_state of the component Vfio. Performing a manipulation results in infinite loop.
This vulnerability is identified as CVE-2026-64474. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/383272