Fwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 19
> Anfang der weitergeleiteten Nachricht: > > Von: "SANS AtRisk" <consensussecurityvulnerabilityalert@email.sans.org> > Betreff: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 19 > Datum: 14. Mai 2026 um 16:09:12 MESZ > An: <be@neosec.eu> > Antwort an: "S
Eigenanreicherung — kein Mirror der Originalquelle
> Anfang der weitergeleiteten Nachricht: > > Von: "SANS AtRisk" <consensussecurityvulnerabilityalert@email.sans.org> > Betreff: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 19 > Datum: 14. Mai 2026 um 16:09:12 MESZ > An: <be@neosec.eu> > Antwort an: "S
Quelle: SANS @RISK. NEOSEC Intel zeigt aus lizenzrechtlichen Gründen keine 1:1-Spiegelung. Volltext und Experten-Einordnung beim Original.
Verknüpfte Empfehlungen
- CVE-2016-5195Linux Kernel — Linux Kernel Race Condition Vulnerability
- CVE-2022-0847Linux Kernel — Linux Kernel Privilege Escalation Vulnerability
- CVE-2022-0847OSV-Eintrag
- CVE-2025-14543Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This iss…
- CVE-2025-71284Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the rad…
- CVE-2026-0073OSV-Eintrag
- CVE-2026-0073In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to re…
- CVE-2026-0300Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
- CVE-2026-0300A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenti…
- CVE-2026-23631Redis: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode
- CVE-2026-23631cve.org:CVE-2026-23631
- CVE-2026-23631redis-server Lua use-after-free may allow remote code execution
- CVE-2026-23631redis-server Lua use-after-free may allow remote code execution
- CVE-2026-23631redis-server Lua use-after-free may allow remote code execution
- CVE-2026-23631redis-server Lua use-after-free may allow remote code execution
- CVE-2026-23631Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica sync…
- CVE-2026-24118VM2 Sandbox Breakout Through __lookupGetter__
- CVE-2026-24118vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code…
- CVE-2026-24118vm2: Mehrere Schwachstellen
- CVE-2026-24120VM2 Has Sandbox Breakout Through Promise Species
- CVE-2026-24120vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers …
- CVE-2026-24781VM2 Has Sandbox Breakout Through Inspect Function
- CVE-2026-24781vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This a…
- CVE-2026-25293Buffer overflow due to incorrect authorization in PLC FW
- CVE-2026-25588cve.org:CVE-2026-25588
- CVE-2026-25588RedisTimeSeries RESTORE invalid memory access may allow remote code execution
- CVE-2026-25588RedisTimeSeries RESTORE invalid memory access may allow remote code execution
- CVE-2026-25588RedisTimeSeries RESTORE invalid memory access may allow remote code execution
- CVE-2026-25588RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values…
- CVE-2026-26332VM2 Has a Sandbox Escape Issue via SuppressedError
- CVE-2026-26332vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This is…
- CVE-2026-26956VM2 Has a WASM Sandbox Escape
- CVE-2026-26956vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside…
- CVE-2026-27960OSV-Eintrag
- CVE-2026-27960OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege e…
- CVE-2026-28780Apache HTTP Server: Mehrere Schwachstellen
- CVE-2026-28780cve.org:CVE-2026-28780
- CVE-2026-28780Debian apache2: security update
- CVE-2026-28780Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
- CVE-2026-28780Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
- CVE-2026-31431Linux Kernel — Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
- CVE-2026-31431IBM QRadar SIEM: Mehrere Schwachstellen
- CVE-2026-31431Linux Kernel: Mehrere Schwachstellen
- CVE-2026-31431Debian linux: security update
- CVE-2026-31431Debian linux: security update
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place
- CVE-2026-31431Linux kernel (IoT) vulnerabilities
- CVE-2026-31431Linux kernel (Low Latency) vulnerabilities
- CVE-2026-31431Linux kernel (Azure) vulnerabilities
- CVE-2026-31431Linux kernel (Azure) vulnerabilities
- CVE-2026-31431Linux kernel (Intel IoTG Real-time) vulnerabilities
- CVE-2026-31431Linux kernel (NVIDIA Tegra IGX) vulnerabilities
- CVE-2026-31431Linux kernel (NVIDIA) vulnerabilities
- CVE-2026-31431Linux kernel (GCP) vulnerabilities
- CVE-2026-31431Linux kernel (Azure)vulnerabilities
- CVE-2026-31431Linux kernel (Azure) vulnerabilities
- CVE-2026-31431Linux kernel (Oracle) vulnerabilities
- CVE-2026-31431Linux kernel (NVIDIA) vulnerabilities
- CVE-2026-31431Linux kernel vulnerabilities
- CVE-2026-31431Linux kernel vulnerabilities
- CVE-2026-31431Linux kernel vulnerabilities
- CVE-2026-31431Linux kernel vulnerabilities
- CVE-2026-31431Linux kernel vulnerabilities
- CVE-2026-31431Linux kernel vulnerabilities
- CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved:
- CVE-2026-31431Linux kernel (NVIDIA Tegra) vulnerabilities
- CVE-2026-31431Linux kernel (Low Latency) vulnerabilities
- CVE-2026-31431Kernel Live Patch Security Notice
- CVE-2026-31705Linux Kernel: Mehrere Schwachstellen
- CVE-2026-31705cve.org:CVE-2026-31705
- CVE-2026-31705ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment
- CVE-2026-31705In the Linux kernel, the following vulnerability has been resolved:
- CVE-2026-31718cve.org:CVE-2026-31718
- CVE-2026-31718ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger
- CVE-2026-31718In the Linux kernel, the following vulnerability has been resolved:
- CVE-2026-33109Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
- CVE-2026-33109Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
- CVE-2026-33446CVE-2026-33446 is a buffer overflow in the authentication sub-system of
- CVE-2026-33447CVE-2026-33447 is a buffer overflow in a message parsing function of the
- CVE-2026-33587Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker conta…
- CVE-2026-33823Microsoft Team Events Portal Information Disclosure Vulnerability
- CVE-2026-33823Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
- CVE-2026-33844Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
- CVE-2026-33844Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
- CVE-2026-33844cve.org:CVE-2026-33844
- CVE-2026-35051Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication
- CVE-2026-35051Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Tra…
- CVE-2026-35428Azure Cloud Shell Spoofing Vulnerability
- CVE-2026-35428Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing …
- CVE-2026-36356The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /act…
- CVE-2026-37531AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget i…
- CVE-2026-37534Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Protocol_Data…
- CVE-2026-37541Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not prope…
- CVE-2026-37709Snipe-IT: Mehrere Schwachstellen
- CVE-2026-37709cve.org:CVE-2026-37709
- CVE-2026-37709Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute …
- CVE-2026-38428Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated…
- CVE-2026-38431ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject…
- CVE-2026-39858Traefik: Pre-authentication decision bypass due to forwarded alias spoofing
- CVE-2026-39858Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnera…
- CVE-2026-40010Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket.
- CVE-2026-40281Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
- CVE-2026-40281Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control ch…
- CVE-2026-40379Azure Entra ID Spoofing Vulnerability
- CVE-2026-40379Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-40682XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
- CVE-2026-40982Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker…
- CVE-2026-41089Windows Netlogon Remote Code Execution Vulnerability
- CVE-2026-41089Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
- CVE-2026-41103Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
- CVE-2026-41103Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges …
- CVE-2026-41589Wish has SCP Path Traversal that allows arbitrary file read/write
- CVE-2026-41589cve.org:CVE-2026-41589
- CVE-2026-41589Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is …
- CVE-2026-41940WebPros cPanel & WHM and WP2 (WordPress Squared) — WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
- CVE-2026-41940cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain una…
- CVE-2026-42027Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader
- CVE-2026-42087OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version …
- CVE-2026-42088OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Scrip…
- CVE-2026-42090Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android versio…
- CVE-2026-42208BerriAI LiteLLM — BerriAI LiteLLM SQL Injection Vulnerability
- CVE-2026-42208LiteLLM has SQL Injection in Proxy API key verification
- CVE-2026-42208LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used du…
- CVE-2026-42233n8n has SQL Injection in Oracle Database Node via Limit Field
- CVE-2026-42233n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation all…
- CVE-2026-42235n8n Vulnerable to XSS via MCP OAuth client
- CVE-2026-42235n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MC…
- CVE-2026-42238Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore
- CVE-2026-42238Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is com…
- CVE-2026-42364An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration c…
- CVE-2026-42368A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead t…
- CVE-2026-42369GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native application…
- CVE-2026-42370A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to a…
- CVE-2026-42373D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh w…
- CVE-2026-42374D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with t…
- CVE-2026-42375D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with t…
- CVE-2026-42376D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80t…
- CVE-2026-42482A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of se…
- CVE-2026-42483A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code…
- CVE-2026-42484A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute …
- CVE-2026-42778The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
- CVE-2026-42779The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
- CVE-2026-42796Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query param…
- CVE-2026-42809Apache Polaris can issue broad temporary ("vended") storage credentials during
- CVE-2026-42810Apache Polaris accepts literal `*` characters in namespace and table names. When it
- CVE-2026-42811In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
- CVE-2026-42812In Apache Iceberg, the table's metadata files are control files: they tell readers
- CVE-2026-42826Azure DevOps Information Disclosure Vulnerability
- CVE-2026-42826Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
- CVE-2026-42880ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
- CVE-2026-42880ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
- CVE-2026-42880Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing …
- CVE-2026-42994Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx suppl…
- CVE-2026-43011cve.org:CVE-2026-43011
- CVE-2026-43011In the Linux kernel, the following vulnerability has been resolved:
- CVE-2026-43038cve.org:CVE-2026-43038
- CVE-2026-43038In the Linux kernel, the following vulnerability has been resolved:
- CVE-2026-43039cve.org:CVE-2026-43039
- CVE-2026-43039In the Linux kernel, the following vulnerability has been resolved:
- CVE-2026-43534OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
- CVE-2026-43534OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers ca…
- CVE-2026-43566OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events
- CVE-2026-43566OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carr…
- CVE-2026-43575OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browse…
- CVE-2026-43578OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background a…
- CVE-2026-43581OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.…
- CVE-2026-43870Apache Thrift: Node.js web_server.js multi-vulnerability
- CVE-2026-43870Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption
- CVE-2026-43870Apache Thrift: Node.js web_server.js multi-vulnerability
- CVE-2026-43870Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP He…
- CVE-2026-44109OpenClaw: Feishu webhook and card-action validation now fail closed
- CVE-2026-44109OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests t…
- CVE-2026-4670Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.
- CVE-2026-4670cve.org:CVE-2026-4670
- CVE-2026-5081Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure.
- CVE-2026-5081cve.org:CVE-2026-5081
- CVE-2026-5174Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation.
- CVE-2026-5174cve.org:CVE-2026-5174
- CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
- CVE-2026-6973An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access …
- CVE-2026-7161An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast pa…
- CVE-2026-7161cve.org:CVE-2026-7161
- CVE-2026-7372A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to a…
- CVE-2026-7372cve.org:CVE-2026-7372
- CVE-2026-7411In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remot…
- CVE-2026-7411cve.org:CVE-2026-7411
- CVE-2026-7414Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices runnin…
- CVE-2026-7414cve.org:CVE-2026-7414
- CVE-2026-7415The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same n…
- CVE-2026-7415cve.org:CVE-2026-7415
- CVE-2026-7482Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
- CVE-2026-7482cve.org:CVE-2026-7482
- CVE-2026-7482Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF fi…
- CVE-2026-7853A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. Thi…
- CVE-2026-7853cve.org:CVE-2026-7853
- CVE-2026-7854A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.as…
- CVE-2026-7854cve.org:CVE-2026-7854
Mehr zu Fwd
Weitere Empfehlungen
- osv:CVE-2026-53338nonenet: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues()
- osv:GO-2026-4899noneSliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver
- osv:GHSA-c279-989m-238fnoneSliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted
- osv:CVE-2026-23070noneOcteontx2-af: Add proper checks for fwdata
- osv:CVE-2023-53372nonesctp: fix a potential overflow in sctp_ifwdtsn_skip
- osv:CVE-2022-49604noneip: Fix data-races around sysctl_ip_fwd_use_pmtu.
- osv:CVE-2022-49603noneip: Fix data-races around sysctl_ip_fwd_update_priority.
- osv:GSD-2022-1004784noneip: Fix data-races around sysctl_ip_fwd_use_pmtu.
Weitere News-Einträge
- Schwachstellesans-atrisk2026-05-28Fwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 21
- Schwachstellesans-atrisk2026-05-21Fwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 20
- Newssans-ouchFwd: OUCH! World Cup Fever: Don’t Let Scammers Score
- Newssans-ouchFwd: OUCH! The Power of the Passphrase: Why Longer Beats Smarter