Posts of last 24 hours
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.44/7.1.8. Affected is the function ovpn_nl_peer_set_doit of the component ovpn. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-74727. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/394504
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.44/7.1.8. This impacts the function xfs_buf_free of the component XFS. Such manipulation of the argument b_addr leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-74728. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
https://vuldb.com/vuln/394503
A vulnerability identified as very critical has been detected in Linux Kernel up to 6.12.103/6.18.44/7.1.8. This affects the function enic_remove of the component enic. This manipulation causes use after free.
This vulnerability is handled as CVE-2026-74725. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/394502
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 7.1.8. The impacted element is the function __bpf_nf_ct_lookup/__bpf_nf_ct_alloc_entry of the component BPF. The manipulation of the argument opts results in null pointer dereference.
This vulnerability is known as CVE-2026-74715. Attacking locally is a requirement. No exploit is available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/394501
A vulnerability was found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. It has been rated as problematic. The affected element is the function devlink_nl_reload_doit of the component devlink. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-74718. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/394500
A vulnerability was found in Linux Kernel up to 6.12.103/6.18.44/7.1.8. It has been declared as critical. Impacted is the function create_direct_keys of the component vdpa. Executing a manipulation can lead to out-of-bounds read.
This vulnerability appears as CVE-2026-74712. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/394499
A vulnerability was found in Linux Kernel up to 6.18.44/7.1.8. It has been classified as problematic. This issue affects the function pmbus_notify of the file drivers/hwmon/pmbus/pmbus_core.c of the component pmbus. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-74711. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/394498
A vulnerability was found in Linux Kernel up to 6.12.103/6.18.44/7.1.8 and classified as very critical. This vulnerability affects unknown code of the component xsk. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-74710. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/394497
A vulnerability has been found in Linux Kernel up to 7.1.8 and classified as very critical. This affects the function __skb_udp_tunnel_segment of the component UDP Tunnel Segmentation. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-74705. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/394496
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 7.1.8. Affected by this issue is the function bnge_aux_dev_release of the component bnge. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-74706. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/394495