Search CVE reports


Toggle filters

1 – 10 of 46992 results

Status is adjusted based on your filters.


CVE-2026-84838

Medium priority
Needs evaluation

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell...

1 affected package

rpm

Package 20.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-84837

Medium priority
Needs evaluation

A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in...

1 affected package

rpm

Package 20.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-78662

Medium priority
Needs evaluation

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established...

10 affected packages

golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...

Package 20.04 LTS
golang-1.17
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
golang-1.26
golang-1.27
golang-defaults Needs evaluation
Show all 10 packages Show less packages

CVE-2026-78410

Medium priority
Needs evaluation

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor...

1 affected package

util-linux

Package 20.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-78409

Medium priority
Needs evaluation

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep...

1 affected package

util-linux

Package 20.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-78408

Medium priority
Needs evaluation

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations...

1 affected package

util-linux

Package 20.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-76642

Medium priority
Needs evaluation

[Unknown description]

1 affected package

util-linux

Package 20.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-74994

Medium priority
Needs evaluation

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-74835

Medium priority
Needs evaluation

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-73812

Medium priority
Needs evaluation

httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages