๐จ CVE-2026-74378
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
get_srq_wqe() reads wqe->dma.num_sge from the shared receive queue
buffer, which is mapped into userspace. It validates num_sge against
max_sge, but then re-reads the same field to calculate the memcpy
size. A concurrent userspace thread can modify num_sge between
validation and use, causing a heap buffer overflow when copying the
WQE into qp->resp.srq_wqe.
Read num_sge into a local variable and use it for both the bounds
check and the size calculation.
๐@cveNotify
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
get_srq_wqe() reads wqe->dma.num_sge from the shared receive queue
buffer, which is mapped into userspace. It validates num_sge against
max_sge, but then re-reads the same field to calculate the memcpy
size. A concurrent userspace thread can modify num_sge between
validation and use, causing a heap buffer overflow when copying the
WQE into qp->resp.srq_wqe.
Read num_sge into a local variable and use it for both the bounds
check and the size calculation.
๐@cveNotify
๐จ CVE-2026-74474
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use pskb_network_may_pull() for transmit path header pulls
In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was
being called to verify the availability of network layer headers (ARP, IPv6/ND,
IP/IPv6 MDB keys).
However, during transmit skb->data points to the MAC header, so skb_network_offset(skb)
is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data
rather than skb_network_offset(skb) + len, which can leave part of the network header
in non-linear frags.
Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly
account for the MAC header offset.
๐@cveNotify
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use pskb_network_may_pull() for transmit path header pulls
In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was
being called to verify the availability of network layer headers (ARP, IPv6/ND,
IP/IPv6 MDB keys).
However, during transmit skb->data points to the MAC header, so skb_network_offset(skb)
is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data
rather than skb_network_offset(skb) + len, which can leave part of the network header
in non-linear frags.
Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly
account for the MAC header offset.
๐@cveNotify
๐จ CVE-2026-72991
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-15892
The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP is enabled, relying on the end: label to k_free() them. When CONFIG_MCUMGR_GRP_SETTINGS_ACCESS_HOOK is also enabled and the application access hook rejects a request by returning status MGMT_CB_ERROR_RC, the handler executed return ret_rc; directly, bypassing end: and leaking the heap allocation on every rejected request.
The settings handlers are reachable over the unauthenticated SMP transport (Bluetooth LE, UART, or UDP, depending on product configuration). The access hook is the mechanism applications use to deny unauthorized settings access, and MGMT_CB_ERROR_RC is a common rejection style, so an attacker who can send settings read/write/delete commands that the hook rejects triggers a heap leak on each attempt.
Because the leaked memory is never reclaimed until reboot, a sustained stream of rejected requests monotonically exhausts the kernel heap until k_malloc() fails, denying mcumgr service and impacting any other heap consumer on the device โ a denial of service. The impact is availability-only; there is no memory corruption or information disclosure. Only configurations that select the heap buffer type, enable the access hook, and register a hook that returns MGMT_CB_ERROR_RC are affected (the default stack buffer type cannot leak).
๐@cveNotify
The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP is enabled, relying on the end: label to k_free() them. When CONFIG_MCUMGR_GRP_SETTINGS_ACCESS_HOOK is also enabled and the application access hook rejects a request by returning status MGMT_CB_ERROR_RC, the handler executed return ret_rc; directly, bypassing end: and leaking the heap allocation on every rejected request.
The settings handlers are reachable over the unauthenticated SMP transport (Bluetooth LE, UART, or UDP, depending on product configuration). The access hook is the mechanism applications use to deny unauthorized settings access, and MGMT_CB_ERROR_RC is a common rejection style, so an attacker who can send settings read/write/delete commands that the hook rejects triggers a heap leak on each attempt.
Because the leaked memory is never reclaimed until reboot, a sustained stream of rejected requests monotonically exhausts the kernel heap until k_malloc() fails, denying mcumgr service and impacting any other heap consumer on the device โ a denial of service. The impact is availability-only; there is no memory corruption or information disclosure. Only configurations that select the heap buffer type, enable the access hook, and register a hook that returns MGMT_CB_ERROR_RC are affected (the default stack buffer type cannot leak).
๐@cveNotify
GitHub
mgmt: mcumgr: fix heap leak on settings access hook rejection ยท zephyrproject-rtos/zephyr@fabc488
settings_mgmt_read()/_write()/_delete() each allocate key_name (and
data, for read) from the heap when CONFIG_MCUMGR_GRP_SETTINGS_
BUFFER_TYPE_HEAP is enabled, then optionally call an application
a...
data, for read) from the heap when CONFIG_MCUMGR_GRP_SETTINGS_
BUFFER_TYPE_HEAP is enabled, then optionally call an application
a...
๐จ CVE-2026-16726
Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows
attackers to stop Windows.
๐@cveNotify
Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows
attackers to stop Windows.
๐@cveNotify
USB Driver "PTUsbDrvA5" - Panasonic
Panasonic USB Driver "PTUsbDrvA5" information
๐จ CVE-2026-68955
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
๐@cveNotify
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
๐@cveNotify
Rakuten Kobo
Security Advisory - Kobo Desktop App Installer
A vulnerability has been identified in a prior version of the installer for Kobo Desktop App regarding, which could allow a malicious DLL in the same directory as the installer to be loaded. As a r...
๐จ CVE-2026-82762
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
๐จ CVE-2026-82763
Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
๐จ CVE-2026-82764
Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.
๐@cveNotify
Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.
๐@cveNotify
jvn.jp
JVNVU#90314828: Multiple vulnerabilities in Contec PC-HELPER series
Japan Vulnerability Notes
๐จ CVE-2026-82766
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
๐จ CVE-2026-82767
Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
๐จ CVE-2026-82769
Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
๐จ CVE-2026-82770
Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
๐@cveNotify
Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
๐@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
๐จ CVE-2026-82771
Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
๐จ CVE-2026-82772
Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
๐@cveNotify
Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
๐@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
๐จ CVE-2026-82773
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
jvn.jp
JVNVU#96551518: Multiple vulnerabilities in Contec CONPROSYS series
Japan Vulnerability Notes
๐จ CVE-2026-82774
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
jvn.jp
JVNVU#96551518: Multiple vulnerabilities in Contec CONPROSYS series
Japan Vulnerability Notes
๐จ CVE-2026-82775
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
๐@cveNotify
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
๐@cveNotify
jvn.jp
JVNVU#96551518: Multiple vulnerabilities in Contec CONPROSYS series
Japan Vulnerability Notes
๐จ CVE-2026-82776
Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
๐@cveNotify
jvn.jp
JVNVU#96551518: Multiple vulnerabilities in Contec CONPROSYS series
Japan Vulnerability Notes
๐จ CVE-2026-82777
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
jvn.jp
JVNVU#96551518: Multiple vulnerabilities in Contec CONPROSYS series
Japan Vulnerability Notes
๐จ CVE-2026-82779
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
๐@cveNotify
jvn.jp
JVNVU#96551518: Multiple vulnerabilities in Contec CONPROSYS series
Japan Vulnerability Notes