CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-37807, CVE-2026-23265, CVE-2026-43022 +679 more CVEs: Linux 5.15, 2.6.34, 4.15 (+10 more affected versions)

CVE-2025-37807, CVE-2026-23265, CVE-2026-43022, CVE-2026-46321, CVE-2026-46322, CVE-2026-52917, CVE-2026-52923, CVE-2026-52927, CVE-2026-52929, CVE-2026-52935, CVE-2026-52942, CVE-2026-52943, CVE-2026-52947, CVE-2026-52994, CVE-2026-53136, CVE-2026-53137, CVE-2026-53138, CVE-2026-53143, CVE-2026-53146, CVE-2026-53147, CVE-2026-53149, CVE-2026-53156, CVE-2026-53157, CVE-2026-53160, CVE-2026-53161, CVE-2026-53184, CVE-2026-53189, CVE-2026-53194, CVE-2026-53195, CVE-2026-53199, CVE-2026-53202, CVE-2026-53205, CVE-2026-53209, CVE-2026-53223, CVE-2026-53229, CVE-2026-53253, CVE-2026-53255, CVE-2026

CVE-2025-37807

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-23265

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-43022

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-46321

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-46322

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · High privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-52917

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-52923

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-52927

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-52929

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-52935

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-52942

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-52943

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-52947

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-52994

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53136

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53137

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53138

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Physical access · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53143

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53146

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53147

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Physical access · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and availability impact as low; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53149

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53156

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53157

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53160

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53161

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53184

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53189

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53194

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53195

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53199

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53202

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53205

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53209

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53223

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality impact as low; integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53229

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53253

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53255

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53267

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53268

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53272

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53329

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53330

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53356

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53362

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53366

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53381

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53383

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53387

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-53388

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53389

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53390

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53391

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53392

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53397

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53400

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53401

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-53402

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63794

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63802

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63803

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63805

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63806

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63809

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63812

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63814

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63816

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63817

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63819

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63823

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63824

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63827

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63833

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63867

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63869

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63870

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63875

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63879

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63881

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63884

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63889

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63909

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63913

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63920

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63925

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63927

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63930

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63942

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63954

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63968

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63970

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-63971

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-63985

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · High privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and availability impact as low; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64002

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64003

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64004

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64005

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64009

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64017

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64023

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64026

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64036

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64095

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64123

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64188

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64189

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64210

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64222

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64239

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64242

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64243

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64245

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64246

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64266

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64270

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64271

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64272

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64273

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64274

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64276

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64277

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64279

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64283

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64286

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64287

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · High privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64296

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64298

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64299

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64304

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64312

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64317

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64318

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64322

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64323

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64324

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64333

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64368

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64372

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64374

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64375

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64378

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64379

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64380

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64388

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64389

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as none; integrity impact as low; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64395

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64398

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64401

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64402

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64403

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as low; integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64411

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64412

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64413

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64418

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64420

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64422

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64423

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64430

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64432

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64435

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64436

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64440

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64442

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64443

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64444

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64448

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64449

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64452

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64456

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64463

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64468

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64469

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64481

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64496

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64524

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64532

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64533

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64536

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64539

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64540

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64543

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64545

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64546

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64547

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64550

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64556

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64560

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64563

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64567

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64568

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64570

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64574

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64576

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64577

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64578

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64580

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64581

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64582

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64583

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64584

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-64585

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64599

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-64600

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68091

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68096

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68097

Affected technology

Linux · e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 to before 5a2d9fe0e87c71baa0aaa1cfc1361892fcd1ece0, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 to before b7cb5bf0855470799f12da825de91e48951b3876, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 to before 62d80d7c2d9428085e7458ad4c06ca8c0984039b, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 to before 337022d9dfac441c3b35e4455a51aa981996e02e, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 to before 61fd3559199f7fa693dcbff35e59477e24af041a, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 to before 5152c6d49e3fd4e9f2e857c57527aead752f1f87
Linux

Linux · 5.15
Linux

Component: Not specified by the source
File: fs/smb/server/smbacl.c

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68098

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68100

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68104

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68106

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68107

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68108

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68116

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68118

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68119

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68121

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68125

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68129

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68131

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68140

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68141

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68142

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68143

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68145

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68148

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68149

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68153

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68155

Affected technology

Linux · ba75bb98cfb93b62c54af25bf67ff90857264bbe to before ba5f0015bfd376d764163045a61c17be75f44dae, ba75bb98cfb93b62c54af25bf67ff90857264bbe to before caf082ef8609a6ac26159ce115f55ab7d00231a3, ba75bb98cfb93b62c54af25bf67ff90857264bbe to before e3ccd4ecab09b22f507f49cb7ed9990c7158ceab, ba75bb98cfb93b62c54af25bf67ff90857264bbe to before 0591a15815b498be628a937146e44487d599ba33, ba75bb98cfb93b62c54af25bf67ff90857264bbe to before cd0d41bc569632eaaeccde9d2a6bc919ec00c407, ba75bb98cfb93b62c54af25bf67ff90857264bbe to before e67e8b694872c9bc66996040f9de9242f6236ed9, ba75bb98cfb93b62c54af25bf67ff90857264bbe to before 3b249546f59c3d6d3592c10657f82bc3f1faa07c, ba75bb98cfb93b62c54af25bf67ff90857264bbe to before 40480eee361ed9676b3f844d532ac28b47251634
Linux

Linux · 2.6.34
Linux

Component: Not specified by the source
File: net/ceph/mon_client.c

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68157

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68178

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68179

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68189

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68192

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68196

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68199

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68202

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68204

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68216

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68219

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68222

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68236

Affected technology

Linux · 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f to before 92b7c6e3a1546c6db868b07e93fa6fb950d1d3a0, 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f to before bf9c06c70f496f1ba4474caf95c69696c828340e, 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f to before 01ba5b36898d6258f584269537cc49e7b05cf7c6, 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f to before ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76, 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f to before 5182e442e61397d446c36995b8f5676942d35b82, 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f to before 679f23f0a3606afcef1ffabd72222f00a54ad9e3, 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f to before 0676fecbb5242aa22c057e78326d6d6041db034c, 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f to before 9fa26b9eed6195bf840f39ac183b9a6237548755
Linux

Linux · 4.15
Linux

Component: Not specified by the source
File: drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68245

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68253

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68255

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68258

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68260

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68262

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68263

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68266

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68273

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68284

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68287

Affected technology

Linux · ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f to before 1275a4769c126405c6c63b6372daff120ac679a6, ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f to before 0da8f531336b28a59b23e5a67d40eaed15906201, ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f to before 6048ed2dfb33426c8aef32f8d225ea91c66813db, ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f to before 925669d4cfd47a9019ab29b40676215bab5dae35, ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f to before 4a9e30764e80693bcf875c776170edce20f94fe0, ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f to before 7089f7ab99c89f443c92d8fcc585e63f2727f0b3
Linux

Linux · 5.4
Linux

Component: Not specified by the source
File: net/core/drop_monitor.c

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68290

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68293

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68294

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68297

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68299

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68314

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68315

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68320

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68322

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68323

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68326

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Physical access · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality impact as low; integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68329

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68335

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68338

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68340

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68348

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68352

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68353

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68354

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68370

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68371

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68373

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68376

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68377

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68383

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68389

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68391

Affected technology

Linux · 7b445e220db9a2c58be5d09bbbd322abf1b1452a to before 84674dd1d3192ecb050827d3148642609c0c9dbb, 7b445e220db9a2c58be5d09bbbd322abf1b1452a to before b56f2ecafc08f372bf0529f9c4f3f429cb1702dc, 7b445e220db9a2c58be5d09bbbd322abf1b1452a to before f915e74b6f18293d1d69a2a3305ef321ff7c0172, 7b445e220db9a2c58be5d09bbbd322abf1b1452a to before d5b3b484b62bb0f4542e7622789d28871626cdf0, 7b445e220db9a2c58be5d09bbbd322abf1b1452a to before ecdcb55ea1c01dda074406f38058785a69526734, 7b445e220db9a2c58be5d09bbbd322abf1b1452a to before da55f570191d5d72f10c607a7043b947eb05ea46
Linux

Linux · 6.0
Linux

Component: Not specified by the source
File: net/bluetooth/mgmt.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68392

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68397

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68398

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68399

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68400

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68401

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68402

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as low; integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68404

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68408

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68409

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68414

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68417

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68419

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality impact as none; integrity impact as low; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68425

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as none; integrity impact as low; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68432

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68433

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as low; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68442

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68445

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68446

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68447

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68452

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-68453

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68454

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68466

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68467

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68471

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68474

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-68479

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72005

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72009

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72012

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72019

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72021

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72024

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72029

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72035

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as none; integrity impact as low; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72036

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72045

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72049

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72051

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72052

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72053

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72054

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72055

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72057

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72061

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72066

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72067

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72072

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72089

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72099

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as none; integrity impact as high; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72102

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72105

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72107

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72108

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72109

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72110

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72113

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72114

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72115

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72116

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72117

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72118

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72119

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72120

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72121

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72122

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72123

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72133

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72135

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72136

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72144

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72146

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72148

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality impact as none; integrity impact as low; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72149

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72157

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72160

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72162

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72164

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and availability impact as low; integrity impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72165

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72170

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72171

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72172

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72175

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72181

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72195

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72196

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72197

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72213

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as none; integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72225

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72227

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72231

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72232

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as low; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72233

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72235

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72242

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72243

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72244

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72247

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72250

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72252

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72253

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72254

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72261

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72262

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72282

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72284

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72297

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72298

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72301

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72302

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72304

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72310

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72312

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as low; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72314

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72330

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72334

Affected technology

Linux · ccf74f2390d60a2f9a75ef496d2564abb478f46a to before d2df29dc9abda2fc10ff522eac0969f5b77b3637, ccf74f2390d60a2f9a75ef496d2564abb478f46a to before 7250b6b5ba9b737cff2c2c1d0760360c7b6bca00, ccf74f2390d60a2f9a75ef496d2564abb478f46a to before 49aeb54e3c912ef785311264a51ab9f3698e421b, ccf74f2390d60a2f9a75ef496d2564abb478f46a to before 5e53e285f8c989662e34d4938c728a94226bff34, ccf74f2390d60a2f9a75ef496d2564abb478f46a to before 990e65eb9387c4ddfa7f68782b6644c2c35d489f, ccf74f2390d60a2f9a75ef496d2564abb478f46a to before e054c1a6ae7310d2815778fddb87da616e11c255
Linux

Linux · 6.0
Linux

Component: Not specified by the source
File: net/bluetooth/iso.c

Attack conditions (Source advisory, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72335

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72338

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72340

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72342

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72343

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72347

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as low; integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72350

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72352

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72369

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72371

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72373

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72374

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72375

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72378

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72382

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72389

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72390

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72397

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as none; integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72400

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72404

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72405

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72406

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72409

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72410

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72416

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72418

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72419

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72420

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72423

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72425

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72427

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72435

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72438

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72440

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72444

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72449

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72450

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72459

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72460

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72464

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72469

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72470

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72476

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72478

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72480

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72483

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72485

Affected technology

Linux · 3d4ff657e454f8dba3e5e268e731e6e28c6031c1 to before dd3c9e1c9858c797ba78f4ca6c0fc663eeac6d72, 3d4ff657e454f8dba3e5e268e731e6e28c6031c1 to before aed6915c2f304ed34281856c53e374483c71b68b, 3d4ff657e454f8dba3e5e268e731e6e28c6031c1 to before 09c44549820df67048be3ba19c723bac72ebb98e, 3d4ff657e454f8dba3e5e268e731e6e28c6031c1 to before 8ca9adc805884d3bb5038082462577f86c2c4a10, 3d4ff657e454f8dba3e5e268e731e6e28c6031c1 to before 1563ae33dc4f5ebac96b93af2ef72e72aaaa31ae
Linux

Linux · 6.5
Linux

Component: Not specified by the source
Function: iterates
File: drivers/hwtracing/coresight/coresight-platform.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-72492

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-72502

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74256

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74257

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74258

Affected technology

Linux · 89ae89f53d201143560f1e9ed4bfa62eee34f88e to before ff6c5ee77dcc98381290d16af53f6262625870a6, 89ae89f53d201143560f1e9ed4bfa62eee34f88e to before 2c387db784293256d35fd3d438f577cc82bb823d, 89ae89f53d201143560f1e9ed4bfa62eee34f88e to before a9f1395028c2bbe18e57864cc355c11faff488cb, 89ae89f53d201143560f1e9ed4bfa62eee34f88e to before c6d51ad36490013ee9df94a372d3bf794bd304d1, 89ae89f53d201143560f1e9ed4bfa62eee34f88e to before 4d87a251d45b4a95eb4c0abcfab809c9f231258a
Linux

Linux · 6.6
Linux

Component: Not specified by the source
File: kernel/trace/bpf_trace.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74262

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74270

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74281

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74282

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74283

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74288

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74289

Affected technology

Linux · c3852ef7f2f8f75a9f85a864bec1f6f5a3068eea to before 8bdb20b8a581495062b5879f4e9d435da648b3b0, c3852ef7f2f8f75a9f85a864bec1f6f5a3068eea to before 7907a395701b339c2d68f37456d395e953c74795, c3852ef7f2f8f75a9f85a864bec1f6f5a3068eea to before 7980a13add57f97c5da1dc961d0145a6ad2a7f98, c3852ef7f2f8f75a9f85a864bec1f6f5a3068eea to before bea03e887db5a8a79234531faf14cf2c4d8816c3, c3852ef7f2f8f75a9f85a864bec1f6f5a3068eea to before 676482da8d938ea72c26da0fc86af2d2ec238ab2, c3852ef7f2f8f75a9f85a864bec1f6f5a3068eea to before 06b693d2eb6651a63ad85bad8673de3b7d4edd6d
Linux

Linux · 4.10
Linux

Component: Not specified by the source
File: include/net/ip_fib.h, net/ipv4/fib_trie.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74292

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74293

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74294

Affected technology

Linux · b82b734c0e9a75e1b956214ac523a8eb590f51f3 to before 91797708f99e4a910ab019760069c0a7e00a6fc0, b82b734c0e9a75e1b956214ac523a8eb590f51f3 to before 90703664dbc5a4bf3d84f649404318f3cafdbe69, b82b734c0e9a75e1b956214ac523a8eb590f51f3 to before 8a6d6735e7c02e88841cca1497ff3d8089f2ef24, b82b734c0e9a75e1b956214ac523a8eb590f51f3 to before 96f5b92d958bc34500500f29fab8e0b908f25397, b82b734c0e9a75e1b956214ac523a8eb590f51f3 to before 0965892cc486ca554d72eeb62d85ccf8d0137a5a, b82b734c0e9a75e1b956214ac523a8eb590f51f3 to before d65adf85477247be04ac86886f8edfaa047b5d4a
Linux

Linux · 5.7
Linux

Component: Not specified by the source
File: sound/soc/meson/aiu-acodec-ctrl.c, sound/soc/meson/aiu-codec-ctrl.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.3/10) rates confidentiality and availability impact as high; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74295

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74296

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74297

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74300

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74312

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74313

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74314

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74317

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · High privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74321

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74330

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74334

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74338

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74340

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74341

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74344

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74347

Affected technology

Linux · 50978462300f74dc48aea4a38471cb69bdf741a5 to before b2e84317f334d834fb06c9b340ea465f398b6d4f, 50978462300f74dc48aea4a38471cb69bdf741a5 to before 44583fd5735cb0bdf3bfe11b1e51504ce387bdb7, 50978462300f74dc48aea4a38471cb69bdf741a5 to before 9aeb0dcfeb460d33d61d434148b51103ab1d2013, 50978462300f74dc48aea4a38471cb69bdf741a5 to before 7d6a9cdb8d3a51d9cfe546a09a518ab3d2671549
Linux

Linux · 3.4
Linux

Component: Not specified by the source
File: include/net/netfilter/nf_conntrack_timeout.h, net/netfilter/nf_conntrack_core.c, net/netfilter/nf_conntrack_timeout.c, net/netfilter/nfnetlink_cttimeout.c, net/netfilter/nft_ct.c, net/netfilter/xt_CT.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74349

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as none; integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74356

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74359

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74363

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74365

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74374

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74375

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74377

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74378

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74380

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74385

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74387

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74388

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74390

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74397

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74438

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74443

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74444

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74446

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74450

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74453

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74454

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74456

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74461

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74465

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74467

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74469

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74470

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74471

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74479

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74481

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74482

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74485

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74488

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74490

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74492

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74496

Affected technology

Linux · 23461551c00628c3f3fe9cf837bf53cf8f212b63 to before 0ee628a58d83e571f36ec9f07624d6845e420c50, 23461551c00628c3f3fe9cf837bf53cf8f212b63 to before a6fca682cfa2041e31aa72cc397c4a1406eb7468, 23461551c00628c3f3fe9cf837bf53cf8f212b63 to before b3f9c3e60aa25453774f899d25b5e61dd0bec1d5, 23461551c00628c3f3fe9cf837bf53cf8f212b63 to before 99f4d3120b244f92e5df787152041296a2860cb5, 23461551c00628c3f3fe9cf837bf53cf8f212b63 to before 58835985c035a8333742f829ad7e0889a082f9d3, 23461551c00628c3f3fe9cf837bf53cf8f212b63 to before 9042867d4701728f0c6527215b11471759904d8f, 23461551c00628c3f3fe9cf837bf53cf8f212b63 to before a28d8903bfe76089ea4bbdbff9976965f9ef8107, 23461551c00628c3f3fe9cf837bf53cf8f212b63 to before b14361aca6350ff7907b0e9903c7b94dc7d5d4a0
Linux

Linux · 3.18
Linux

Component: Not specified by the source
File: net/ipv4/fou_core.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74497

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74507

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74508

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74509

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74510

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74512

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74515

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74516

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74518

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74519

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74522

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74523

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74527

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74530

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74531

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74533

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74534

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74535

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74536

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74537

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74540

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74544

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74548

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74549

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74550

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74551

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74557

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74563

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 4.0 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74564

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74565

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74567

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74572

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74574

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74575

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74578

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74579

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as none; integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74580

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74581

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74582

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74583

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74584

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74586

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74587

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74588

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74589

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74590

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74592

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74594

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74595

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74597

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74598

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as high; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74601

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74603

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74604

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74605

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74606

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74607

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74608

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74609

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74610

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74611

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74612

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74613

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74614

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74615

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74616

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74621

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74624

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74625

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74626

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74628

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74630

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74631

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74632

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74634

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74635

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74637

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74641

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74646

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74647

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74648

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74649

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74651

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74656

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74660

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74661

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74662

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74663

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74666

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74667

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74668

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74669

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74670

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74675

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74678

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74684

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74687

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74688

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74689

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74690

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74691

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74692

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74695

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74696

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74697

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74700

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74701

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74704

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74705

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74710

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74711

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74713

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74714

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74715

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74717

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74720

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74723

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74724

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74725

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74726

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74730

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74733

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74736

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74737

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74739

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74743

Affected technology

Linux · b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 to before c2ef3f134b069c54b9cc95cce1a16c38c4939336, b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 to before 7b0eb3e0f363ca79a3af9efd2e87c6258f11da2b, b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 to before 8cd90e850e434577bf6774778657d26d6995e53f, b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 to before 28afc87bd8da0b3348bbbd834c8a89e83712cf5e, b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 to before 8f6a05dbac05725e0786701eb04778c5bdbe4eaa, b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 to before 96fa90b74385b7f2b0d97251dd43d5ee6ca44668, b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 to before bc9a00fb78e32bccc39d763bfd13a450705bac5d, b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 to before cef51860becd9700217c81732ca1eb1ea6ed6fe1
Linux

Linux · 2.6.23
Linux

Component: Not specified by the source
File: drivers/net/macvlan.c

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-74744

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74746

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74747

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74748

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-74752

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80521

Affected technology

Linux · 5dfd283f4651d04dbb70ceb9ae5c4a30eda3c52a to before 2b6c2842692d08e7acaf32d1eb47f95def35f3fe, de7921631ff323369aa63a4324695ab54ea4047e to before 6fda5c51b8e43a8440f76e65c89d9f95ddb2ef33, 4090fa373f0e763c43610853d2774b5979915959 to before 1293fd69a50d188a5788b08ba3741a3e86be1608, 4090fa373f0e763c43610853d2774b5979915959 to before fe198b077864feafd4aa4b33b1a5ce26f50195a2, 4090fa373f0e763c43610853d2774b5979915959 to before e3702470ced94fad74d71e2232f022d2eb752a6d, 4090fa373f0e763c43610853d2774b5979915959 to before 594d905195024b228c962627ae5ae7c17bd582a4, 6.1.141 to before 6.1.189, 6.6.93 to before 6.6.158
Linux

Linux · 6.10
Linux

Component: Not specified by the source
File: net/unix/garbage.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-80526

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80527

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80528

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80536

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80540

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80541

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80547

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80548

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80549

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80550

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80551

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80552

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80553

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80554

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80555

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80556

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80557

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80558

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80559

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80560

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80561

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80565

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80568

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80569

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80570

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80572

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80574

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80576

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80578

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80579

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80580

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80583

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80584

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80585

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80586

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80587

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80589

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80721

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-80901

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-97509

Affected technology

Linux · d1ff70241a275133e1a0258b7c23588b122276c8 to before a4567e5380e4e46d0ea9a28d2d675e5c6f013d54, d1ff70241a275133e1a0258b7c23588b122276c8 to before daeaa6c7211d03ed061b0dd22a875fad9372b090, d1ff70241a275133e1a0258b7c23588b122276c8 to before cca72fe513f3d6b1279fe83483f8a8990adbe0c6, d1ff70241a275133e1a0258b7c23588b122276c8 to before 57359bb31526c2f1bb0a7b9b69d8b8a6bd3f0e9f, d1ff70241a275133e1a0258b7c23588b122276c8 to before 8ab12d015884b8aa85ea7ed58c5a0bae4264fe60, d1ff70241a275133e1a0258b7c23588b122276c8 to before ea60ae6233ca0fc0d414e9c11f0d86c63b303fc7, d1ff70241a275133e1a0258b7c23588b122276c8 to before 8b4060998637f06975fceee9b73845d8672d411e
Linux

Linux · 4.15
Linux

Component: Not specified by the source
File: drivers/thunderbolt/xdomain.c

Attack conditions (Source advisory, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CVE
CVE-2026-46321, CVE-2026-46322, CVE-2026-52917, CVE-2026-52923, CVE-2026-52927, CVE-2026-52929, CVE-2026-52935, CVE-2026-52942, CVE-2026-52943, CVE-2026-52947, CVE-2026-52994, CVE-2026-53136, CVE-2026-53137, CVE-2026-53138, CVE-2026-53143, CVE-2026-53146, CVE-2026-53147, CVE-2026-53149, CVE-2026-53156, CVE-2026-53157, CVE-2026-53160, CVE-2026-53161, CVE-2026-53184, CVE-2026-53189, CVE-2026-53194, CVE-2026-53195, CVE-2026-53199, CVE-2026-53202, CVE-2026-53205, CVE-2026-53209, CVE-2026-53223, CVE-2026-53229, CVE-2026-53253, CVE-2026-53255, CVE-2026-53267, CVE-2026-53268, CVE-2026-53272, CVE-2026-53329, CVE-2026-53330, CVE-2026-53356, CVE-2026-53362, CVE-2026-53366, CVE-2026-53381, CVE-2026-53383, CVE-2026-53387, CVE-2026-53388, CVE-2026-53389, CVE-2026-53390, CVE-2026-53391, CVE-2026-53392, CVE-2026-53397, CVE-2026-53400, CVE-2026-53401, CVE-2026-53402, CVE-2026-63794, CVE-2026-63802, CVE-2026-63803, CVE-2026-63805, CVE-2026-63806, CVE-2026-63809, CVE-2026-63812, CVE-2026-63814, CVE-2026-63816, CVE-2026-63817, CVE-2026-63819, CVE-2026-63823, CVE-2026-63824, CVE-2026-63827, CVE-2026-63833, CVE-2026-63867, CVE-2026-63869, CVE-2026-63870, CVE-2026-63875, CVE-2026-63879, CVE-2026-63881, CVE-2026-63884, CVE-2026-63889, CVE-2026-63909, CVE-2026-63913, CVE-2026-63920, CVE-2026-63925, CVE-2026-63927, CVE-2026-63930, CVE-2026-63942, CVE-2026-63954, CVE-2026-63968, CVE-2026-63970, CVE-2026-63971, CVE-2026-63985, CVE-2026-64002, CVE-2026-64003, CVE-2026-64004, CVE-2026-64005, CVE-2026-64009, CVE-2026-64017, CVE-2026-64023, CVE-2026-64026, CVE-2026-64036, CVE-2026-64095, CVE-2026-64123, CVE-2026-64188, CVE-2026-64189, CVE-2026-64210, CVE-2026-64222, CVE-2026-64239, CVE-2026-64242, CVE-2026-64243, CVE-2026-64245, CVE-2026-64246, CVE-2026-64266, CVE-2026-64270, CVE-2026-64271, CVE-2026-64272, CVE-2026-64273, CVE-2026-64274, CVE-2026-64276, CVE-2026-64277, CVE-2026-64279, CVE-2026-64283, CVE-2026-64286, CVE-2026-64287, CVE-2026-64296, CVE-2026-64298, CVE-2026-64299, CVE-2026-64304, CVE-2026-64312, CVE-2026-64317, CVE-2026-64318, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64333, CVE-2026-64368, CVE-2026-64372, CVE-2026-64374, CVE-2026-64375, CVE-2026-64378, CVE-2026-64379, CVE-2026-64380, CVE-2026-64388, CVE-2026-64389, CVE-2026-64395, CVE-2026-64398, CVE-2026-64401, CVE-2026-64402, CVE-2026-64403, CVE-2026-64411, CVE-2026-64412, CVE-2026-64413, CVE-2026-64418, CVE-2026-64420, CVE-2026-64422, CVE-2026-64423, CVE-2026-64430, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64440, CVE-2026-64442, CVE-2026-64443, CVE-2026-64444, CVE-2026-64448, CVE-2026-64449, CVE-2026-64452, CVE-2026-64456, CVE-2026-64463, CVE-2026-64468, CVE-2026-64469, CVE-2026-64481, CVE-2026-64496, CVE-2026-64524, CVE-2026-64532, CVE-2026-64533, CVE-2026-64536, CVE-2026-64539, CVE-2026-64540, CVE-2026-64543, CVE-2026-64545, CVE-2026-64546, CVE-2026-64547, CVE-2026-64550, CVE-2026-64556, CVE-2026-64560, CVE-2026-64563, CVE-2026-64567, CVE-2026-64568, CVE-2026-64570, CVE-2026-64574, CVE-2026-64576, CVE-2026-64577, CVE-2026-64578, CVE-2026-64580, CVE-2026-64581, CVE-2026-64582, CVE-2026-64583, CVE-2026-64584, CVE-2026-64585, CVE-2026-64599, CVE-2026-64600, CVE-2026-68091, CVE-2026-68096, CVE-2026-68097, CVE-2026-68098, CVE-2026-68100, CVE-2026-68104, CVE-2026-68106, CVE-2026-68107, CVE-2026-68108, CVE-2026-68116, CVE-2026-68118, CVE-2026-68119, CVE-2026-68121, CVE-2026-68125, CVE-2026-68129, CVE-2026-68131, CVE-2026-68140, CVE-2026-68141, CVE-2026-68142, CVE-2026-68143, CVE-2026-68145, CVE-2026-68148, CVE-2026-68149, CVE-2026-68153, CVE-2026-68155, CVE-2026-68157, CVE-2026-68178, CVE-2026-68179, CVE-2026-68189, CVE-2026-68192, CVE-2026-68196, CVE-2026-68199, CVE-2026-68202, CVE-2026-68204, CVE-2026-68216, CVE-2026-68219, CVE-2026-68222, CVE-2026-68236, CVE-2026-68245, CVE-2026-68253, CVE-2026-68255, CVE-2026-68258, CVE-2026-68260, CVE-2026-68262, CVE-2026-68263, CVE-2026-68266, CVE-2026-68273, CVE-2026-68284, CVE-2026-68287, CVE-2026-68290, CVE-2026-68293, CVE-2026-68294, CVE-2026-68297, CVE-2026-68299, CVE-2026-68314, CVE-2026-68315, CVE-2026-68320, CVE-2026-68322, CVE-2026-68323, CVE-2026-68326, CVE-2026-68329, CVE-2026-68335, CVE-2026-68338, CVE-2026-68340, CVE-2026-68348, CVE-2026-68352, CVE-2026-68353, CVE-2026-68354, CVE-2026-68370, CVE-2026-68371, CVE-2026-68373, CVE-2026-68376, CVE-2026-68377, CVE-2026-68383, CVE-2026-68389, CVE-2026-68391, CVE-2026-68392, CVE-2026-68397, CVE-2026-68398, CVE-2026-68399, CVE-2026-68400, CVE-2026-68401, CVE-2026-68402, CVE-2026-68404, CVE-2026-68408, CVE-2026-68409, CVE-2026-68414, CVE-2026-68417, CVE-2026-68419, CVE-2026-68425, CVE-2026-68432, CVE-2026-68433, CVE-2026-68442, CVE-2026-68445, CVE-2026-68446, CVE-2026-68447, CVE-2026-68452, CVE-2026-68453, CVE-2026-68454, CVE-2026-68466, CVE-2026-68467, CVE-2026-68471, CVE-2026-68474, CVE-2026-68479, CVE-2026-72005, CVE-2026-72009, CVE-2026-72012, CVE-2026-72019, CVE-2026-72021, CVE-2026-72024, CVE-2026-72029, CVE-2026-72035, CVE-2026-72036, CVE-2026-72045, CVE-2026-72049, CVE-2026-72051, CVE-2026-72052, CVE-2026-72053, CVE-2026-72054, CVE-2026-72055, CVE-2026-72057, CVE-2026-72061, CVE-2026-72066, CVE-2026-72067, CVE-2026-72072, CVE-2026-72089, CVE-2026-72099, CVE-2026-72102, CVE-2026-72105, CVE-2026-72107, CVE-2026-72108, CVE-2026-72109, CVE-2026-72110, CVE-2026-72113, CVE-2026-72114, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72119, CVE-2026-72120, CVE-2026-72121, CVE-2026-72122, CVE-2026-72123, CVE-2026-72133, CVE-2026-72135, CVE-2026-72136, CVE-2026-72144, CVE-2026-72146, CVE-2026-72148, CVE-2026-72149, CVE-2026-72157, CVE-2026-72160, CVE-2026-72162, CVE-2026-72164, CVE-2026-72165, CVE-2026-72170, CVE-2026-72171, CVE-2026-72172, CVE-2026-72175, CVE-2026-72181, CVE-2026-72195, CVE-2026-72196, CVE-2026-72197, CVE-2026-72213, CVE-2026-72225, CVE-2026-72227, CVE-2026-72231, CVE-2026-72232, CVE-2026-72233, CVE-2026-72235, CVE-2026-72242, CVE-2026-72243, CVE-2026-72244, CVE-2026-72247, CVE-2026-72250, CVE-2026-72252, CVE-2026-72253, CVE-2026-72254, CVE-2026-72261, CVE-2026-72262, CVE-2026-72282, CVE-2026-72284, CVE-2026-72297, CVE-2026-72298, CVE-2026-72301, CVE-2026-72302, CVE-2026-72304, CVE-2026-72310, CVE-2026-72312, CVE-2026-72314, CVE-2026-72330, CVE-2026-72334, CVE-2026-72335, CVE-2026-72338, CVE-2026-72340, CVE-2026-72342, CVE-2026-72343, CVE-2026-72347, CVE-2026-72350, CVE-2026-72352, CVE-2026-72369, CVE-2026-72371, CVE-2026-72373, CVE-2026-72374, CVE-2026-72375, CVE-2026-72378, CVE-2026-72382, CVE-2026-72389, CVE-2026-72390, CVE-2026-72397, CVE-2026-72400, CVE-2026-72404, CVE-2026-72405, CVE-2026-72406, CVE-2026-72409, CVE-2026-72410, CVE-2026-72416, CVE-2026-72418, CVE-2026-72419, CVE-2026-72420, CVE-2026-72423, CVE-2026-72425, CVE-2026-72427, CVE-2026-72435, CVE-2026-72438, CVE-2026-72440, CVE-2026-72444, CVE-2026-72449, CVE-2026-72450, CVE-2026-72459, CVE-2026-72460, CVE-2026-72464, CVE-2026-72469, CVE-2026-72470, CVE-2026-72476, CVE-2026-72478, CVE-2026-72480, CVE-2026-72483, CVE-2026-72485, CVE-2026-72492, CVE-2026-72502, CVE-2026-74256, CVE-2026-74257, CVE-2026-74258, CVE-2026-74262, CVE-2026-74270, CVE-2026-74281, CVE-2026-74282, CVE-2026-74283, CVE-2026-74288, CVE-2026-74289, CVE-2026-74292, CVE-2026-74293, CVE-2026-74294, CVE-2026-74295, CVE-2026-74296, CVE-2026-74297, CVE-2026-74300, CVE-2026-74312, CVE-2026-74313, CVE-2026-74314, CVE-2026-74317, CVE-2026-74321, CVE-2026-74330, CVE-2026-74334, CVE-2026-74338, CVE-2026-74340, CVE-2026-74341, CVE-2026-74344, CVE-2026-74347, CVE-2026-74349, CVE-2026-74356, CVE-2026-74359, CVE-2026-74363, CVE-2026-74365, CVE-2026-74374, CVE-2026-74375, CVE-2026-74377, CVE-2026-74378, CVE-2026-74380, CVE-2026-74385, CVE-2026-74387, CVE-2026-74388, CVE-2026-74390, CVE-2026-74397, CVE-2026-74438, CVE-2026-74443, CVE-2026-74444, CVE-2026-74446, CVE-2026-74450, CVE-2026-74453, CVE-2026-74454, CVE-2026-74456, CVE-2026-74461, CVE-2026-74465, CVE-2026-74467, CVE-2026-74469, CVE-2026-74470, CVE-2026-74471, CVE-2026-74479, CVE-2026-74481, CVE-2026-74482, CVE-2026-74485, CVE-2026-74488, CVE-2026-74490, CVE-2026-74492, CVE-2026-74496, CVE-2026-74497, CVE-2026-74507, CVE-2026-74508, CVE-2026-74509, CVE-2026-74510, CVE-2026-74512, CVE-2026-74515, CVE-2026-74516, CVE-2026-74518, CVE-2026-74519, CVE-2026-74522, CVE-2026-74523, CVE-2026-74527, CVE-2026-74530, CVE-2026-74531, CVE-2026-74533, CVE-2026-74534, CVE-2026-74535, CVE-2026-74536, CVE-2026-74537, CVE-2026-74540, CVE-2026-74544, CVE-2026-74548, CVE-2026-74549, CVE-2026-74550, CVE-2026-74551, CVE-2026-74557, CVE-2026-74563, CVE-2026-74564, CVE-2026-74565, CVE-2026-74567, CVE-2026-74572, CVE-2026-74574, CVE-2026-74575, CVE-2026-74578, CVE-2026-74579, CVE-2026-74580, CVE-2026-74581, CVE-2026-74582, CVE-2026-74583, CVE-2026-74584, CVE-2026-74586, CVE-2026-74587, CVE-2026-74588, CVE-2026-74589, CVE-2026-74590, CVE-2026-74592, CVE-2026-74594, CVE-2026-74595, CVE-2026-74597, CVE-2026-74598, CVE-2026-74601, CVE-2026-74603, CVE-2026-74604, CVE-2026-74605, CVE-2026-74606, CVE-2026-74607, CVE-2026-74608, CVE-2026-74609, CVE-2026-74610, CVE-2026-74611, CVE-2026-74612, CVE-2026-74613, CVE-2026-74614, CVE-2026-74615, CVE-2026-74616, CVE-2026-74621, CVE-2026-74624, CVE-2026-74625, CVE-2026-74626, CVE-2026-74628, CVE-2026-74630, CVE-2026-74631, CVE-2026-74632, CVE-2026-74634, CVE-2026-74635, CVE-2026-74637, CVE-2026-74641, CVE-2026-74646, CVE-2026-74647, CVE-2026-74648, CVE-2026-74649, CVE-2026-74651, CVE-2026-74656, CVE-2026-74660, CVE-2026-74661, CVE-2026-74662, CVE-2026-74663, CVE-2026-74666, CVE-2026-74667, CVE-2026-74668, CVE-2026-74669, CVE-2026-74670, CVE-2026-74675, CVE-2026-74678, CVE-2026-74684, CVE-2026-74687, CVE-2026-74688, CVE-2026-74689, CVE-2026-74690, CVE-2026-74691, CVE-2026-74692, CVE-2026-74695, CVE-2026-74696, CVE-2026-74697, CVE-2026-74700, CVE-2026-74701, CVE-2026-74704, CVE-2026-74705, CVE-2026-74710, CVE-2026-74711, CVE-2026-74713, CVE-2026-74714, CVE-2026-74715, CVE-2026-74717, CVE-2026-74720, CVE-2026-74723, CVE-2026-74724, CVE-2026-74725, CVE-2026-74726, CVE-2026-74730, CVE-2026-74733, CVE-2026-74736, CVE-2026-74737, CVE-2026-74739, CVE-2026-74743, CVE-2026-74744, CVE-2026-74746, CVE-2026-74747, CVE-2026-74748, CVE-2026-74752, CVE-2026-80521, CVE-2026-80526, CVE-2026-80527, CVE-2026-80528, CVE-2026-80536, CVE-2026-80540, CVE-2026-80541, CVE-2026-80547, CVE-2026-80548, CVE-2026-80549, CVE-2026-80550, CVE-2026-80551, CVE-2026-80552, CVE-2026-80553, CVE-2026-80554, CVE-2026-80555, CVE-2026-80556, CVE-2026-80557, CVE-2026-80558, CVE-2026-80559, CVE-2026-80560, CVE-2026-80561, CVE-2026-80565, CVE-2026-80568, CVE-2026-80569, CVE-2026-80570, CVE-2026-80572, CVE-2026-80574, CVE-2026-80576, CVE-2026-80578, CVE-2026-80579, CVE-2026-80580, CVE-2026-80583, CVE-2026-80584, CVE-2026-80585, CVE-2026-80586, CVE-2026-80587, CVE-2026-80589, CVE-2026-80721, CVE-2026-80901, CVE-2026-97509
Product
linux-nvidia-tegra
CCR priority
0.0 /100 (P5)
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H · OSV.dev
EPSS
0.00199 · percentile 0.08887 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-37807.html