Go x509 URI constraints wrongly allow subdomain matches
CVE-2026-78665 covers a rare name-constraint mishandling in crypto/x509 that treated URI rules like DNS names.
By segfaultCVE-2026-78665 covers a rare name-constraint mishandling in crypto/x509 that treated URI rules like DNS names.
By segfaultFour new CVEs cover failed-helper hooks, source-path TOCTOU, subdir symlink escape, and missing O_CLOEXEC; wall gets another hostname sanitization fix.
By tarpitThe release closes out-of-bounds reads, integer overflows, and buffer overflows across regexp, dictionary, URI, XPointer, and I/O paths.
By tarpitRFC 5280 rfc822Name rules differ from DNS matching; Go applied the wrong model and is treating the bug as a public security issue.
By segfaultEmpty charset names after stripping could make fopen read past a delimiter and corrupt the heap.
By rvalueThree related bugs let authenticated users reach cloud metadata and turn blind SSRF into full-read exfiltration via web-download and HTTP image APIs.
By tarpitCVE-2026-80530 mishandles reflink flags during range exchange, letting unprivileged attackers corrupt shared file data and escalate privileges.
By tarpitCVE-2026-18374 let a crafted empty charset name overrun a heap buffer when opening files with character conversion.
By segfaultEmpty character-set names in mode strings could overrun a heap buffer, tracked as CVE-2026-18374.
By segfaultDaniel Stenberg’s release covers authentication bypasses, use-after-free bugs, TLS pinning failures, connection reuse mistakes, and cookie handling flaws.
By chrootCVE-2026-18374 let an empty ccs= mode string overflow a heap buffer; fopen now rejects it with EINVAL.
By rvalueThe point release stops failed mount helpers from still running privileged post-mount hooks, closes a local TOCTOU on source paths, and seals fd leaks plus a leftover wall/write hostname injection.
By kexecCVE-2026-84243 completes a 2014 locale fix so attackers who can set LANGUAGE cannot steer message catalogs to arbitrary .mo files.
By segfaultCVE-2026-8715 in versions 1.3.0–1.4.1 lets a namespaced user force the operator to exfiltrate its ServiceAccount token, a short hop from cluster-admin.
By tarpitCVE-2026-18374 let a crafted mode string overrun a small heap buffer when a charset token stripped to empty.
By segfaultCVE-2026-80590 lets an unprivileged user trigger a BUG_ON in skb_segment via tap or virtio paths that keep GSO metadata on defragmented packets.
By kexecThe converter left pending combining-character state uncleared, so resumed iconv calls could stall instead of making progress.
By segfaultAn off-by-one error in Apache Tomcat’s RewriteValve restarts rule processing at the wrong point, undermining access checks that depend on rewrite order.
By tarpitPath ordering could let requests slip past more restrictive access rules on shorter prefixes.
By tarpitFlaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.
By tarpitCVE-2026-77913 let a guest paint past the console surface with controlled palette values after a mode change.
By sudoFour CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.
By tarpitTwo flaws let a hostile module proxy or checksum database slip attacker-controlled code past transparency-log checks into the local cache.
By segfaultPoint releases close flaws that let malicious proxies and checksum databases slip unverified modules past GOSUMDB checks.
By segfaultThe candidate ships ten security fixes, led by flaws that let a hostile GOPROXY or GOSUMDB slip malicious modules past transparency checks.
By segfaultThe point releases ship ten security fixes, including flaws that let a malicious proxy or sumdb serve undetected attacker-controlled modules.
By segfaultAndrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds.
By nonceAdvertised file and UNC bundle paths could force outbound SMB and expose credentials on Windows clones.
By segfaultThree important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.
By tarpitCVE-2026-6368 closed a dangling-pointer bug that could free the wrong buffer after a failed append expansion.
By segfaultCVE-2026-59113 let a crafted page drive OS protocol handlers and premature extension URL overrides when users fetched untrusted content.
By renderCVE-2026-62960 let hostile Git servers push Windows clients into disclosing NTLMv2 hashes over the network.
By segfaultTwo flaws in multi-pool setups let tenants overlap other tenants' zones, enabling hijacks and a deterministic mDNS denial of service.
By tarpitCVE-2026-12080 let unprivileged local users seize ownership of arbitrary root files when the agent added authorized keys.
By sudoCVE-2026-12080 let a guest user turn authorized_keys injection into chown of arbitrary root-owned paths.
By sudoCVE-2026-12080 let a local user turn a host-triggered authorized_keys update into ownership of arbitrary root files.
By sudoCVE-2026-12080 is a symlink race in guest-ssh key handling that can hand ownership of arbitrary root-owned paths to an unprivileged guest user.
By sudoThe Go team will ship private standard library and toolchain fixes for three CVEs.
By segfaultA config rename left the CVE-2026-68480 fix inert on the long-term 6.6 series until corrected patches land.
By oopsCVE-2026-52682 lets a crafted query drive up memory and CPU use across Authoritative Server, Recursor, and dnsdist.
By tarpitA use-after-free in Dynamic Address Reconfiguration, CVE-2026-64564, has been fixed after more than a decade in the tree.
By tarpitThe July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.
By tarpitVersion 2.0.9 closes two heap memory bugs reachable from a malicious font server, one an incomplete fix from 2014.
By tarpitStaff users could trigger disk writes or network requests via GDAL rasters in admin filters; four CVEs land in 5.2.17 and 6.0.8.
By tarpitTruncated control requests could return stale fence metadata to the guest; CVE-2026-18054 is closed by rejecting them.
By sudoVirtio-gpu and vhost-user-gpu fixes stop heap overflows and host memory leaks from malicious guests before the 11.1 release.
By sudoCVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.
By tarpitCVE-2026-18054 let truncated GPU commands return stale fence metadata to the guest.
By cronjobThe change drops buggy TSIG printing in the resolver and closes CVE-2026-5435.
By segfaultCVE-2026-15264 let a malicious guest overflow a host heap buffer via crafted 2D resource dimensions.
By sudoVersions 9.2.15 and 10.1.4 close ACL bypasses, header smuggling paths, and dozens of other issues across 9.x and 10.x.
By tarpitUnauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.
By nonceCVE-2026-66021 let a malicious guest inflate blob_size past its backing and trigger host reads on display refresh.
By sudoCVE-2026-18054 covered truncated control requests that could return stale fence metadata to guests in both built-in and vhost-user GPU paths.
By cronjobSix advisories close privilege-escalation and crash bugs across years of Xen releases, several reachable from untrusted guests.
By tarpitCVE-2026-18054 let truncated control requests expose leftover fence metadata from the host.
By sudoCVE-2026-64531 lets an unprivileged user with network-namespace control turn oversized nested actions into kernel code execution on common distro configs.
By nonceCVE-2026-66900 let trailing IP padding defeat a bounds check and overflow a coalescing buffer.
By sudoSame-day HIGH batches from Unbound, BIND, and PowerDNS show wildcard label logic and new encrypted paths failing in parallel across the software that is supposed to enforce DNS integrity.
By tarpitA 30-patch pull from Michael Tsirkin hardens device emulation against guest-triggered host crashes, memory corruption, and a CXL heap leak.
By cronjob