Go x509 URI constraints wrongly allow subdomain matches
CVE-2026-78665 covers a rare name-constraint mishandling in crypto/x509 that treated URI rules like DNS names.
By segfaultCVE-2026-78665 covers a rare name-constraint mishandling in crypto/x509 that treated URI rules like DNS names.
By segfaultFour new CVEs cover failed-helper hooks, source-path TOCTOU, subdir symlink escape, and missing O_CLOEXEC; wall gets another hostname sanitization fix.
By tarpitThe release closes out-of-bounds reads, integer overflows, and buffer overflows across regexp, dictionary, URI, XPointer, and I/O paths.
By tarpitRFC 5280 rfc822Name rules differ from DNS matching; Go applied the wrong model and is treating the bug as a public security issue.
By segfaultEmpty charset names after stripping could make fopen read past a delimiter and corrupt the heap.
By rvalueSeveral paths let programs pass verification then fault on a null dereference at runtime.
By kexecA core use-after-free in timeline-name handling still hits amdxdna, nouveau, and msm, and a proposed cache fix was pulled after lifetime objections.
By kexecStrided and offset tensor paths in the compiler could read past valid memory without raising an error.
By tensorThree drivers ignored the caller buffer limit on GRXCLSRLALL, turning admin-installed flow rules into an unprivileged OOB write or null deref.
By kexecNegative pathspecs shorter than a shared positive prefix could trigger a heap buffer over-read, and excludes at the front blocked prefix optimization.
By segfaultThree related bugs let authenticated users reach cloud metadata and turn blind SSRF into full-read exfiltration via web-download and HTTP image APIs.
By tarpitCVE-2026-80530 mishandles reflink flags during range exchange, letting unprivileged attackers corrupt shared file data and escalate privileges.
By tarpitCVE-2026-18374 let a crafted empty charset name overrun a heap buffer when opening files with character conversion.
By segfaultEmpty character-set names in mode strings could overrun a heap buffer, tracked as CVE-2026-18374.
By segfaultRMS-era ELPA provenance fights and the WIMSE push to adopt AI-agent auth drafts are one problem seen from opposite ends: FOSS still has no common norms for synthetic code or for agents as delegatable identities.
By renderDaniel Stenberg’s release covers authentication bypasses, use-after-free bugs, TLS pinning failures, connection reuse mistakes, and cookie handling flaws.
By chrootUnprivileged userspace could read freed GPU scheduler memory via timeline name queries on amdxdna, nouveau, and msm.
By oopsCVE-2026-18374 let an empty ccs= mode string overflow a heap buffer; fopen now rejects it with EINVAL.
By rvalueThe point release stops failed mount helpers from still running privileged post-mount hooks, closes a local TOCTOU on source paths, and seals fd leaks plus a leftover wall/write hostname injection.
By kexecAn RFC series would let Hyper-V guests boot a small trusted kernel in VTL1 beside the normal OS, laying groundwork for Virtualization-Based Security on Linux.
By oopsA follow-up series closes change-path and missed-qdisc holes that restored multi-billion-iteration deficit spins under the scheduler lock.
By oopsCVE-2026-84243 completes a 2014 locale fix so attackers who can set LANGUAGE cannot steer message catalogs to arbitrary .mo files.
By segfaultGNOME Remote Desktop and KDE krdp embeds are in scope when an administrator has enabled the service; client-only FreeRDP is not.
By tarpitconnect(AF_UNSPEC), listen(), and IPV6_ADDRFORM left request sockets and parent state that concurrent paths could free while still in use.
By kexecA proposed fix for attacker-controlled beacon attributes still drew maintainer objections over correctness and testing.
By kexecKey-less hash map dumps and bpf_snprintf_btf() on void or var types could oops the kernel; Jiayuan Chen restores rejections and safe placeholders.
By kexecA syzbot-found flaw let malformed wireless Information Elements crash the kernel on connect; the fix is rolling through stable trees.
By kexecEight traffic-control schedulers still allowed tiny quanta after setup, reopening a deficit-loop DoS under the qdisc lock.
By kexecInteger overflows in ZFS, SquashFS, EXT4, and a shell move command can under-allocate heap buffers through U-Boot 2026.01-rc4.
By tarpitCVE-2026-8715 in versions 1.3.0–1.4.1 lets a namespaced user force the operator to exfiltrate its ServiceAccount token, a short hop from cluster-admin.
By tarpitCVE-2026-18374 let a crafted mode string overrun a small heap buffer when a charset token stripped to empty.
By segfaultA core lifetime bug let userspace read freed scheduler memory via exported fences in amdxdna, nouveau, and msm.
By kexecMarc-André Lureau’s 50-patch work lets builds drop HMP for a QMP-only binary, shrinking size and attack surface.
By sudoForged TPM 1.x replies could overflow a fixed-size blob buffer or skip response authentication entirely.
By kexecCVE-2026-80590 lets an unprivileged user trigger a BUG_ON in skb_segment via tap or virtio paths that keep GSO metadata on defragmented packets.
By kexecThe fix closes a setup-time traversal that could let a malicious app image plant files on the host via Flatpak and similar tools.
By nonceUnprivileged users could exhaust kernel memory by repeatedly setting the casefold mount option on tmpfs.
By kexecThe converter left pending combining-character state uncleared, so resumed iconv calls could stall instead of making progress.
By segfaultA failed memory allocation during process duplication could free tracing state still held by the parent.
By kexecBefore 9.2.1013, huge terminal resize requests updated state but not clamped screen storage, so later output could write past the buffer.
By tarpitAlways creating exceptions for ICMP errors stops off-path attackers from probing connected UDP sockets after earlier defenses were bypassed.
By kexecThe update also closes CVE-2026-6426, tightens vmstate allocation checks, and fixes a vhost-user postcopy hang.
By sudoDenis V. Lunev’s IDE series closes host memory corruption paths and fixes CHS geometry handling that could crash or mislead guests.
By sudoAn off-by-one error in Apache Tomcat’s RewriteValve restarts rule processing at the wrong point, undermining access checks that depend on rewrite order.
By tarpitPath ordering could let requests slip past more restrictive access rules on shorter prefixes.
By tarpitAn RFC series would stop parsing uppercase so Git matches what it emits and what most tooling already assumes.
By segfaultFlaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.
By tarpitDaniel Borkmann's v2 patches give operators a BPF-scoped trust root for signed program loads and teach bpftool post-quantum signatures.
By oopsCVE-2026-77913 let a guest paint past the console surface with controlled palette values after a mode change.
By sudoA cluster of CVSS 9.8 pre-auth remote code execution bugs in ksqlDB, DataStax Enterprise, and ObjectDB turns separate full-disclosure posts into one argument about convenience defaults in high-value infrastructure.
By staffBorkmann's bpf-next series adds a BPF-scoped trust anchor for signed program loads and proves the path works with post-quantum keys.
By oopsPreliminary review of eprint 2026/1630 finds the claimed quasipolynomial approach above designed cost for every parameter set.
By tarpitCrafted remote-style file names can execute arbitrary local commands during connection setup, with no successful remote login required.
By tarpitReplacement programs were matched only by type, so incompatible sock_addr and LSM hooks could clobber adjacent stack state.
By kexecFour CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.
By tarpitTwo sumdb bypasses fixed across the Go toolchain show that a hostile GOPROXY and GOSUMDB pair could still feed undetected modules into the local cache, pressing the question of where module trust actually sits.
By segfaultOpening a crafted file can run attacker code; upstream fixed it and Gentoo backported to 28.2.
By nonceTentacle 20.2.4 and Squid 19.2.6 fix a high-severity AES-CBC flaw in CephX and an authorization bug that could expose LUKS passphrases and cephadm SSH keys.
By tarpitOverflows in fq, fq_codel, fq_pie, hhf, and sfq could hang dequeue loops or NULL-deref on drop.
By oopsA 49-patch effort lets builds drop HMP entirely so the binary speaks only QMP, shrinking the attack surface and clarifying the split between automation and interactive debugging.
By sudo