Changes

ConflictsAtomAsk about things

Today

297 new conflicts 2 source health 1 conflict resolved

13:46GitHub advisories: failing → partial
13:02Red Hat: cvss:number,cwe:code,packages:text,severity:code | cve → read again as cvss:number,cvss_vector:code,cwe:code,packages:text,severity:code | cve
13:02org.hibernate/hibernate-core: Hibernate ORM: SQL Injection via unescaped JSON path segment allows data exfiltration and authorization bypass: sources agree again about CVSS
13:02conflict kernel: smb/server: fix tree connection leak in smb2_tree_connect(): sources now disagree about Severity GitHub advisories unknown · NVD medium · Red Hat medium
13:02conflict kernel: nvdimm: pmem: keep PREFLUSH before data writes: sources now disagree about Severity GitHub advisories unknown · NVD medium · Red Hat medium
13:02conflict kernel: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init(): sources now disagree about Severity GitHub advisories unknown · NVD medium · Red Hat medium
13:02conflict kernel: wifi: mt76: mt7921: validate CLC firmware records: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ppp_async: drop the errored frame instead of resetting its headroom: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: drm/virtio: use the DMA API for resource backing on Xen: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: drm/virtio: use the DMA API for resource backing on Xen: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 7
13:02conflict kernel: accel/qaic: Address potential out-of-bounds read in resp_worker(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: nvme-rdma: fix -EIO cleanup order in queue_rq: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: nvme: fix racy access to FDP placement id array: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: nvmet-rdma: fix queue leak when connect backlog is exceeded: sources now disagree about Severity GitHub advisories unknown · NVD medium · Red Hat medium
13:02conflict kernel: bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Fix BPF_F_CPU validation for sparse CPU IDs: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: bpf: Fix BPF_F_CPU validation for sparse CPU IDs: sources now disagree about CVSS GitHub advisories 7 · NVD 7 · Red Hat 5.5
13:02conflict kernel: bpf: Fix percpu map update indexing with sparse CPU IDs: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: drm/gud: validate GUD_ROTATION_0 is present in supported rotations: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: printk: Don't WARN on kthread_run failure: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel/amdxdna: reject a command chain that carries no commands: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel/amdxdna: put the chained BO when its mapping fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel: ethosu: Don't read the U65 rounding mode as a storage mode: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: accel: ethosu: Don't read the U65 rounding mode as a storage mode: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: drm/cirrus-qemu: Validate BAR0 size during probe: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ntfs: propagate reparse index insertion failure: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ntfs: fix kmap_local leak in write_mft_record_nolock() error paths: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ntfs: only count successfully cleared runs when freeing clusters: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ntfs: do not mark the volume clean in sync_fs when errors were recorded: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ntfs: treat any nonzero dio zero-range return as an error: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ntfs: bound $AttrDef table walk to the loaded table size: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ntfs: reject invalid sectors_per_cluster in the boot sector: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: check_cond_jmp_op(): properly infer if register is null: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ntfs: leave HasEA flag untouched on setxattr failure: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: stmmac: fix dma mapping leak in stmmac_tso_xmit(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START: sources now disagree about CVSS GitHub advisories 8.1 · NVD 8.1 · Red Hat 7
13:02conflict kernel: scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: smb/client: validate new EOF for insert range: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: smb/client: validate new EOF for zero range: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: smb/client: fix stale page cache in insert/collapse range: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: smb/client: invalidate fscache for fallocate range operations: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del(): sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del(): sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 7
13:02conflict kernel: watchdog: msc313e: Fix NULL pointer dereference in PM callbacks: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: netfs: Fix subreq ref leak: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: netfs: break unbuffered write when netfs_alloc_subrequest() fails: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: netfs: Fix readahead synchronisation issues by loading all folios upfront: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: cachefiles: Fix potential UAF/KASAN warning: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ksmbd: safely drain sessions during logoff: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: ksmbd: safely drain sessions during logoff: sources now disagree about CVSS GitHub advisories 8.8 · NVD 8.8 · Red Hat 5.5
13:02conflict kernel: ksmbd: propagate DACL parsing errors: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ksmbd: rate limit unmapped SID errors: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ksmbd: fix listener task lifetime on netdev events: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: ksmbd: fix listener task lifetime on netdev events: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: Bluetooth: btintel: validate version TLV value lengths: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: Bluetooth: btintel: bound firmware ID by TLV length: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: Bluetooth: hci_core: Fix race condition during device registration: sources now disagree about Severity GitHub advisories unknown · NVD medium · Red Hat medium
13:02conflict kernel: Bluetooth: hci_core: Fix race condition during device registration: sources now disagree about CVSS NVD 4.7 · Red Hat 5.5
13:02conflict kernel: Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan: sources now disagree about CVSS GitHub advisories 7.5 · NVD 7.5 · Red Hat 7
13:02conflict kernel: Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: drm/pagemap: Prevent double migration of device pages: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: ethernet: oa_tc6: Improve the error recovery: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: igmp: convert struct ip_sf_list to RCU: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: btrfs: fix the possible bioc_list memory leak during error: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: btrfs: do not force reloc root creation during qgroup_account_snapshot(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: reject BPF_PSEUDO_FUNC reference to the main program: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bonding: do not clear curr_active_slave prematurely when releasing all slaves: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net: Remove conflicting altnames for dying netns in __dev_change_net_namespace(): sources now disagree about Severity GitHub advisories high · NVD high · Red Hat low
13:02conflict kernel: net: Remove conflicting altnames for dying netns in __dev_change_net_namespace(): sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: net/rds: use wq_has_sleeper() in release_in_xmit(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/rds: clear cp_flags bits individually in rds_conn_path_reset(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks(): sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks(): sources now disagree about CVSS GitHub advisories 8.1 · NVD 8.1 · Red Hat 7
13:02conflict kernel: net/rds: acquire the fastpath locks in rds_conn_shutdown(): sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: net/rds: acquire the fastpath locks in rds_conn_shutdown(): sources now disagree about CVSS GitHub advisories 8.1 · NVD 8.1 · Red Hat 7
13:02conflict kernel: net/rds: don't let rds_conn_shutdown() consume a concurrent drop: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: erofs: disable LZ4 rolling decompression for now: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ALSA: caiaq: Fix potential double-free at error path: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Reject key-less BTF for hash maps: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Fix NULL-ptr-deref when showing a void BTF type: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: bpf: Fix NULL-ptr-deref in btf_var_show(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Mark signal tracepoint siginfo arguments as scalar: sources now disagree about Severity GitHub advisories unknown · NVD medium · Red Hat low
13:02conflict kernel: bpf: Reject tail calls directly from callback frames: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: bpf: Reject resilient lock operations in rbtree callbacks: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Mark sched_process_wait argument as nullable: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: bpf: Mark syscall helpers as sleepable: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ring-buffer: Add checking nr_subbufs to persistent ring buffer validation: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: nvme: remove stale namespaces by NSID range during scan: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: nvme: remove stale namespaces by NSID range during scan: sources now disagree about CVSS GitHub advisories 7.5 · NVD 7.5 · Red Hat 5.5
13:02conflict kernel: ASoC: Intel: avs: Clean up the bus when fetching ML caps fails: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ASoC: Intel: avs: Fix unbalanced module reference count: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ASoC: Intel: avs: Refactor and fix init_config access: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: bcmasp: clear txcb->last before writing each descriptor: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: net: bcmasp: clear txcb->last before writing each descriptor: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context: sources now disagree about CVSS GitHub advisories 7.5 · NVD 7.5 · Red Hat 7
13:02conflict kernel: bpf: zero extend the result of an arena 32-bit cmpxchg: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: don't rewrite bpf_fastcall patterns entered by a jump: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Check ancestor frames for rbtree callbacks: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Mark bpf_btf_find_by_name_kind() as sleepable: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: bpf: Mark faultable stack helpers as sleepable: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: bpf: Reject legacy packet loads from callbacks: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: bpf: Don't infer non-NULL from a pointer with an unbounded offset: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Don't resurrect a scalar id dropped by collect_linked_regs(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Don't predict JMP32 pointer vs zero comparisons: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: bpf: Mark the zero register precise for a register-form NULL check: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Require MEM_PERCPU for percpu kptr stores: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Keep refcount_acquire nullable for borrowed RCU kptrs: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: bpf: Reject untrusted allocated-object pointers: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Preserve special fields in recycled rhtab elements: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Cancel special fields when recycling rhtab elements: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Mark NULL kptr stores precise: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Preserve inner map identity in callback frames: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing: Fix subbuf resize races with trace_pipe_raw readers: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: nexthop: Initialize extack in remove_nh_grp_entry(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size: sources now disagree about CVSS GitHub advisories 7 · NVD 7 · Red Hat 5.5
13:02conflict kernel: eth: nfp: bound the ntuple rule dump by the caller's buffer size: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: eth: nfp: bound the ntuple rule dump by the caller's buffer size: sources now disagree about CVSS GitHub advisories 7 · NVD 7 · Red Hat 5.5
13:02conflict kernel: eth: nfp: drop the replaced rule from the list when reprogramming fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size: sources now disagree about CVSS GitHub advisories 7 · NVD 7 · Red Hat 5.5
13:02conflict kernel: net: bridge: mcast: properly convert mglist to rcu: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: s390/ism: folio_put() after error: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: vxlan: reject dynamic fdb entries that reference a nexthop id: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: vxlan: reject dynamic fdb entries that reference a nexthop id: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 7
13:02conflict kernel: net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: reject oversized tx_queue_len at netlink parse time: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: pds_core: fix cmd_regs access racing BAR unmap on reset: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: mark a NULL call argument precise: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: mctp: i3c: serialize probe with bus removal: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/sched: defer qdisc freeing after failed creation: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: net/sched: defer qdisc freeing after failed creation: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: net/mlx5e: Fix use-after-free race in sample_restore_put(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/mlx5: E-Switch, prevent mc_list repopulation during vport disable: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/sched: fq_pie: clamp quantum in change path: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/sched: sfq: clamp quantum in change path: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net/sched: hhf: clamp quantum in change and init paths: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net/sched: drr: clamp quantum in change class: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net/sched: ets: clamp quantum in parse and fallback paths: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net: macb: fix NULL pointer dereference on unbind with fixed-link: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: bpf: Reject non-scalar bpf_loop iteration counts: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: erofs: delimit inode_share cache key components: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: iommu/amd: Do not reallocate GA log buffers on resume: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: iommu/amd: Fix ineffective error check in nested domain allocation: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: iommu/amd: Fix ineffective error check in nested domain allocation: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: hwmon: (ltc4282) Make sure clk_init_data is fully initialized: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: hwmon: Fix potential UAF in pec_store: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: netfilter: nfnetlink_log: cope with concurrent instance destruction: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: virtio_ring: fix stale descriptor flags after a failed packed add: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: virtio: fix use-after-free in unregister_virtio_device(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: virtio_console: do not free control-out buffers on remove: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: vhost/vdpa: reject VRING_NUM larger than device max: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: vhost-vdpa: protect config_ctx from being freed under the config callback: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: vdpa_sim_blk: reject out-of-range sector starts: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: vdpa_sim_blk: reject out-of-range sector starts: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 7
13:02conflict kernel: vdpa_sim_net: check TX pull result before RX copy: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: vdpa_sim_net: check TX pull result before RX copy: sources now disagree about CVSS GitHub advisories 7.5 · NVD 7.5 · Red Hat 7
13:02conflict kernel: vduse: validate virtqueue alignment: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: vhost: invalidate vring access on IOTLB transitions: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: virtio_input: reset device if input_register_device() fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: virtio_input: stop callbacks before unregistering input device: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: af_unix: Update last skb marker in manage_oob(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net: ipv6: Fix UDP length overflow with PMTU discover and big MTU: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: vduse: return compat ioctl results directly: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: ethernet: cortina: Fix budget accounting: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: ethernet: cortina: Count dropped frames as NAPI work: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: s390/debug: Fix NULL pointer dereference in debug_set_level(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ice: add missing xa_destroy for sched_node_ids: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: eth: ice: don't dereference pointers from TP_printk(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: Bluetooth: btusb: Fix UAF of btusb_data by rx_work: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: Bluetooth: btintel_pcie: validate packet_len before skb_put_data: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: macb: destroy the phylink instance on the probe error path: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: macb: put the "mdio" child node reference on success: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: nstree: check listing permission before taking a namespace reference: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: nstree: check listing permission before taking a namespace reference: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: watchdog: msc313e: Avoid division by zero: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: watchdog: msc313e: Fix clock leak and spurious timer in settimeout(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: hwmon: (corsair-cpro) Create debugfs entries after hwmon registration: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: hwmon: (corsair-cpro) Remove debugfs entries when probe fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: octeontx2-pf: reset HTB scheduler topology before freeing queues: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: vxlan: initialize _md in vxlan_xmit_one(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ppp_synctty: ensure a writeable skb header: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: stmmac: initialize ptp_lock at probe time: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net/mlx5e: Move representor vnic reporter to eswitch devlink port: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: perf/core: Allow list_del during perf_event_overflow(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: perf/x86/intel: Prevent drain_pebs() reentry: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/sched: cls_route: free emptied bucket on filter move: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net: hinic: fix mailbox segment buffer overflow: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: net: hinic: fix mailbox segment buffer overflow: sources now disagree about CVSS GitHub advisories 8.8 · NVD 8.8 · Red Hat 7
13:02conflict kernel: net: net_failover: Fix the deadlock in net_failover_slave_name_change(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net: mana: restore the XDP program pointer when pre-allocation fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/rds: fix tcp stream corruption with large pages: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: stmmac: fix TX descriptor availability check for TSO traffic: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: net: stmmac: fix TX descriptor availability check for TSO traffic: sources now disagree about CVSS GitHub advisories 7 · NVD 7 · Red Hat 5.5
13:02conflict kernel: sunvdc: unmap LDC cookies when the descriptor send fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: configfs: pin the symlink target's dirent instead of chasing ->ci_dentry: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: configfs: unhash the dentry before dropping the item in rmdir: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: x86/amd_node: Fix potential NULL pointer dereference: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: x86/amd_node: Fix PCI device reference counting in amd_smn_init(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: x86/mm: Fix user-space data loss with MADV_FREE and THP: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: x86/alternatives: Exclude text poking against change_page_attr(): sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: ipv6: fix fib6 walker UAF on seq stop: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: ipv6: fix fib6 walker UAF on seq stop: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 7
13:02conflict kernel: ipmr: account multicast table and route memory: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: reboot: fix cad_pid use-after-free race: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ftrace: fork: Initialize function graph state before copy_exec_state(): sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: ftrace: fork: Initialize function graph state before copy_exec_state(): sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 7
13:02conflict kernel: tracing: Fix memory corruption from the histogram stacktrace modifier: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing: Set the trace clock before registering the histogram trigger: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing: Fix memory corruption from a "STACKTRACE" histogram key: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing: Take trace_array reference when opening a tracer options file: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing: Don't dereference trace_event_file in deferred trigger free: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ALSA: us122l: Prevent write upgrades for read mappings: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ALSA: usbusx2y: validate URB actual_length in interrupt callback: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: drm/amdgpu: skip the VMID 0 flush for VRAM: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ufs: create the root dentry after loading cylinder metadata: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: ufs: validate cylinder group metadata before caching it: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: tick/broadcast: Plug clockevents replacement race: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing/user_events: Don't destroy fields when event removal fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing: Free histogram the var ref when its initialization fails: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: tracing: Free histogram var refs regardless of how often they are referenced: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: tracing: Free histogram the field rejected for a bad modifier: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: tracing: Keep the entry count when the histogram stats allocation fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing: Take the reference before publishing the named histogram trigger: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: tracing: Undo the registration when enabling the histogram trigger fails: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel/ivpu: Validate firmware log buffer metadata: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel/ivpu: Limit firmware log name prints to field size: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel: ethosu: Fix ethosu_job_open() return value: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel: ethosu: Ensure cmd stream ends with a stop op: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel: ethosu: Ensure SRAM size is 0 on mapping failure: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: accel: ethosu: Ensure SRAM region size matches job: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: accel: ethosu: Ensure SRAM region size matches job: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: ASoC: sprd: validate compress buffer sizes against fixed allocations: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: ASoC: sprd: validate compress buffer sizes against fixed allocations: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 5.5
13:02conflict kernel: ASoC: sti: initialize IRQ lock before requesting IRQ: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: Bluetooth: btrtl: Don't leak return code when parsing firmware format v2: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: bootconfig: Fix integer overflow in initrd size check: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: cpufreq: zero-initialize policy cpumask before sysfs publication: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: cpufreq: initialize policy rwsem before sysfs publication: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: exit: hold a reference to thread_pid across proc_flush_pid: sources now disagree about Severity GitHub advisories high · NVD high · Red Hat medium
13:02conflict kernel: exit: hold a reference to thread_pid across proc_flush_pid: sources now disagree about CVSS GitHub advisories 7.8 · NVD 7.8 · Red Hat 7
13:02conflict kernel: fs: don't return -EINVAL for successful nested thaw: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: genetlink: pin family module during policy dump: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: drm/drm_exec: fix up contended obj when num_objects is 0: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: drm/i915: Fix memory leak in query_perf_config_list(): sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. You should upgrade the affected component.: sources now disagree about Severity GitHub advisories medium · NVD low
13:02conflict A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation of the argument role_id can lead to improper privilege management. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.2.6 is able to mitigate this issue. This patch is called 5469d70336fbb25e8e513683e82b32982ce8aa82. Upgrading the affected component is advised.: sources now disagree about Severity GitHub advisories low · NVD medium
13:02conflict A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such manipulation of the argument editassid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories low · NVD medium
13:02conflict A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument fid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories medium · NVD high
13:02conflict A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestudent.php of the component Student Update Functionality. The manipulation of the argument eno results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories low · NVD medium
13:02conflict A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the argument gid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories medium · NVD high
13:02conflict A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component Faculty Authentication. Executing a manipulation of the argument fid/pass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories medium · NVD high
13:02conflict A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories medium · NVD high
13:02conflict A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories medium · NVD high
13:02conflict A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories medium · NVD high
13:02conflict A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerializationIT.java of the component LangChain4j-agentic. This manipulation causes deserialization. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. Upgrading to version 1.5.3-beta11, 1.11.10-beta19 and 1.18.1-beta28 is able to resolve this issue. Upgrading the affected component is advised. The project maintainer kindly explains: "The issue was reported to us privately on 23 July 2026 and fixed in releases published on 29 July 2026. It is tracked as GHSA-gmwr-7wmf-mrjm. Exploitation requires an application to have enabled AgenticScope persistence, which is opt-in, and an attacker who can already write to that store. All maintained release lines have been patched.": sources now disagree about Severity GitHub advisories low · NVD medium
13:02conflict A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of the file Program.cs of the component Automatic Update. Executing a manipulation of the argument version/url/packagekey/package name can lead to channel accessible by non-endpoint. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.: sources now disagree about Severity GitHub advisories low · NVD medium
13:02conflict A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to address this issue. The patch is named 78c1222ec0e2119d84684032da1541120a2cdd23. The affected component should be upgraded.: sources now disagree about Severity GitHub advisories medium · NVD high
13:02conflict A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function echo of the file admin/fun/addLog.php. The manipulation of the argument reason/detail leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.: sources now disagree about Severity GitHub advisories low · NVD medium
13:02conflict A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is an unknown functionality of the file example_lite.sql. Executing a manipulation can lead to use of default credentials. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.: sources now disagree about Severity GitHub advisories low · NVD medium
13:02conflict A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performing a manipulation results in cross-site request forgery. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.: sources now disagree about Severity GitHub advisories low · NVD medium
13:02conflict A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes authorization bypass. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.: sources now disagree about Severity GitHub advisories medium · NVD high
13:02conflict Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team, because after the team-scoped lookup misses the backend falls back to a team-agnostic path concatenated from the unvalidated key. The Execution API Variables route accepts a path-shaped key, so this is reachable from ordinary Dag code. Affects multi-team deployments using the HashiCorp Vault secrets backend. Single-team deployments are not affected, as there is no cross-team boundary to cross. This is the same class as CVE-2026-86465, CVE-2026-68870, CVE-2026-68871 and CVE-2026-68872 in the Akeyless, Azure Key Vault, Yandex Lockbox and Amazon secrets backends. Users of apache-airflow-providers-hashicorp are recommended to upgrade to version 4.8.0 or later, which fixes the issue.: sources now disagree about Severity GitHub advisories unknown · NVD medium
13:02conflict kernel: drm/rockchip: analogix_dp: fix unchecked bound endpoint name length: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: io_uring/rw: end write accounting from ->ki_complete: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: io_uring/net: don't overconsume buffers when using MSG_TRUNC: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: ring-buffer: Check resize_disabled before publishing the new subbuf order: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net/sched: act_api: release all action references on NEWACTION failure: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net: bridge: use option bits for CFM/MRP frame handlers: sources now disagree about Severity GitHub advisories unknown · Red Hat low
13:02conflict kernel: net: dsa: tag_brcm: legacy FCS: request needed tailroom: sources now disagree about Severity GitHub advisories unknown · Red Hat medium
13:02conflict kernel: net: mana: Reserve extra CQ slot for the fence completion CQE: sources now disagree about Severity GitHub advisories unknown · Red Hat low

Older