CVE-2021-47210
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Remove WARN_ON in tps6598x_block_read Calling tps659
CVSS
5.5
Medium
EPSS
0.2%
p13
KEV
—
Exploit Today
4
0-100
Published: Apr 10, 2024 · Last modified: Aug 11, 2026 · CWE-125
0.2%EPSS · 30 days0.2%
2026-07-262026-08-23
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Remove WARN_ON in tps6598x_block_read Calling tps6598x_block_read with a higher than allowed len can be handled by just returning an error. There's no need to crash systems with panic-on-warn enabled.
- git.kernel.orghttps://git.kernel.org/stable/c/2a897d384513ba7f7ef05611338b9a6ec6aeac00
- git.kernel.orghttps://git.kernel.org/stable/c/2c71811c963b6c310a29455d521d31a7ea6c5b5e
- git.kernel.orghttps://git.kernel.org/stable/c/30dcfcda8992dc42f18e7d35b6a1fa72372d382d
- git.kernel.orghttps://git.kernel.org/stable/c/b7a0a63f3fed57d413bb857de164ea9c3984bc4e
- git.kernel.orghttps://git.kernel.org/stable/c/eff8b7628410cb2eb562ca0d5d1f12e27063733e
- git.kernel.orghttps://git.kernel.org/stable/c/2a897d384513ba7f7ef05611338b9a6ec6aeac00
- git.kernel.orghttps://git.kernel.org/stable/c/2c71811c963b6c310a29455d521d31a7ea6c5b5e
- git.kernel.orghttps://git.kernel.org/stable/c/30dcfcda8992dc42f18e7d35b6a1fa72372d382d
- git.kernel.orghttps://git.kernel.org/stable/c/b7a0a63f3fed57d413bb857de164ea9c3984bc4e
- git.kernel.orghttps://git.kernel.org/stable/c/eff8b7628410cb2eb562ca0d5d1f12e27063733e
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-781577.4 HIG—
——0A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.13hCVE-2026-780493.7 LOW47.1%
——14A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes of the file src/ClientServer/address_space/internal/sopc_node_mgt_helper_internal.c of the component AddNodes Service. The manipulation of the argument UserAccessLevel leads to out-of-bounds read. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is aafbd37d381b618312ebdf5ddf57027f62c14fdd. It is suggested to install a patch to address this issue.2dCVE-2026-772197.1 HIG3.1%
——1GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.3dCVE-2026-772376.5 MED2.3%
——1Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later.3dCVE-2026-547897.5 HIG32.7%
——10mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.3dCVE-2026-502786.5 MED16.3%
——5iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.3d