CVE-2022-48782
In the Linux kernel, the following vulnerability has been resolved: mctp: fix use after free Clang static analysis reports this problem ro
CVSS
8.8
High
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Jul 16, 2024 · Last modified: Aug 4, 2026 · CWE-416
0.3%EPSS · 30 days0.3%
2026-08-122026-09-09
In the Linux kernel, the following vulnerability has been resolved: mctp: fix use after free Clang static analysis reports this problem route.c:425:4: warning: Use of memory after it is freed trace_mctp_key_acquire(key); ^~~~~~~~~~~~~~~~~~~~~~~~~~~ When mctp_key_add() fails, key is freed but then is later used in trace_mctp_key_acquire(). Add an else statement to use the key only when mctp_key_add() is successful.
- git.kernel.orghttps://git.kernel.org/stable/c/1dd3ecbec5f606b2a526c47925c8634b1a6bb81e
- git.kernel.orghttps://git.kernel.org/stable/c/7e5b6a5c8c44310784c88c1c198dde79f6402f7b
- git.kernel.orghttps://git.kernel.org/stable/c/1dd3ecbec5f606b2a526c47925c8634b1a6bb81e
- git.kernel.orghttps://git.kernel.org/stable/c/7e5b6a5c8c44310784c88c1c198dde79f6402f7b
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-878777.7 HIG—
——0zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.1dCVE-2026-878257.7 HIG—
——0zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.1dCVE-2026-87657—15.8%
——5Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-876488.3 HIG20.0%
——6Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-876469.6 CRI26.5%
——8Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)1dCVE-2026-876398.3 HIG26.9%
——8Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)1d