CVE-2024-26739
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb
CVSS
7.8
High
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Apr 3, 2024 · Last modified: Aug 4, 2026 · CWE-416
0.3%EPSS · 30 days0.3%
2026-08-072026-09-04
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the core to drop the skb by setting the retcode to SHOT. If we have called tcf_mirred_forward(), however, the skb is out of our hands and returning SHOT will lead to UaF. Move the retval override to the error path which actually need it.
- git.kernel.orghttps://git.kernel.org/stable/c/0117fe0a4615a7c8d30d6ebcbf87332fbe63e6fd
- git.kernel.orghttps://git.kernel.org/stable/c/166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210
- git.kernel.orghttps://git.kernel.org/stable/c/28cdbbd38a4413b8eff53399b3f872fd4e80db9d
- git.kernel.orghttps://git.kernel.org/stable/c/9d3ef89b6a5e9f2e940de2cef3d543be0be8dec5
- git.kernel.orghttps://git.kernel.org/stable/c/e873e8f7d03a2ee5b77fb1a305c782fed98e2754
- git.kernel.orghttps://git.kernel.org/stable/c/f4e294bbdca8ac8757db436fc82214f3882fc7e7
- git.kernel.orghttps://git.kernel.org/stable/c/166c2c8a6a4dc2e4ceba9e10cfe81c3e469e3210
- git.kernel.orghttps://git.kernel.org/stable/c/28cdbbd38a4413b8eff53399b3f872fd4e80db9d
- git.kernel.orghttps://git.kernel.org/stable/c/f4e294bbdca8ac8757db436fc82214f3882fc7e7
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-860965.9 MED—
——0PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to freed heap memory, corrupting unrelated objects or allocator metadata and destabilizing heap operations.1dCVE-2026-851977.6 HIG8.0%
——2A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.1dCVE-2026-45200—3.6%
——1Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption.
Scenario caused by fabricating a specific combination of flags on the allocation interface that would cause an incorrect double free event when freed.2dCVE-2026-850498.8 HIG23.3%
——7Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-850488.3 HIG25.4%
——8Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-850429.6 CRI27.4%
——8Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)2d