CVE-2024-35874
In the Linux kernel, the following vulnerability has been resolved: aio: Fix null ptr deref in aio_complete() wakeup list_del_init_careful
CVSS
7.8
High
EPSS
0.2%
p11
KEV
—
Exploit Today
3
0-100
Published: May 19, 2024 · Last modified: Aug 4, 2026 · CWE-476
0.2%EPSS · 30 days0.2%
2026-07-152026-08-12
In the Linux kernel, the following vulnerability has been resolved: aio: Fix null ptr deref in aio_complete() wakeup list_del_init_careful() needs to be the last access to the wait queue entry - it effectively unlocks access. Previously, finish_wait() would see the empty list head and skip taking the lock, and then we'd return - but the completion path would still attempt to do the wakeup after the task_struct pointer had been overwritten.
- git.kernel.orghttps://git.kernel.org/stable/c/9678bcc6234d83759fe091c197f5017a32b468da
- git.kernel.orghttps://git.kernel.org/stable/c/caeb4b0a11b3393e43f7fa8e0a5a18462acc66bd
- git.kernel.orghttps://git.kernel.org/stable/c/9678bcc6234d83759fe091c197f5017a32b468da
- git.kernel.orghttps://git.kernel.org/stable/c/caeb4b0a11b3393e43f7fa8e0a5a18462acc66bd
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-186996.5 MED21.3%
——6An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations.2dCVE-2026-656817.5 HIG55.7%
——17Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.2dCVE-2026-627026.8 MED54.5%
——16Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.2dCVE-2026-613456.5 MED61.0%
——18Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.23hCVE-2026-591386.5 MED61.0%
——18Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.22hCVE-2026-591327.5 HIG69.2%
——21Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.21h