CVE-2024-35963
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sock: Fix not validating setsockopt user input Check us
CVSS
7.1
High
EPSS
0.2%
p15
KEV
—
Exploit Today
4
0-100
Published: May 20, 2024 · Last modified: Aug 4, 2026 · CWE-1284
0.2%EPSS · 30 days0.2%
2026-07-292026-08-26
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sock: Fix not validating setsockopt user input Check user input length before copying data.
- git.kernel.orghttps://git.kernel.org/stable/c/0c18a64039aa3f1c16f208d197c65076da798137
- git.kernel.orghttps://git.kernel.org/stable/c/50173882bb187e70e37bac01385b9b114019bee2
- git.kernel.orghttps://git.kernel.org/stable/c/781f3a97a38a338bc893b6db7f9f9670bf1a9e37
- git.kernel.orghttps://git.kernel.org/stable/c/b2186061d6043d6345a97100460363e990af0d46
- git.kernel.orghttps://git.kernel.org/stable/c/50173882bb187e70e37bac01385b9b114019bee2
- git.kernel.orghttps://git.kernel.org/stable/c/b2186061d6043d6345a97100460363e990af0d46
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-45201—4.5%
——1Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to improper validation of the said value.
Such crafted log2 page size could lead to 4K pages being treated as higher order pages and allowing read and/or write access to the memory beyond 4K threshold.7dCVE-2026-776403.7 LOW11.7%
——4tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.6dCVE-2026-535877.5 HIG32.1%
——10libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.7dCVE-2026-608207.4 HIG26.5%
——8Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).7dCVE-2026-758977.5 HIG40.9%
——12Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.7dCVE-2026-666796.5 MED26.1%
——8Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.7d