CVE-2024-39478
In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variabl
CVSS
7.8
High
EPSS
0.2%
p9
KEV
—
Exploit Today
3
0-100
Published: Jul 5, 2024 · Last modified: Aug 4, 2026 · CWE-770
0.2%EPSS · 30 days0.2%
2026-07-132026-08-10
In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.
- git.kernel.orghttps://git.kernel.org/stable/c/5944de192663f272033501dcd322b008fca72006
- git.kernel.orghttps://git.kernel.org/stable/c/d7f01649f4eaf1878472d3d3f480ae1e50d98f6c
- git.kernel.orghttps://git.kernel.org/stable/c/5944de192663f272033501dcd322b008fca72006
- git.kernel.orghttps://git.kernel.org/stable/c/d7f01649f4eaf1878472d3d3f480ae1e50d98f6c
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-730897.5 HIG—
———Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `<year>-<month>-<day>` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7.5hCVE-2026-541137.5 HIG—
———Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.5hCVE-2026-155617.5 HIG—
——0A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.5hCVE-2026-195176.5 MED—
——0Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.5hCVE-2026-667614.3 MED—
——0SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.7hCVE-2026-582385.9 MED—
——0SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.7h