CVE-2025-22004
In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->send() operation free
CVSS
8.6
High
EPSS
0.3%
p28
KEV
—
Exploit Today
8
0-100
Published: Apr 3, 2025 · Last modified: Jul 30, 2026 · CWE-416
0.3%EPSS · 30 days0.3%
2026-08-182026-09-15
In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->send() operation frees skb so save the length before calling ->send() to avoid a use after free.
- git.kernel.orghttps://git.kernel.org/stable/c/326223182e4703cde99fdbd36d07d0b3de9980fb
- git.kernel.orghttps://git.kernel.org/stable/c/50e288097c2c6e5f374ae079394436fc29d1e88e
- git.kernel.orghttps://git.kernel.org/stable/c/51e8be9578a2e74f9983d8fd8de8cafed191f30c
- git.kernel.orghttps://git.kernel.org/stable/c/82d9084a97892de1ee4881eb5c17911fcd9be6f6
- git.kernel.orghttps://git.kernel.org/stable/c/8cd90c7db08f32829bfa1b5b2b11fbc542afbab7
- git.kernel.orghttps://git.kernel.org/stable/c/9566f6ee13b17a15d0a47667ad1b1893c539f730
- git.kernel.orghttps://git.kernel.org/stable/c/f3009d0d6ab78053117f8857b921a8237f4d17b3
- git.kernel.orghttps://git.kernel.org/stable/c/f3271f7548385e0096739965961c7cbf7e6b4762
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-92627——
———A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An attacker who can supply a crafted HDF5 file containing a specially constructed compound datatype can trigger the use-after-free when the file is parsed by an application that reads the affected dataset, such as h5dump. This can result in a crash and, depending on heap layout and allocator behavior, may be exploitable for further memory corruption up to remote code execution.4hCVE-2026-196667.5 HIG—
———On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.5hCVE-2026-196625.9 MED—
———An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.6hCVE-2026-827205.9 MED—
———NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads are not user controlled and the use-after-free leads to early returns. However, a hardened allocator can catch the use-after-free and controllably terminate the process resulting to denial of service.5hCVE-2026-782276.5 MED—
———NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retransmission buffer keeps a shallow pointer into the output buffer for as long as a STREAM frame may be resent. On a client RESET_STREAM, the output buffer is freed but ngtcp2 still holds the matching retransmission entries. The next PTO timeout makes ngtcp2 re-encode the STREAM frame and copy from the freed buffer. A malicious actor that can query Unbound over DoQ and that withholds ACKs, sends RESET_STREAM, and waits for PTO, reaches this use-after-free with no privilege. This leads to retransmissions against freed memory and eventually an abnormal server exit under a 20-query spray.4hCVE-2026-858938.8 HIG—
———Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.21h