CVE-2025-38068
In the Linux kernel, the following vulnerability has been resolved: crypto: lzo - Fix compression buffer overrun Unlike the decompression
CVSS
7.8
High
EPSS
0.2%
p5
KEV
—
Exploit Today
2
0-100
Published: Jun 18, 2025 · Last modified: Jul 30, 2026 · CWE-787
0.2%EPSS · 30 days0.2%
2026-07-032026-07-30
In the Linux kernel, the following vulnerability has been resolved: crypto: lzo - Fix compression buffer overrun Unlike the decompression code, the compression code in LZO never checked for output overruns. It instead assumes that the caller always provides enough buffer space, disregarding the buffer length provided by the caller. Add a safe compression interface that checks for the end of buffer before each write. Use the safe interface in crypto/lzo.
- git.kernel.orghttps://git.kernel.org/stable/c/0acdc4d6e679ba31d01e3e7e2e4124b76d6d8e2a
- git.kernel.orghttps://git.kernel.org/stable/c/167373d77c70c2b558aae3e327b115249bb2652c
- git.kernel.orghttps://git.kernel.org/stable/c/4b173bb2c4665c23f8fcf5241c7b06dfa6b5b111
- git.kernel.orghttps://git.kernel.org/stable/c/7caad075acb634a74911830d6386c50ea12566cd
- git.kernel.orghttps://git.kernel.org/stable/c/a98bd864e16f91c70b2469adf013d713d04d1d13
- git.kernel.orghttps://git.kernel.org/stable/c/cc47f07234f72cbd8e2c973cdbf2a6730660a463
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-346417.8 HIG—
———Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.12hCVE-2026-54715——
——0GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.19hCVE-2026-11771——
——0OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server2dCVE-2026-478769.3 CRI—
——0VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.2dCVE-2026-17544——
——0Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.1dCVE-2026-177279.6 CRI11.1%
——3Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)1d