CVE-2025-39849
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() If
CVSS
8.8
High
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Published: Sep 19, 2025 · Last modified: Jul 30, 2026 · CWE-787
0.1%EPSS · 30 days0.2%
2026-07-152026-08-12
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() If the ssid->datalen is more than IEEE80211_MAX_SSID_LEN (32) it would lead to memory corruption so add some bounds checking.
- git.kernel.orghttps://git.kernel.org/stable/c/31229145e6ba5ace3e9391113376fa05b7831ede
- git.kernel.orghttps://git.kernel.org/stable/c/5cb7cab7adf9b1e6a99e2081b0e30e9e59d07523
- git.kernel.orghttps://git.kernel.org/stable/c/62b635dcd69c4fde7ce1de4992d71420a37e51e3
- git.kernel.orghttps://git.kernel.org/stable/c/8e751d46336205abc259ed3990e850a9843fb649
- git.kernel.orghttps://git.kernel.org/stable/c/e472f59d02c82b511bc43a3f96d62ed08bf4537f
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/html/ssa-032379.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-196966.6 MED—
——0Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows5hCVE-2026-0297——
——0A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).9hCVE-2026-188886.5 MED—
——0The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.17hCVE-2026-196425.9 MED—
——0An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in an application that processes crafted Base64-encoded input.
To remediate this issue, users should upgrade to version 1.11.862.17hCVE-2026-170839.8 CRI—
——0IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.9hCVE-2026-172189.8 CRI—
——0IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.17h