CVE-2025-71112
In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Currently, the VLAN id
CVSS
8.8
High
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Published: Jan 14, 2026 · Last modified: Jul 30, 2026 · CWE-125
0.1%EPSS · 30 days0.1%
2026-08-042026-08-31
In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Currently, the VLAN id may be used without validation when receive a VLAN configuration mailbox from VF. The length of vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause out-of-bounds memory access once the VLAN id is bigger than or equal to VLAN_N_VID. Therefore, VLAN id needs to be checked to ensure it is within the range of VLAN_N_VID.
- git.kernel.orghttps://git.kernel.org/stable/c/00e56a7706e10b3d00a258d81fcb85a7e96372d6
- git.kernel.orghttps://git.kernel.org/stable/c/42c91dfa772c57de141e5a55a187ac760c0fd7e1
- git.kernel.orghttps://git.kernel.org/stable/c/46c7d9fe8dd869ea5de666aba8c1ec1061ca44a8
- git.kernel.orghttps://git.kernel.org/stable/c/6ef935e65902bfed53980ad2754b06a284ea8ac1
- git.kernel.orghttps://git.kernel.org/stable/c/91a51d01be5c9f82c12c2921ca5cceaa31b67128
- git.kernel.orghttps://git.kernel.org/stable/c/95cca255a7a5ad782639ff0298c2a486707d1046
- git.kernel.orghttps://git.kernel.org/stable/c/b7b4f3bf118f51b67691a55b464f04452e5dc6fc
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/html/ssa-019113.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-842704.3 MED—
———A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service.9hCVE-2026-826184.3 MED19.7%
——6A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affected element is the function set_range_matrix_on_string_array of the file src/Common/opcua_types/sopc_builtintypes.c of the component String Array Range Writing. This manipulation causes out-of-bounds read. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.2dCVE-2026-826087.4 HIG14.1%
——4A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to correct this issue. The vendor points out, that "[v]ersion 5.5.0 is old and not maintained anymore."2dCVE-2026-823306.1 MED2.0%
——1A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.1dCVE-2026-823286.1 MED1.9%
——1A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.1dCVE-2026-823246.1 MED2.5%
——1A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.1d