PULSE
LIVE97signals / 24h
FEED
ransomdeadlock reclama a Hardware Asesorias Software Ltda · CL · Technologyransomdeadlock reclama a Tesco Engineer · GB · Retail & E-Commerceransomglobal secret group reclama a Louisiana Coalition Against | Domestic Violence · US · Otherransomcrpxo reclama a ProSmile Family Dental Care · US · Healthcareransomcrpxo reclama a Qube Aviation Catering · US · Transportationransomcrpxo reclama a Performance Data Solutions · US · Professional Servicesransomcrpxo reclama a Host & Protect (RedBlink) · US · Technologyransomcrpxo reclama a RnnR Cloud · US · Technologyransomcrpxo reclama a CodeConductor.ai · US · Technologyransomcrpxo reclama a Prei Capital · US · Financial Servicesransomcrpxo reclama a FLP Law Group LLP · US · Professional Servicesransomcrpxo reclama a Summit Hill Insurance · US · Financial Servicesransomcrpxo reclama a MRO Aerospace · US · Manufacturingransomincransom reclama a takethehop.com · US · Hospitalityransomdeadlock reclama a Hardware Asesorias Software Ltda · CL · Technologyransomdeadlock reclama a Tesco Engineer · GB · Retail & E-Commerceransomglobal secret group reclama a Louisiana Coalition Against | Domestic Violence · US · Otherransomcrpxo reclama a ProSmile Family Dental Care · US · Healthcareransomcrpxo reclama a Qube Aviation Catering · US · Transportationransomcrpxo reclama a Performance Data Solutions · US · Professional Servicesransomcrpxo reclama a Host & Protect (RedBlink) · US · Technologyransomcrpxo reclama a RnnR Cloud · US · Technologyransomcrpxo reclama a CodeConductor.ai · US · Technologyransomcrpxo reclama a Prei Capital · US · Financial Servicesransomcrpxo reclama a FLP Law Group LLP · US · Professional Servicesransomcrpxo reclama a Summit Hill Insurance · US · Financial Servicesransomcrpxo reclama a MRO Aerospace · US · Manufacturingransomincransom reclama a takethehop.com · US · Hospitality
← All CVEs
CVE WatchJul 23, 2026

CVE-2026-45782

Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can cause a use-after-f

CVSS

No CVSS

EPSS

0.1%

p4

KEV

Exploit Today

1

0-100

Published: Jun 10, 2026 · Last modified: Jul 23, 2026 · CWE-416

EPSS · 30d
0.1%EPSS · 30 days0.1%
2026-06-302026-07-25
Technical description

Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can cause a use-after-free in the cloud-hypervisor process by submitting two virtio-block descriptor chains that reuse the same head_index while asynchronous block I/O is enabled (e.g. io_uring, aio). When the kernel completes the duplicate operation before the original, the completion path frees a bounce buffer that the kernel is still actively reading from or writing to, corrupting the freed memory. This issue has been patched in versions 51.2 and 52.0.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-497437.8 HIG
1.5%
0Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition.2d
CVE-2026-168068.8 HIG
35.6%
11Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)2d
CVE-2026-168058.8 HIG
26.9%
8Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)2d
CVE-2026-168048.3 HIG
21.0%
6Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)2d
CVE-2026-130716.5 MED
15.8%
5An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.4d
CVE-2026-528635.9 MED
16.0%
5In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.3d