CVE-2026-53021
In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix integer overflow in UNMAP bounds check sbc_exe
CVSS
5.5
Medium
EPSS
0.1%
p2
KEV
—
Exploit Today
1
0-100
Published: Jun 24, 2026 · Last modified: Jul 15, 2026 · CWE-190
0.1%EPSS · 30 days0.1%
2026-08-032026-08-31
In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix integer overflow in UNMAP bounds check sbc_execute_unmap() checks LBA + range does not exceed the device capacity, but does not guard against LBA + range wrapping around on 64-bit overflow. Add an overflow check matching the pattern already used for WRITE_SAME in the same file.
- git.kernel.orghttps://git.kernel.org/stable/c/02115986d027ade793e7f6be87e91d6a796d0aa3
- git.kernel.orghttps://git.kernel.org/stable/c/2bf2d65f76697820dbc4227d13866293576dd90a
- git.kernel.orghttps://git.kernel.org/stable/c/2e1ed9a7b6ea5bfefb5d80a02b1c71c7dee1f0dd
- git.kernel.orghttps://git.kernel.org/stable/c/3facdecc3fcf115cc4f9b3d8f118d6705e2456a8
- git.kernel.orghttps://git.kernel.org/stable/c/51075df70c46e60a9773f2dcd28299e40dac36fb
- git.kernel.orghttps://git.kernel.org/stable/c/5efc3ef4758f8d98c257419fa21daca3227de61a
- git.kernel.orghttps://git.kernel.org/stable/c/c08ab702c4699c6efb9d60bdb15b73e7a627ee7e
- git.kernel.orghttps://git.kernel.org/stable/c/d7aef29573c7c5cdb2dfad939253287a6329c2a4
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-547559.6 CRI31.6%
——9Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckValid100Params. Royalty payout paths in core/kapp/accounts/accounts.go, core/kapp/market/market.go, and core/kapp/ito/ito.go then credit each oversized split amount and silently discard a negative remainder, allowing ordinary asset transfers, marketplace purchases, or ITO purchases to create unbacked KLV or other assets. This issue is fixed in version 1.7.19.16hCVE-2026-19313—38.9%
——12An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.3dCVE-2026-383507.5 HIG24.9%
——7An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.4dCVE-2026-383497.5 HIG24.9%
——7An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.4dCVE-2026-383487.5 HIG24.9%
——7An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.4dCVE-2026-383467.5 HIG24.9%
——7An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.4d