CVE-2022-48654
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find() nf
CVSS
7.1
Alto
EPSS
0.2%
p15
KEV
—
Exploit Today
5
0-100
Publicado: 28 abr 2024 · Última mod.: 4 ago 2026 · CWE-908
0.2%EPSS · 30 días0.2%
2026-07-312026-08-27
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find() nf_osf_find() incorrectly returns true on mismatch, this leads to copying uninitialized memory area in nft_osf which can be used to leak stale kernel stack data to userspace.
- git.kernel.orghttps://git.kernel.org/stable/c/559c36c5a8d730c49ef805a72b213d3bba155cc8
- git.kernel.orghttps://git.kernel.org/stable/c/5d75fef3e61e797fab5c3fbba88caa74ab92ad47
- git.kernel.orghttps://git.kernel.org/stable/c/633c81c0449663f57d4138326d036dc6cfad674e
- git.kernel.orghttps://git.kernel.org/stable/c/721ea8ac063d70c2078c4e762212705de6151764
- git.kernel.orghttps://git.kernel.org/stable/c/816eab147e5c6f6621922b8515ad9010ceb1735e
- git.kernel.orghttps://git.kernel.org/stable/c/559c36c5a8d730c49ef805a72b213d3bba155cc8
- git.kernel.orghttps://git.kernel.org/stable/c/5d75fef3e61e797fab5c3fbba88caa74ab92ad47
- git.kernel.orghttps://git.kernel.org/stable/c/633c81c0449663f57d4138326d036dc6cfad674e
- git.kernel.orghttps://git.kernel.org/stable/c/721ea8ac063d70c2078c4e762212705de6151764
- git.kernel.orghttps://git.kernel.org/stable/c/816eab147e5c6f6621922b8515ad9010ceb1735e
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-792856.5 MED21.1%
——6Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)10hCVE-2026-792706.5 MED21.1%
——6Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)10hCVE-2026-792694.3 MED15.0%
——4Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-792296.5 MED21.1%
——6Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)10hCVE-2026-792216.5 MED8.7%
——3Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)10hCVE-2026-791206.5 MED15.4%
——5Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)10h