CVE-2022-48665
In the Linux kernel, the following vulnerability has been resolved: exfat: fix overflow for large capacity partition Using int type for se
CVSS
7.1
Alto
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Publicado: 28 abr 2024 · Última mod.: 4 ago 2026 · CWE-191
0.2%EPSS · 30 días0.2%
2026-07-152026-08-11
In the Linux kernel, the following vulnerability has been resolved: exfat: fix overflow for large capacity partition Using int type for sector index, there will be overflow in a large capacity partition. For example, if storage with sector size of 512 bytes and partition capacity is larger than 2TB, there will be overflow.
- git.kernel.orghttps://git.kernel.org/stable/c/17244f71765dfec39e84493993993e896c376d09
- git.kernel.orghttps://git.kernel.org/stable/c/2e9ceb6728f1dc2fa4b5d08f37d88cbc49a20a62
- git.kernel.orghttps://git.kernel.org/stable/c/17244f71765dfec39e84493993993e896c376d09
- git.kernel.orghttps://git.kernel.org/stable/c/2e9ceb6728f1dc2fa4b5d08f37d88cbc49a20a62
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-187276.5 MED—
———A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram Protocol (UDP) length can cause the DHCPv6 payload length to underflow. An unauthenticated attacker on an adjacent network segment can exploit this by sending specially crafted IPv6 UDP traffic while the client is in an active DHCPv6 exchange, leading to a denial of service due to a process crash or service disruption.5hCVE-2026-734336.6 MED—
———A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated string scanning to read far beyond the allocated heap buffer. Date-format normalization may also write beyond the buffer end. Confirmed impacts include heap out-of-bounds read, out-of-bounds write, heap information disclosure (adjacent data appearing in parsed metadata), and application crash/denial of service. The avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer, so opening or previewing a crafted AVI is sufficient to trigger the issue. Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).5hCVE-2026-186877.1 ALT—
——0MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.1dCVE-2026-713896.2 MED—
——0CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.6hCVE-2026-649097.8 ALT—
——0Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.22hCVE-2026-635157.8 ALT—
——0Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.22h