CVE-2022-48717
In the Linux kernel, the following vulnerability has been resolved: ASoC: max9759: fix underflow in speaker_gain_control_put() Check for n
CVSS
7.1
Alto
EPSS
0.2%
p13
KEV
—
Exploit Today
4
0-100
Publicado: 20 jun 2024 · Última mod.: 4 ago 2026 · CWE-787
0.2%EPSS · 30 días0.2%
2026-07-232026-08-20
In the Linux kernel, the following vulnerability has been resolved: ASoC: max9759: fix underflow in speaker_gain_control_put() Check for negative values of "priv->gain" to prevent an out of bounds access. The concern is that these might come from the user via: -> snd_ctl_elem_write_user() -> snd_ctl_elem_write() -> kctl->put()
- git.kernel.orghttps://git.kernel.org/stable/c/4c907bcd9dcd233da6707059d777ab389dcbd964
- git.kernel.orghttps://git.kernel.org/stable/c/5a45448ac95b715173edb1cd090ff24b6586d921
- git.kernel.orghttps://git.kernel.org/stable/c/71e60c170105d153e34d01766c1e4db26a4b24cc
- git.kernel.orghttps://git.kernel.org/stable/c/a0f49d12547d45ea8b0f356a96632dd503941c1e
- git.kernel.orghttps://git.kernel.org/stable/c/baead410e5db49e962a67fffc17ac30e44b50b7c
- git.kernel.orghttps://git.kernel.org/stable/c/f114fd6165dfb52520755cc4d1c1dfbd447b88b6
- git.kernel.orghttps://git.kernel.org/stable/c/4c907bcd9dcd233da6707059d777ab389dcbd964
- git.kernel.orghttps://git.kernel.org/stable/c/5a45448ac95b715173edb1cd090ff24b6586d921
- git.kernel.orghttps://git.kernel.org/stable/c/71e60c170105d153e34d01766c1e4db26a4b24cc
- git.kernel.orghttps://git.kernel.org/stable/c/a0f49d12547d45ea8b0f356a96632dd503941c1e
- git.kernel.orghttps://git.kernel.org/stable/c/baead410e5db49e962a67fffc17ac30e44b50b7c
- git.kernel.orghttps://git.kernel.org/stable/c/f114fd6165dfb52520755cc4d1c1dfbd447b88b6
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-547897.5 ALT—
———mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.2hCVE-2026-776427.5 ALT—
——0tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.20hCVE-2026-197836.7 MED—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation.20hCVE-2026-194378.1 ALT—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.20hCVE-2026-188428.4 ALT—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write.2hCVE-2026-188328.8 ALT—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.7h