CVE-2024-26856
In the Linux kernel, the following vulnerability has been resolved: net: sparx5: Fix use after free inside sparx5_del_mact_entry Based on
CVSS
8.8
Alto
EPSS
0.3%
p25
KEV
—
Exploit Today
7
0-100
Publicado: 17 abr 2024 · Última mod.: 4 ago 2026 · CWE-416
0.3%EPSS · 30 días0.3%
2026-08-162026-09-12
In the Linux kernel, the following vulnerability has been resolved: net: sparx5: Fix use after free inside sparx5_del_mact_entry Based on the static analyzis of the code it looks like when an entry from the MAC table was removed, the entry was still used after being freed. More precise the vid of the mac_entry was used after calling devm_kfree on the mac_entry. The fix consists in first using the vid of the mac_entry to delete the entry from the HW and after that to free it.
- git.kernel.orghttps://git.kernel.org/stable/c/0de693d68b0a18d5e256556c7c62d92cca35ad52
- git.kernel.orghttps://git.kernel.org/stable/c/71809805b95052ff551922f11660008fb3666025
- git.kernel.orghttps://git.kernel.org/stable/c/89d72d4125e94aa3c2140fedd97ce07ba9e37674
- git.kernel.orghttps://git.kernel.org/stable/c/e46274df1100fb0c06704195bfff5bfbd418bf64
- git.kernel.orghttps://git.kernel.org/stable/c/e83bebb718fd1f42549358730e1206164e0861d6
- git.kernel.orghttps://git.kernel.org/stable/c/0de693d68b0a18d5e256556c7c62d92cca35ad52
- git.kernel.orghttps://git.kernel.org/stable/c/71809805b95052ff551922f11660008fb3666025
- git.kernel.orghttps://git.kernel.org/stable/c/89d72d4125e94aa3c2140fedd97ce07ba9e37674
- git.kernel.orghttps://git.kernel.org/stable/c/e46274df1100fb0c06704195bfff5bfbd418bf64
- git.kernel.orghttps://git.kernel.org/stable/c/e83bebb718fd1f42549358730e1206164e0861d6
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-906876.3 MED—
———A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is able to resolve this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.1hCVE-2026-237874.2 MED—
———An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.5hCVE-2026-905785.3 MED—
———A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version abi-16.23 can resolve this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.12hCVE-2026-703418.5 ALT47.7%
——14Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.2dCVE-2026-578427.0 ALT0.8%
——0NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time.3dCVE-2026-781337.5 ALT35.2%
——11libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.3d