CVE-2024-27045
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix a potential buffer overflow in 'dp_dsc_clock_en_re
CVSS
7.0
Alto
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 1 may 2024 · Última mod.: 4 ago 2026 · CWE-120
0.3%EPSS · 30 días0.3%
2026-08-132026-09-09
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix a potential buffer overflow in 'dp_dsc_clock_en_read()' Tell snprintf() to store at most 10 bytes in the output buffer instead of 30. Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_debugfs.c:1508 dp_dsc_clock_en_read() error: snprintf() is printing too much 30 vs 10
- git.kernel.orghttps://git.kernel.org/stable/c/440f059837418fac1695b65d3ebc6080d33be877
- git.kernel.orghttps://git.kernel.org/stable/c/4b09715f1504f1b6e8dff0e9643630610bc05141
- git.kernel.orghttps://git.kernel.org/stable/c/ad76fd30557d6a106c481e4606a981221ca525f7
- git.kernel.orghttps://git.kernel.org/stable/c/cf114d8d4a8d78df272116a745bb43b48cef65f4
- git.kernel.orghttps://git.kernel.org/stable/c/d346b3e5b25c95d504478507eb867cd3818775ab
- git.kernel.orghttps://git.kernel.org/stable/c/eb9327af3621d26b1d83f767c97a3fe8191a3a65
- git.kernel.orghttps://git.kernel.org/stable/c/ff28893c96c5e0927a4da10cd24a3522ca663515
- git.kernel.orghttps://git.kernel.org/stable/c/440f059837418fac1695b65d3ebc6080d33be877
- git.kernel.orghttps://git.kernel.org/stable/c/4b09715f1504f1b6e8dff0e9643630610bc05141
- git.kernel.orghttps://git.kernel.org/stable/c/ad76fd30557d6a106c481e4606a981221ca525f7
- git.kernel.orghttps://git.kernel.org/stable/c/cf114d8d4a8d78df272116a745bb43b48cef65f4
- git.kernel.orghttps://git.kernel.org/stable/c/d346b3e5b25c95d504478507eb867cd3818775ab
- git.kernel.orghttps://git.kernel.org/stable/c/eb9327af3621d26b1d83f767c97a3fe8191a3a65
- git.kernel.orghttps://git.kernel.org/stable/c/ff28893c96c5e0927a4da10cd24a3522ca663515
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-428086.8 MED—
———An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11.
The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer.
Internally, the stream processing mechanism in {{comm_intf_process_stream_response()}} discards the requested {{number_of_samples}} argument and copies the entirety of the streaming ring buffer's accumulated data into {{coines_stream_rsp_buf}}.
Subsequently, {{coines_read_stream_sensor_data()}} unconditionally executes a {{memcpy}} of the ring buffer size into the caller-provided buffer without verifying if the destination memory allocation is large enough.
A malicious or compromised hardware board connected via USB or BLE can exploit this by streaming a high volume of sensor samples, causing a heap or stack-based buffer overflow on the host desktop environment.
This can result in a Denial of Service (DoS) or potential arbitrary code execution on the host machine.21hCVE-2026-879319.6 CRÍ—
———A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.22hCVE-2026-716137.8 ALT—
———Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_process() function. Fixed in 9a253a07fd3f6b48022bba74302bf39388dda859.20hCVE-2026-588397.8 ALT0.2%
——0In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2026-588237.8 ALT0.1%
——0In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2026-552903.3 BAJ2.0%
——1In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.20h