CVE-2024-35874
In the Linux kernel, the following vulnerability has been resolved: aio: Fix null ptr deref in aio_complete() wakeup list_del_init_careful
CVSS
7.8
Alto
EPSS
0.2%
p11
KEV
—
Exploit Today
3
0-100
Publicado: 19 may 2024 · Última mod.: 4 ago 2026 · CWE-476
0.2%EPSS · 30 días0.2%
2026-07-152026-08-12
In the Linux kernel, the following vulnerability has been resolved: aio: Fix null ptr deref in aio_complete() wakeup list_del_init_careful() needs to be the last access to the wait queue entry - it effectively unlocks access. Previously, finish_wait() would see the empty list head and skip taking the lock, and then we'd return - but the completion path would still attempt to do the wakeup after the task_struct pointer had been overwritten.
- git.kernel.orghttps://git.kernel.org/stable/c/9678bcc6234d83759fe091c197f5017a32b468da
- git.kernel.orghttps://git.kernel.org/stable/c/caeb4b0a11b3393e43f7fa8e0a5a18462acc66bd
- git.kernel.orghttps://git.kernel.org/stable/c/9678bcc6234d83759fe091c197f5017a32b468da
- git.kernel.orghttps://git.kernel.org/stable/c/caeb4b0a11b3393e43f7fa8e0a5a18462acc66bd
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-186996.5 MED21.3%
——6An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations.2dCVE-2026-656817.5 ALT55.7%
——17Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.2dCVE-2026-627026.8 MED54.5%
——16Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.2dCVE-2026-613456.5 MED61.0%
——18Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.1dCVE-2026-591386.5 MED61.0%
——18Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.22hCVE-2026-591327.5 ALT69.2%
——21Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.22h