CVE-2024-40929
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: check n_ssids before accessing the ssids In some v
CVSS
7.1
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 12 jul 2024 · Última mod.: 4 ago 2026 · CWE-125
0.4%EPSS · 30 días0.4%
2026-08-202026-09-17
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: check n_ssids before accessing the ssids In some versions of cfg80211, the ssids poinet might be a valid one even though n_ssids is 0. Accessing the pointer in this case will cuase an out-of-bound access. Fix this by checking n_ssids first.
- git.kernel.orghttps://git.kernel.org/stable/c/29a18d56bd64b95bd10bda4afda512558471382a
- git.kernel.orghttps://git.kernel.org/stable/c/3c4771091ea8016c8601399078916f722dd8833b
- git.kernel.orghttps://git.kernel.org/stable/c/60d62757df30b74bf397a2847a6db7385c6ee281
- git.kernel.orghttps://git.kernel.org/stable/c/62e007bdeb91c6879a4652c3426aef1cd9d2937b
- git.kernel.orghttps://git.kernel.org/stable/c/9e719ae3abad60e245ce248ba3f08148f375a614
- git.kernel.orghttps://git.kernel.org/stable/c/f777792952d03bbaf8329fdfa99393a5a33e2640
- git.kernel.orghttps://git.kernel.org/stable/c/29a18d56bd64b95bd10bda4afda512558471382a
- git.kernel.orghttps://git.kernel.org/stable/c/3c4771091ea8016c8601399078916f722dd8833b
- git.kernel.orghttps://git.kernel.org/stable/c/60d62757df30b74bf397a2847a6db7385c6ee281
- git.kernel.orghttps://git.kernel.org/stable/c/62e007bdeb91c6879a4652c3426aef1cd9d2937b
- git.kernel.orghttps://git.kernel.org/stable/c/9e719ae3abad60e245ce248ba3f08148f375a614
- git.kernel.orghttps://git.kernel.org/stable/c/f777792952d03bbaf8329fdfa99393a5a33e2640
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-92925——
——0In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding
and total length but never checked that string-carrying extensions are
properly null-terminated, allowing a crafted packet to trigger
out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.1dCVE-2026-252827.9 ALT0.9%
——0Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.1dCVE-2026-924755.3 MED3.8%
——1A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. Upgrading to version abi-16.26 will fix this issue. Patch name: c74a3065038ede35c1c7b75fa493a69ef6bcdb84. It is recommended to upgrade the affected component.2dCVE-2026-734626.5 MED15.9%
——5On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior.2dCVE-2026-567196.5 MED31.4%
——9MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.2dCVE-2026-76151—49.2%
——15Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (application crash) via an excessively large Cache-Control header value returned by an untrusted or compromised HTTP server to an application using QNetworkAccessManager. Only the client side of the connection is affected and 32-bit builds are not affected; the out-of-bounds access is read-only, with no information disclosure and no code execution.2d