CVE-2024-41019
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate ff offset This adds sanity checks for ff offset. Th
CVSS
7.8
Alto
EPSS
0.2%
p13
KEV
—
Exploit Today
4
0-100
Publicado: 29 jul 2024 · Última mod.: 4 ago 2026 · CWE-125
0.2%EPSS · 30 días0.2%
2026-07-232026-08-20
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate ff offset This adds sanity checks for ff offset. There is a check on rt->first_free at first, but walking through by ff without any check. If the second ff is a large offset. We may encounter an out-of-bound read.
- git.kernel.orghttps://git.kernel.org/stable/c/35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0
- git.kernel.orghttps://git.kernel.org/stable/c/50c47879650b4c97836a0086632b3a2e300b0f06
- git.kernel.orghttps://git.kernel.org/stable/c/617cf144c206f98978ec730b17159344fd147cb4
- git.kernel.orghttps://git.kernel.org/stable/c/6ae7265a7b816879fd0203e83b5030d3720bbb7a
- git.kernel.orghttps://git.kernel.org/stable/c/818a257428644b8873e79c44404d8fb6598d4440
- git.kernel.orghttps://git.kernel.org/stable/c/82c94e6a7bd116724738aa67eba6f5fedf3a3319
- git.kernel.orghttps://git.kernel.org/stable/c/35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0
- git.kernel.orghttps://git.kernel.org/stable/c/50c47879650b4c97836a0086632b3a2e300b0f06
- git.kernel.orghttps://git.kernel.org/stable/c/617cf144c206f98978ec730b17159344fd147cb4
- git.kernel.orghttps://git.kernel.org/stable/c/6ae7265a7b816879fd0203e83b5030d3720bbb7a
- git.kernel.orghttps://git.kernel.org/stable/c/818a257428644b8873e79c44404d8fb6598d4440
- git.kernel.orghttps://git.kernel.org/stable/c/82c94e6a7bd116724738aa67eba6f5fedf3a3319
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-547897.5 ALT—
———mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.6hCVE-2026-502786.5 MED—
———iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.7hCVE-2026-55894——
——0Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An application using CS_ARCH_SH with CS_MODE_SH2A or CS_MODE_SH4A and CS_MODE_SHFPU can pass crafted bytecode through cs_disasm_iter() or cs_disasm(), causing the decode[idx] test to read outside the table and terminate the process with a segmentation fault. No code execution or information disclosure was demonstrated. This issue is fixed in version 6.0.0-Alpha10.7hCVE-2026-187167.9 ALT—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.6hCVE-2026-174237.7 ALT—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.6hCVE-2026-171247.8 ALT—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds read.1d