CVE-2024-56557
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer The AD7
CVSS
7.8
Alto
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Publicado: 27 dic 2024 · Última mod.: 4 ago 2026 · CWE-120
0.2%EPSS · 30 días0.2%
2026-07-312026-08-28
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer The AD7923 was updated to support devices with 8 channels, but the size of tx_buf and ring_xfer was not increased accordingly, leading to a potential buffer overflow in ad7923_update_scan_mode().
- git.kernel.orghttps://git.kernel.org/stable/c/00663d3e000c31d0d49ef86a809f5c107c2d09cd
- git.kernel.orghttps://git.kernel.org/stable/c/218ecc35949129171ca39bcc0d407c8dc4cd0bbc
- git.kernel.orghttps://git.kernel.org/stable/c/3a4187ec454e19903fd15f6e1825a4b84e59a4cd
- git.kernel.orghttps://git.kernel.org/stable/c/6e4d236d9c4b38571c394d3ab6e85dfb71c33ed3
- git.kernel.orghttps://git.kernel.org/stable/c/e5cac32721997cb8bcb208a29f4598b3faf46338
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-823436.1 MED—
——0A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents.21hCVE-2026-751247.5 ALT—
——0PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parse_query_string to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an oversized GET request to dispatcher.cgi to cause denial of service of the web management interface and potentially trigger memory corruption.20hCVE-2026-801867.6 ALT33.6%
——10A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.21hCVE-2026-647055.5 MED1.7%
——1A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able to cause unexpected system termination or write kernel memory.2dCVE-2026-713997.8 ALT9.7%
——3Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.2dCVE-2026-783226.5 MED20.3%
——6A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.21h