Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Advisory [CVE-2026-68124] handle zero-length frames to prevent rx buffer overflow
handle zero-length frames to prevent rx buffer overflow. Red Hat rates this a security issue. Weakness: CWE-787.
Advisory [CVE-2026-68213] Return queued buffers on start_streaming failure
Return queued buffers on start_streaming() failure. Red Hat rates this a security issue. Weakness: CWE-772.
Advisory [CVE-2026-68327] Only reset hardware after BAR mapping
Only reset hardware after BAR mapping. Red Hat rates this a security issue. Weakness: CWE-476.
Advisory [CVE-2026-68203] fix cleanup bugs in vivid_init
fix cleanup bugs in vivid_init(). Red Hat rates this a security issue. Weakness: CWE-772.
Advisory [CVE-2026-68285] Fix memory leak in bpf_jit_free
Fix memory leak in bpf_jit_free(). Red Hat rates this a security issue. Weakness: CWE-772.
Advisory [CVE-2026-68230] Add validations for ae and awb config
Add validations for ae and awb config. Red Hat rates this a security issue. Weakness: CWE-787.
Advisory [CVE-2026-68120] Workaround for TX hang caused by hardware packet parsing
Workaround for TX hang caused by hardware packet parsing. Red Hat rates this a security issue. Weakness: CWE-437.
Advisory [CVE-2026-68225] fix critical pointer access in alvium_ctrl_init
fix critical pointer access in alvium_ctrl_init. Red Hat rates this a security issue. Weakness: CWE-476.
Advisory [CVE-2026-68094] Preserve rq tracking across local DSQ dispatch
Preserve rq tracking across local DSQ dispatch. Red Hat rates this a security issue. Weakness: CWE-367.
Advisory [CVE-2026-68095] fix race between registration and connection abortion
fix race between registration and connection abortion. Red Hat rates this a security issue. Weakness: CWE-367.
Advisory [CVE-2026-68340] validate poll response sensor blocks
validate poll response sensor blocks. Red Hat rates this a security issue. Weakness: CWE-125.
Advisory [CVE-2026-68370] prevent fifo_req reuse during giveback
prevent fifo_req reuse during giveback. Red Hat rates this a security issue. Weakness: CWE-821.
Advisory [CVE-2026-68302] re-read skb header pointers after every pull
re-read skb header pointers after every pull. Red Hat rates this a security issue. Weakness: CWE-825.
Advisory [CVE-2026-68220] Add missing v4l2_subdev_cleanup in crossbar and pipe
Add missing v4l2_subdev_cleanup() in crossbar and pipe. Red Hat rates this a security issue. Weakness: CWE-772.
Advisory [CVE-2026-68314] mctp i3c: clean up notifier and buses if driver register fails
mctp i3c: clean up notifier and buses if driver register fails. Red Hat rates this a security issue. Weakness: CWE-772.
Advisory [CVE-2026-68223] Fix memory leak in error path of vdec_open
Fix memory leak in error path of vdec_open. Red Hat rates this a security issue. Weakness: CWE-772.
Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation
Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Critical [CVE-2026-71558] Heap type confusion vulnerability in Apache Fory C++ deserialization
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.
Critical [CVE-2026-71560] Out-of-bounds Read vulnerability in Apache Fory C++ deserialization
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
High [CVE-2026-48120] Remote Code Execution via malicious backup files
Remote Code Execution via malicious backup files. Red Hat rates this important (CVSS 8.6). Weakness: CWE-94.