Skip to main content

Threats Tagged 'cve-2026-52976'

View all threats tagged with 'cve-2026-52976'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-52976

Threats Tagged 'cve-2026-52976'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.10. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:54768 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ Security Fix(es): * kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518) * samba: Missing access check on reparse point operations (CVE-2026-1933) * sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474) * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) * rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot. (CVE-2026-29518) * unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292) * vim: Vim: Arbitrary Code Execution via crafted directory names (CVE-2026-47162) * vim: Vim: Arbitrary code execution via crafted step-definition patterns (CVE-2026-47167) * vim: Vim: Arbitrary code execution via Python omni-completion (CVE-2026-52858) * acl: Symlink traversal privilege escalation via libacl functions (CVE-2026-54369) * vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) * openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002) * kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026) * libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() (CVE-2026-14164) * sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476) * unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622) * vim: Vim: Out-of-bounds Write in Spell File Word Count (CVE-2026-55693) * vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) * vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion (CVE-2026-59856) * vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion (CVE-2026-59858) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: crypto: seqiv - Do not use req->iv after crypto_aead_encrypt (CVE-2025-71131) * kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054) * kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976) Bug Fix(es) and Enhancement(s): * RHEL9.4 - dasd: Fix PPRC copy pair swap state and format information. [rhel-9.6.z] (JIRA:RHEL-176469) * [xfstests xfs/017] xfs_repair fails and hit XFS: Assertion failed: 0, file: fs/xfs/xfs_icache.c, line: 1840 [rhel-9.6.z] (JIRA:RHEL-188771) * nfs: backport patch which checks delegation validity in nfs_start_delegation_return_locked to RHEL 9 [rhel-9.6.z] (JIRA:RHEL-212042) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113) * kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147) * kernel: flex_proportions: make fprop_new_period() hardirq safe (CVE-2026-23168) * kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530) * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116) * kernel: fanotify: fix false positive on permission events (CVE-2026-46150) * kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215) * kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976) * kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950) * kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009) * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071) * kernel: can: bcm: thrtimer use-after-free during RX operation teardown () Bug Fix(es) and Enhancement(s): * nfsd_file slab cache objects remaining on kmem_cache_shutdown during nfsd teardown while running bz1477872 testcase (JIRA:RHEL-173103) * tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [rhel-10.2.z] (JIRA:RHEL-183975) * [RHEL10-debug]: BUG: KASAN: slab-use-after-free in __pv_queued_spin_lock_slowpath [rhel-10.2.z] (JIRA:RHEL-186311) * ice: driver update 2026-06, part 1 [rhel-10.2.z] (JIRA:RHEL-191324) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116) * kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984) * kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990) * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852) * kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116) * kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984) * kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990) * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852) * kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() Two error handling issues exist in xe_exec_queue_create_ioctl(): 1. When xe_hw_engine_group_add_exec_queue() fails, the error path jumps to put_exec_queue which skips xe_exec_queue_kill(). If the VM is in preempt fence mode, xe_vm_add_compute_exec_queue() has already added the queue to the VM's compute exec queue list. Skipping the kill leaves the queue on that list, leading to a dangling pointer after the queue is freed. 2. When xa_alloc() fails after xe_hw_engine_group_add_exec_queue() has succeeded, the error path does not call xe_hw_engine_group_del_exec_queue() to remove the queue from the hw engine group list. The queue is then freed while still linked into the hw engine group, causing a use-after-free. Fix both by: - Changing the xe_hw_engine_group_add_exec_queue() failure path to jump to kill_exec_queue so that xe_exec_queue_kill() properly removes the queue from the VM's compute list. - Adding a del_hw_engine_group label before kill_exec_queue for the xa_alloc() failure path, which removes the queue from the hw engine group before proceeding with the rest of the cleanup. (cherry picked from commit 37c831f401746a45d510b312b0ed7a77b1e06ec8)

Join the discussion

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cve-2026-52976
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses