Skip to main content

Threats Tagged 'cve-2026-72098'

View all threats tagged with 'cve-2026-72098'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-72098

Threats Tagged 'cve-2026-72098'

Click on any threat for detailed analysis and mitigation recommendations

0

Red Hat has issued a security advisory for multiple vulnerabilities in the Linux kernel packages used in Red Hat Enterprise Linux 8 and related products. The update addresses a range of issues including integer overflow, use-after-free, buffer overflow, and other memory corruption vulnerabilities across various kernel subsystems such as EDAC/bluefield, Wi-Fi drivers, KVM, networking, blk-cgroup, SCSI, and dm-verity. These vulnerabilities have been assigned CVE identifiers and are rated with a security impact of Important by Red Hat. The advisory recommends applying the update and rebooting the system to mitigate these issues.

Join the discussion
0

Red Hat has issued a security advisory for the kernel-rt packages, which provide the Real Time Linux Kernel for systems requiring high determinism. The update addresses multiple vulnerabilities including integer overflow, use-after-free, buffer overflow, and other memory safety issues across various kernel subsystems such as EDAC/bluefield, wifi mac80211, KVM nSVM, net qrtr, blk-cgroup, scsi, dm-verity, and others. These vulnerabilities have been assigned CVEs ranging from 2024 to 2026. The advisory rates the update as important and recommends applying the update and rebooting the system to ensure the fixes take effect.

Join the discussion

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133) * kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339) * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493) * kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015) * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149) * kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266) * kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306) * kernel: Revert "net/smc: Introduce TCP ULP support" (CVE-2026-46330) * kernel: netfilter: conntrack: remove sprintf usage (CVE-2026-53002) * kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223) * kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275) * kernel: ipv4: account for fraggap on the paged allocation path (CVE-2026-53366) * kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CVE-2026-64034) * kernel: rhashtable: clear stale iter->p on table restart (CVE-2026-64563) * kernel: smb: client: fix double-free in SMB2_close() replay (CVE-2026-64597) * kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129) * kernel: net: bridge: stop fast-leave after deleting a port group (CVE-2026-74480) Bug Fix(es) and Enhancement(s): * KSM to deduplicate only zero pages [rhel-9.8.z] (JIRA:RHEL-249161) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the post-increment pushes it past roots). This value is then passed as no_eras to decode_rs8(). Inside the RS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator polynomial loop writes lambda[j] where j can reach nroots + 1 — one element past the end of lambda[] (which is sized nroots + 1, valid indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting the syndrome buffer.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-2026-72098
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses