Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-53322

vfio/pci: Clean up DMABUFs before disabling function_CVE-2026-53322

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling function On device shutdown, make...

Linux Linux 5d74781ebc86c5fa9e9d6934024c505412de9b52 CVE
CRITICAL 9.8 CVE-2026-53309

ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison_CVE-2026-53309

In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-...

Linux Linux ea2034416b54700e30371f2ad6517cbb94674083 CVE
HIGH 7.8 CVE-2026-53300

net: enetc: fix NTMP DMA use-after-free issue_CVE-2026-53300

In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix NTMP DMA use-after-free issue The AI-generated review reporte...

Linux Linux 4701073c3debd16d7f534f3eb808bd9b50601c0c CVE
HIGH 7.8 CVE-2026-53290

drm/xe/eustall: Fix drm_dev_put called before stream disable in close_CVE-2026-53290

In the Linux kernel, the following vulnerability has been resolved: drm/xe/eustall: Fix drm_dev_put called before stream disable in close In xe_e...

Linux Linux 9a0b11d4cf3b4324378c322b7043962e648681ed CVE
HIGH 7.5 CVE-2026-53284

btrfs: only release the dirty pages io tree after successful writes_CVE-2026-53284

In the Linux kernel, the following vulnerability has been resolved: btrfs: only release the dirty pages io tree after successful writes [WARNING]...

Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 CVE
HIGH 8.8 CVE-2026-53281

iommu/vt-d: Avoid NULL pointer dereference or refcount corruption_CVE-2026-53281

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit 60f0...

Linux Linux 60f030f7418d3f1d94f2fb207fe3080e1844630b CVE
LOW 2.3 CVE-2026-13483

arc53 DocsGPT Credential Storage encryption.py encrypt_credentials data authenticity_CVE-2026-13483

A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encr...

arc53 DocsGPT 0.1 CVE
MEDIUM 6.3 CVE-2026-13482

skypilot-org skypilot User ID server.py username.encode weak hash_CVE-2026-13482

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the...

skypilot-org skypilot 0.1 CVE
HIGH 7.4 CVE-2026-10646

Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation_CVE-2026-10646

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct...

zephyrproject zephyr 4.0.0 CVE
MEDIUM 4.2 CVE-2026-10644

Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer_CVE-2026-10644

The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains an out-of-bounds write in i...

zephyrproject zephyr 4.4.0 CVE