CVE-2025-20796
published 2026-01-06CVE-2025-20796: In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.07%
0.1th percentile
In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10314745; Issue ID: MSV-5553.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 10.11.0 < 10.11.10 | 10.11.10 |
| android | — | — | |
| mediatek_inc | mediatek_chipset | — | — |
| mediatek_inc | mediatek_chipset | — | — |
| mediatek_inc | mediatek_chipset | — | — |
| msrc | cbl2_clamav_0.105.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_clamav_0.103.6-1_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_glibc_2.28-12_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost doesn't properly validate channel membership at the time of data retrieval
ghsa·2026-02-13
CVE-2026-20796 [LOW] CWE-367 Mattermost doesn't properly validate channel membership at the time of data retrieval
Mattermost doesn't properly validate channel membership at the time of data retrieval
Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549
GHSA
GHSA-gcc9-9787-r555: In imgsys, there is a possible out of bounds write due to improper input validation
ghsa_unreviewed·2026-01-06
CVE-2025-20796 [HIGH] CWE-1285 GHSA-gcc9-9787-r555: In imgsys, there is a possible out of bounds write due to improper input validation
In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10314745; Issue ID: MSV-5553.
Microsoft
ClamAV Truncated File Denial of Service Vulnerability Affecting Cisco Products: April 2022
vendor_msrc·2022-05-10·CVSS 5.5
CVE-2022-20796 [MEDIUM] CWE-476 ClamAV Truncated File Denial of Service Vulnerability Affecting Cisco Products: April 2022
ClamAV Truncated File Denial of Service Vulnerability Affecting Cisco Products: April 2022
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
cisco: cisco
Customer Action Required: Yes
Remediation: CBL-Mariner
Microsoft
In the GNU C Library (aka glibc or libc6) through 2.29 check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
vendor_msrc·2019-02-12·CVSS 7.5
CVE-2018-20796 [HIGH] CWE-674 In the GNU C Library (aka glibc or libc6) through 2.29 check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
In the GNU C Library (aka glibc or libc6) through 2.29 check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflec
No detection rules found.
No public exploits indexed.
2026-01-06
Published