CVE-2026-0137
published 2026-06-16CVE-2026-0137: In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local…
PriorityP427medium5.8
EPSS
0.07%
0.1th percentile
In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| msrc | azl3_vim_9.2.0088-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_vim_9.2.0088-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
cisa5.8MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android edgetpu-dmabuf.c edgetpu_sync_fence_group_shutdown use after free
vuldb·2026-06-16
CVE-2026-0137 [CRITICAL] Google Android edgetpu-dmabuf.c edgetpu_sync_fence_group_shutdown use after free
A vulnerability categorized as critical has been discovered in Google Android. Impacted is the function edgetpu_sync_fence_group_shutdown of the file edgetpu-dmabuf.c. The manipulation results in use after free.
This vulnerability is reported as CVE-2026-0137. The attack requires a local approach. No exploit exists.
GHSA
In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free.
ghsa_unreviewed·2026-06-16
CVE-2026-0137 [HIGH] CWE-416 In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free.
In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CISA
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
cisa·2026-06-09·CVSS 5.8
CVE-2026-7473 [MEDIUM] CWE-1023 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Vulnerability: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Affected: Arista Extensible Operating System
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137 ; https://nvd.nist.gov/vuln/detail/CVE-2026-7473
Remediation Due Date: 2026-06-23
Red Hat
vim: NFA regex engine NULL pointer dereference
vendor_redhat·2026-03-12·CVSS 5.3
CVE-2026-32249 [MEDIUM] CWE-476 vim: NFA regex engine NULL pointer dereference
vim: NFA regex engine NULL pointer dereference
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits the composing bytes of that character as separate NFA states. This corrupts the NFA postfix stack, resulting in NFA_START_COLL having a NULL out1 pointer. When nfa_max_width() subsequently traverses the compiled NFA to estimate match width for the look-behind assertion, it dereferences state->out1->out without a NULL check, causing a segmentation fault. This vulnerability is fixed in 9.2.0137.
A flaw was found in Vim. A NULL pointer dereference can occur when the NFA regex compiler processes a spec
Microsoft
NFA regex engine NULL pointer dereference affects Vim < 9.2.0137
vendor_msrc·2026-03-10·CVSS 5.3
CVE-2026-32249 [MEDIUM] CWE-476 NFA regex engine NULL pointer dereference affects Vim < 9.2.0137
NFA regex engine NULL pointer dereference affects Vim < 9.2.0137
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
No detection rules found.
No public exploits indexed.
2026-06-16
Published