CVE-2026-22050
published 2026-01-12CVE-2026-22050: ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.19%
8.6th percentile
ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netapp | ontap | — | — |
| netapp | ontap | — | — |
| netapp | ontap_9 | >= 9.16.1 < 9.16.1P9 | 9.16.1P9 |
| netapp | ontap_9 | >= 9.17.1 < 9.17.1P2 | 9.17.1P2 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxc4-9x7v-pg3w: ONTAP versions 9
ghsa_unreviewed·2026-01-12
CVE-2026-22050 [MEDIUM] CWE-639 GHSA-hxc4-9x7v-pg3w: ONTAP versions 9
ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none.
Red Hat
kernel: ALSA: usb-audio: Prevent excessive number of frames
vendor_redhat·2026-02-14·CVSS 7.8
CVE-2026-23208 [HIGH] CWE-805 kernel: ALSA: usb-audio: Prevent excessive number of frames
kernel: ALSA: usb-audio: Prevent excessive number of frames
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Prevent excessive number of frames
In this case, the user constructed the parameters with maxpacksize 40
for rate 22050 / pps 1000, and packsize[0] 22 packsize[1] 23. The buffer
size for each data URB is maxpacksize * packets, which in this example
is 40 * 6 = 240; When the user performs a write operation to send audio
data into the ALSA PCM playback stream, the calculated number of frames
is packsize[0] * packets = 264, which exceeds the allocated URB buffer
size, triggering the out-of-bounds (OOB) issue reported by syzbot [1].
Added a check for the number of single data URB frames when calculating
the number of frames to prevent [1].
[1]
BUG: K
No detection rules found.
No public exploits indexed.
2026-01-12
Published