CVE-2026-31409
published 2026-04-06CVE-2026-31409: In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESSION_SETUP…
PriorityP347high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.45%
36.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: unset conn->binding on failed binding request
When a multichannel SMB2_SESSION_SETUP request with
SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true
but never clears it on the error path. This leaves the connection in
a binding state where all subsequent ksmbd_session_lookup_all() calls
fall back to the global sessions table. This fix it by clearing
conn->binding = false in the error path.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.10-1 (forky) | linux 6.19.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 7e8b270813079c785696bce8802a3f920665c88c | 7e8b270813079c785696bce8802a3f920665c88c |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < d073870dab8f6dadced81d13d273ff0b21cb7f4e | d073870dab8f6dadced81d13d273ff0b21cb7f4e |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 6ebef4a220a1ebe345de899ebb9ae394206fe921 | 6ebef4a220a1ebe345de899ebb9ae394206fe921 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 89afe5e2dbea6e9d8e5f11324149d06fa3a4efca | 89afe5e2dbea6e9d8e5f11324149d06fa3a4efca |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 9feb2d1bf86d9e5e66b8565f37f8d3a7d281a772 | 9feb2d1bf86d9e5e66b8565f37f8d3a7d281a772 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 6260fc85ed1298a71d24a75d01f8b2e56d489a60 | 6260fc85ed1298a71d24a75d01f8b2e56d489a60 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 282343cf8a4a5a3603b1cb0e17a7083e4a593b03 | 282343cf8a4a5a3603b1cb0e17a7083e4a593b03 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.10-1 | 6.19.10-1 |
| linux | linux_kernel | >= 5.15 < 6.1.167 | 6.1.167 |
| linux | linux_kernel | >= 6.13 < 6.18.20 | 6.18.20 |
| linux | linux_kernel | >= 6.19 < 6.19.10 | 6.19.10 |
| linux | linux_kernel | >= 6.2 < 6.6.130 | 6.6.130 |
| linux | linux_kernel | >= 6.7 < 6.12.78 | 6.12.78 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ksmbd: unset conn->binding on failed binding request
vendor_redhat·2026-04-06
CVE-2026-31409 CWE-390 kernel: ksmbd: unset conn->binding on failed binding request
kernel: ksmbd: unset conn->binding on failed binding request
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: unset conn->binding on failed binding request
When a multichannel SMB2_SESSION_SETUP request with
SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true
but never clears it on the error path. This leaves the connection in
a binding state where all subsequent ksmbd_session_lookup_all() calls
fall back to the global sessions table. This fix it by clearing
conn->binding = false in the error path.
A flaw was found in ksmbd, a component of the Linux kernel. This vulnerability occurs when a multichannel Server Message Block (SMB2) session setup request, specifically one with a binding flag, fails. Due to an error in handling this failure, ksmbd in
Debian
CVE-2026-31409: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: unse...
vendor_debian·2026
CVE-2026-31409 CVE-2026-31409: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: unse...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESSION_SETUP request with SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true but never clears it on the error path. This leaves the connection in a binding state where all subsequent ksmbd_session_lookup_all() calls fall back to the global sessions table. This fix it by clearing conn->binding = false in the error path.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.19.10-1)
sid: resolved (fixed in 6.19.10-1)
trixie: open
GHSA
GHSA-5qj3-gjq7-62fm: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: unset conn->binding on failed binding request
When a multichannel SMB2_SE
ghsa_unreviewed·2026-04-06
CVE-2026-31409 GHSA-5qj3-gjq7-62fm: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: unset conn->binding on failed binding request
When a multichannel SMB2_SE
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: unset conn->binding on failed binding request
When a multichannel SMB2_SESSION_SETUP request with
SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true
but never clears it on the error path. This leaves the connection in
a binding state where all subsequent ksmbd_session_lookup_all() calls
fall back to the global sessions table. This fix it by clearing
conn->binding = false in the error path.
OSV
CVE-2026-31409: In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESS
osv·2026-04-06
CVE-2026-31409 CVE-2026-31409: In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESS
In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESSION_SETUP request with SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true but never clears it on the error path. This leaves the connection in a binding state where all subsequent ksmbd_session_lookup_all() calls fall back to the global sessions table. This fix it by clearing conn->binding = false in the error path.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-33220 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-33220 [HIGH] CVE-2025-33220 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33220 :
Linux Ubuntu vulnerability analysis and mitigation
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the memory is freed. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
Source : NVD
## 7.8
Score
Published January 28, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
nvidia-graphics-drivers-580
nvidia-graphics-drivers-580-server
So
Wiz
CVE-2023-54203 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54203 CVE-2023-54203 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54203 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr
When smb1 mount fails, KASAN detect slab-out-of-bounds in
init_smb2_rsp_hdr like the following one.
For smb1 negotiate(56bytes) , init_smb2_rsp_hdr() for smb2 is called.
The issue occurs while handling smb1 negotiate as smb2 server operations.
Add smb server operations for smb1 (get_cmd_val, init_rsp_hdr,
allocate_rsp_buf, check_user_session) to handle smb1 negotiate so that
smb2 server operation does not handle it.
[ 411.400423] CIFS: VFS: Use of the less secure dialect vers=1.0 is
not recommended unless required for access to very old servers
[ 411.400452] CIFS: Attempting to mount \192.168.45.13
Wiz
CVE-2017-20229 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2017-20229 [CRITICAL] CVE-2017-20229 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2017-20229 :
Linux Ubuntu vulnerability analysis and mitigation
MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges.
Source : NVD
## 9.3
Score
Published March 28, 2026
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Linux Ubuntu
Echo
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
mawk
Sources
NVD
Ec
Wiz
CVE-2026-3856 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-3856 [MEDIUM] CVE-2026-3856 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3856 :
Linux Ubuntu vulnerability analysis and mitigation
IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.
Source : NVD
## 9.1
Score
Published March 17, 2026
Severity CRITICAL
CNA Score 5.3
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
NVD
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Mar 19, 2026
## Get a CVE risk assessment
Get a prioritized view
Wiz
CVE-2025-68350 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2025-68350 CVE-2025-68350 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68350 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
exfat: fix divide-by-zero in exfat_allocate_bitmap
The variable max_ra_count can be 0 in exfat_allocate_bitmap(),
which causes a divide-by-zero error in the subsequent modulo operation
(i % max_ra_count), leading to a system crash.
When max_ra_count is 0, it means that readahead is not used. This patch
load the bitmap without readahead.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-
Wiz
CVE-2025-13350 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2025-13350 [HIGH] CVE-2025-13350 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13350 :
Linux Ubuntu vulnerability analysis and mitigation
Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two references; on Ubuntu Linux 6.8 (Noble Numbat) kernel tree, they have only the queue reference, so the buffer is freed while still reachable and subsequent queue walks dereference freed memory, yielding a reliable local privilege escalation (LPE) caused by a use-after-free (UAF). Ubuntu builds that have already taken the new GC stack from commit 4090fa373f0e, and mainline Linux kernels shipping that infrastructure are unaffected because they no longer e
Wiz
CVE-2025-68377 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2025-68377 CVE-2025-68377 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68377 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ns: initialize ns_list_node for initial namespaces
Make sure that the list is always initialized for initial namespaces.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
NVD
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Dec 26, 2025
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what'
Wiz
CVE-2023-54217 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54217 CVE-2023-54217 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54217 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
Revert "drm/msm: Add missing check and destroy for alloc_ordered_workqueue"
This reverts commit 643b7d0869cc7f1f7a5ac7ca6bd25d88f54e31d0.
A recent patch that tried to fix up the msm_drm_init() paths with
respect to the workqueue but only ended up making things worse:
First, the newly added calls to msm_drm_uninit() on early errors would
trigger NULL-pointer dereferences, for example, as the kms pointer would
not have been initialised. (Note that these paths were also modified by
a second broken error handling patch which in effect cancelled out this
part when merged.)
Second, the newly added allocation sanity check would still leak the
previously
Wiz
CVE-2026-33191 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-33191 [HIGH] CVE-2026-33191 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33191 :
Linux Ubuntu vulnerability analysis and mitigation
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2
are vulnerable to null byte injection in URL path parameters. A remote attacker can inject null bytes (URL-encoded as %00) into the supi path parameter of the UDM's Nudm_SubscriberDataManagement API. This causes URL parsing failure in Go's net/url package with the error "invalid control character in URL", resulting in a 500 Internal Server Error. This null byte injection vulnerability can be exploited for denial of service attacks. When the supi parameter contains null characters, the UDM attempts to construct a URL for UDR that includes these control characters. Go's URL parser rejects them, causin
Wiz
CVE-2025-68248 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2025-68248 CVE-2025-68248 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68248 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
vmw_balloon: indicate success when effectively deflating during migration
When migrating a balloon page, we first deflate the old page to then
inflate the new page.
However, if inflating the new page succeeded, we effectively deflated the
old page, reducing the balloon size.
In that case, the migration actually worked: similar to migrating+
immediately deflating the new page. The old page will be freed back to
the buddy.
Right now, the core will leave the page be marked as isolated (as we
returned an error). When later trying to putback that page, we will run
into the WARN_ON_ONCE() in balloon_page_putback().
That handling was changed in commit
Wiz
CVE-2025-68761 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2025-68761 CVE-2025-68761 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68761 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
hfs: fix potential use after free in hfs_correct_next_unused_CNID()
This code calls hfs_bnode_put(node) which drops the refcount and then
dreferences "node" on the next line. It's only safe to use "node"
when we're holding a reference so flip these two lines around.
Source : NVD
Published January 5, 2026
CNA Score N/A
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
NVD
Ubuntu 16.04, 18.04, 20.04 Sever
Wiz
CVE-2023-54075 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54075 CVE-2023-54075 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54075 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ASoC: mediatek: common: Fix refcount leak in parse_dai_link_info
Add missing of_node_put()s before the returns to balance
of_node_get()s and of_node_put()s, which may get unbalanced
in case the for loop 'for_each_available_child_of_node' returns
early.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
NVD
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM N
Wiz
CVE-2026-33065 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-33065 [MEDIUM] CVE-2026-33065 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33065 :
Linux Ubuntu vulnerability analysis and mitigation
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling DELETE requests with an empty supi path parameter. This leaks internal error handling behavior and makes it difficult for clients to distinguish between client-side errors and server-side failures. When a client sends a DELETE request with an empty supi (e.g., double slashes // in URL path), the UDM forwards the malformed request to UDR, which correctly returns 400. However, UDM propagates this as 500 SYSTEM_FAILURE instead of returning the appropriate 400 error to the client. This
Wiz
CVE-2025-71103 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2025-71103 [MEDIUM] CVE-2025-71103 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-71103 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: adreno: fix deferencing ifpc_reglist when not declared
On plaforms with an a7xx GPU not supporting IFPC, the ifpc_reglist
if still deferenced in a7xx_patch_pwrup_reglist() which causes
a kernel crash:
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008
...
pc : a6xx_hw_init+0x155c/0x1e4c [msm]
lr : a6xx_hw_init+0x9a8/0x1e4c [msm]
...
Call trace:
a6xx_hw_init+0x155c/0x1e4c [msm] (P)
msm_gpu_hw_init+0x58/0x88 [msm]
adreno_load_gpu+0x94/0x1fc [msm]
msm_open+0xe4/0xf4 [msm]
drm_file_alloc+0x1a0/0x2e4 [drm]
drm_client_init+0x7c/0x104 [drm]
drm_fbdev_client_setup+0x94/0xcf0 [drm_client_lib]
drm_client_setup+0xb4/0
Wiz
CVE-2026-31409 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-31409 [MEDIUM] CVE-2026-31409 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-31409 :
Linux Debian vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: unset conn->binding on failed binding request
When a multichannel SMB2_SESSION_SETUP request with
SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true
but never clears it on the error path. This leaves the connection in
a binding state where all subsequent ksmbd_session_lookup_all() calls
fall back to the global sessions table. This fix it by clearing
conn->binding = false in the error path.
Source : NVD
Published April 6, 2026
CNA Score N/A
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile
Wiz
CVE-2025-71110 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-71110 [HIGH] CVE-2025-71110 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-71110 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
mm/slub: reset KASAN tag in defer_free() before accessing freed memory
When CONFIG_SLUB_TINY is enabled, kfree_nolock() calls kasan_slab_free()
before defer_free(). On ARM64 with MTE (Memory Tagging Extension),
kasan_slab_free() poisons the memory and changes the tag from the
original (e.g., 0xf3) to a poison tag (0xfe).
When defer_free() then tries to write to the freed object to build the
deferred free list via llist_add(), the pointer still has the old tag,
causing a tag mismatch and triggering a KASAN use-after-free report:
BUG: KASAN: slab-use-after-free in defer_free+0x3c/0xbc mm/slub.c:6537
Write at addr f3f000000854f020 by task kworker/u8:
Wiz
CVE-2025-68355 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2025-68355 CVE-2025-68355 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68355 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix exclusive map memory leak
When excl_prog_hash is 0 and excl_prog_hash_size is non-zero, the map also
needs to be freed. Otherwise, the map memory will not be reclaimed, just
like the memory leak problem reported by syzbot [1].
syzbot reported:
BUG: memory leak
backtrace (crc 7b9fb9b4):
map_create+0x322/0x11e0 kernel/bpf/syscall.c:1512
__sys_bpf+0x3556/0x3610 kernel/bpf/syscall.c:6131
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Proba
Wiz
CVE-2020-37011 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2020-37011 [HIGH] CVE-2020-37011 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2020-37011 :
Linux Ubuntu vulnerability analysis and mitigation
Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to cause an infinite malloc() loop and potentially crash the gnome-font-viewer process.
Source : NVD
## 8.4
Score
Published January 29, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
Linux Ubuntu
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
gnome-font-viewer
Sources
NVD
Echo S
Wiz
CVE-2026-33064 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-33064 [HIGH] CVE-2026-33064 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33064 :
Linux Ubuntu vulnerability analysis and mitigation
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure panic caused by Nil Pointer Dereference in the /sdm-subscriptions endpoint. A remote attacker can cause the UDM service to panic and crash by sending a crafted POST request to the /sdm-subscriptions endpoint with a malformed URL path containing path traversal sequences (../) and a large JSON payload. The DataChangeNotificationProcedure function in notifier.go attempts to access a nil pointer without proper validation, causing a complete service crash with "runtime error: invalid memory address or nil pointer dereference". Exploitation would result in UDM functionality dis
Wiz
CVE-2026-33192 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-33192 [HIGH] CVE-2026-33192 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33192 :
Linux Ubuntu vulnerability analysis and mitigation
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling PATCH requests with an empty supi path parameter. Additionally, the UDM incorrectly translates the PATCH method to PUT when forwarding to UDR, indicating a deeper architectural issue. This leaks internal error handling behavior, making it difficult for clients to distinguish between client-side errors and server-side failures. The issue has been patched in version 1.4.2.
Source : NVD
## 8.7
Score
Published March 20, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
L
Wiz
CVE-2026-1788 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.6
CVE-2026-1788 [MEDIUM] CVE-2026-1788 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1788 :
Linux Ubuntu vulnerability analysis and mitigation
: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet processing module modules) allows : Buffer Manipulation.This issue affects Xquic Server: through 1.8.3.
Source : NVD
## 6.6
Score
Published February 3, 2026
Severity MEDIUM
CNA Score 6.6
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
NVD
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 04, 2026
## Get a CVE risk assessment
Get a
Wiz
CVE-2023-54231 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54231 CVE-2023-54231 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54231 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
net: libwx: fix memory leak in wx_setup_rx_resources
When wx_alloc_page_pool() failed in wx_setup_rx_resources(), it doesn't
release DMA buffer. Add dma_free_coherent() in the error path to release
the DMA buffer.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
NVD
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Jan 02, 2026
## Get a
Wiz
CVE-2025-68731 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2025-68731 CVE-2025-68731 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68731 :
Linux Ubuntu vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
accel/amdxdna: Fix an integer overflow in aie2_query_ctx_status_array()
The unpublished smatch static checker reported a warning.
drivers/accel/amdxdna/aie2_pci.c:904 aie2_query_ctx_status_array()
warn: potential user controlled sizeof overflow
'args->num_element * args->element_size' '1-u32max(user) * 1-u32max(user)'
Even this will not cause a real issue, it is better to put a reasonable
limitation for element_size and num_element. Add condition to make sure
the input element_size <= 4K and num_element <= 1K.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit
Bugzilla
CVE-2026-31409 kernel: ksmbd: unset conn->binding on failed binding request
bugzilla·2026-04-06
CVE-2026-31409 CVE-2026-31409 kernel: ksmbd: unset conn->binding on failed binding request
CVE-2026-31409 kernel: ksmbd: unset conn->binding on failed binding request
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: unset conn->binding on failed binding request
When a multichannel SMB2_SESSION_SETUP request with
SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true
but never clears it on the error path. This leaves the connection in
a binding state where all subsequent ksmbd_session_lookup_all() calls
fall back to the global sessions table. This fix it by clearing
conn->binding = false in the error path.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026040629-CVE-2026-31409-d22c@gregkh/T
https://git.kernel.org/stable/c/282343cf8a4a5a3603b1cb0e17a7083e4a593b03https://git.kernel.org/stable/c/6260fc85ed1298a71d24a75d01f8b2e56d489a60https://git.kernel.org/stable/c/6ebef4a220a1ebe345de899ebb9ae394206fe921https://git.kernel.org/stable/c/7e8b270813079c785696bce8802a3f920665c88chttps://git.kernel.org/stable/c/89afe5e2dbea6e9d8e5f11324149d06fa3a4efcahttps://git.kernel.org/stable/c/9feb2d1bf86d9e5e66b8565f37f8d3a7d281a772https://git.kernel.org/stable/c/d073870dab8f6dadced81d13d273ff0b21cb7f4e
2026-04-06
Published