CVE-2026-8086
published 2026-05-07CVE-2026-8086: A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such…
PriorityP348high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.6th percentile
A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argument DimensionName leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version 3.12.4RC1 is capable of addressing this issue. The name of the patch is 9491e794f1757f08063ea2f7a274ad2994afa636. It is advisable to upgrade the affected component.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| osgeo | gdal | <= 3.12.4 | — |
| osgeo | gdal | — | — |
| osgeo | gdal | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-72pg-5w29-wjx6: A vulnerability was identified in OSGeo gdal up to 3
ghsa_unreviewed·2026-05-07
CVE-2026-8086 [LOW] CWE-119 GHSA-72pg-5w29-wjx6: A vulnerability was identified in OSGeo gdal up to 3
A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argument DimensionName leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version 3.12.4RC1 is capable of addressing this issue. The name of the patch is 9491e794f1757f08063ea2f7a274ad2994afa636. It is advisable to upgrade the affected component.
Red Hat
kernel: Linux kernel (ice): Denial of Service via out-of-range ptype in VIRTCHNL
vendor_redhat·2026-08-10·CVSS 4.7
CVE-2026-68128 [HIGH] CWE-787 kernel: Linux kernel (ice): Denial of Service via out-of-range ptype in VIRTCHNL
kernel: Linux kernel (ice): Denial of Service via out-of-range ptype in VIRTCHNL
In the Linux kernel, the following vulnerability has been resolved:
ice: reject out-of-range ptype in ice_parser_profile_init
set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of
ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from
providing ptype >= 1024 through VIRTCHNL, resulting in a write past
the end of the bitmap and a kernel page fault.
Reproduced with a custom kernel module injecting a crafted
VIRTCHNL_OP_ADD_RSS_CFG on E810-C QSFP (8086:1592),
FW 4.91 0x800214af 1.3909.0, ICE COMMS DDP 1.3.53.0,
kernel 7.1.0-rc1.
crash_parser: ice_parser_profile_init @ ffffffffc0d61b60
crash_parser: setting ptype=0xffff (max valid=1023)
crash_parser: calling ice_parser_profile_init -- e
No detection rules found.
No public exploits indexed.
https://github.com/OSGeo/gdal/https://github.com/OSGeo/gdal/commit/9491e794f1757f08063ea2f7a274ad2994afa636https://github.com/OSGeo/gdal/issues/14356https://github.com/OSGeo/gdal/pull/14361https://github.com/OSGeo/gdal/releases/tag/v3.12.4RC1https://github.com/biniamf/pocs/tree/main/gdal-swinqdims_bofhttps://vuldb.com/submit/808038https://vuldb.com/vuln/361839https://vuldb.com/vuln/361839/ctihttps://github.com/OSGeo/gdal/issues/14356https://vuldb.com/submit/808038
2026-05-07
Published