A vulnerability has been found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc1 and classified as critical. This vulnerability affects the function hclgevf_knic_setup of the component Vf Driver. This manipulation causes uninitialized pointer.
This vulnerability is handled as CVE-2025-71064. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability classified as critical was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.3/6.19-rc3. This vulnerability affects the function xdp_convert_buff_to_frame. The manipulation results in denial of service.
This vulnerability is reported as CVE-2025-71095. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability has been found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.3/6.19-rc3 and classified as critical. Affected by this issue is the function fib_table_flush. This manipulation causes improper update of reference count.
This vulnerability appears as CVE-2025-71097. The attacker needs to be present on the local network. There is no available exploit.
The affected component should be upgraded.
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.3/6.19-rc3 and classified as critical. This affects the function ip6gre_header. Such manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2025-71098. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. It has been rated as critical. The affected element is the function parse_apply_sb_mount_options in the library string.h of the component ext4. Performing a manipulation of the argument s_mount_opts results in buffer overflow.
This vulnerability is identified as CVE-2025-71123. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. This vulnerability affects the function sock_kmalloc of the file algif_kpp.c. The manipulation leads to improper initialization.
This vulnerability is traded as CVE-2025-71113. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. This issue affects the function allocate_resource of the file /proc/iomem of the component VIA Watchdog Driver. The manipulation results in allocation of resources.
This vulnerability is known as CVE-2025-71114. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc2. The impacted element is the function svcauth_gss of the component SUNRPC. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2025-71120. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc1. It has been classified as critical. Affected is the function vlan_del_fail_bmap of the component net. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-71112. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.3/6.19-rc3. Impacted is the function crypto_aead_encrypt. Executing a manipulation can lead to null pointer dereference.
The identification of this vulnerability is CVE-2025-71131. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in TinyOS up to 2.1.2. Affected by this vulnerability is the function strcat. Executing a manipulation can lead to out-of-bounds write.
This vulnerability is registered as CVE-2026-22211. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in feast-dev feast and classified as problematic. The affected element is an unknown function of the component WebSocket Endpoint. The manipulation results in resource consumption.
This vulnerability is cataloged as CVE-2026-23538. The attack may be launched remotely. There is no exploit available.
A vulnerability identified as critical has been detected in QEMU. Affected by this vulnerability is the function cpu_physical_memory_map of the file hw/hyperv/syndbg.c of the component KVM. Performing a manipulation results in out-of-bounds write.
This vulnerability is reported as CVE-2026-3842. The attack may be carried out on the physical device. No exploit exists.
It is suggested to install a patch to address this issue.
A vulnerability identified as critical has been detected in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-15909. The attack is possible to be carried out remotely. No exploit exists.
This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability categorized as problematic has been discovered in Red Hat Keycloak. Impacted is an unknown function of the component JWT Authorization Grant Processing. Executing a manipulation can lead to improper authorization.
This vulnerability is registered as CVE-2026-1609. It is possible to launch the attack remotely. No exploit is available.
A vulnerability categorized as critical has been discovered in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection.
This vulnerability is handled as CVE-2026-15907. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. A technical fix is planned to be released.