A vulnerability labeled as critical has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper neutralization of special elements used in a template engine.
This vulnerability is referenced as CVE-2026-9498. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2. Affected by this vulnerability is the function smu_sys_set_pp_table. This manipulation causes buffer overflow.
This vulnerability is handled as CVE-2025-21780. The attack can only be done within the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.15/6.13.3/6.14-rc2. It has been rated as critical. Impacted is an unknown function of the component tracing. The manipulation of the argument mmap leads to memory corruption.
This vulnerability is documented as CVE-2025-21778. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2. This issue affects some unknown processing of the component Hypercall Page Handler. Such manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2025-21779. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2. This affects the function usb_hub_to_struct_hub. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2025-21776. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.