{
  "query": {
    "page": "27"
  },
  "count": 20,
  "total": 47281,
  "page": 27,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T20:46:13.413Z",
    "kev": "2026-10-06T20:45:13.270Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T20:46:13.412Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=27",
    "next": "https://spydr.io/threats.json?page=28"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-106016",
      "url": "https://spydr.io/cve/CVE-2026-106016",
      "published": "2026-10-06T13:16:47.290Z",
      "modified": "2026-10-06T16:00:36.547Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox"
      ],
      "cwes": [],
      "description": "Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1."
    },
    {
      "id": "CVE-2026-105919",
      "url": "https://spydr.io/cve/CVE-2026-105919",
      "published": "2026-10-06T13:16:47.120Z",
      "modified": "2026-10-06T18:16:50.443Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "Kusalkasilva"
      ],
      "products": [
        "Kusalkasilva Learning-Management-System"
      ],
      "cwes": [
        "CWE-74",
        "CWE-89"
      ],
      "description": "A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of the component Administrator Login Endpoint. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105836",
      "url": "https://spydr.io/cve/CVE-2026-105836",
      "published": "2026-10-06T13:16:46.913Z",
      "modified": "2026-10-06T13:16:47.037Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Webkul"
      ],
      "products": [
        "Webkul QloApps"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign room IDs in the id_rooms parameter to change status, floor, comments, or inactive dates, disrupting availability and bookings."
    },
    {
      "id": "CVE-2026-105835",
      "url": "https://spydr.io/cve/CVE-2026-105835",
      "published": "2026-10-06T13:16:46.760Z",
      "modified": "2026-10-06T16:08:43.180Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "planka"
      ],
      "products": [
        "planka"
      ],
      "cwes": [
        "CWE-307"
      ],
      "description": "PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full access token."
    },
    {
      "id": "CVE-2026-105834",
      "url": "https://spydr.io/cve/CVE-2026-105834",
      "published": "2026-10-06T13:16:46.597Z",
      "modified": "2026-10-06T17:17:19.303Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "rundeck"
      ],
      "products": [
        "rundeck"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data."
    },
    {
      "id": "CVE-2026-56596",
      "url": "https://spydr.io/cve/CVE-2026-56596",
      "published": "2026-10-06T12:16:49.327Z",
      "modified": "2026-10-06T16:00:36.547Z",
      "score": 3.5,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "hcl.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "HCL Software"
      ],
      "products": [
        "HCL Software HCL BigFix Service Management"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to supply unexpected or malformed data, enabling processing errors, business logic bypasses, and unintended application behavior."
    },
    {
      "id": "CVE-2026-105918",
      "url": "https://spydr.io/cve/CVE-2026-105918",
      "published": "2026-10-06T12:16:47.287Z",
      "modified": "2026-10-06T18:16:50.310Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "Kusalkasilva"
      ],
      "products": [
        "Kusalkasilva Learning-Management-System"
      ],
      "cwes": [
        "CWE-74",
        "CWE-89"
      ],
      "description": "A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-75820",
      "url": "https://spydr.io/cve/CVE-2026-75820",
      "published": "2026-10-06T11:17:30.020Z",
      "modified": "2026-10-06T15:03:59.427Z",
      "score": 1.8,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "cert.pl",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "GNU"
      ],
      "products": [
        "GNU Aspell"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service. This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3."
    },
    {
      "id": "CVE-2026-75819",
      "url": "https://spydr.io/cve/CVE-2026-75819",
      "published": "2026-10-06T11:17:29.883Z",
      "modified": "2026-10-06T15:03:59.427Z",
      "score": 1.8,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "cert.pl",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "GNU"
      ],
      "products": [
        "GNU Aspell"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "GNU Aspell contains an out-of-bounds read vulnerability in ReadOnlyDict::load() in readonly_ws.cpp. When loading a binary .rws dictionary file, it uses offset fields from the file header as byte indices into a heap buffer without validating their bounds. An attacker can trigger this by convincing a user to run aspell with a crafted dictionary file supplied through --master, --dict-dir, or configuration options, leading to heap memory disclosure or a denial of service via application crash. This issue was fixed in commit 941953b25031bc9104e83f58e138a664b8dedc3f which will be released in version 0.60.8.3."
    },
    {
      "id": "CVE-2026-75818",
      "url": "https://spydr.io/cve/CVE-2026-75818",
      "published": "2026-10-06T11:17:29.730Z",
      "modified": "2026-10-06T15:03:59.427Z",
      "score": 1.8,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "cert.pl",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "GNU"
      ],
      "products": [
        "GNU Aspell"
      ],
      "cwes": [
        "CWE-122"
      ],
      "description": "GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in prog/prezip.c. The decompressor does not properly check buffer space, so a crafted compressed file can cause out-of-bounds read and write operations on the heap. An attacker who convinces a user to process a malicious compressed file with prezip-bin can trigger memory corruption, leading to a processs crash. This issue was fixed in commit 15b188437f9e0192d4ac4472ad66a4e2f62a782f which will be released in version 0.60.8.3."
    },
    {
      "id": "CVE-2026-105985",
      "url": "https://spydr.io/cve/CVE-2026-105985",
      "published": "2026-10-06T11:17:16.857Z",
      "modified": "2026-10-06T15:18:12.170Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "craftcms"
      ],
      "products": [
        "craftcms cms"
      ],
      "cwes": [
        "CWE-1336"
      ],
      "description": "Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required."
    },
    {
      "id": "CVE-2026-103831",
      "url": "https://spydr.io/cve/CVE-2026-103831",
      "published": "2026-10-06T11:17:13.783Z",
      "modified": "2026-10-06T15:18:12.170Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "incibe.es",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "TrueLayer"
      ],
      "products": [
        "TrueLayer Magento 2 Plugin"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin, due to the use of PHP's native unserialize() function without restrictions on the classes allowed when retrieving data stored in the cache. An attacker who already has the ability to write manipulated data to the cache backend used by Magento—such as Redis or Memcached—could inject specially crafted PHP objects and trigger their deserialization, potentially leading to arbitrary code execution via gadget strings available in the application environment. Exploitation therefore requires a prerequisite condition that allows writing to the cache infrastructure, either through access to the local file system or to a cache infrastructure accessible from the Magento environment."
    },
    {
      "id": "CVE-2026-84854",
      "url": "https://spydr.io/cve/CVE-2026-84854",
      "published": "2026-10-06T10:16:54.230Z",
      "modified": "2026-10-06T16:08:43.180Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "wibu-systems-ag"
      ],
      "products": [
        "wibu-systems-ag wibukey"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In the WibuKey driver for Windows below Version 6.72, insufficient validation of user input when calculating the size of a kernel buffer could cause small amounts of data to be written outside the intended kernel buffer. This can lead to a system crash. Under unfavorable circumstances, adjacent kernel memory may be modified."
    },
    {
      "id": "CVE-2026-80327",
      "url": "https://spydr.io/cve/CVE-2026-80327",
      "published": "2026-10-06T10:16:52.117Z",
      "modified": "2026-10-06T16:00:36.547Z",
      "score": 5.1,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:X/RE:M/U:Amber",
      "score_source": "pingidentity.com",
      "epss": 0.00484,
      "epss_percentile": 0.39612,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Ping Identity"
      ],
      "products": [
        "Ping Identity PingGateway"
      ],
      "cwes": [
        "CWE-601"
      ],
      "description": "An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later)."
    },
    {
      "id": "CVE-2026-98372",
      "url": "https://spydr.io/cve/CVE-2026-98372",
      "published": "2026-10-06T09:18:31.743Z",
      "modified": "2026-10-06T09:18:31.743Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.00161,
      "epss_percentile": 0.04705,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() iptfs_skb_reset_frag_walk() advances to the fragment containing @offset with an unbounded loop: while (offset >= walk->past + walk->frags[walk->fragi].len) walk->past += walk->frags[walk->fragi++].len; walk->fragi is advanced and walk->frags[walk->fragi] is dereferenced without ever checking fragi against walk->nr_frags. When the requested offset is at or beyond the total length spanned by the walk's fragments, fragi runs past nr_frags and off the end of the fixed-size on-stack frags[MAX_SKB_FRAGS + 1] array, reading out-of-bounds stack memory. The two callers behave differently: iptfs_skb_add_frags() already guards against this with if (!walk->nr_frags || offset >= walk->total + walk->initial_offset) return len; but iptfs_skb_can_add_frags() has no such guard and calls iptfs_skb_reset_frag_walk() unconditionally, so it performs the out-of-range walk. Its own \"fragi < walk->nr_frags\" bound check runs only afterwards, too late to prevent the read. This is reachable from the receive path: a crafted IP-TFS (AGGFRAG) payload delivered to an IPTFS SA drives iptfs_reassem_cont() -> iptfs_skb_can_add_frags() with an offset past the fragment total, e.g.: BUG: KASAN: stack-out-of-bounds in iptfs_skb_reset_frag_walk+0x235/0x250 Read of size 4 at addr ffff888008ad7210 by task repro/345 iptfs_skb_reset_frag_walk+0x235/0x250 net/xfrm/xfrm_iptfs.c:392 iptfs_skb_can_add_frags+0x155/0x310 net/xfrm/xfrm_iptfs.c:420 iptfs_reassem_cont+0xcf8/0x1140 net/xfrm/xfrm_iptfs.c:902 iptfs_input_ordered+0x552/0x670 net/xfrm/xfrm_iptfs.c:1280 iptfs_input+0x3d6/0xde0 net/xfrm/xfrm_iptfs.c:1741 xfrm_input+0x282f/0x6140 net/xfrm/xfrm_input.c:700 xfrm4_esp_rcv+0x93/0x120 net/ipv4/xfrm4_protocol.c:104 ip_rcv+0x278/0x2d0 net/ipv4/ip_input.c:612 Give iptfs_skb_can_add_frags() the same up-front guard that iptfs_skb_add_frags() already has, so the walk is never entered with an out-of-range offset. When it triggers, the caller falls back to the existing linearize-and-copy path, which is safe."
    },
    {
      "id": "CVE-2026-98371",
      "url": "https://spydr.io/cve/CVE-2026-98371",
      "published": "2026-10-06T09:18:31.613Z",
      "modified": "2026-10-06T09:18:31.613Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.00161,
      "epss_percentile": 0.04706,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short inner tot_len When the start of an inner packet is split across two outer packets such that fewer than 4 bytes land at the end of the first one, __input_process_payload() saves those bytes as a runt and skips the iplen/iphlen validation performed for in-place packets. When the continuation packet arrives, iptfs_reassem_cont() only requires the declared inner length to be >= sizeof(ra_runt) (6) before allocating the reassembly skb with that attacker-controlled length. However, __iptfs_iphlen() always returns the fixed minimum IP header size (20 for IPv4, 40 for IPv6), so for an inner IPv4 tot_len in [6, 19] the header-completion copy writes past the declared packet length, and the subsequent \"ipremain -= copylen\" underflows to ~4GB, leaving the payload copy length bounded only by blkoff (up to 64KB). At runtime the skb_put() tailroom check turns this into skb_over_panic(), i.e. an unprivileged kernel panic (DoS), reachable locally via userns+netns IPTFS SAs and remotely against IPTFS VPN gateways when the decrypted outer skb is linear (e.g. AF_PACKET taps, tun/tap delivery). Align the runt path with the normal path by requiring the declared inner length to cover at least the IP header size. This also subsumes the previous >= sizeof(ra_runt) check, since the minimum IP header is always larger than the runt buffer. This issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab."
    },
    {
      "id": "CVE-2026-98370",
      "url": "https://spydr.io/cve/CVE-2026-98370",
      "published": "2026-10-06T09:18:31.450Z",
      "modified": "2026-10-06T09:18:31.450Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.00172,
      "epss_percentile": 0.05936,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list. A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free. Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request."
    },
    {
      "id": "CVE-2026-98369",
      "url": "https://spydr.io/cve/CVE-2026-98369",
      "published": "2026-10-06T09:18:31.280Z",
      "modified": "2026-10-06T09:18:31.280Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.0018,
      "epss_percentile": 0.06957,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): WARNING: suspicious RCU usage in ip6_pkt_drop include/net/addrconf.h:389 suspicious rcu_dereference_check() usage! Call Trace: __in6_dev_get_safely include/net/addrconf.h:389 [inline] ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620 ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651 xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806 process_one_work kernel/workqueue.c:3322 [inline] process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405 worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486 When commit 4f4920669d21 (\"xfrm: Reinject transport-mode packets through workqueue\") converted xfrm_trans_reinject from a tasklet to a workqueue, the reinjection loop ceased running in softirq context. Workqueue workers run in process context where local_bh_disable() does not enter an RCU read-side critical section under CONFIG_PREEMPT_RCU. Because finish callbacks (such as ip6_rcv_finish) expect to run under an RCU read lock (performing route lookups, l3mdev lookups, and accessing RCU-protected data structures), invoking them in workqueue context without rcu_read_lock() triggers RCU lockdep warnings. Furthermore, packets queued to the workqueue via xfrm_trans_queue_net() may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref). Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev with blackhole_netdev, so dst entries do not keep skb->dev alive while queued in the workqueue. Fix these issues by: 1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the caller's RCU section to ensure dst is reference-counted before queuing. 2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue deferral so skb->dev remains valid during finish() callback processing. 3. Acquiring rcu_read_lock() around the finish callback invocation loop in xfrm_trans_reinject()."
    },
    {
      "id": "CVE-2026-98368",
      "url": "https://spydr.io/cve/CVE-2026-98368",
      "published": "2026-10-06T09:18:31.130Z",
      "modified": "2026-10-06T09:18:31.130Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.00168,
      "epss_percentile": 0.0556,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutating skb frags On the out-of-place output path (esp->inplace == false) ESP rewrites the skb frag array: esp_output_head() appends a trailer frag and esp_output_tail() replaces the frags with a destination page, both referenced with get_page(). When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the payload frags are owned by the ubuf and must not be referenced or unreferenced individually, but ESP mutates the frag array without ever downgrading the skb. This breaks the managed-frag invariant two ways: - esp_ssg_unref() walks the source scatterlist and drops a page reference for every frag, including the ubuf-owned payload frags, pushing their refcount below the GUP pin bias while the pages are still pinned, i.e. a use-after-free of the zerocopy pages; - esp_output_tail() installs its destination page as frag 0 with get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so skb_release_data() takes the skip_unref branch and never drops that reference, leaking the x->xfrag page at packet rate. Fix this the way every other frag-mutating site does (__ip_append_data(), __ip6_append_data(), tcp_sendmsg_locked()) and call skb_zcopy_downgrade_managed() before ESP touches the frag array: it takes a real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS, so the per-frag unref in esp_ssg_unref() and the frag release in skb_release_data() are both balanced and no mixed-ownership frag array is left behind."
    },
    {
      "id": "CVE-2026-98367",
      "url": "https://spydr.io/cve/CVE-2026-98367",
      "published": "2026-10-06T09:18:30.970Z",
      "modified": "2026-10-06T09:18:30.970Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.00172,
      "epss_percentile": 0.05992,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did. Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock is released before the error path cleanup. A concurrent ibv_modify_qp() transitioning the QP to ERROR can race in this window: siw_accept() ibv_modify_qp(ERROR) ---------------------- ---------------------- siw_qp_modify() fails up_write(&qp->state_lock) down_write(&qp->state_lock) nextstate_from_idle(): if (qp->cep) siw_cep_put(qp->cep) <- frees cep qp->cep = NULL goto error cep->qp = NULL <- UAF Clear qp->cep and drop the association reference taken by siw_cep_get(), all under the write lock held from the initial down_write(&qp->state_lock). Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free the cep before siw_accept() is done with it."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
