CVE-2026-95512Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader Exploitation status Not confirmed Fix Not confirmed Published 10/02/2026 Severity Medium CVE-2026-103242Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag Exploitation status Not known exploited Fix Not confirmed Published 09/30/2026 Severity High CVE-2026-95520Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102010Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity High CVE-2026-95521Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm Exploitation status Not known exploited Fix Not confirmed Published 09/24/2026 Severity High CVE-2026-95519Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) Exploitation status Not known exploited Fix Not confirmed Published 09/24/2026 Severity High CVE-2026-88840Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity Medium CVE-2026-88839Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity Medium CVE-2026-88837Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting authentication Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity Medium CVE-2026-88835Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity Medium CVE-2026-88831Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity Medium CVE-2026-88832Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-88830Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-96512Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-95619Gcc: libstdc++ integer overflow in `new` operator Exploitation status Not known exploited Fix Not confirmed Published 09/22/2026 Severity High CVE-2026-95511Exploitation status Not confirmed Fix Not confirmed Published 09/22/2026 Severity Unknown CVE-2026-93653Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service) Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-76781Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute Exploitation status Not known exploited Fix Not confirmed Published 09/17/2026 Severity Medium CVE-2026-92925Redis: redis: out-of-bounds read via crafted cluster bus packets Exploitation status Not known exploited Fix Not confirmed Published 09/17/2026 Severity High CVE-2026-42784Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion Exploitation status Not known exploited Fix Not confirmed Published 09/16/2026 Severity High CVE-2025-11395Podman: arbitrary file write when importing oci archive Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity Medium CVE-2026-85234Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engine Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-79699Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directory Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity Medium CVE-2026-79705Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity Medium CVE-2026-85013Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters Exploitation status Public exploit Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-18495Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough Exploitation status Not known exploited Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-88265Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown Exploitation status Not known exploited Fix Not confirmed Published 09/10/2026 Severity Medium CVE-2026-88264Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity Medium CVE-2026-84042Crun: crun: rootful krun with passt executes container payload as host root Exploitation status Not known exploited Fix Not confirmed Published 09/10/2026 Severity High CVE-2026-87876Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) Exploitation status Public exploit Fix Not confirmed Published 09/09/2026 Severity Low CVE-2026-87875Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound Exploitation status Public exploit Fix Not confirmed Published 09/09/2026 Severity Medium CVE-2026-87766Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup Exploitation status Not known exploited Fix YesPublished 09/09/2026 Severity High CVE-2026-74860Libxml2: double-free/uaf in libxml2 python bindings Exploitation status Not known exploited Fix Not confirmed Published 09/08/2026 Severity High CVE-2026-86469Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path Exploitation status Public exploit Fix Not confirmed Published 09/07/2026 Severity Medium CVE-2026-84838Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() Exploitation status Not known exploited Fix Not confirmed Published 09/02/2026 Severity High CVE-2026-84837Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path Exploitation status Not known exploited Fix Not confirmed Published 09/02/2026 Severity High CVE-2026-78409Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks Exploitation status Public exploit Fix Not confirmed Published 09/02/2026 Severity High CVE-2026-78410Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection Exploitation status Public exploit Fix Not confirmed Published 09/02/2026 Severity High CVE-2026-78408Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority Exploitation status Public exploit Fix Not confirmed Published 09/02/2026 Severity High CVE-2026-84233Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames Exploitation status Not known exploited Fix Not confirmed Published 09/01/2026 Severity High CVE-2026-18743Popt-devel: popt-static: short realloc in poptconfigfiletostring Exploitation status Not known exploited Fix Not confirmed Published 09/01/2026 Severity Low CVE-2026-13732Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf Exploitation status Not known exploited Fix Not confirmed Published 08/31/2026 Severity High CVE-2026-82327Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data Exploitation status Not known exploited Fix Not confirmed Published 08/28/2026 Severity Medium CVE-2026-19685Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615) Exploitation status Not known exploited Fix Not confirmed Published 08/24/2026 Severity Critical CVE-2026-78367Rpm: rpmbuild gettarspec() crafted tar member name → macro injection Exploitation status Public exploit Fix Not confirmed Published 08/24/2026 Severity High CVE-2026-19582Exploitation status Not confirmed Fix Not confirmed Published 08/20/2026 Severity Unknown CVE-2026-43961Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-19617Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser Exploitation status Not known exploited Fix Not confirmed Published 08/14/2026 Severity Medium CVE-2026-19730Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives Exploitation status Public exploit Fix Not confirmed Published 08/13/2026 Severity Medium CVE-2026-19548Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing Exploitation status Not known exploited Fix Not confirmed Published 08/12/2026 Severity Medium CVE-2026-72693Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login Exploitation status Not known exploited Fix Not confirmed Published 08/11/2026 Severity High CVE-2026-15816Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() Exploitation status Not known exploited Fix Not confirmed Published 08/07/2026 Severity High CVE-2026-18938P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems Exploitation status Not known exploited Fix Not confirmed Published 08/07/2026 Severity Medium CVE-2026-19079Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selinux label manipulation Exploitation status Not known exploited Fix Not confirmed Published 08/07/2026 Severity Medium CVE-2026-18839Popt-devel: popt-static: size_t underflow in singleoptionhelp Exploitation status Not known exploited Fix Not confirmed Published 08/05/2026 Severity Low CVE-2026-44605Rpm: heap buffer overflow in ndb slot table parsing Exploitation status Not known exploited Fix Not confirmed Published 08/05/2026 Severity Medium CVE-2026-71227Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-71226Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-71225Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-18739Popt-devel: popt-static: off-by-one in poptstuffargs Exploitation status Not known exploited Fix Not confirmed Published 08/04/2026 Severity Low CVE-2026-18477Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape Exploitation status Not known exploited Fix Not confirmed Published 08/03/2026 Severity Medium CVE-2026-18508Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite Exploitation status Not known exploited Fix Not confirmed Published 08/03/2026 Severity Medium CVE-2026-18220Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing Exploitation status Not known exploited Fix Not confirmed Published 07/29/2026 Severity High CVE-2026-15003Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service Exploitation status Not known exploited Fix Not confirmed Published 07/27/2026 Severity Medium CVE-2026-16730Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup Exploitation status Not known exploited Fix Not confirmed Published 07/24/2026 Severity Medium CVE-2026-16552Exploitation status Not confirmed Fix Not confirmed Published 07/22/2026 Severity Unknown CVE-2026-16517Libarchive: libarchive: signed integer overflow in archive_write_zip_header Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Low CVE-2026-59851Libssh: libssh: authentication bypass via missing gssapi principal check Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity High CVE-2026-59850Libssh: libssh: use-after-free via data callbacks on closed channels Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Medium CVE-2026-59849Libssh: libssh: denial of service via automatic certificate authentication loop Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Low CVE-2026-59848Libssh: libssh: denial of service via sftp responses with unknown request ids Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Medium CVE-2026-59847Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Medium CVE-2026-59846Libssh: libssh: information disclosure via proxycommand %r username expansion Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Low CVE-2026-16445Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity High CVE-2026-59844Libssh: libssh: denial of service via oversized sftp read length Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Medium CVE-2026-59845Libssh: libssh: denial of service via unchecked proxycommand fork() failure Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Medium CVE-2026-59843Libssh: libssh: denial of service via zero advertised channel packet size Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Medium CVE-2026-59842Libssh: libssh: information disclosure via short gssapi curve25519 public key Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Low CVE-2026-15370Libssh: libssh: stack buffer overflow in sftp server longname construction Exploitation status Not known exploited Fix Not confirmed Published 07/21/2026 Severity Medium CVE-2026-15588Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering Exploitation status Public exploit Fix Not confirmed Published 07/20/2026 Severity Medium CVE-2026-48863Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service Exploitation status Not known exploited Fix YesPublished 07/16/2026 Severity High CVE-2026-15028Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header Exploitation status Not known exploited Fix Not confirmed Published 07/10/2026 Severity Low CVE-2026-58016Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity High CVE-2026-58015Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Medium CVE-2026-58014Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" Exploitation status Public exploit Fix YesPublished 06/30/2026 Severity High CVE-2026-58013Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Medium CVE-2026-58012Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Medium CVE-2026-58011Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime Exploitation status Public exploit Fix YesPublished 06/30/2026 Severity Medium CVE-2026-58010Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Medium CVE-2026-12610Sssd: use-after-free crash in sssd' 'sssd_pam' process Exploitation status Not known exploited Fix Not confirmed Published 06/30/2026 Severity Medium CVE-2026-14164Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack() Exploitation status Public exploit Fix Not confirmed Published 06/30/2026 Severity High CVE-2026-13757P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing Exploitation status Not known exploited Fix Not confirmed Published 06/29/2026 Severity Medium CVE-2026-12912Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image Exploitation status Not known exploited Fix Not confirmed Published 06/29/2026 Severity High CVE-2026-54371attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr Exploitation status Not known exploited Fix YesPublished 06/29/2026 Severity High CVE-2026-54369acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions Exploitation status Not known exploited Fix YesPublished 06/29/2026 Severity High CVE-2026-13595Util-linux: util-linux: heap use-after-free in libblkid nested partition probing Exploitation status Not known exploited Fix Not confirmed Published 06/29/2026 Severity Medium CVE-2026-48618Exploitation status Not known exploited Fix YesPublished 06/26/2026 Severity High CVE-2026-48933Exploitation status Not known exploited Fix YesPublished 06/26/2026 Severity High CVE-2026-52845Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` Exploitation status Public exploit Fix YesPublished 06/23/2026 Severity High CVE-2026-55654Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination Exploitation status Not known exploited Fix Not confirmed Published 06/23/2026 Severity Low