DE EN FR
hlukh.ch Updated: 2026-02-26T18:02:00.643Z · week: 2021-W10

Security Warnings

Curated from public advisories. Focus: visibility, context and fast export — no clickbait.

Latest warnings
CVE-2021-20203
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2021-20203
MSRC 2026‑02‑26 Low
CVE-2020-27618
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2020-27618
MSRC 2026‑02‑26 Medium
CVE-2020-8277
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2020-8277
MSRC 2026‑02‑26 High
CVE-2020-8032
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2020-8032
MSRC 2026‑02‑26 High
CVE-2021-27803
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2021-27803
MSRC 2026‑02‑26 High
CVE-2021-21309
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2021-21309
MSRC 2026‑02‑26 High
CVE-2021-22134
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.
2026‑02‑26 · CVE-2021-22134
MSRC 2026‑02‑26 Medium
CVE-2020-35508
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.
2026‑02‑26 · CVE-2020-35508
MSRC 2026‑02‑26 Medium
CVE-2020-35492
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example by convincing a user to open a file in an application using cairo or if an application uses cairo on untrusted input) to cause a stack buffer overflow -&gt; out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality integrity as well as system availability.
2026‑02‑26 · CVE-2020-35492
MSRC 2026‑02‑26 High
CVE-2021-20231
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
2026‑02‑26 · CVE-2021-20231
MSRC 2026‑02‑26 Critical
CVE-2021-20232
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
2026‑02‑26 · CVE-2021-20232
MSRC 2026‑02‑26 Critical
CVE-2020-14372
A flaw was found in grub2 in versions prior to 2.06 where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded and executed by the kernel defeating its Secure Boot lockdown and allowing the attacker to load unsigned code. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-14372
MSRC 2026‑02‑26 High
CVE-2020-25647
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-25647
MSRC 2026‑02‑26 High
CVE-2021-20233
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2021-20233
MSRC 2026‑02‑26 High
CVE-2020-27779
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-27779
MSRC 2026‑02‑26 High
CVE-2021-20225
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2021-20225
MSRC 2026‑02‑26 Medium
CVE-2020-25632
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-25632
MSRC 2026‑02‑26 High
CVE-2020-27749
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents using a 1kB stack buffer for temporary storage without sufficient bounds checking. If the function is called with a command line that references a variable with a sufficiently large payload it is possible to overflow the stack buffer corrupt the stack frame and control execution which could also circumvent Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-27749
MSRC 2026‑02‑26 Medium
CVE-2021-20286
A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
2026‑02‑26 · CVE-2021-20286
MSRC 2026‑02‑26 Low
CVE-2020-35521
A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c a crafted TIFF file can lead to an abort resulting in denial of service.
2026‑02‑26 · CVE-2020-35521
MSRC 2026‑02‑26 Medium
CVE-2020-27827
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
2026‑02‑26 · CVE-2020-27827
MSRC 2026‑02‑26 High
CVE-2021-20271
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature header was modified to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity confidentiality and system availability.
2026‑02‑26 · CVE-2021-20271
MSRC 2026‑02‑26 High
CVE-2021-20227
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
2026‑02‑26 · CVE-2021-20227
MSRC 2026‑02‑26 Medium
CVE-2021-3411
A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2021-3411
MSRC 2026‑02‑26 Medium
CVE-2021-3470
A heap overflow issue was found in Redis in versions before 5.0.10 before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users who use jemalloc or glibc malloc.
2026‑02‑26 · CVE-2021-3470
MSRC 2026‑02‑26 Medium
CVE-2020-35524
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.
2026‑02‑26 · CVE-2020-35524
MSRC 2026‑02‑26 High
CVE-2020-25639
A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.
2026‑02‑26 · CVE-2020-25639
MSRC 2026‑02‑26 Medium
CVE-2021-3467
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
2026‑02‑26 · CVE-2021-3467
MSRC 2026‑02‑26 Medium
CVE-2021-3443
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
2026‑02‑26 · CVE-2021-3443
MSRC 2026‑02‑26 Medium
CVE-2021-3416
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.
2026‑02‑26 · CVE-2021-3416
MSRC 2026‑02‑26 Medium
CVE-2021-28964
A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation aka CID-dbcc7d57bffc.
2026‑02‑26 · CVE-2021-28964
MSRC 2026‑02‑26 Medium
CVE-2021-27928
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37 10.3 before 10.3.28 10.4 before 10.4.18 and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.
2026‑02‑26 · CVE-2021-27928
MSRC 2026‑02‑26 High
CVE-2021-20255
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host resulting in a denial of service. The highest threat from this vulnerability is to system availability.
2026‑02‑26 · CVE-2021-20255
MSRC 2026‑02‑26 Medium
CVE-2021-3392
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
2026‑02‑26 · CVE-2021-3392
MSRC 2026‑02‑26 Low
CVE-2021-20270
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file as demonstrated by input that only contains the "exception" keyword.
2026‑02‑26 · CVE-2021-20270
MSRC 2026‑02‑26 High
CVE-2020-35523
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.
2026‑02‑26 · CVE-2020-35523
MSRC 2026‑02‑26 High
CVE-2021-28950
An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode aka CID-775c5033a0d1.
2026‑02‑26 · CVE-2021-28950
MSRC 2026‑02‑26 Medium
CVE-2021-28951
An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread but concurrently that SQPOLL thread is waiting for a signal to start aka CID-3ebba796fa25.
2026‑02‑26 · CVE-2021-28951
MSRC 2026‑02‑26 Medium
CVE-2021-28153
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink it incorrectly also creates the target of the symlink as an empty file which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists then the contents of that file correctly remain unchanged.)
2026‑02‑26 · CVE-2021-28153
MSRC 2026‑02‑26 Medium
CVE-2021-28361
An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected) the iSCSI target can crash with a NULL pointer dereference.
2026‑02‑26 · CVE-2021-28361
MSRC 2026‑02‑26 High
CVE-2021-29647
An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure aka CID-50535249f624.
2026‑02‑26 · CVE-2021-29647
MSRC 2026‑02‑26 Medium
CVE-2021-29648
An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF) which can cause a system crash upon an unexpected access attempt (in map_create in kernel/bpf/syscall.c or check_btf_info in kernel/bpf/verifier.c) aka CID-350a5c4dd245.
2026‑02‑26 · CVE-2021-29648
MSRC 2026‑02‑26 Medium
CVE-2021-29650
An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value aka CID-175e476b8cdf.
2026‑02‑26 · CVE-2021-29650
MSRC 2026‑02‑26 Medium
CVE-2021-29649
An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak related to a lack of cleanup steps in kernel/usermode_driver.c and kernel/bpf/preload/bpf_preload_kern.c aka CID-f60a85cad677.
2026‑02‑26 · CVE-2021-29649
MSRC 2026‑02‑26 Medium
CVE-2021-29646
An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes aka CID-0217ed2848e8.
2026‑02‑26 · CVE-2021-29646
MSRC 2026‑02‑26 Medium
CVE-2021-29265
An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and shared status aka CID-9380afd6df70.
2026‑02‑26 · CVE-2021-29265
MSRC 2026‑02‑26 Medium
CVE-2020-27171
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory aka CID-10d2bb2e6b1d.
2026‑02‑26 · CVE-2020-27171
MSRC 2026‑02‑26 Medium
CVE-2020-27170
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.
2026‑02‑26 · CVE-2020-27170
MSRC 2026‑02‑26 Medium
CVE-2021-29266
An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v-&gt;config_ctx has an invalid value upon re-opening a character device aka CID-f6bbf0010ba0.
2026‑02‑26 · CVE-2021-29266
MSRC 2026‑02‑26 High
CVE-2021-29264
An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale Gianfar Ethernet driver allows attackers to cause a system crash because a negative fragment size is calculated in situations involving an rx queue overrun when jumbo packets are used and NAPI is enabled aka CID-d8861bab48b6.
2026‑02‑26 · CVE-2021-29264
MSRC 2026‑02‑26 Medium
Page 1