DE EN FR
hlukh.ch Updated: 2026-02-26T18:02:00.643Z · week: 2025-W37

Security Warnings

Curated from public advisories. Focus: visibility, context and fast export — no clickbait.

Latest warnings
CVE-2025-55558
A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
2026‑02‑24 · CVE-2025-55558
MSRC 2026‑02‑24 High
CVE-2025-55557
A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
2026‑02‑24 · CVE-2025-55557
MSRC 2026‑02‑24 High
CVE-2025-55553
A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
2026‑02‑24 · CVE-2025-55553
MSRC 2026‑02‑24 High
CVE-2025-55319
Agentic AI and Visual Studio Code Remote Code Execution Vulnerability
2026‑02‑24 · CVE-2025-55319
MSRC 2026‑02‑24 High
CVE-2025-39751
ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control
2026‑02‑24 · CVE-2025-39751
MSRC 2026‑02‑24 High
CVE-2025-39757
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
2026‑02‑24 · CVE-2025-39757
MSRC 2026‑02‑24 High
CVE-2025-38729
ALSA: usb-audio: Validate UAC3 power domain descriptors, too
2026‑02‑24 · CVE-2025-38729
MSRC 2026‑02‑24 High
CVE-2025-55560
An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
2026‑02‑24 · CVE-2025-55560
MSRC 2026‑02‑24 High
CVE-2025-55551
An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
2026‑02‑24 · CVE-2025-55551
MSRC 2026‑02‑24 High
CVE-2025-9905
Arbitary Code execution in Keras load_model()
2026‑02‑24 · CVE-2025-9905
MSRC 2026‑02‑24 High
CVE-2025-9906
Arbitrary Code execution in Keras Safe Mode
2026‑02‑24 · CVE-2025-9906
MSRC 2026‑02‑24 High
CVE-2025-39828
atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control().
2026‑02‑24 · CVE-2025-39828
MSRC 2026‑02‑24 High
CVE-2025-58754
Axios is vulnerable to DoS attack through lack of data size check
2026‑02‑24 · CVE-2025-58754
MSRC 2026‑02‑24 High
CVE-2025-55316
Azure Connected Machine Agent Elevation of Privilege Vulnerability
2026‑02‑24 · CVE-2025-55316
MSRC 2026‑02‑24 High
CVE-2025-49692
Azure Connected Machine Agent Elevation of Privilege Vulnerability
2026‑02‑24 · CVE-2025-49692
MSRC 2026‑02‑24 High
CVE-2025-39860
Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
2026‑02‑24 · CVE-2025-39860
MSRC 2026‑02‑24 High
CVE-2025-39861
Bluetooth: vhci: Prevent use-after-free by removing debugfs files early
2026‑02‑24 · CVE-2025-39861
MSRC 2026‑02‑24 High
CVE-2025-39810
bnxt_en: Fix memory corruption when FW resources change during ifdown
2026‑02‑24 · CVE-2025-39810
MSRC 2026‑02‑24 High
CVE-2023-53187
btrfs: fix use-after-free of new block group that became unused
2026‑02‑24 · CVE-2023-53187
MSRC 2026‑02‑24 High
CVE-2025-39790
bus: mhi: host: Detect events pointing to unexpected TREs
2026‑02‑24 · CVE-2025-39790
MSRC 2026‑02‑24 High
CVE-2023-53254
cacheinfo: Fix shared_cpu_map to handle shared caches at different levels
2026‑02‑24 · CVE-2023-53254
MSRC 2026‑02‑24 High
CVE-2025-39873
can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB
2026‑02‑24 · CVE-2025-39873
MSRC 2026‑02‑24 High
CVE-2025-54108
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
2026‑02‑24 · CVE-2025-54108
MSRC 2026‑02‑24 High
CVE-2025-39838
cifs: prevent NULL pointer dereference in UTF16 conversion
2026‑02‑24 · CVE-2025-39838
MSRC 2026‑02‑24 High
CVE-2025-58063
CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
2026‑02‑24 · CVE-2025-58063
MSRC 2026‑02‑24 High
CVE-2025-39721
crypto: qat - flush misc workqueue during device shutdown
2026‑02‑24 · CVE-2025-39721
MSRC 2026‑02‑24 High
CVE-2025-58060
cups has Authentication bypass with AuthType Negotiate
2026‑02‑24 · CVE-2025-58060
MSRC 2026‑02‑24 High
CVE-2025-55223
DirectX Graphics Kernel Elevation of Privilege Vulnerability
2026‑02‑24 · CVE-2025-55223
MSRC 2026‑02‑24 High
CVE-2025-38703
drm/xe: Make dma-fences compliant with the safe access rules
2026‑02‑24 · CVE-2025-38703
MSRC 2026‑02‑24 High
CVE-2025-55238
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
2026‑02‑24 · CVE-2025-55238
MSRC 2026‑02‑24 High
CVE-2025-39817
efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
2026‑02‑24 · CVE-2025-39817
MSRC 2026‑02‑24 High
CVE-2025-38692
exfat: add cluster chain loop check for dir
2026‑02‑24 · CVE-2025-38692
MSRC 2026‑02‑24 High
CVE-2025-38701
ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr
2026‑02‑24 · CVE-2025-38701
MSRC 2026‑02‑24 High
CVE-2025-38702
fbdev: fix potential buffer overflow in do_register_framebuffer()
2026‑02‑24 · CVE-2025-38702
MSRC 2026‑02‑24 High
CVE-2025-38685
fbdev: Fix vmalloc out-of-bounds write in fast_imageblit
2026‑02‑24 · CVE-2025-38685
MSRC 2026‑02‑24 High
CVE-2025-39866
fs: writeback: fix use-after-free in __mark_inode_dirty()
2026‑02‑24 · CVE-2025-39866
MSRC 2026‑02‑24 High
CVE-2025-39691
fs/buffer: fix use-after-free when call bh_read() helper
2026‑02‑24 · CVE-2025-39691
MSRC 2026‑02‑24 High
CVE-2025-39689
ftrace: Also allocate and copy hash for reading of filter files
2026‑02‑24 · CVE-2025-39689
MSRC 2026‑02‑24 High
CVE-2025-38710
gfs2: Validate i_depth for exhash directories
2026‑02‑24 · CVE-2025-38710
MSRC 2026‑02‑24 High
CVE-2025-55236
Graphics Kernel Remote Code Execution Vulnerability
2026‑02‑24 · CVE-2025-55236
MSRC 2026‑02‑24 High
CVE-2025-38735
gve: prevent ethtool ops after shutdown
2026‑02‑24 · CVE-2025-38735
MSRC 2026‑02‑24 High
CVE-2025-39824
HID: asus: fix UAF via HID_CLAIMED_INPUT validation
2026‑02‑24 · CVE-2025-39824
MSRC 2026‑02‑24 High
CVE-2025-39806
HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
2026‑02‑24 · CVE-2025-39806
MSRC 2026‑02‑24 High
CVE-2025-53805
HTTP.sys Denial of Service Vulnerability
2026‑02‑24 · CVE-2025-53805
MSRC 2026‑02‑24 High
CVE-2025-39853
i40e: Fix potential invalid access when MAC list is empty
2026‑02‑24 · CVE-2025-39853
MSRC 2026‑02‑24 High
CVE-2022-50406
iomap: iomap: fix memory corruption when recording errors during writeback
2026‑02‑24 · CVE-2022-50406
MSRC 2026‑02‑24 High
CVE-2025-38688
iommufd: Prevent ALIGN() overflow
2026‑02‑24 · CVE-2025-38688
MSRC 2026‑02‑24 High
CVE-2025-39702
ipv6: sr: Fix MAC comparison to be constant-time
2026‑02‑24 · CVE-2025-39702
MSRC 2026‑02‑24 High
CVE-2025-38698
jfs: Regular file corruption check
2026‑02‑24 · CVE-2025-38698
MSRC 2026‑02‑24 High
CVE-2025-38697
jfs: upper bound check of tree index in dbAllocAG
2026‑02‑24 · CVE-2025-38697
MSRC 2026‑02‑24 High
Page 1