DE EN FR
hlukh.ch Stand: 2026-02-26T21:02:01.989Z · week: 2025-W11

Sicherheitswarnungen

Kuratiert aus öffentlich verfügbaren Advisories. Fokus: Sichtbarkeit, Einordnung und schneller Export – ohne Clickbait.

Neueste Warnungen
CVE-2025-21846
acct: perform last write from workqueue
2026‑02‑21 · CVE-2025-21846
MSRC 2026‑02‑21 Mittel
CVE-2024-12905
An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.
2026‑02‑21 · CVE-2024-12905
MSRC 2026‑02‑21 Hoch
CVE-2025-27363
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.
2026‑02‑21 · CVE-2025-27363
MSRC 2026‑02‑21 Hoch
CVE-2025-1550
Arbitrary Code Execution via Crafted Keras Config for Model Loading
2026‑02‑21 · CVE-2025-1550
MSRC 2026‑02‑21 Kritisch
CVE-2025-21870
ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers
2026‑02‑21 · CVE-2025-21870
MSRC 2026‑02‑21 Mittel
CVE-2025-21847
ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data()
2026‑02‑21 · CVE-2025-21847
MSRC 2026‑02‑21 Mittel
CVE-2025-24070
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2025-24070
MSRC 2026‑02‑21 Hoch
CVE-2025-31160
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by running certain types of unprivileged processes while a different user runs atop.
2026‑02‑21 · CVE-2025-31160
MSRC 2026‑02‑21 Niedrig
CVE-2025-21199
Azure Agent Installer for Backup and Site Recovery Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2025-21199
MSRC 2026‑02‑21 Mittel
CVE-2025-26627
Azure Arc Installer Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2025-26627
MSRC 2026‑02‑21 Hoch
CVE-2025-24049
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2025-24049
MSRC 2026‑02‑21 Hoch
CVE-2025-21384
Azure Health Bot Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2025-21384
MSRC 2026‑02‑21 Hoch
CVE-2025-26683
Azure Playwright Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2025-26683
MSRC 2026‑02‑21 Hoch
CVE-2025-24986
Azure Promptflow Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2025-24986
MSRC 2026‑02‑21 Mittel
CVE-2023-53010
bnxt: Do not read past the end of test names
2026‑02‑21 · CVE-2023-53010
MSRC 2026‑02‑21 Mittel
CVE-2025-21867
bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()
2026‑02‑21 · CVE-2025-21867
MSRC 2026‑02‑21 Hoch
CVE-2025-21853
bpf: avoid holding freeze_mutex during mmap operation
2026‑02‑21 · CVE-2025-21853
MSRC 2026‑02‑21 Mittel
CVE-2025-21825
bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT
2026‑02‑21 · CVE-2025-21825
MSRC 2026‑02‑21 Mittel
CVE-2024-58088
bpf: Fix deadlock when freeing cgroup storage
2026‑02‑21 · CVE-2024-58088
MSRC 2026‑02‑21 Mittel
CVE-2024-58089
btrfs: fix double accounting race when btrfs_run_delalloc_range() failed
2026‑02‑21 · CVE-2024-58089
MSRC 2026‑02‑21 Mittel
CVE-2023-53008
cifs: fix potential memory leaks in session setup
2026‑02‑21 · CVE-2023-53008
MSRC 2026‑02‑21 Mittel
CVE-2025-2312
cifs.upcall makes an upcall to the wrong namespace in containerized environments
2026‑02‑21 · CVE-2025-2312
MSRC 2026‑02‑21 Mittel
CVE-2024-40635
containerd has an integer overflow in User ID handling
2026‑02‑21 · CVE-2024-40635
MSRC 2026‑02‑21 Mittel
CVE-2022-49750
cpufreq: CPPC: Add u64 casts to avoid overflowing
2026‑02‑21 · CVE-2022-49750
MSRC 2026‑02‑21 Mittel
CVE-2025-24997
DirectX Graphics Kernel File Denial of Service Vulnerability
2026‑02‑21 · CVE-2025-24997
MSRC 2026‑02‑21 Mittel
CVE-2023-53009
drm/amdkfd: Add sync after creating vram bo
2026‑02‑21 · CVE-2023-53009
MSRC 2026‑02‑21 Mittel
CVE-2023-53002
drm/i915: Fix a memory leak with reused mmap_offset
2026‑02‑21 · CVE-2023-53002
MSRC 2026‑02‑21 Mittel
CVE-2023-52981
drm/i915: Fix request ref counting during error capture & debugfs dump
2026‑02‑21 · CVE-2023-52981
MSRC 2026‑02‑21 Mittel
CVE-2025-21862
drop_monitor: fix incorrect initialization order
2026‑02‑21 · CVE-2025-21862
MSRC 2026‑02‑21 Mittel
CVE-2025-21872
efi: Don't map the entire mokvar table to determine its size
2026‑02‑21 · CVE-2025-21872
MSRC 2026‑02‑21 Mittel
CVE-2025-30348
encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data).
2026‑02‑21 · CVE-2025-30348
MSRC 2026‑02‑21 Mittel
CVE-2022-49742
f2fs: initialize locks earlier in f2fs_fill_super()
2026‑02‑21 · CVE-2022-49742
MSRC 2026‑02‑21 Mittel
CVE-2025-21858
geneve: Fix use-after-free in geneve_find_dev().
2026‑02‑21 · CVE-2025-21858
MSRC 2026‑02‑21 Hoch
CVE-2025-31176
Gnuplot: gnuplot segmentation fault on plot3d_points
2026‑02‑21 · CVE-2025-31176
MSRC 2026‑02‑21 Mittel
CVE-2025-31181
Gnuplot: gnuplot segmentation fault on x11_graphics
2026‑02‑21 · CVE-2025-31181
MSRC 2026‑02‑21 Mittel
CVE-2025-31179
Gnuplot: gnuplot segmentation fault on xstrftime
2026‑02‑21 · CVE-2025-31179
MSRC 2026‑02‑21 Mittel
CVE-2025-29923
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
2026‑02‑21 · CVE-2025-29923
MSRC 2026‑02‑21 Niedrig
CVE-2024-45778
Grub2: fs/bfs: integer overflow in the bfs parser.
2026‑02‑21 · CVE-2024-45778
MSRC 2026‑02‑21 Mittel
CVE-2024-45779
Grub2: fs/bfs: integer overflow leads to heap oob read in the bfs parser
2026‑02‑21 · CVE-2024-45779
MSRC 2026‑02‑21 Mittel
CVE-2025-1125
Grub2: fs/hfs: integer overflow may lead to heap based out-of-bounds write
2026‑02‑21 · CVE-2025-1125
MSRC 2026‑02‑21 Mittel
CVE-2024-45782
Grub2: fs/hfs: strcpy() using the volume name (fs/hfs.c:382)
2026‑02‑21 · CVE-2024-45782
MSRC 2026‑02‑21 Mittel
CVE-2024-45780
Grub2: fs/tar: integer overflow causes heap oob write
2026‑02‑21 · CVE-2024-45780
MSRC 2026‑02‑21 Mittel
CVE-2025-0685
Grub2: jfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data
2026‑02‑21 · CVE-2025-0685
MSRC 2026‑02‑21 Mittel
CVE-2025-0684
Grub2: reiserfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data
2026‑02‑21 · CVE-2025-0684
MSRC 2026‑02‑21 Mittel
CVE-2025-0686
Grub2: romfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading dat
2026‑02‑21 · CVE-2025-0686
MSRC 2026‑02‑21 Mittel
CVE-2025-0678
Grub2: squash4: integer overflow may lead to heap based out-of-bounds write when reading data
2026‑02‑21 · CVE-2025-0678
MSRC 2026‑02‑21 Mittel
CVE-2025-0689
Grub2: udf: heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution
2026‑02‑21 · CVE-2025-0689
MSRC 2026‑02‑21 Mittel
CVE-2025-21865
gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().
2026‑02‑21 · CVE-2025-21865
MSRC 2026‑02‑21 Mittel
CVE-2025-2153
HDF5 h5 File H5SM.c H5SM_delete heap-based overflow
2026‑02‑21 · CVE-2025-2153
MSRC 2026‑02‑21 Mittel
CVE-2025-2915
HDF5 H5Faccum.c H5F__accum_free heap-based overflow
2026‑02‑21 · CVE-2025-2915
MSRC 2026‑02‑21 Hoch
Seite 1