It was discovered that the Traffic-Control Index (TCINDEX) implementation
in the Linux kernel did not properly perform filter deactivation in some
situations. A local attacker could possibly use this to gain elevated
privileges. Please note that with the fix for this CVE, kernel support for
the TCINDEX classifier has been removed. (CVE-2023-1829)
It was discovered that a race condition existed in the io_uring subsystem
in the Linux kernel, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-1872)
More Stories
USN-7285-2: nginx vulnerability
USN-7285-1 fixed vulnerabilities in nginx. This update provides the corresponding updates for Ubuntu 24.04 LTS. Original advisory details: It was...
firefox-137.0-2.fc42
FEDORA-2025-4e7468921a Packages in this update: firefox-137.0-2.fc42 Update description: Updated to latest upstream (137.0) Read More
firefox-137.0-2.fc40
FEDORA-2025-d48f900812 Packages in this update: firefox-137.0-2.fc40 Update description: Updated to latest upstream (137.0) Read More
firefox-137.0-2.fc41
FEDORA-2025-96c31e2086 Packages in this update: firefox-137.0-2.fc41 Update description: Updated to latest upstream (137.0) Read More
ZDI-25-196: Apple macOS ICC Profile Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to...
ZDI-25-195: Apple macOS CoreGraphics Image Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. User interaction is required to...