Search CVE reports


Toggle filters

21 – 30 of 59628 results

Status is adjusted based on your filters.


CVE-2026-84788

Medium priority
Needs evaluation

[io/channel-socket: do not treat a zero length write as an error]

2 affected packages

qemu, qemu-hwe

Package 16.04 LTS
qemu Needs evaluation
qemu-hwe —
Show less packages

CVE-2026-77913

Medium priority
Needs evaluation

[hw/display/vga: fix text-mode OOB write after a graphics surface switch]

2 affected packages

qemu, qemu-hwe

Package 16.04 LTS
qemu Needs evaluation
qemu-hwe —
Show less packages

CVE-2026-77185

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

mina, mina2

Package 16.04 LTS
mina Needs evaluation
mina2 Needs evaluation
Show less packages

CVE-2026-66900

Medium priority
Needs evaluation

[hw/net/virtio-net: strip trailing padding when caching RSC segment]

2 affected packages

qemu, qemu-hwe

Package 16.04 LTS
qemu Needs evaluation
qemu-hwe —
Show less packages

CVE-2026-66899

Medium priority
Needs evaluation

[virtio-balloon: fix free-page BH teardown on unrealize]

2 affected packages

qemu, qemu-hwe

Package 16.04 LTS
qemu Needs evaluation
qemu-hwe —
Show less packages

CVE-2026-17588

Medium priority
Needs evaluation

[hw/usb/hcd-xhci: Set reentrancy guard in timer functions]

2 affected packages

qemu, qemu-hwe

Package 16.04 LTS
qemu Needs evaluation
qemu-hwe —
Show less packages

CVE-2026-16271

Medium priority
Needs evaluation

[hw/display/qxl: validate primary surface stride against width]

2 affected packages

qemu, qemu-hwe

Package 16.04 LTS
qemu Needs evaluation
qemu-hwe —
Show less packages

CVE-2026-74225

Medium priority
Needs evaluation

U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6...

2 affected packages

u-boot, u-boot-nezha

Package 16.04 LTS
u-boot Needs evaluation
u-boot-nezha —
Show less packages

CVE-2026-74222

Medium priority
Needs evaluation

U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead...

2 affected packages

u-boot, u-boot-nezha

Package 16.04 LTS
u-boot Needs evaluation
u-boot-nezha —
Show less packages

CVE-2026-74221

Medium priority
Needs evaluation

U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized...

2 affected packages

u-boot, u-boot-nezha

Package 16.04 LTS
u-boot Needs evaluation
u-boot-nezha —
Show less packages