Posts of last 24 hours
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.44/7.1.8. Affected is the function ovpn_nl_peer_set_doit of the component ovpn. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-74727. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/394504
A vulnerability was found in Linux Kernel up to 7.1.8. It has been declared as problematic. This affects the function amdxdna_insert_pages of the component amdxdna. The manipulation results in reachable assertion.
This vulnerability is reported as CVE-2026-74716. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/394513
A vulnerability has been found in Linux Kernel up to 7.1.8 and classified as very critical. This affects the function __skb_udp_tunnel_segment of the component UDP Tunnel Segmentation. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-74705. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/394496
A vulnerability, which was classified as critical, has been found in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user_invitation_code.py of the component Public Invitation-Code Redemption Endpoint. The manipulation of the argument code leads to missing authentication.
This vulnerability is referenced as CVE-2026-78154. Remote exploitation of the attack is possible. No exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
https://vuldb.com/vuln/394536
Роботы уже бегают, боксируют и работают на публику, однако главный барьер скрыт не в механике, а в способности понимать реальный мир.
https://www.securitylab.ru/news/576359.php
Submit #882887 / VDB-394536
https://vuldb.com/submit/882887
New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click Adversa AI researcher Rony Utevsky devised a new attack technique, called Cryptographic Context Injection, that bypasses AI safety filters by sending instructions as AES-encrypted ciphertext and tricking the model into decrypting them inside its own code execution runtime. […]
https://securityaffairs.com/197717/hacking/zero-click-grok-chat-history-theft-adversa-ai-demonstrates-cryptographic-context-injection.html
A vulnerability classified as problematic was found in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation can lead to null pointer dereference.
The identification of this vulnerability is CVE-2026-78148. The attack may be launched remotely. There is no exploit available.
The pull request to fix this issue awaits acceptance.
https://vuldb.com/vuln/394535
A vulnerability classified as critical has been found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization.
This vulnerability was named CVE-2026-78147. The attack may be initiated remotely. There is no available exploit.
This vulnerability is distinct from CVE-2026-34159 (GHSA-j8rj-fmpv-wcxw, PR #20908), which only added a buffer==nullptr rejection in create_node() and does not validate op or op_params. The reported GitHub issue was closed automatically due to inactivity.
https://vuldb.com/vuln/394534
CyberLeek утверждает, что подготовил аварийный слив играбельного билда, если с источником что-нибудь случится.
https://www.securitylab.ru/news/576377.php