A vulnerability categorized as critical has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal.
This vulnerability was named CVE-2026-7020. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical was found in Linux Kernel up to 6.18.7. This affects the function tty_port_link_device of the file drivers/tty/tty_io.c. The manipulation results in race condition.
This vulnerability is identified as CVE-2026-23115. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Linux Kernel up to 6.18.7. It has been rated as critical. This impacts the function fpsimd_restore_current_state of the component arm64. This manipulation causes state issue.
This vulnerability appears as CVE-2026-23114. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.9. This issue affects the function nvmet_tcp_build_pdu_iovec of the component nvmet-tcp. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2026-23112. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.121/6.12.67/6.18.7. Impacted is an unknown function. This manipulation causes denial of service.
This vulnerability is handled as CVE-2026-23113. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.199/6.1.162/6.6.123/6.12.69/6.18.9. Impacted is the function nft_map_catchall_activate of the component nf_tables. The manipulation results in improper update of reference count.
This vulnerability is known as CVE-2026-23111. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.18.9. This impacts the function ieee80211_ocb_rx_no_sta of the component OCB Interface. Performing a manipulation results in privilege escalation.
This vulnerability is reported as CVE-2025-71224. The attacker must have access to the local network to execute the attack. No exploit exists.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.123/6.12.69/6.18.9. The impacted element is the function smb2_open of the component smb. The manipulation leads to improper update of reference count.
This vulnerability is uniquely identified as CVE-2025-71223. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability marked as problematic has been reported in Apache HTTP Server up to 2.4.66. Impacted is an unknown function of the component .htaccess Handler. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2026-24072. An attack has to be approached locally. There is no exploit available.
It is suggested to upgrade the affected component.