Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-14164
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may…
Patch available
MEDIUM 6.5
CVE-2026-43706
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS S…
Ipados
26.5.2+
HIGH 8.8
CVE-2026-53322
In the Linux kernel, the following vulnerability has been resolved:
vfio/pci: Clean up DMABUFs before disabling function
On device shutdown, make v…
Linux Kernel
7.0.10+
HIGH 7.8
CVE-2026-53294
In the Linux kernel, the following vulnerability has been resolved:
mailbox: mailbox-test: don't free the reused channel
The RX channel can be alia…
Linux Kernel
5.10.258 / 5.15.209+
HIGH 7.8
CVE-2026-53286
In the Linux kernel, the following vulnerability has been resolved:
idpf: fix double free and use-after-free in aux device error paths
When auxilia…
Linux Kernel
6.18.33 / 7.0.10+
HIGH 7.8
CVE-2026-53233
In the Linux kernel, the following vulnerability has been resolved:
netdev: fix double-free in netdev_nl_bind_rx_doit()
Sashiko flags that genlmsg_…
Linux Kernel
6.12.94 / 6.18.36+
HIGH 7.8
CVE-2026-53067
In the Linux kernel, the following vulnerability has been resolved:
PCI: endpoint: pci-ep-msi: Fix error unwind and prevent double alloc
pci_epf_al…
Linux Kernel
6.18.33 / 7.0.10+
HIGH 7.8
CVE-2026-53009
In the Linux kernel, the following vulnerability has been resolved:
ice: fix double-free of tx_buf skb
If ice_tso() or ice_tx_csum() fail, the erro…
Linux Kernel
7.0.10+
CRITICAL 9.8
CVE-2026-52993
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix double-free in tipc_buf_append()
tipc_msg_validate() can potentially …
Linux Kernel
5.10.258 / 5.15.209+
MEDIUM 6.5
CVE-2026-55653
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path…
Hardened Images
No fix yet
MEDIUM 6.8
CVE-2026-56109
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows at…
Patch available
HIGH 7.5
CVE-2026-11576
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label,…
Threadx Netx Duo
after 6.5.0.202601
HIGH 8.8
CVE-2026-12043
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a serv…
Mitigation only
MEDIUM 5.8
CVE-2026-46690
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB rea…
Unbounded Spsc
after 0.2.0
MEDIUM 5.0
CVE-2026-35188
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering
a crafted response through the status_request extension, triggering a
d…
OpenSSL
3.6.3+
HIGH 7.8
CVE-2026-46279
In the Linux kernel, the following vulnerability has been resolved:
mm/alloc_tag: clear codetag for pages allocated before page_ext initialization
…
Linux Kernel
6.18.27 / 7.0.4+
HIGH 8.8
CVE-2026-44422
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id…
Freerdp
3.26.0+
HIGH 7.8
CVE-2026-46189
In the Linux kernel, the following vulnerability has been resolved:
RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
Sashiko …
Linux Kernel
5.10.258 / 5.15.209+
HIGH 7.8
CVE-2026-46183
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/sysfs-schemes: protect path kfree() with damon_sysfs_lock
damon_sysfs_…
Linux Kernel
7.0.7+
HIGH 7.0
CVE-2026-46164
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix double free in create_space_info_sub_group() error path
When kobject…
Linux Kernel
6.2 / 6.6.141+
HIGH 7.8
CVE-2026-46162
In the Linux kernel, the following vulnerability has been resolved:
ice: fix double free in ice_sf_eth_activate() error path
When auxiliary_device_…
Linux Kernel
6.12.88 / 6.18.30+
HIGH 7.8
CVE-2026-46129
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix double free in create_space_info() error path
When kobject_init_and_…
Linux Kernel
6.1.175 / 6.6.140+
HIGH 7.8
CVE-2026-45920
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix dirtyclusters double decrement on fs shutdown
fstests test generic/38…
Linux Kernel
5.10.253 / 5.15.203+
HIGH 7.8
CVE-2026-45891
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: fix double free issue for tx spare buffer
In hns3_set_ringparam(), a…
Linux Kernel
5.15.202 / 6.1.165+
HIGH 7.8
CVE-2026-45852
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix double free in rxe_srq_from_init
In rxe_srq_from_init(), the queu…
Linux Kernel
5.10.259 / 5.15.210+
MEDIUM 5.9
CVE-2026-48850
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
Putty
0.84+
CRITICAL 9.8
CVE-2020-37239
libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature ove…
Mitigation only
HIGH 7.0
CVE-2026-34341
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.8
CVE-2026-33838
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
MEDIUM 6.7
CVE-2026-32170
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+