Six critical security vulnerabilities disclosed across Linux and open-source software

On 2026-08-25, six CVEs were disclosed covering security flaws in Linux kernel SCTP networking (CVE-2026-74586, 74587, 74588), CakePHP authentication (CVE-2026-77337), Unbound DNS validator (CVE-2026-33278), and Perl regex compilation (CVE-2026-8376). Vulnerabilities range from use-after-free memory errors to remote code execution and denial-of-service conditions.

22 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-74586: Linux kernel SCTP may use a removed network address

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74586 - linux The Linux kernel's SCTP networking code could keep a reference to a network address that had just been deleted, allowing later code to try to use it after it was freed. This could cause a crash… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The Linux kernel's SCTP networking code could keep a reference to a network address that had just been d

CVE-2026-74587: Linux kernel SCTP can trigger a crash after peer restart

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74587 - linux A part of the Linux operating system that handles SCTP network traffic could mistakenly use memory that has already been released when a connection is restarted. This may cause the system to… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec A part of the Linux operating system that handles SCTP network traffic could mistakenly use memory that has

CVE-2026-74588: Linux SCTP may crash after peer IP removal

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74588 - linux The networking part of the Linux kernel that handles the SCTP protocol could use a memory address that has already been freed when a peer’s IP address is removed. This can cause the system to… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The networking part of the Linux kernel that handles the SCTP protocol could use a memory address that has

CVE-2026-74591: Linux kernel file mapping could misplace data in memory

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74591 - linux A bug in the Linux kernel's file handling code could cause data to be stored at the wrong location in memory, leading to occasional crashes such as illegal instruction or segmentation faults.… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec A bug in the Linux kernel's file handling code could cause data to be stored at the wrong location in memo

CVE-2026-74597: Linux IPv6 tunneling can corrupt memory on malformed packets

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74597 - linux When a Linux server processes certain IPv6 tunnel error messages, leftover data from the outer packet can be mistakenly used while handling the inner packet. This can cause memory corruption,… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec When a Linux server processes certain IPv6 tunnel error messages, leftover data from the outer packet can

CVE-2026-74608: Linux SMB client can crash during network updates

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74608 - linux The SMB client code in the Linux kernel could access memory that has already been released when a network interface list is refreshed while a channel is being created. This can cause the system… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The SMB client code in the Linux kernel could access memory that has already been released when a networ

CVE-2026-74611: Linux kernel TLS handling may overwrite received data

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74611 - linux The Linux operating system’s core code that processes encrypted network traffic can mistakenly write data into the wrong memory area when a certain TLS 1.3 feature is used. This could cause… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The Linux operating system’s core code that processes encrypted network traffic can mistakenly write data in

CVE-2026-74612: Linux veth may expose kernel memory to apps

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74612 - linux The virtual Ethernet (veth) driver in Linux could miscalculate packet sizes after certain packet processing, causing it to copy extra data—including internal kernel pointers—into user… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The virtual Ethernet (veth) driver in Linux could miscalculate packet sizes after certain packet processing, causi

CVE-2026-74616: Linux XDP cloning can corrupt network packet data

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74616 - linux A bug in the Linux kernel's XDP feature could let specially crafted network traffic overwrite important packet information, potentially causing network services to behave incorrectly. The problem… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec A bug in the Linux kernel's XDP feature could let specially crafted network traffic overwrite importan

CVE-2026-74617: Linux operating system could mishandle device lock, causing freezes

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74617 - linux A part of the Linux operating system that communicates with certain hardware devices could start processing signals before it is fully set up, which may cause the system to freeze or crash.… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec A part of the Linux operating system that communicates with certain hardware devices could start processing

CVE-2026-74628: Linux X25 network code can crash when a connection closes

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74628 - linux The X25 network component in the Linux kernel could use memory that had already been freed when a timer fires, potentially causing the system to crash or become unstable. This happens when a… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The X25 network component in the Linux kernel could use memory that had already been freed when a timer fir

CVE-2026-74665: Linux kernel network packet size error can expose internal data

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74665 - linux A part of the Linux operating system that handles fast network traffic could miscalculate the size of certain large UDP messages, causing extra memory from the system core to be passed to… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec A part of the Linux operating system that handles fast network traffic could miscalculate the size of certain

CVE-2026-74669: Linux kernel ICMP processing could corrupt memory

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74669 - linux A coding mistake in the Linux kernel's handling of certain network error messages could let unexpected data overwrite memory, potentially causing crashes or instability. The issue occurs when the… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec A coding mistake in the Linux kernel's handling of certain network error messages could let unexpected

CVE-2026-74688: Linux SCTP module may use removed network connection

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74688 - linux A part of the Linux operating system that handles a network protocol called SCTP could try to send data using a network connection that has already been closed. This might cause the system to… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec A part of the Linux operating system that handles a network protocol called SCTP could try to send data us

CVE-2026-74705: Linux kernel UDP tunnel may free memory too early

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74705 - linux The Linux operating system’s core code that handles UDP tunnel traffic could release a piece of memory before it’s finished using it. This mistake can cause the system to crash or be manipulated… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The Linux operating system’s core code that handles UDP tunnel traffic could release a piece of memory

CVE-2026-74712: mlx5 driver can read beyond allocated memory

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74712 - linux The Linux kernel's mlx5 network driver may read a little extra data past the end of a memory block when setting up virtual devices. This could cause system instability or crashes, especially in… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The Linux kernel's mlx5 network driver may read a little extra data past the end of a memory block when

CVE-2026-74723: Linux Btrfs can crash on malformed compressed files

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74723 - linux The Btrfs file system in Linux may hit a memory error when it tries to read a specially crafted file that uses LZO compression but lacks proper headers. This can cause the system to stop… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The Btrfs file system in Linux may hit a memory error when it tries to read a specially crafted file that uses

CVE-2026-74727: OpenVPN kernel can unintentionally restore deleted connections

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74727 - linux A race condition in the Linux kernel's OpenVPN component could cause a connection that was supposed to be removed to be re‑added to internal tables. This can lead to the system accessing memory… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec A race condition in the Linux kernel's OpenVPN component could cause a connection that was supposed to b

CVE-2026-74730: Linux NFS server can crash when state cleanup is delayed

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-74730 - linux The Linux network file system (NFS) code could accidentally use memory that had already been released if a cleanup operation was postponed. This could cause the server to become unstable or stop… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #CVE #infosec The Linux network file system (NFS) code could accidentally use memory that had already been released i

CVE-2026-77337: CakePHP Authentication can be bypassed or overloaded

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-77337 Older versions of CakePHP's login system could be tricked into accepting a fake cookie, letting someone get into an account without a password and possibly slowing the server down. This affects versions before… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec If you are using the CakePHP Authentication plugin in versions before 2.11.2, 3.3.7, or 4.2.1, an attac

CVE-2026-33278: Unbound DNSSEC Validator Allows Remote Code Execution

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-33278 - unbound The Unbound DNS software used on Debian 11 has a weakness that could let an attacker cause it to return incorrect DNS information. This could disrupt network traffic or direct… Too many irrelevant or confusing CVEs? Use stackflag.com #unbound #RootDebian11 #CVE #infosec Unbound DNSSEC validation software has a vulnerability that could allow hackers to crash the system or e

CVE-2026-8376: Perl versions through 5.43.10 allow a heap overflow when compiling regex

stream:bsky-jetstreamother35d ago kagi ↗

CVE-2026-8376 - perl The Perl programming language included in Alpine Linux version 3.23 had a security weakness that could allow a malicious user to execute commands on the system or cause it to crash.… Too many irrelevant or confusing CVEs? Use stackflag.com #perl #RootAlpine323 #CVE #infosec A specific type of regular expression can cause a memory overflow in 32-bit versions of Perl, potentiall