CVE-2026-41035 In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka –xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

Information published.


CVE-2026-44608 Use after free and crash under special conditions in RPZ code

Information published.


CVE-2026-42959 Crash during DNSSEC validation of malicious content

Information published.


CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section

Information published.


CVE-2026-32792 Packet of death with DNSCrypt

Information published.


CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Information published.


CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

Information published.


CVE-2026-43352 i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue

Information published.


CVE-2026-31717 ksmbd: validate owner of durable handle on reconnect

Information published.


CVE-2026-41673 xmldom: Denial of service via uncontrolled recursion in XML serialization

Information published.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

AbuseIPDB Contributor Badge