Product
Denial of Service Vulnerability in FreeIPA Migration Handler
1 rule 1 TTP 1 CVEAn unauthenticated remote denial-of-service vulnerability in FreeIPA, tracked as CVE-2026-73197, allows attackers to exhaust system memory by sending oversized form POST requests to the migration endpoint.
Integer Overflow Vulnerability in libvirt NodeGetFreePages RPC Handler
1 TTP 1 CVEAn integer overflow vulnerability (CVE-2026-18917) in the libvirt NodeGetFreePages RPC handler allows an unprivileged local user to trigger a heap buffer overflow and achieve potential local privilege escalation.
Code Injection Vulnerability in Perl DBI
1 TTP 1 CVEAn incomplete patch for CVE-2026-14380 introduced a code injection vulnerability (CWE-94) in the perl-DBI package for Red Hat Enterprise Linux 9 and 10, potentially allowing authenticated attackers to execute arbitrary code.
Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module
1 rule 1 TTP 1 CVEA file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.
Command Injection in PCP linux_sockets PMDA
1 TTP 1 CVEA command injection vulnerability (CVE-2026-16524) in the PCP linux_sockets PMDA allows local attackers to execute arbitrary commands by injecting shell metacharacters into the network.persocket.filter metric.
CVE-2026-64611: libcupsfilters Denial of Service via Malformed Printer Advertisement
1 TTP 1 CVEA high-severity denial of service vulnerability, CVE-2026-64611, exists in the `cfIEEE1284NormalizeMakeModel()` function of libcupsfilters, allowing a network-adjacent attacker to cause sustained CPU consumption and system unresponsiveness by broadcasting a specially crafted printer advertisement with an empty model field in the IEEE-1284 device ID.
PipeWire Vulnerability CVE-2026-5674 Allows Sandbox Escape and Arbitrary Code Execution
4 TTPs 1 CVEA critical vulnerability, CVE-2026-5674, exists in PipeWire, a multimedia server, enabling an attacker to escape sandboxed applications like Flatpak by exploiting its PulseAudio compatibility layer to load a malicious library, leading to arbitrary code execution outside the sandbox and potential system compromise.
CVE-2026-14476: SSSD AD GPO Provider Path Traversal to Root File Write and Authentication Bypass
5 TTPs 1 CVEA path traversal vulnerability (CVE-2026-14476) in SSSD's Active Directory Group Policy Object (AD GPO) provider allows an authenticated attacker with AD GPO management access to write arbitrary files outside the GPO cache directory with root privileges, leading to Kerberos configuration injection and potential authentication bypass on Red Hat Enterprise Linux systems.
CVE-2026-58384: GIMP PSD Parser Integer Overflow Leads to RCE/DoS
2 TTPs 1 CVEAn integer overflow vulnerability (CVE-2026-58384) exists in GIMP's PSD parser within the `read_RLE_channel()` function, leading to undersized heap allocations that can cause subsequent heap memory corruption, potentially resulting in denial of service or arbitrary code execution.
CVE-2026-58380: GIMP PNM Parser Off-by-One Error Leads to RCE
1 CVEA high-severity off-by-one error, CVE-2026-58380, in GIMP's PNM file format parser (specifically the `pnmscanner_gettoken()` function) allows an attacker to corrupt memory by crafting a malicious PNM file, potentially leading to denial of service or arbitrary code execution when the file is opened.