Skip to content
Threat Feed

Tag

Kernel-Vulnerability

10 briefs RSS
high advisory

Improper Access Control in Tonec Internet Download Manager Kernel Driver

CVE-2026-90493 is a local privilege escalation vulnerability in the Tonec Internet Download Manager idmwfp.sys kernel driver, allowing attackers with local access to manipulate improper access controls.

Internet Download Manager windows privilege-escalation kernel-vulnerability
1t 1c
high advisory

Local Privilege Escalation in PassMark Software Drivers

PassMark PerformanceTest, BurnInTest, and OSForensics contain a vulnerability in the DirectIo64.sys driver that allows local users to clear arbitrary physical memory bits, enabling privilege escalation.

PerformanceTest +2 privilege-escalation windows kernel-vulnerability
1t 1c
high advisory

Exposure of Certificate Authority Private Keys in IBM AIX and PowerVM VIOS

IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 contain intermediate CA private keys within publicly available update files, potentially allowing remote attackers to bypass security restrictions.

AIX +5 vulnerability cve-2026-15065 ibm security-bypass denial-of-service privilege-escalation kernel-vulnerability powervm
3t 1c updated
medium advisory

Integer Overflow in AMD KFD Driver

A 32-bit integer overflow vulnerability in the AMD KFD kernel driver allows for potential memory corruption during CWSR size calculations.

Linux kernel vulnerability linux-kernel amd denial-of-service kernel-vulnerability product-news
1c
medium advisory

NULL Pointer Dereference in Linux ath11k Wi-Fi Driver

CVE-2026-68362 describes a NULL pointer dereference vulnerability in the Linux kernel ath11k driver that may lead to denial-of-service or potential code execution via crafted interactions.

ath11k linux kernel-vulnerability denial-of-service vulnerability linux-kernel networking cve-2026-68355
1t 1c
medium advisory

Vulnerability in AMD Display Driver for Linux Kernel

A memory management flaw in the AMD display driver (drm/amd/display) for the Linux kernel allows for improper handling of DisplayPort Multi-Stream Transport (DP MST) configurations.

amdgpu vulnerability linux kernel informational product-news linux-kernel kernel-security kernel-vulnerability +1
1t 1c
medium advisory

Vulnerability in Linux KVM MMU Page Management

CVE-2026-64561 identifies a flaw in the Linux KVM hypervisor where incorrect validation of MMU pages could lead to memory management inconsistencies.

KVM vulnerability linux virtualization informational privilege-escalation kernel kernel-vulnerability arm64
1t 1c updated
high advisory

Linux Kernel MPLS NULL Pointer Dereference Vulnerability

A NULL pointer dereference vulnerability in the Linux kernel's MPLS subsystem, specifically affecting configurations where CONFIG_INET is disabled, can lead to a denial-of-service condition.

Linux Kernel vulnerability linux kernel informational stability cve filesystem product-news +13
2t 1c updated
high advisory

Kernel Local Privilege Escalation Vulnerability CVE-2026-17523

A critical local privilege escalation (LPE) vulnerability, tracked as CVE-2026-17523 and identified as an Expired Pointer Dereference (CWE-825), exists within the kernel, primarily affecting Red Hat Enterprise Linux 8, enabling an unprivileged local user to execute arbitrary code within the kernel, leading to root privileges and full control over the compromised system.

Red Hat Enterprise Linux 8 privilege-escalation kernel-vulnerability linux lpe cve
1t 1c
high advisory

Linux Kernel proc_readdir_de() Use-After-Free Local Privilege Escalation

A local privilege escalation vulnerability exists in the Linux Kernel versions ~3.14+ through 6.18-rc5 due to a use-after-free in the proc_readdir_de() function, where a concurrent traversal can dereference a freed entry's fields during network device unregistration, leading to privilege escalation via modprobe_path overwrite.

PoC Linux Kernel +2 local-privilege-escalation kernel-vulnerability use-after-free linux
2r 1t 1c 3i updated