Database/Kernel, userspace & hypervisor
glibc (iconv): Out-of-bounds write in the ISO-2022-CN-EXT iconv converter - turns PHP/app file-read bugs into RCE
CVSS 8.8CVE-2024-2961Kernel, userspace & hypervisorcurated
Impact
Out-of-bounds write in the ISO-2022-CN-EXT iconv converter - turns PHP/app file-read bugs into RCE
Who can reach it
Unauthenticated network (via an app) or local user
What to do
Package update + restart all consuming services
References
Related entries
- Linux kernel (drivers/iommu/intel): The VT-d I/O page-fault reporting path looks up the faulting device with noCVE-2024-35843 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu): A dropped return statement made the IOMMU fault handler process a partial PRICVE-2024-44994 · Linux kernel (drivers/iommu)High
- Linux kernel (arch/x86/kvm/vmx): KVM's guest/host-mode Intel PT virtualization was broken end to end and theCVE-2024-53135 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel mlx5_ib (pkey change notifier): A race between InfiniBand device deregistration and the pkey-change workCVE-2024-53224 · Linux kernel mlx5_ib (pkey change notifier)High
- Linux kernel (drivers/iommu/intel): Use-after-free of VT-d cache-tag objects. Device-TLB cache tags outlive the IOMMUCVE-2024-56669 · Linux kernel (drivers/iommu/intel)High
- OpenSSL: oversized AEAD IV in a CMS EnvelopedData message overflows a stack buffer before authenticationCVE-2025-15467 · OpenSSL CMS/PKCS#7 AEAD parameter parsing (3.0, 3.3-3.6)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.