How an out-of-bounds read in MariaDB's .frm metadata parser can be turned into a forged C++ object with a fake vtable, reaching arbitrary code execution as the mariadbd process (MDEV-40571).
When started with --reranking, llama.cpp lets a remote attacker trigger a denial of service (std::bad_alloc, HTTP 500) via a negative top_n on POST /rerank (CVE-2026-52132).
A crafted GGUF file with an empty metadata key reaches an assertion in llama.cpp's gguf_reader::read and aborts the process. Affects any binary that loads GGUF files (CVE-2026-52131).
A deeply nested JSON schema exhausts the recursion stack in llama.cpp's grammar converter, crashing the server. Only POST /completions is affected (CVE-2026-52130).
An in-depth analysis of two vulnerabilities found in Netis MEX605 router firmware v2.00.06: OS command injection via the ping diagnostic tool, and DOM-based XSS in the NTP server configuration.
Analysis of an Integer Overflow (SMBGhost) and an uninitialized kernel memory leak (SMBleed) in the SMBv3.1.1 decompression routine, and a Pre-Auth RCE achieved by chaining the two bugs
Mounting a crafted btrfs image twice causes an rwsem_down_write_slowpath use-after-free because rwsem_owner_flags returns an already freed task_struct pointer.
A setxattr operation after mounting a crafted ext4 image causes a slab-out-of-bounds write in ext4_xattr_set_entry because a large old_size value is used in a memset call.
__btrfs_free_extent in fs/btrfs/extent-tree.c calls btrfs_print_leaf in a certain ENOENT case, leaking potentially sensitive register values to local users through dmesg.
ext4_empty_dir in fs/ext4/namei.c allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can return zero after a crafted ext4 image is mounted.
btrfs_root_node in fs/btrfs/ctree.c allows a NULL pointer dereference because rcu_dereference(root->node) can return zero when a crafted btrfs image is mounted.
A crafted btrfs image triggers a NULL pointer dereference in btrfs_verify_dev_extents because fs_devices->devices is mishandled inside find_device (fs/btrfs/volumes.c) in Linux kernels before 5.1.