Several recently identified dangerous vulnerabilities:
- Six vulnerabilities in the file synchronization utility rsync. The most critical issue (CVE-2026-29518), caused by a race condition when handling symbolic links, allows privilege escalation when running rsync in background mode without chroot isolation. The attack is executed by replacing a file with a symbolic link pointing to an arbitrary file in the system, after the check has been performed but before the write operation begins. The vulnerabilities have been fixed in rsync release 3.4.3. CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Vulnerabilities (CVE-2026-8631) in HPLIP, a set of open-source drivers for printers and MFPs, allowing privilege escalation and code execution in the system. The issues are caused by command substitution and buffer overflow vulnerabilities. The vulnerabilities have been addressed in HPLIP update 3.26.4. CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Vulnerabilities in the D-Bus service used in qSnapper, a graphical interface for managing Btrfs snapshots. The vulnerabilities can lead to privilege escalation in the system (CVE-2026-41046), leakage of information about changes between snapshots (CVE-2026-41047), and bypassing authentication when accessing Polkit (CVE-2026-41045). The most dangerous vulnerability is caused by a lack of checks for the '../' characters in paths passed to the snapper::Snapper() function when accessed via D-Bus, which can be exploited to replace the configuration file for libsnapper in the handler executed with elevated privileges.
CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch. - A vulnerability (CVE-2026-48095) in the 7-Zip archiver leads to a buffer overflow when processing compressed NTFS data. Potentially, this vulnerability could allow the attacker's code to be executed when accessing a specially crafted NTFS file system image through 7-Zip. The vulnerability has been fixed in version 7-Zip 26.01. CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- In the DNS server Unbound 1.25.1, 11 vulnerabilities have been fixed. The most dangerous vulnerabilities include: CVE-2026-33278 — potential remote code execution during DNSSEC validation, CVE-2026-44608 — accessing already freed memory in the RPZ code, and CVE-2026-42944 — heap overflow when processing nsid. CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- A vulnerability (CVE-2026-3593) in the BIND DNS server allows for a use-after-free memory access and corruption of memory contents by sending a specially crafted request to server DNS-over-HTTPS. The issue has been resolved in BIND versions 9.20.23 and 9.21.22. Configurations not using DNS-over-HTTPS are not affected. CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- A vulnerability (CVE-2026-47243) in Kata Containers, a stack for running containers using virtualization-based isolation, allows a user with root privileges in the container to create a symbolic link with root permissions on the host system. By creating a symbolic link in /etc/cron.d, it is possible to execute one's own code with root privileges in the host environment. The vulnerability is triggered by the possibility of sending a direct FUSE_SYMLINK request to the virtiofsd handler running on the host side. The issue manifests when using runtime-rs and has been fixed in release 3.31.0.
CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- A vulnerability (CVE-2026-46529) in the Atril document viewer leads to code execution by an attacker upon clicking a link within a specially crafted PDF file that combines a PDF document and library in ELF format. An exploit exists. A similar issue is present in the PDF viewers Evince and Xreader. The problem is caused by the lack of escaping special characters in shell quoting within the ev_spawn() function. The vulnerability has been addressed in Evince 48.2, Atril 1.28.4/1.26.3, and Xreader 4.6.4/3.6.7. CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- A vulnerability (CVE not assigned) in the Yelp help viewer (GNOME Help) allows access to the host system files by bypassing the sandbox environment of Flatpak packages through the opening of a specially crafted help file. The vulnerability resembles last year's problem and is characterized by using a CSS style substitution embedded in an SVG file. The issue has been fixed in Yelp release 49.1.
- A vulnerability (CVE-2026-41054) in haveged, the background process for generating entropy for a pseudorandom number generator, allows a user to escalate their privileges to the root user by sending a specially crafted command through a controlling Unix socket. The problem has been resolved in haveged release 1.9.21. CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- 11 vulnerabilities in the PostgreSQL DBMS, the most dangerous of which (CVE-2026-6637) can lead to code execution at the operating system level with the privileges of the PostgreSQL server process when specially crafted SQL queries are executed (the attacker must have unprivileged access to the DBMS). Another dangerous vulnerability (CVE-2026-6475) allows for file overwrites on server (e.g., /var/lib/postgres/.bashrc) through manipulation of symbolic links during operations with pg_basebackup and pg_rewind. Issues have been fixed in PostgreSQL releases 18.4, 17.10, 16.14, 15.18, and 14.23. A working exploit has also been published for the previously identified vulnerability (CVE-2026-2005) in the pgcrypto extension.
CVE in distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- The Suricata network intrusion detection and prevention system has identified 16 vulnerabilities, of which four are assigned a critical severity level. Details about the vulnerabilities are not yet publicly disclosed, but given their severity, they may allow remote code execution on the server when inspecting specially crafted traffic. The vulnerabilities have been mitigated in Suricata releases 8.0.5 and 7.0.16.
- A vulnerability (CVE-2026-8053) in MongoDB Server allows a user with write access to the database to initiate a buffer overflow and achieve code execution on the server with the privileges of the mongod process. The vulnerability has been fixed in MongoDB releases 5.0.33, 6.0.28, 7.0.34, 8.0.23, 8.2.9, and 8.3.2. CVEs in the distributions: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Ten vulnerabilities (CVE not assigned) in the Memcached in-memory data caching system, the most dangerous of which lead to buffer overflows when specially crafted requests are sent and could potentially be exploited for code execution on the server. The vulnerabilities have been fixed in Memcached version 1.6.42.
Source: opennet.ru
