Tag
#denial-of-service
Understanding and Defending Against CVE-2026-74742: A Linux Kernel Vulnerability in veth
CVE-2026-74742 is a vulnerability in the Linux kernel's veth (virtual Ethernet) driver. It causes a queue stall in multi-queue setups with GRO (Generic Receive Offload) enabled and no XDP (eXpress Data Path) program attached, leading to a potential denial-of-service (DoS). This analysis provides an in-depth look at the vulnerability, its exploitation mechanics, real-world impact, detection strategies, and defensive recommendations.
CVE-2026-72522: libexpat Vulnerability Allows Denial of Service
A medium-severity vulnerability (CVE-2026-72522) in libexpat before version 2.8.3 can lead to a denial-of-service (DoS) attack due to an out-of-bounds read and infinite loop during Unicode processing. This vulnerability has a CVSS score of 6.2 and is not currently being actively exploited. Affected products include libexpat versions prior to 2.8.3.