VDB

GCVE-110-NCSC-2026-346

GCVE-110-NCSC-2026-346
Advisory PublishedCVSS 8.6/10
Vulnetix · Advisory published September 8, 2026
Multiple Linux kernel vulnerabilities, including the critical 'Copy Fail' flaw in the algif_aead crypto module causing privilege escalation and data corruption, were fixed by reverting to out-of-place operations, affecting various subsystems and vendors such as NetApp and SUSE.

Weaknesses (CWE)

CWE-190Integer Overflow or WraparoundCWE-140Improper Neutralization of DelimitersCWE-823Use of Out-of-range Pointer OffsetCWE-787Out-of-bounds WriteCWE-427Uncontrolled Search Path ElementCWE-732Incorrect Permission Assignment for Critical ResourceCWE-35Path Traversal: '.../...//'CWE-457Use of Uninitialized VariableCWE-476NULL Pointer DereferenceCWE-125Out-of-bounds ReadCWE-121Stack-based Buffer OverflowCWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-319Cleartext Transmission of Sensitive InformationCWE-272Least Privilege ViolationCWE-640Weak Password Recovery Mechanism for Forgotten PasswordCWE-1288Improper Validation of Consistency within InputCWE-94Improper Control of Generation of Code ('Code Injection')CWE-434Unrestricted Upload of File with Dangerous TypeCWE-489Active Debug CodeCWE-1188Initialization of a Resource with an Insecure DefaultCWE-620Unverified Password ChangeCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-306Missing Authentication for Critical FunctionCWE-331Insufficient EntropyCWE-770Allocation of Resources Without Limits or ThrottlingCWE-215Insertion of Sensitive Information Into Debugging CodeCWE-494Download of Code Without Integrity CheckCWE-23Relative Path Traversal

Risk Scores

CVSS 3.1
8.6/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
Siemensvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

562 records in the GCVE database · Updated September 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›