Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · arm

arm

· 21 Critical

Total CVEs

196

Critical

21

Products

145

Search All CVEs →

196

Products (145)

mbed tls72 CVEsvalhall gpu kernel driver52 CVEsbifrost gpu kernel driver33 CVEs5th gen gpu architecture kernel driver25 CVEsmidgard gpu kernel driver18 CVEscortex-a728 CVEsmbed os7 CVEscortex-a736 CVEscortex-a72 firmware6 CVEscortex-a57 firmware6 CVEscortex-a576 CVEsmbed6 CVEsavalon gpu kernel driver6 CVEscortex-a77 firmware6 CVEscortex-a776 CVEscortex-a6 CVEscortex-a73 firmware6 CVEscortex-a785 CVEscortex-a78 firmware5 CVEscortex-a75 firmware5 CVEstf-psa-crypto5 CVEscortex-a755 CVEscortex-x2 firmware4 CVEscortex-x24 CVEscortex-x1 firmware4 CVEscortex-x14 CVEscortex-a78ae firmware4 CVEscortex-a78ae4 CVEscortex-a764 CVEsarm development studio4 CVEstrusted firmware-m4 CVEsneoverse n24 CVEscortex-a7104 CVEsmbed crypto4 CVEscortex-a76 firmware4 CVEsmali gpu kernel driver4 CVEscortex-a710 firmware4 CVEsneoverse n2 firmware4 CVEsvalhall gpu userspace driver3 CVEs5th gen gpu architecture userspace driver3 CVEsarm73 CVEsarm compiler3 CVEsarm compiler for embedded fusa3 CVEsarm compiler for functional safety3 CVEsbifrost gpu userspace driver3 CVEscortex-a76ae3 CVEscortex-a76ae firmware3 CVEscortex-x33 CVEscortex-x3 firmware3 CVEscortex-x43 CVEscortex-x4 firmware3 CVEscortex-x9253 CVEscortex-x925 firmware3 CVEsds development studio3 CVEsneoverse-v13 CVEsneoverse-v1 firmware3 CVEsneoverse-v23 CVEsneoverse-v2 firmware3 CVEsneoverse-v33 CVEsneoverse-v3 firmware3 CVEsneoverse-v3ae3 CVEsneoverse-v3ae firmware3 CVEsneoverse n13 CVEsneoverse n1 firmware3 CVEsscp firmware3 CVEstrusted firmware-a3 CVEsneoverse-e12 CVEsneoverse-e1 firmware2 CVEsc1-pro firmware2 CVEsc1-pro2 CVEscortex-a78c firmware2 CVEscortex-a532 CVEscortex-a53 firmware2 CVEsc1-ultra firmware2 CVEsc1-premium firmware2 CVEsc1-premium2 CVEsc1-ultra2 CVEscortex-a652 CVEscortex-a65 firmware2 CVEscortex-a65ae2 CVEscortex-a65ae firmware2 CVEscortex-a78c2 CVEscortex-r72 CVEsadaptive scalable texture compression encoder2 CVEscortex-r7 firmware2 CVEsarm trusted firmware2 CVEscortex-r82 CVEscortex-a15 firmware2 CVEscortex-a152 CVEscortex-r8 firmware2 CVEsfast models2 CVEsarm-trusted-firmware2 CVEslinaro forge1 CVEsbifrost android gralloc module1 CVEsavalon android gralloc module1 CVEsmbed-coap1 CVEsmbed-mqtt1 CVEsmbed-os1 CVEsarmv8-m firmware1 CVEsarmv8-m1 CVEsmbed studio1 CVEsmbed ualloc1 CVEsarm mobile studio1 CVEsmidguard gpu kernel driver1 CVEsneoverse-n21 CVEsneoverse-n2 firmware1 CVEsarm compiler for embedded1 CVEscortex-a551 CVEscortex-a55 firmware1 CVEscortex-a35 firmware1 CVEscortex-a351 CVEscortex-a34 firmware1 CVEsnn android neural networks driver1 CVEscortex-a32 firmware1 CVEscortex-a321 CVEscortex-a17 firmware1 CVEscortex-a171 CVEscortex-a12 firmware1 CVEscortex-a121 CVEscortex-a341 CVEscmsis-rtos1 CVEsclang1 CVEschina star-mc1 firmware1 CVEschina star-mc11 CVEscortex-a81 CVEscortex-a8 firmware1 CVEscortex-a91 CVEscortex-a9 firmware1 CVEscortex-m331 CVEscortex-m33 firmware1 CVEscortex-m35p1 CVEscortex-m35p firmware1 CVEscortex-m551 CVEscortex-m55 firmware1 CVEscortex-r1 CVEscortex-x1c1 CVEscortex-x1c firmware1 CVEsaarch64cryptolib1 CVEsarm1 CVEs5th gen gpu architecture firmware1 CVEsutgard gpu kernel driver1 CVEsvalhall android gralloc module1 CVEsvalhall gpu firmware1 CVEsgnu toolchain1 CVEskeil mdk1 CVEs

Recent Vulnerabilities

View all 196
CVE-2026-34877CRITICAL 9.8

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.

CVE-2026-34873CRITICAL 9.1

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

CVE-2026-34872CRITICAL 9.1

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).

CVE-2025-66442MEDIUM 5.1

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

CVE-2026-34874HIGH 7.5

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

CVE-2026-34871MEDIUM 6.7

An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

CVE-2026-25835HIGH 7.7

Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).

CVE-2026-25833HIGH 7.5

Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function

CVE-2026-34875CRITICAL 9.8

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

CVE-2026-25834MEDIUM 6.5

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

CVE-2026-0995LOW 3.6

An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesses related to SME.

CVE-2025-0647HIGH 7.9

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.

CVE-2025-8045MEDIUM 4.0

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r53p0 through r54p1; Arm 5th Gen GPU Architecture Kernel Driver: from r53p0 through r54p1.

CVE-2025-6349MEDIUM 5.1

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r53p0 through r54p1; Arm 5th Gen GPU Architecture Kernel Driver: from r53p0 through r54p1.

CVE-2025-2879MEDIUM 5.1

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to expose sensitive data.This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p4, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p4, from r50p0 through r54p0.

CVE-2025-59438MEDIUM 5.3

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

CVE-2025-54764MEDIUM 6.2

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.

CVE-2025-3212MEDIUM 5.3

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p4, from r50p0 through r51p0; Valhall GPU Kernel Driver: from r41p0 through r49p4, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p4, from r50p0 through r54p0.

CVE-2025-0932MEDIUM 4.3

Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to gain access to already freed memory.This issue affects Bifrost GPU Userspace Driver: from r48p0 through r49p3, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r48p0 through r49p3, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Userspace Driver: from r48p0 through r49p3, from r50p0 through r54p0.

CVE-2025-7427MEDIUM 5.9

Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio.

CVE-2025-49087MEDIUM 4.0

In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.

CVE-2025-47917HIGH 8.9

Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as an output argument. The documentation does not suggest that the function will free that pointer; however, the function does call mbedtls_asn1_free_named_data_list() on that argument, which performs a deep free(). As a result, application code that uses this function (relying only on documented behavior) is likely to still hold pointers to the memory blocks that were freed, resulting in a high risk of use-after-free or double-free. In particular, the two sample programs x509/cert_write and x509/cert_req are affected (use-after-free if the san string contains more than one DN).

CVE-2025-48965MEDIUM 4.0

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.

CVE-2025-52497MEDIUM 4.8

Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.

CVE-2025-52496HIGH 7.8

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.