厂商发布
厂商对产品安全、配置或策略的更新说明。
-
Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel
This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information.
This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information.This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information.扩展字段
{ "author": "[email protected]", "bulletin_id": "2026-029-AWS", "content_type": "Important (requires attention)", "details": { "Bulletin ID": "2026-029-AWS", "Content Type": "Important (requires attention)", "Publication Date": "05/13/2026 18:45 PM PDT", "Scope": "AWS" }, "publication_detail": "05/13/2026 18:45 PM PDT", "scope": "AWS" } -
Ongoing updates on Copy.fail and variants
This is an ongoing issue. This bulletin will be updated as more information becomes available.
This is an ongoing issue. This bulletin will be updated as more information becomes available.This is an ongoing issue. This bulletin will be updated as more information becomes available.扩展字段
{ "author": "[email protected]", "bulletin_id": "2026-030-AWS", "content_type": "Important (requires attention)", "details": { "Bulletin ID": "2026-030-AWS", "Content Type": "Important (requires attention)", "Publication Date": "05/13/2026 10:00 PM PDT", "Scope": "AWS" }, "publication_detail": "05/13/2026 10:00 PM PDT", "scope": "AWS" } -
CVE-2026-8178 - Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
Amazon Redshift JDBC Driver is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs). We identified an issue in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An…
Amazon Redshift JDBC Driver is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs). We identified an issue in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. AnAmazon Redshift JDBC Driver is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs). We identified an issue in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An actor who can influence the connection URL could potentially execute code in the application context.扩展字段
{ "author": "[email protected]", "bulletin_id": "2026-028-AWS", "content_type": "Important (requires attention)", "details": { "Bulletin ID": "2026-028-AWS", "Content Type": "Important (requires attention)", "Impacted versions": "Amazon Redshift JDBC Driver < 2.2.2", "Publication Date": "2026/05/08 11:30 AM PDT", "Scope": "AWS" }, "publication_detail": "2026/05/08 11:30 AM PDT", "scope": "AWS" } -
CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP
FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424, where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware res…
FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424, where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware resFreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424, where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware reset).扩展字段
{ "author": "[email protected]", "bulletin_id": "2026-022-AWS", "content_type": "Important (requires attention)", "details": { "Bulletin ID": "2026-022-AWS", "Content Type": "Important (requires attention)", "Impacted versions": "FreeRTOS-Plus-TCP >=V4.0.0 AND <=V4.2.5, >=V4.3.0 AND <= V4.4.0", "Publication Date": "2026/04/29 12:20 PM PDT", "Scope": "AWS" }, "publication_detail": "2026/04/29 12:20 PM PDT", "scope": "AWS" } -
Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer Underflow
FreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. - CVE-2026-7422: Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own re…
FreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. - CVE-2026-7422: Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own reFreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. - CVE-2026-7422: Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own registered endpoints. - CVE-2026-7423: Integer underflow in the ICMP and ICMPv6 echo reply handlers allows an adjacent network device to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the field is large enough, resulting in a heap out-of-bounds read.扩展字段
{ "author": "[email protected]", "bulletin_id": "2026-021-AWS", "content_type": "Important (requires attention)", "details": { "Bulletin ID": "2026-021-AWS", "Content Type": "Important (requires attention)", "Impacted versions": ">=V4.0.0 AND <=V4.2.5, >=V4.3.0 AND <=V4.4.0", "Publication Date": "2026/04/29 12:00 PM PDT", "Scope": "AWS" }, "publication_detail": "2026/04/29 12:00 PM PDT", "scope": "AWS" } -
CVE-2026-7191- Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS
QnABot on AWS is an open-source solution that provides a multi-channel, multi-language conversational interface powered by Amazon Lex, Amazon OpenSearch Service, and optionally Amazon Bedrock.
QnABot on AWS is an open-source solution that provides a multi-channel, multi-language conversational interface powered by Amazon Lex, Amazon OpenSearch Service, and optionally Amazon Bedrock.QnABot on AWS is an open-source solution that provides a multi-channel, multi-language conversational interface powered by Amazon Lex, Amazon OpenSearch Service, and optionally Amazon Bedrock.扩展字段
{ "author": "[email protected]", "bulletin_id": "2026-020-AWS", "content_type": "Important (requires attention)", "details": { "Bulletin ID": "2026-020-AWS", "Content Type": "Important (requires attention)", "Impacted versions": "<=7.2.4", "Publication Date": "2026/04/27 13:15 PM PDT", "Scope": "AWS" }, "publication_detail": "2026/04/27 13:15 PM PDT", "scope": "AWS" } -
CVE-2026-6437 - Mount Option Injection in Amazon EFS CSI Driver
The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System.
The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System.The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System.扩展字段
{ "author": "[email protected]", "bulletin_id": "2026-016-AWS", "content_type": "Important (requires attention)", "details": { "Bulletin ID": "2026-016-AWS", "Content Type": "Important (requires attention)", "Impacted versions": "EFS CSI Driver <&equal; v3.0.0", "Publication Date": "2026/04/17 11:15 AM PDT", "Scope": "AWS" }, "publication_detail": "2026/04/17 11:15 AM PDT", "scope": "AWS" } -
CVE-2026-5747 - Out-of-bounds Write in Firecracker virtio-pci Transport
Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services.
Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services.Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services.扩展字段
{ "author": "[email protected]", "bulletin_id": "2026-015-AWS", "content_type": "Important (requires attention)", "details": { "Bulletin ID": "2026-015-AWS", "Content Type": "Important (requires attention)", "Impacted versions": "Firecracker >= 1.13.0 AND <= 1.14.3 AND 1.15.0", "Publication Date": "2026/04/07 15:30 PM PDT", "Scope": "AWS" }, "publication_detail": "2026/04/07 15:30 PM PDT", "scope": "AWS" }