Fixes
Bugs I found or fixed in other people's code, and what happened next. In January I published that kernel bugs hide for years; in March I wrote the fixes for two twenty-year-olds. Every line links to the commit, CVE, or bug report, so you don't have to take my word for it.
fix I wrote the patch · reported / found my report, their fix ·confirmed real, fix pending · dup real, someone got there first
linux
- 2026-04-23reportednetfilter: nf_conntrack_sip: don't use simple_strtoul
- 2026-03-12fixnetfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case
- 2026-03-12fixnetfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
- 2026-03-11fixbpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN
- 2026-03-06fixnetfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()
- 2026-03-19reportedbpf: Fix sync_linked_regs regarding BPF_ADD_CONST32 zext propagation
- 2026-03-13fixpnfs/flexfiles: validate ds_versions_cnt is non-zero
- 2026-03-12fixnetfilter: xt_time: use unsigned int for monthday bit shift
qemu
ffmpeg
- 2026-03-24reportedavcodec/alsdec: fix abs(INT_MIN) UB in read_diff_float_data()
- 2026-03-23reportedavcodec/pngdec: fix dead overflow check in decode_text_to_exif()
- 2026-03-12foundavcodec/wmv2dec: More Checks about reading skip bits
- 2026-03-12foundavformat/matroskadec: Check audio.sub_packet_h * audio.frame_size
ghostscript
- 2026-03-12reportedisave.c: short truncation of struct offset in alloc_save_change_in() (line 488)
- 2026-03-12reportedpdf_deref.c: off-by-one bounds check + use-before-check + missing bounds checks in 3 functions
- 2026-03-12reportedpdf_image.c: int truncation in pdfi_get_image_data_size() causes incorrect image rendering
- 2026-03-12reportedHeap buffer overflow (11 bytes) in gsicc_set_device_profile_colorants() via 2-channel ICC profile
- 2026-03-12reportedzgeneric.c: packedarray_continue() not fixed for Bug 701550 — r_dec_size before push causes element skip
- 2026-03-12reportedgxfill.c: signed integer overflows in legacy scan converter (y_fast_max, band mask) — UBSan confirmed
- 2026-03-12reportedUse-after-free via refcount ordering in pdfi_copy_truetype_font() (pdf/pdf_fontTT.c:743)
- 2026-03-12reportedpdf_font.c: int64_t to int truncation of font buffer length in pdfi_load_font_buffer() and pdfi_load_font_file()
- 2026-03-11reportedPDF interpreter: filter bomb protection bypass via abbreviated filter names (pdf_file.c)
- 2026-03-11reportedHeap buffer overflow write in cmap_endfbrange_func() via mismatched bfrange code sizes (pdf/pdf_cmap.c)
- 2026-03-11reportedpdf_font1.c: missing fbuflen check before fbuf[0]/fbuf[1] access at line 542
- 2026-03-11reportedpdf_int.c: C operator precedence bug in 6 pdfi_set_error_stop() calls bypasses -dPDFSTOPONERROR
mupdf
- 2026-04-23reportedHeap OOB read in TTF cmap format 0/6 missing offset check (subset-ttf.c:531)
- 2026-04-23reportedHeap OOB read in CFF INDEX bounds check missing base offset (subset-cff.c:299)
- 2026-04-23reportedHeap OOB read in CFF charset format 0 missing bounds check (subset-cff.c:1475)
- 2026-04-23dupHeap OOB read in tiff_decode_tiles() via integer overflow in tile buffer size (load-tiff.c:670)
- 2026-04-23dupStack OOB in CFF charstring put/get off-by-one (subset-cff.c:1095)
libtiff
little-cms
libpng
mihomo
- 2026-06-05fixfix: socks4 readUntilNull unbounded memory allocation
- 2026-06-05fixfix: vision TLS filter out-of-bounds read via crafted session_id length
- 2026-06-05fixfix: trojan protocol WaitReadFrom panic via oversized UDP relay length field
- 2026-06-05fixfix: quic sniffer out-of-bounds read causes process crash via single UDP packet