SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

25 results for “kev-cve-2022-37042” · 1.67 s · cached

Facets · 1 entity types

25 CVE
CVE-2026-43331CVE

CVE-2026-43331

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments() function changes segment registers, invalidatin…

CVSS 5.5EPSS 0.1%linux
Match for kev-cve-2022-37042
CVE-2026-31553CVE

CVE-2026-31553

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva + offset" to get the virtual addresses of…

CVSS 8.8EPSS 0.2%
Match for kev-cve-2022-37042
CVE-2026-43402CVE

CVE-2026-43402

In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent use-after-free Guillaume reported crashes via corrupted RCU callback function …

CVSS 9.8EPSS 0.7%
Match for kev-cve-2022-37042
CVE-2026-31590CVE

CVE-2026-31590

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION Drop the WARN in sev_pin_memory() on npages overflowing an in…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2022-37042
CVE-2026-46082CVE

CVE-2026-46082

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inj…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2022-37042
CVE-2026-23112CVE

CVE-2026-23112

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU leng…

CVSS 9.8EPSS 0.4%linux
Match for kev-cve-2022-37042
CVE-2025-29922CVE

CVE-2025-29922

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting an object vi…

CVSS 9.6EPSS 0.4%
Match for kev-cve-2022-37042
CVE-2026-34612CVE

CVE-2026-34612

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Exec…

CVSS 9.9EPSS 0.7%kestra
Match for kev-cve-2022-37042
CVE-2026-31558CVE

CVE-2026-31558

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a cpuid parameter whose type is int, so cp…

CVSS 8.8EPSS 0.2%
Match for kev-cve-2022-37042
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2022-37042
CVE-2026-47292CVE

CVE-2026-47292

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.5%microsoft
Match for kev-cve-2022-37042
CVE-2026-40938CVE

CVE-2026-40938

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's r…

CVSS 7.5EPSS 0.9%linuxfoundation
Match for kev-cve-2022-37042
CVE-2026-27112CVE

CVE-2026-27112

Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoints of both Kargo's legacy gRPC API and newer REST…

CVSS 9.9EPSS 0.8%
Match for kev-cve-2022-37042
CVE-2026-23742CVE

CVE-2026-23742

Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua…

CVSS 8.8EPSS 0.5%
Match for kev-cve-2022-37042
CVE-2026-33642CVE

CVE-2026-33642

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned …

CVSS 9.9EPSS 0.4%kovidgoyal
Match for kev-cve-2022-37042
CVE-2026-31432CVE

CVE-2026-31432

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as READ + QUERY_INFO(Security) is received,…

CVSS 8.8EPSS 0.6%linux
Match for kev-cve-2022-37042
CVE-2026-46221CVE

CVE-2026-46221

In the Linux kernel, the following vulnerability has been resolved: EDAC/versalnet: Fix device name memory leak The device name allocated via kzalloc() in init_one_mc() is assigned to dev->init_nam…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2022-37042
CVE-2026-39429CVE

CVE-2026-39429

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and…

CVSS 8.2EPSS 0.5%kcp
Match for kev-cve-2022-37042
CVE-2026-31234CVE

CVE-2026-31234

Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for distributed task coordination, lacks authentication…

CVSS 9.8EPSS 1.0%
Match for kev-cve-2022-37042
CVE-2022-48703CVE

CVE-2022-48703

In the Linux kernel, the following vulnerability has been resolved: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR In some case, the GDDV returns a package with a buffer…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2022-37042
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.