In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | NVD | 8.8 | 2.8 | 5.9 |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Primary | cve.org | 9.4 | — | — |
| 4.0 | Secondary | GHSA | 9.4 | — | — |
| 4.0 | Secondary | ENISA EUVD | 9.4 | — | — |
| 4.0 | Secondary | NVD | 9.4 | — | — |