In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | cve.org | 9.3 | — | — |
| 3.1 | Primary | cve.org | 9.3 | — | — |
| 3.1 | Primary | cve.org | 9.3 | — | — |
| 3.1 | Primary | cve.org | 9.3 | — | — |
| 3.1 | Primary | cve.org | 9.3 | — | — |
| 3.1 | Primary | cve.org | 9.3 | — | — |
| 3.1 | Primary | cve.org | 9.3 | — | — |
| 3.1 | Secondary | NVD | 9.3 | 3.9 | 4.7 |
| 3.1 | Secondary | GHSA | 9.3 | — | — |
| 3.1 | Secondary | ENISA EUVD | 9.3 | — | — |