MontaVista continually monitors the security community and customers for threats. We follow the community on CVE scoring (NVD) and set fix priority accordingly for affected products. Please view the following CVEs that have been remediated or are in process by clicking the CVE Year to the left or use the CVE Filters below.
For inquiries regarding Security Vulnerabilities, please see our Vulnerability Response Policy or email our PSIRT team security@mvista.com. Email messages and attachments can be encrypted using PGP and a MontaVista PSIRT PGP key, which is available for download here.
| CVE | Score | Severity | Package | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-35334 |
7.5 (i)
| HIGH | strongswan | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | 2026-07-13 |
| CVE-2026-54423 |
6.5 (i)
| MEDIUM | ironic | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control. | 2026-07-10 |
| CVE-2026-44918 |
8.7 (i)
| HIGH | ironic | OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. | 2026-07-10 |
| CVE-2026-15308 |
7.5 (i)
| HIGH | python | The incremental HTML parser (html.parser.HTMLParser) allows for CPUdenial-of-service through repeated unterminated markup declarations whenprocessing uncontrolled data. | 2026-07-09 |
| CVE-2026-56003 |
8.8 (i)
| HIGH | libxfont | A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server. | 2026-07-08 |
| CVE-2026-56002 |
8.8 (i)
| HIGH | libxfont | A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server. | 2026-07-08 |
| CVE-2026-56001 |
8.8 (i)
| HIGH | libxfont | A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont | 2026-07-08 |
| CVE-2026-56000 |
7.8 (i)
| HIGH | xorg-server xwayland | Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory. | 2026-07-08 |
| CVE-2026-60000 |
7.5 (i)
| HIGH | openssh | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication. | 2026-07-08 |
| CVE-2026-59999 |
7.5 (i)
| HIGH | openssh | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. | 2026-07-08 |