๐ต๏ธ RESEARCH & DEEP DIVES
-
CVE-2026-45200: Double free in Imagination Graphics DDK _FreeOSPages affects driver versions 24.2-26.1
Imagination Technologies disclosed CVE-2026-45200, a double free in the Graphics DDK kernel driver's _FreeOSPages caused by incorrect allocation flags.- Affects Imagination Technologies Graphics DDK versions 24.2 RTM2, 25.1 RTM2, and 26.1 RTM1; 1.18, 23.2, and 26.1 RTM2 are unaffected
- A non-privileged local user can trigger a double free and kernel heap corruption via improper GPU driver IOCTL calls
- The bug stems from _EncodeAllocationFlags setting an incorrect allocation flag, so a crafted flag combination on the allocation interface causes _FreeOSPages to free the allocation twice
- Tracked as CWE-416 (Use After Free), assigned by Imagination Technologies, published 2026-09-04
๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Risky Bulletin: Russia tells data centers to deploy drone defenses โ Risky Business News
-
code-projects Hospital Information System addReq.php findBySearch sql injecti... โ CVE ThreatInt
-
GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSetKernel software... โ CVE ThreatInt
-
itsourcecode Sales and Inventory System inv_del.php sql injectionA flaw has b... โ CVE ThreatInt
-
light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode c... โ CVE ThreatInt
-
A Public-Key-Dependent Adversarial-Deletion Ceiling for Fixed-Alphabet Multi-Bit Pseudorandom Codes โ arXiv cs.CR
-
Privacy-Preserving Heterogeneous Multi-LLM Federated Inference for Cognitive Diagnosis โ arXiv cs.CR
-
PrivateHub: Contrastive Diffusion Model for Private Sensor-Intensive Environment Data Generation โ arXiv cs.CR
-
When Optimization Becomes Manipulation: Defending Generative Search against Malicious Generative Engine Optimization โ arXiv cs.CR
-
Privacy-Preserving Topology-Guided Safety for LLM-Based Multi-Agent Systems via Federated Graph Learning โ arXiv cs.CR
-
Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks โ arXiv cs.CR
-
Boundary-Mutation Testing for Pattern-Based Secret Detection: A Rule-Level Method and Cross-Scanner Evaluation โ arXiv cs.CR
-
Population-Calibrated Graph Screening at 835-Million-Address Scale, with Label-Free Transfer to New Chains โ arXiv cs.CR
-
Differentially private federated learning with Byzantine-robust aggregation: A cross-domain framework for secure model training in banking and healthcare systems โ arXiv cs.CR
-
A Bayesian Correlated Equilibrium for Early Insider-Threat Detection โ arXiv cs.CR
-
SecDT: A Profile-Based Security Layer for TRDP Communications โ arXiv cs.CR
-
Trust Me, I'm Your Developer: Self-Issued Authentication in Large Language Models โ arXiv cs.CR
-
Memetic Search for Supersingular Elliptic Curves over $\mathbb{F}_p$ โ arXiv cs.CR
-
After Cheap Discovery: From unknown to known-and-unfixed โ arXiv cs.CR
-
Long-Range Indirect Control-Flow Prediction in Stripped Binaries via Dual Virtual Hubs and Multi-Task Graph Learning โ arXiv cs.CR
-
Spruce: Scalable Private Outsourced Retrieval Using Compact Embeddings โ arXiv cs.CR
-
Privacy, Robustness, and Fairness Trade-offs in Federated Intrusion Detection: Geometric Indistinguishability at the Aggregation Interface โ arXiv cs.CR
-
The Native-Signature Boundary in Post-Quantum Distributed Authorization โ arXiv cs.CR
-
Security and Privacy in the Musical Metaverse: Threat Analysis and Design Implications โ arXiv cs.CR
-
AlcaTRAz - Anchored Tree-Rule Defense Against Jailbreaks โ arXiv cs.CR
-
OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests โ Cyber Security News
-
Botnet Takedowns Are Working โ But DDoS Operators Are Already Adapting โ Cyber Security News
๐ CVEs & KEV
- CVE-2026-85091 โ zlib โ CVSS 8.3 โ zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacatezlib versions 1....