Subscribe to Security Announcements

Stay updated with the latest security alerts and discover how Bigstack addresses security vulnerabilities.

Bigstack Security Advisories

Bigstack Security Advisories document remediation for security vulnerabilities that are reported in Bigstack products.

Filter
Advisory ID Product Severity CVE(s) Description Updated On
Advisory ID
Product
CubeCOS
Severity
Low
CVE(s)
CVE-2026-3195
Description
CVE-2026-3195 virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb
Updated On
2026-06-22
Product
CubeCOS
Severity
Low
CVE(s)
CVE-2026-43284, CVE-2026-43500
Description
Dirty Frag: A vulnerability in the Linux kernel network subsystem
Updated On
2026-06-11
Advisory ID
Product
CubeCOS
Severity
High
CVE(s)
CVE-2026-46333
Description
CVE-2026-46333 ssh-keysign-pwn: Linux Kernel Local Privilege Escalation Vulnerability
Updated On
2026-05-26
Advisory ID
Product
CubeCOS
Severity
Low
CVE(s)
CVE-2026-31635
Description
CVE-2026-31635 RxRPC: A vulnerability has been identified in the Linux Kernel’s Remote Procedure Call (RxRPC) protocol implementation (CONFIG_RXGK).
Updated On
2026-05-26
Advisory ID
Product
CubeCOS
Severity
Low
CVE(s)
CVE-2026-42945
Description
CVE-2026-42945 NGINX Rift: Heap buffer overflow vulnerability impacting ngx_http_rewrite_module
Updated On
2026-05-26
Advisory ID
Product
CubeCOS
Severity
High
CVE(s)
Copy Fail 2
Description
Copy fail 2: A Linux kernel local privilege escalation vulnerability has been found in the Linux kernel's algif_aead cryptographic algorithm interface.
Updated On
2026-05-14
Advisory ID
Product
CubeCOS
Severity
Low
CVE(s)
CVE-2026-43039
Description
Vulnerability in the ICSSG-PRUETH network driver within the Linux kernel
Updated On
2026-05-13
Advisory ID
Product
CubeCOS
Severity
High
CVE(s)
CVE-2026-31431
Description
Copy fail: A Linux kernel local privilege escalation vulnerability has been found in the Linux kernel's algif_aead cryptographic algorithm interface.
Updated On
2026-05-07
Advisory ID
Product
CubeCOS
Severity
Low
CVE(s)
CVE-2026-28386
Description
OpenSSL: Out-of-bounds read on x86-64 systems with AVX-512 support when using AES-CFB128 encryption
Updated On
2026-04-27
Advisory ID
Product
CubeCOS
Severity
Low
CVE(s)
CVE-2025-23048, CVE-2025-49812
Description
httpd: access control bypass by trusted clients is possible using TLS 1.3 session resumption
Updated On
2025-09-30

If you’ve discovered a vulnerability, please contact us.

To help us assess and address the issue, your report should include the following details:

  • A brief description of the vulnerability.
  • Affected product and version(s), if known.
  • Any potential workarounds or fixes.
  • Example code or proof of concept, if available.

Once we receive your report, our Security Team will review the information and get back to you as soon as possible.

Report Security Issue