One invalidates a widely deployed cross-privilege defense; the other makes web-management reachability sufficient for root execution, although CISA's records conflict on the first fixed RouterOS release.
Public artifacts demonstrate the cross-privilege break end to end.
The Linux kernel cBPF JIT on x86 systems, demonstrated on stock Ubuntu 24.04.
Cross-privilege disclosure of arbitrary host memory from an unprivileged process
Deployed Spectre-v2 defenses no longer close this path: public artifacts demonstrate arbitrary host-memory recovery from an unprivileged process.
An unprivileged process that can install cBPF filters trains the dispatcher, frees its JIT allocation and forces controlled address reuse; a stale indirect-branch prediction then enters newly generated code at an obsolete or misaligned offset.
The demonstrated chain recovers KASLR state, follows kernel aliases into arbitrary process memory and extracts a live su process's root password hash in an average of three to five minutes on the tested systems.
The upstream Linux mitigation issues an indirect branch prediction barrier when a JIT allocation is reused.
The first two questions are unknown because this is a runtime kernel hardening change, not a documented artifact-revocation fix.
Web-management reachability is the only remote prerequisite established in the public record.
MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.
Unauthenticated arbitrary code execution as root
RouterOS takes the second slot over Firefox because its chain is established from one unauthenticated request to root, while Mozilla's advisory does not establish direct web reachability or host-operating-system execution for any listed flaw.
A crafted request body reaches an integer underflow before authentication and turns it into attacker-controlled execution as root.
CISA's remediation text says 7.23 or later, while its product-status data marks versions earlier than 7.24 affected; the first fixed release is therefore not settled in the public record.
The advisory is internally inconsistent: it marks all versions below 7.24 affected while recommending 7.23 or later as remediation.
Firefox, a cross-platform web browser.
Mozilla labels the flaws as sandbox escapes or privilege escalations, but its public advisory does not establish direct web delivery or host-operating-system execution for any individual CVE.
VMware vCenter Server, the virtualization-management appliance used by vSphere, VMware Cloud Foundation and related platforms.
A traversal-bearing RFC 5424 APP-NAME makes the dynamic rsyslog template write a root-owned cron entry outside its intended directory.
The operational change is public code documenting a tested root shell on vCenter 9.0.2.0.
Authlib, a Python OAuth, OpenID Connect and JOSE library used by web applications and microservices.
Authlib initializes verification as successful and performs zero signature checks, so a consumer that trusts the result can accept forged identity, authorization, inter-service or configuration claims.
No vendor patch or downstream application inventory was available in the reviewed material.
TeamViewer Full Client and Host, cross-platform remote-support clients on Windows, Linux and macOS.
Attacker-controlled access parameters override the target's configured feature permissions during session establishment.
TeamViewer says code execution can follow, but it does not identify the affected feature, resulting process or execution context.
nginx Open Source and NGINX Plus web, reverse-proxy and stream servers on affected configurations.
The attack applies only when a configuration evaluates a regex capture before an attacker-influenced regex map variable in the same two-pass buffer; we do not know how common that pattern is.
Public modes now use the shorter-capture path to disclose heap addresses and the longer-capture path to replace a cleanup pointer, ending in system() when the corrupted connection closes.
Viidure Dashcam Android Application, the Android companion app and cloud-storage client for Viidure dashcams
Anyone with the APK and internet access can recover permanent plaintext storage credentials and alter the shared binary store without a Viidure account.
Whether update clients independently reject modified artifacts remains unproven.
OsmAnd for Android, a navigation and offline-mapping application
Crafted intent extras silently replace map-tile or routing endpoints, sending viewed coordinates and route origins and destinations to an attacker-controlled service.
The current upstream manifest still exports the activity, but exact affected and fixed releases remain unknown.
Hitachi Energy RTU500 Series CMU firmware, used by substation remote terminal units.
Network reachability to the update endpoint is enough to submit attacker-selected firmware content.
Public code stops at a harmless marker payload: installation, boot and persistence on stock hardware remain unproven, and no corrected release was established for the end-of-life branches.
Eclipse ThreadX, an embedded real-time operating system used in microcontrollers and connected devices.
On builds with event tracing enabled, a user module can register its own trace-buffer-full callback and make privileged kernel code invoke it when the buffer wraps.
Affected and corrected ThreadX releases remain unknown because the linked vendor advisory was unavailable.
Poco M7 Plus 5G smartphones running Xiaomi HyperOS on the Qualcomm SM6375 platform.
The command injects androidboot.selinux=permissive through an unsanitized ABL parameter while the bootloader remains locked.
The demonstrated route needs physical USB access and a compatible root manager already installed, and the resulting root state ends at reboot.
FreeBSD jails, operating-system-level isolation on FreeBSD hosts.
A jailed process must first receive a directory descriptor from another jail; the variants then clear, lose or bypass FD_RESOLVE_BENEATH through fdescfs, renameat handling or SCM_RIGHTS passing.
Das U-Boot, an embedded bootloader used by network appliances and other devices, when built with CONFIG_IP_DEFRAG=y.
Exposure requires adjacent traffic during use of a CONFIG_IP_DEFRAG-enabled U-Boot network stack.
A duplicated final fragment reaches stale reassembly state, turns payload bytes into hole metadata and drives out-of-bounds writes that redirect control flow into attacker-supplied pkt_buff data.
WatchGuard Firebox network-security appliances running Fireware OS, including appliances serving adjacent wired or wireless networks.
A crafted unauthenticated DHCP packet triggers a stack overflow in Fireware OS fingerd, yielding code execution in the daemon context.
Unsloth and Unsloth Zoo, Python libraries used to load, fine-tune and serve machine-learning models.
When a workflow selects an attacker-controlled model, a newline-bearing model_type survives normalization, enters generated Python source and reaches exec().
WatchGuard Firebox network-security appliances running Fireware OS and configured as BOVPN over TLS clients.
The Firebox must already be configured to connect to the attacker-controlled server; improper certificate validation and code injection then turn server-supplied configuration into root commands.
PFU Image Scanner Driver for Linux, software supporting PFU fi Series and SP Series document scanners on Linux
The path requires an affected scanner driver, local access and user interaction with the vulnerable workflow.
The public record does not identify the workflow, the interacting user's role or whether either primitive reaches root.
U-Boot fragment reassembly now has an adjacent-network control-flow chain; Poco added a device-specific locked-bootloader root route with a preinstalled-manager prerequisite.
No recent BlueZ, NimBLE, Linux or Chrome item established a new radio-reachable attacker capability; the ESP-IDF primitives remain September 3 disclosures without a newer widening event.
Poco's USB route reaches temporary root only with a compatible manager already installed; PFU added local command and file-overwrite primitives whose execution identity remains unclear.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.