CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

794 vulnerabilities with CWE-617
CVE-2026-43344 MEDIUM
perf/x86/intel/uncore: Fix die ID init and look up bugs
CVSS 5.5
CVE-2026-43228 MEDIUM
hfs: Replace BUG_ON with error handling for CNID count checks
CVSS 5.5
CVE-2026-20450 MEDIUM
MediaTek chipset - Remote Denial of Service via Rogue Base Station
CVSS 6.5
CVE-2026-43046 MEDIUM
btrfs: reject root items with drop_progress and zero drop_level
CVSS 5.5
CVE-2026-31739 HIGH
crypto: tegra - Add missing CRYPTO_ALG_ASYNC
CVSS 8.8
CVE-2026-31567 MEDIUM
PM: sleep: Drop spurious WARN_ON() from pm_restore_gfp_mask()
CVSS 5.5
CVE-2026-41485 HIGH
Kyverno Controller Denial of Service via forEach Mutation Panic
CVSS 7.7
CVE-2026-34067 LOW
nimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatch
CVSS 3.1
CVE-2026-34066 MEDIUM
nimiq-blockchain: Peer-triggerable panic during history sync
CVSS 5.3
CVE-2026-34063 HIGH
network-libp2p: Peer can crash the node by opening discovery protocol substream twice
CVSS 7.5
CVE-2026-31451 MEDIUM
ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio
CVSS 5.5
CVE-2026-34069 MEDIUM
nimiq-consensus panics via RequestMacroChain micro-block locator
CVSS 5.3
CVE-2026-31415 MEDIUM
ipv6: avoid overflows in ip6_datagram_send_ctl()
CVSS 5.5
CVE-2026-34933 MEDIUM
Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon
CVSS 5.5
CVE-2026-31398 HIGH
mm/rmap: fix incorrect pte restoration for lazyfree folios
CVSS 7.8
CVE-2026-30867 MEDIUM
CocoaMQTT: Denial of Service via Reachable Assertion in `PUBLISH` Packet Parsing
CVSS 5.7
CVE-2026-34219 MEDIUM
libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow
CVSS 5.9
CVE-2026-33977 MEDIUM
FreeRDP: DoS via WINPR_ASSERT in IMA ADPCM audio decoder (dsp.c:331)
CVSS 6.5
CVE-2026-33952 MEDIUM
FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks
CVSS 6.5
CVE-2026-4046 HIGH
iconv crash due to assertion failure with untrusted input
CVSS 7.5
CVE-2026-5170 MEDIUM
Users could trigger a crash of mongod primaries during promotion to sharded
CVSS 5.3
CVE-2026-3119 MEDIUM
Authenticated query containing a TKEY record may cause named to terminate unexpectedly
CVSS 6.5
CVE-2026-23380 MEDIUM
tracing: Fix WARN_ON in tracing_buffers_mmap_close
CVSS 5.5
CVE-2026-23375 MEDIUM
mm: thp: deny THP for files on anonymous inodes
CVSS 5.5
CVE-2026-23356 MEDIUM
drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
CVSS 5.5
Details
Vulnerabilities 794