CVE-2024-36964
- EPSS 0.02%
- Veröffentlicht 03.06.2024 08:15:09
- Zuletzt bearbeitet 17.12.2025 03:28:54
In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2000 Garbage in plain 9P2000's perm bits is allowed through, which causes it to be able to set (among others) the suid bit. This w...
CVE-2024-36950
- EPSS 0.02%
- Veröffentlicht 30.05.2024 16:15:18
- Zuletzt bearbeitet 17.12.2025 03:29:40
In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: mask bus reset interrupts between ISR and bottom half In the FireWire OHCI interrupt handler, if a bus reset interrupt has occurred, mask bus reset interrupts until...
CVE-2024-36953
- EPSS 0.01%
- Veröffentlicht 30.05.2024 16:15:18
- Zuletzt bearbeitet 23.12.2025 19:16:51
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU that matches the user-provided CPUID, which (of course...
CVE-2024-36954
- EPSS 0.02%
- Veröffentlicht 30.05.2024 16:15:18
- Zuletzt bearbeitet 14.01.2025 16:27:50
In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when it fails, so move '*buf = NULL' after __skb_linearize(), so that the skb can be freed on...
CVE-2024-36957
- EPSS 0.03%
- Veröffentlicht 30.05.2024 16:15:18
- Zuletzt bearbeitet 23.12.2025 19:16:46
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: avoid off-by-one read from userspace We try to access count + 1 byte from userspace with memdup_user(buffer, count + 1). However, the userspace only provides buffer o...
CVE-2024-36940
- EPSS 0.02%
- Veröffentlicht 30.05.2024 16:15:17
- Zuletzt bearbeitet 10.01.2025 18:29:29
In the Linux kernel, the following vulnerability has been resolved: pinctrl: core: delete incorrect free in pinctrl_enable() The "pctldev" struct is allocated in devm_pinctrl_register_and_init(). It's a devm_ managed pointer that is freed by devm_p...
CVE-2024-36941
- EPSS 0.02%
- Veröffentlicht 30.05.2024 16:15:17
- Zuletzt bearbeitet 20.05.2025 15:16:04
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: don't free NULL coalescing rule If the parsing fails, we can dereference a NULL pointer here.
CVE-2024-36946
- EPSS 0.02%
- Veröffentlicht 30.05.2024 16:15:17
- Zuletzt bearbeitet 22.01.2026 20:03:40
In the Linux kernel, the following vulnerability has been resolved: phonet: fix rtm_phonet_notify() skb allocation fill_route() stores three components in the skb: - struct rtmsg - RTA_DST (u8) - RTA_OIF (u32) Therefore, rtm_phonet_notify() shoul...
CVE-2024-36929
- EPSS 0.01%
- Veröffentlicht 30.05.2024 16:15:16
- Zuletzt bearbeitet 22.01.2026 20:03:25
In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become invalid. Return NULL if such an skb is passed to skb_c...
CVE-2024-36933
- EPSS 0.01%
- Veröffentlicht 30.05.2024 16:15:16
- Zuletzt bearbeitet 22.01.2026 20:03:31
In the Linux kernel, the following vulnerability has been resolved: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). syzbot triggered various splats (see [0] and links) by a crafted GSO packet of VIRTIO_NET_HDR_GS...