CVE-2026-64438
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:11
- Zuletzt bearbeitet 03.09.2026 17:55:36
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() The VF2PF interrupt handler queues PF-side response work that stores a raw pointer to per-VF state (struct adf_acc...
CVE-2026-64436
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:10
- Zuletzt bearbeitet 03.09.2026 18:19:24
In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp states pfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by allocating x->calg and copying only the algorithm nam...
CVE-2026-64435
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:09
- Zuletzt bearbeitet 03.09.2026 18:20:28
In the Linux kernel, the following vulnerability has been resolved: audit: Fix data races of skb_queue_len() readers on audit_queue Multiple readers access audit_queue.qlen via skb_queue_len() without holding the queue lock or using READ_ONCE(), wh...
CVE-2026-64434
- EPSS 0.26%
- Veröffentlicht 25.07.2026 08:51:09
- Zuletzt bearbeitet 03.09.2026 18:22:07
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref l2cap_chan_timeout() runs asynchronously and accesses chan->conn. If the connection is torn down while the timer is...
CVE-2026-64429
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:06
- Zuletzt bearbeitet 03.09.2026 18:32:57
In the Linux kernel, the following vulnerability has been resolved: gpio: eic-sprd: use raw_spinlock_t in the irq startup path sprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller state through sprd_eic_update(), which takes sprd_...
CVE-2026-64425
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:03
- Zuletzt bearbeitet 08.09.2026 09:18:19
In the Linux kernel, the following vulnerability has been resolved: io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item commit 10dc95939817 ("io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop") fixed the obvious case where io_...
CVE-2026-64424
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:51:02
- Zuletzt bearbeitet 04.09.2026 15:53:06
In the Linux kernel, the following vulnerability has been resolved: netpoll: fix a use-after-free on shutdown path There is a use-after-free error on netpoll, which is clearly detected by KASAN. BUG: KASAN: slab-use-after-free in _raw_spin_l...
CVE-2026-64423
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:01
- Zuletzt bearbeitet 08.09.2026 09:18:19
In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: remove multicast group from hash table on device destruction When a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through the multicast list and calls ip...
CVE-2026-64422
- EPSS 0.19%
- Veröffentlicht 25.07.2026 08:51:00
- Zuletzt bearbeitet 08.09.2026 09:18:19
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes Reject invalid `net.ipv4.tcp_reordering` values before they reach TCP socket state. The sysctl is stored as an `in...
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:59
- Zuletzt bearbeitet 04.09.2026 15:16:48
In the Linux kernel, the following vulnerability has been resolved: mfd: cros_ec: Delay dev_set_drvdata() until probe success If ec_device_probe() fails, cros_ec_class_release releases memory for the cros_ec_dev structure. However, because the drvd...