- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:53
- Zuletzt bearbeitet 08.09.2026 09:18:19
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer free? If c...
CVE-2026-64412
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:52
- Zuletzt bearbeitet 08.09.2026 09:18:18
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-terminated We need to explicitly check the length, else we may pass non-null terminated string to request_module().
CVE-2026-64411
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:52
- Zuletzt bearbeitet 08.09.2026 09:18:18
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before find_table_lock() update_counters() and compat_update_counters() forward a user-supplied 32-byte table name to find_table_lock() wi...
CVE-2026-64408
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:49
- Zuletzt bearbeitet 04.09.2026 15:28:03
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to re...
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:47
- Zuletzt bearbeitet 04.09.2026 15:30:13
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference befo...
CVE-2026-64403
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:45
- Zuletzt bearbeitet 04.09.2026 14:45:32
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and immediately de...
CVE-2026-64400
- EPSS 0.2%
- Veröffentlicht 25.07.2026 08:50:43
- Zuletzt bearbeitet 04.09.2026 14:46:32
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting caseless retry ksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path resolution within the share root. When a crafted...
CVE-2026-64399
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:42
- Zuletzt bearbeitet 04.09.2026 14:46:44
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination file's data via vfs_clone_file_r...
CVE-2026-64398
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:42
- Zuletzt bearbeitet 04.09.2026 14:46:57
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA FSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via ksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after...
CVE-2026-64397
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:41
- Zuletzt bearbeitet 04.09.2026 14:47:10
In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY ...