CVE-2026-64361
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:17
- Zuletzt bearbeitet 04.09.2026 15:57:14
In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length check_and_correct_requested_length() compares (off + len) against node_size using u32 arithmetic. When the call...
CVE-2026-64360
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:16
- Zuletzt bearbeitet 04.09.2026 15:57:26
In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when check_and_co...
CVE-2026-64359
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:15
- Zuletzt bearbeitet 04.09.2026 15:57:39
In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers Syzbot reported a hung task in nilfs_transaction_begin() where multiple tasks performing chmod() on a nilfs2 m...
CVE-2026-64351
- EPSS 0.19%
- Veröffentlicht 25.07.2026 08:50:10
- Zuletzt bearbeitet 03.09.2026 16:03:31
In the Linux kernel, the following vulnerability has been resolved: net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() kalmia_rx_fixup() computes usb_packet_length = skb->len - (2 * KALMIA_HEADER_LENGTH) as a u16, guarded only by a pre-lo...
CVE-2026-64348
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:08
- Zuletzt bearbeitet 03.09.2026 16:03:56
In the Linux kernel, the following vulnerability has been resolved: usb: free iso schedules on failed submit EHCI and FOTG210 isochronous submits build an ehci_iso_sched before linking the URB to the endpoint queue, and keep the staged schedule in ...
CVE-2026-64347
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:08
- Zuletzt bearbeitet 03.09.2026 16:04:02
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler The OTG branch of composite_setup() falls back to the first configuration when none is selected: if (cdev->...
CVE-2026-64346
- EPSS 0.21%
- Veröffentlicht 25.07.2026 08:50:07
- Zuletzt bearbeitet 03.09.2026 16:04:10
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: Fix use-after-free in gadget_match_driver The udc structure acts as the management structure for the gadget, but their lifecycles are decoupled. A race condition ...
CVE-2026-64345
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:07
- Zuletzt bearbeitet 03.09.2026 16:01:24
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_printer: take kref only for successful open printer_open() returns -EBUSY when the character device is already open, but it increments dev->kref regardless of the re...
CVE-2026-64344
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:06
- Zuletzt bearbeitet 03.09.2026 16:01:33
In the Linux kernel, the following vulnerability has been resolved: USB: idmouse: fix use-after-free on disconnect race mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of object...
CVE-2026-64343
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:05
- Zuletzt bearbeitet 03.09.2026 16:01:39
In the Linux kernel, the following vulnerability has been resolved: USB: ldusb: fix use-after-free on disconnect race mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of objects ...