- EPSS 0.18%
- Veröffentlicht 13.01.2026 15:29:23
- Zuletzt bearbeitet 14.07.2026 13:18:01
In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED), iloc.bh will remain set to NULL. Since ext4_xattr_inode_de...
CVE-2025-68818
- EPSS 0.28%
- Veröffentlicht 13.01.2026 15:29:22
- Zuletzt bearbeitet 30.07.2026 06:24:47
In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path" This reverts commit 0367076b0817d5c75dfb83001ce7ce5c64d803a9. The commit being reverted added code ...
CVE-2025-68819
- EPSS 0.13%
- Veröffentlicht 13.01.2026 15:29:22
- Zuletzt bearbeitet 30.07.2026 06:24:47
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() rlen value is a user-controlled value, but dtv5100_i2c_msg() does not check the size of the rlen value. Therefore, i...
- EPSS 0.18%
- Veröffentlicht 13.01.2026 15:29:20
- Zuletzt bearbeitet 14.07.2026 13:18:00
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, Validate format string parameters Add validation for format string parameters in the firmware tracer to prevent potential security vulnerabilities and crashes ...
CVE-2025-68815
- EPSS 0.13%
- Veröffentlicht 13.01.2026 15:29:19
- Zuletzt bearbeitet 30.07.2026 06:24:47
In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Remove drr class from the active list if it changes to strict Whenever a user issues an ets qdisc change command, transforming a drr class into a strict one, the et...
- EPSS 0.18%
- Veröffentlicht 13.01.2026 15:29:18
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix ipv4 null-ptr-deref in route error path The IPv4 code path in __ip_vs_get_out_rt() calls dst_link_failure() without ensuring skb->dev is set, leading to a NULL pointer de...
CVE-2025-68808
- EPSS 0.13%
- Veröffentlicht 13.01.2026 15:29:15
- Zuletzt bearbeitet 30.07.2026 06:24:46
In the Linux kernel, the following vulnerability has been resolved: media: vidtv: initialize local pointers upon transfer of memory ownership vidtv_channel_si_init() creates a temporary list (program, service, event) and ownership of the memory its...
- EPSS 0.18%
- Veröffentlicht 13.01.2026 15:29:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver After unbinding the driver, another kthread `cros_ec_console_log_work` is still accessing the device, resulting an UA...
- EPSS 0.38%
- Veröffentlicht 13.01.2026 15:29:11
- Zuletzt bearbeitet 30.07.2026 06:24:46
In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds that it is only ...
CVE-2025-68801
- EPSS 0.13%
- Veröffentlicht 13.01.2026 15:29:10
- Zuletzt bearbeitet 30.07.2026 06:24:45
In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_router: Fix neighbour use-after-free We sometimes observe use-after-free when dereferencing a neighbour [1]. The problem seems to be that the driver stores a pointe...