CVE-2026-53216
- EPSS 0.5%
- Veröffentlicht 25.06.2026 08:39:19
- Zuletzt bearbeitet 02.07.2026 20:52:36
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PAGE_SIZE. The XDP path nevertheless initializes eve...
CVE-2026-53215
- EPSS 0.5%
- Veröffentlicht 25.06.2026 08:39:18
- Zuletzt bearbeitet 02.07.2026 20:52:41
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver still owns ...
CVE-2026-53213
- EPSS 0.12%
- Veröffentlicht 25.06.2026 08:39:17
- Zuletzt bearbeitet 02.07.2026 20:52:56
In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer passed to krealloc() with its return value without checking latter: MEM = krealloc(MEM, SZ, GFP);...
CVE-2026-53212
- EPSS 0.15%
- Veröffentlicht 25.06.2026 08:39:16
- Zuletzt bearbeitet 02.07.2026 20:53:00
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix use-after-free on object destroy nft_tunnel_obj_destroy() calls metadata_dst_free() which directly kfree()s the metadata_dst, ignoring the dst_entry refc...
CVE-2026-53208
- EPSS 0.12%
- Veröffentlicht 25.06.2026 08:39:14
- Zuletzt bearbeitet 02.07.2026 20:55:04
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig net/bluetooth/l2cap_core.c:l2cap_sig_channel() accepts BR/EDR signaling packets up to the channel MTU and dispatches e...
CVE-2026-53199
- EPSS 0.5%
- Veröffentlicht 25.06.2026 08:39:08
- Zuletzt bearbeitet 06.07.2026 12:32:29
In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf netvsc_copy_to_send_buf() copies page buffer entries into the VMBus send buffer using phys_to_virt() on the entry PFN. Ent...
CVE-2026-53198
- EPSS 0.44%
- Veröffentlicht 25.06.2026 08:39:07
- Zuletzt bearbeitet 06.07.2026 12:32:35
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL A deferred byte-range lock (an SMB2_LOCK that blocks) registers an async work on conn->async_requests via se...
CVE-2026-53196
- EPSS 0.26%
- Veröffentlicht 25.06.2026 08:39:06
- Zuletzt bearbeitet 18.09.2026 13:18:33
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device I2C EEPROM into a buffer allocated with kmalloc_o...
CVE-2026-53194
- EPSS 0.15%
- Veröffentlicht 25.06.2026 08:39:05
- Zuletzt bearbeitet 15.07.2026 01:16:30
In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_buffer() is called by the generic write path with the bulk-out buffer and its size (bulk_out_size, 64 b...
CVE-2026-53195
- EPSS 0.14%
- Veröffentlicht 25.06.2026 08:39:05
- Zuletzt bearbeitet 06.07.2026 12:36:28
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then cop...