CVE-2026-23318
- EPSS 0.02%
- Veröffentlicht 25.03.2026 10:27:12
- Zuletzt bearbeitet 23.04.2026 21:05:42
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of the validators table for UAC3 AC header descriptor is defined with the wrong protocol version UAC_VERSI...
CVE-2026-23315
- EPSS 0.02%
- Veröffentlicht 25.03.2026 10:27:10
- Zuletzt bearbeitet 23.04.2026 21:06:57
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() Check frame length before accessing the mgmt fields in mt76_connac2_mac_write_txwi_80211 in order to avoi...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:27:07
- Zuletzt bearbeitet 18.04.2026 09:16:18
In the Linux kernel, the following vulnerability has been resolved: net: usb: kaweth: validate USB endpoints The kaweth driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it ...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:27:02
- Zuletzt bearbeitet 18.04.2026 09:16:18
In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message When looking at the data in a USB urb, the actual_length is the size of the buffer passed to the dr...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:59
- Zuletzt bearbeitet 18.04.2026 09:16:18
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() l3mdev_master_dev_rcu() can return NULL when the slave device is being un-slaved from a VRF. All other callers deal with this, ...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:58
- Zuletzt bearbeitet 18.04.2026 09:16:18
In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled, cifs_set_cifscreds() logs the key payload and exposes the plaintext username and p...
- EPSS 0.03%
- Veröffentlicht 25.03.2026 10:26:57
- Zuletzt bearbeitet 27.04.2026 14:16:30
In the Linux kernel, the following vulnerability has been resolved: net: annotate data-races around sk->sk_{data_ready,write_space} skmsg (and probably other layers) are changing these pointers while other cpus might read them concurrently. Add co...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:56
- Zuletzt bearbeitet 18.04.2026 09:16:17
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop When a standalone IPv6 nexthop object is created with a loopback device (e.g., "ip -6 nexthop add id 100 dev l...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:54
- Zuletzt bearbeitet 18.04.2026 09:16:17
In the Linux kernel, the following vulnerability has been resolved: can: ucan: Fix infinite loop from zero-length messages If a broken ucan device gets a message with the message length field set to 0, then the driver will loop for forever in ucan_...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:53
- Zuletzt bearbeitet 18.04.2026 09:16:17
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix refcount leak for tagset_refcnt This leak will cause a hang when tearing down the SCSI host. For example, iscsid hangs with the following call trace: [130120.65271...