CVE-2026-52986
- EPSS 0.55%
- Veröffentlicht 24.06.2026 16:29:00
- Zuletzt bearbeitet 08.09.2026 09:18:12
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strtoul Replace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(), and ct_sip_parse_request() with a new sip_parse_port()...
CVE-2026-52984
- EPSS 0.13%
- Veröffentlicht 24.06.2026 16:28:59
- Zuletzt bearbeitet 14.07.2026 16:47:58
In the Linux kernel, the following vulnerability has been resolved: net/sched: netem: fix queue limit check to include reordered packets The queue limit check in netem_enqueue() uses q->t_len which only counts packets in the internal tfifo. Packets...
CVE-2026-52985
- EPSS 0.12%
- Veröffentlicht 24.06.2026 16:28:59
- Zuletzt bearbeitet 14.07.2026 16:47:44
In the Linux kernel, the following vulnerability has been resolved: netdevsim: zero initialize struct iphdr in dummy sk_buff Syzbot reports a KMSAN uninit-value originating from nsim_dev_trap_skb_build, with the allocation also being performed in t...
CVE-2026-52981
- EPSS 0.53%
- Veröffentlicht 24.06.2026 16:28:57
- Zuletzt bearbeitet 14.07.2026 16:51:14
In the Linux kernel, the following vulnerability has been resolved: neigh: let neigh_xmit take skb ownership neigh_xmit always releases the skb, except when no neighbour table is found. But even the first added user of neigh_xmit (mpls) relied on n...
CVE-2026-52982
- EPSS 0.54%
- Veröffentlicht 24.06.2026 16:28:57
- Zuletzt bearbeitet 14.07.2026 16:49:22
In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb->len for tx statistics aft...
CVE-2026-52975
- EPSS 0.14%
- Veröffentlicht 24.06.2026 16:28:52
- Zuletzt bearbeitet 14.07.2026 16:52:32
In the Linux kernel, the following vulnerability has been resolved: bonding: 3ad: implement proper RCU rules for port->aggregator syzbot found a data-race in bond_3ad_get_active_agg_info / bond_3ad_state_machine_handler [1] which hints at lack of p...
CVE-2026-52972
- EPSS 0.14%
- Veröffentlicht 24.06.2026 16:28:50
- Zuletzt bearbeitet 17.08.2026 05:17:10
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Cap AEAD AD length to 0x80000000 In order to prevent arithmetic overflows when checking the TX buffer size, cap the associated data length to 0x80000000.
CVE-2026-52970
- EPSS 0.13%
- Veröffentlicht 24.06.2026 16:28:48
- Zuletzt bearbeitet 08.09.2026 09:18:12
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix missing expect put in obj eval nft_ct_expect_obj_eval() allocates an expectation and may call nf_ct_expect_related(), but never drops its local reference. A...
CVE-2026-52963
- EPSS 0.13%
- Veröffentlicht 24.06.2026 16:28:43
- Zuletzt bearbeitet 14.07.2026 16:17:50
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI endpoint descriptor scans snd_usbmidi_get_ms_info() validates the internal MIDIStreaming endpoint descriptor size before using baAssocJackID[], but the ...
CVE-2026-52962
- EPSS 0.14%
- Veröffentlicht 24.06.2026 16:28:42
- Zuletzt bearbeitet 14.07.2026 16:18:32
In the Linux kernel, the following vulnerability has been resolved: ceph: fix a buffer leak in __ceph_setxattr() The old_blob in __ceph_setxattr() can store ci->i_xattrs.prealloc_blob value during the retry. However, it is never called the ceph_buf...