CVE-2026-64450
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:20
- Zuletzt bearbeitet 03.09.2026 15:31:34
In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK blocks A broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its data area. tipc_get_gap_ack_blks() only verifies th...
CVE-2026-64449
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:19
- Zuletzt bearbeitet 03.09.2026 15:33:46
In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: bound slave read/write to the kern_buf size The SLAVE-path helpers buffer_to_user() and buffer_from_user() copy 'count' bytes into/out of the fixed-size kern_buf...
CVE-2026-64448
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:18
- Zuletzt bearbeitet 03.09.2026 15:34:28
In the Linux kernel, the following vulnerability has been resolved: smb: client: restrict implied bcc[0] exemption to responses without data area smb2_check_message() has a long-standing quirk that accepts a response whose calculated length is one ...
CVE-2026-64446
- EPSS 0.2%
- Veröffentlicht 25.07.2026 08:51:17
- Zuletzt bearbeitet 03.09.2026 15:38:01
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() supplicant_ie is a 256-byte array in struct security_priv. The WPA and WPA2 IE copy paths use: memcpy...
CVE-2026-64445
- EPSS 0.22%
- Veröffentlicht 25.07.2026 08:51:16
- Zuletzt bearbeitet 03.09.2026 15:39:31
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() OnAuth() has two bugs in the shared-key authentication path. When the Privacy bit is set, rtw_wep_decrypt() i...
CVE-2026-64444
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:15
- Zuletzt bearbeitet 03.09.2026 15:41:03
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a mal...
CVE-2026-64443
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:15
- Zuletzt bearbeitet 03.09.2026 17:27:37
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len...
CVE-2026-64442
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:14
- Zuletzt bearbeitet 03.09.2026 17:28:19
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: ...
CVE-2026-64441
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:51:13
- Zuletzt bearbeitet 03.09.2026 17:46:12
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() Three IE/attribute parsing functions have missing bounds checks. rtw_get_sec_ie() ...
CVE-2026-64440
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:13
- Zuletzt bearbeitet 03.09.2026 17:48:45
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handler() HT_caps_handler() iterates pIE->length bytes and writes into HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struc...