CVE-2026-43407
- EPSS 0.54%
- Veröffentlicht 08.05.2026 14:21:46
- Zuletzt bearbeitet 21.05.2026 19:08:17
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This patch fixes an out-of-bounds access in ceph_handle_auth_reply() that can be triggered by a message of t...
CVE-2026-43405
- EPSS 0.49%
- Veröffentlicht 08.05.2026 14:21:45
- Zuletzt bearbeitet 21.05.2026 19:16:09
In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fixes unnecessary implicit conversions that change signedness of blob_len and num_mon in ceph_monmap_dec...
CVE-2026-43400
- EPSS 0.13%
- Veröffentlicht 08.05.2026 14:21:42
- Zuletzt bearbeitet 21.05.2026 19:27:02
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add upper bound check on user inputs in signal ioctl Huge input values in amdgpu_userq_signal_ioctl can lead to a OOM and could be exploited. So check these input valu...
CVE-2026-43398
- EPSS 0.13%
- Veröffentlicht 08.05.2026 14:21:40
- Zuletzt bearbeitet 21.05.2026 19:29:27
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add upper bound check on user inputs in wait ioctl Huge input values in amdgpu_userq_wait_ioctl can lead to a OOM and could be exploited. So check these input value ag...
CVE-2026-43387
- EPSS 0.12%
- Veröffentlicht 08.05.2026 14:21:33
- Zuletzt bearbeitet 26.05.2026 16:00:40
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: properly validate the data in rtw_get_ie_ex() Just like in commit 154828bf9559 ("staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser"), we don't t...
CVE-2026-43386
- EPSS 0.13%
- Veröffentlicht 08.05.2026 14:21:32
- Zuletzt bearbeitet 26.05.2026 16:03:02
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie The current code checks 'i + 5 < in_len' at the end of the if statement. However, it accesses 'in_ie[i +...
CVE-2026-43382
- EPSS 0.1%
- Veröffentlicht 08.05.2026 14:21:30
- Zuletzt bearbeitet 26.05.2026 17:15:10
In the Linux kernel, the following vulnerability has been resolved: batman-adv: Avoid double-rtnl_lock ELP metric worker batadv_v_elp_get_throughput() might be called when the RTNL lock is already held. This could be problematic when the work queue...
CVE-2026-43383
- EPSS 0.44%
- Veröffentlicht 08.05.2026 14:21:30
- Zuletzt bearbeitet 26.05.2026 17:07:21
In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.
CVE-2026-43381
- EPSS 0.12%
- Veröffentlicht 08.05.2026 14:21:29
- Zuletzt bearbeitet 26.05.2026 17:17:15
In the Linux kernel, the following vulnerability has been resolved: nouveau/dpcd: return EBUSY for aux xfer if the device is asleep If we have runtime suspended, and userspace wants to use /dev/drm_dp_* then just tell it the device is busy instead ...
CVE-2026-43378
- EPSS 0.31%
- Veröffentlicht 08.05.2026 14:21:27
- Zuletzt bearbeitet 20.05.2026 17:16:22
In the Linux kernel, the following vulnerability has been resolved: smb: server: fix use-after-free in smb2_open() The opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is dereferenced after rcu_read_unlock(), creating a use-after-free wind...