CVE-2026-89788
- EPSS 0.19%
- Veröffentlicht 16.09.2026 08:48:25
- Zuletzt bearbeitet 16.09.2026 15:18:09
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_tree_connect() ksmbd_tree_conn_connect() publishes a new tree connection in sess->tree_conns with a single reference and returns i...
CVE-2026-89789
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:25
- Zuletzt bearbeitet 16.09.2026 15:18:09
In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free gtp_newlink()'s error path frees tid_hash and addr_hash without waiting for an RCU grace period aft...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:24
- Zuletzt bearbeitet 16.09.2026 09:17:09
In the Linux kernel, the following vulnerability has been resolved: ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() For casefolded encrypted directories ext4 stores an 8-byte hash trailer after the name (EXT4_DIRENT_...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:23
- Zuletzt bearbeitet 16.09.2026 09:17:09
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init ntfs_reparse_init() and ntfs_objid_init() parse the index root of the $Extend/$Reparse and $Extend/$ObjId metaf...
CVE-2026-89786
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:23
- Zuletzt bearbeitet 16.09.2026 15:18:08
In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-bounds read durin...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:22
- Zuletzt bearbeitet 16.09.2026 09:17:09
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 rpcb_register_inet4() and rpcb_register_inet6() store the result of rpc_sockaddr2uaddr() into map->r_addr w...
CVE-2026-89782
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:21
- Zuletzt bearbeitet 16.09.2026 15:18:08
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MAX entries During $LogFile replay, log_replay() indexes the transaction table by the transact_id taken from the log record header....
CVE-2026-89783
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:21
- Zuletzt bearbeitet 16.09.2026 15:18:08
In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full The depth check in xfrm6_input_addr() is off by one: if (1 + sp->len == XFRM_MAX_DEPTH) goto ...
CVE-2026-89781
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:20
- Zuletzt bearbeitet 16.09.2026 15:18:07
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off = lsn_to_page_off(log, lsn) + log->record_h...
CVE-2026-89779
- EPSS 0.21%
- Veröffentlicht 16.09.2026 08:48:19
- Zuletzt bearbeitet 16.09.2026 15:18:07
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a non-zero ef->size, ntfs_read_ea() only checks that the record fits in the remaining buffer (e...