CVE-2024-26585
- EPSS 0.59%
- Veröffentlicht 21.02.2024 15:15:09
- Zuletzt bearbeitet 04.08.2026 11:16:45
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls c...
CVE-2023-52440
- EPSS 21.91%
- Veröffentlicht 21.02.2024 08:15:45
- Zuletzt bearbeitet 15.08.2026 13:17:40
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in key exchange...
CVE-2023-52441
- EPSS 0.68%
- Veröffentlicht 21.02.2024 08:15:45
- Zuletzt bearbeitet 15.08.2026 13:17:41
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negotiate request s...
CVE-2023-52442
- EPSS 29.64%
- Veröffentlicht 21.02.2024 08:15:45
- Zuletzt bearbeitet 04.08.2026 10:18:27
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() will always return the first request smb2 header ...
CVE-2023-52436
- EPSS 0.3%
- Veröffentlicht 20.02.2024 21:15:08
- Zuletzt bearbeitet 15.08.2026 13:17:39
In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This eliminates the fragile assumption that the unused xattr space ...
CVE-2023-52438
- EPSS 0.3%
- Veröffentlicht 20.02.2024 21:15:08
- Zuletzt bearbeitet 04.08.2026 10:18:27
In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used during the shrinker's callback, which means that using alloc->vma pointer isn't safe as it can race with...
CVE-2023-52439
- EPSS 0.3%
- Veröffentlicht 20.02.2024 21:15:08
- Zuletzt bearbeitet 04.08.2026 10:18:27
In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 ------------------------------------------------------- uio_unregister_device uio_open idev = idr_find() device_unregister...
CVE-2023-52435
- EPSS 0.23%
- Veröffentlicht 20.02.2024 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:39:45
In the Linux kernel, the following vulnerability has been resolved: net: prevent mss overflow in skb_segment() Once again syzbot is able to crash the kernel in skb_segment() [1] GSO_BY_FRAGS is a forbidden value, but unfortunately the following co...
- EPSS 1.02%
- Veröffentlicht 20.02.2024 18:15:50
- Zuletzt bearbeitet 04.08.2026 10:18:26
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts(). This fixes following oops when...
CVE-2024-26581
- EPSS 2.22%
- Veröffentlicht 20.02.2024 13:15:09
- Zuletzt bearbeitet 01.10.2025 19:15:33
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end ...