- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:10
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: purge fragmented skbs during cleanup pn53x_common_clean() purges resp_q before freeing the common PN533 state, but it leaves fragment_skb untouched. The fragmentation ...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:09
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: add data_len bound checks to activation parameter extractors nci_extract_activation_params_iso_dep() and nci_extract_activation_params_nfc_dep() read an inner length byte...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:08
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix out-of-bounds write in nci_target_auto_activated() nci_target_auto_activated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and ...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:07
- Zuletzt bearbeitet 04.09.2026 16:18:05
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a notification into an on-stack ...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:05
- Zuletzt bearbeitet 04.09.2026 16:18:05
In the Linux kernel, the following vulnerability has been resolved: ipv4: reject undersized MTUs in ip_do_fragment() ip_do_fragment() subtracts the IPv4 header length from the effective MTU and passes the resulting payload MTU to ip_frag_next(). I...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:04
- Zuletzt bearbeitet 04.09.2026 16:18:05
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix use-after-free in ip6_finish_output2() ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmi...
- EPSS 0.21%
- Veröffentlicht 04.09.2026 15:13:03
- Zuletzt bearbeitet 04.09.2026 16:18:05
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation lengt...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:02
- Zuletzt bearbeitet 04.09.2026 16:18:05
In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: fix invalid free in LS IOD error path nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD array. If an rqstbuf allocation or response buffer DMA mappin...
- EPSS 0.23%
- Veröffentlicht 04.09.2026 15:13:01
- Zuletzt bearbeitet 04.09.2026 16:18:05
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: bound SGL data length before allocating command buffers nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length and, for the in-capsule offset descriptor (type...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:12:59
- Zuletzt bearbeitet 07.09.2026 15:17:32
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations When fuzzing the nvme target code, I tripped a kernel warning in nvmet_tcp_map_data() because the length pas...