CVE-2026-68391
- EPSS 0.13%
- Veröffentlicht 10.08.2026 12:04:10
- Zuletzt bearbeitet 03.10.2026 11:17:36
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Use of hci_conn in...
CVE-2026-68388
- EPSS 0.52%
- Veröffentlicht 10.08.2026 12:04:07
- Zuletzt bearbeitet 19.08.2026 17:20:47
In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current f...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:04:05
- Zuletzt bearbeitet 19.08.2026 17:20:47
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Reject unhashed UDP sockets on sockmap update UDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means sk_is_refcounted(unbound) = true, while sk_is_refcounted...
CVE-2026-68377
- EPSS 0.13%
- Veröffentlicht 10.08.2026 12:03:55
- Zuletzt bearbeitet 19.08.2026 17:20:47
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_tunnel_key: Defer dst_release to RCU callback Fix a race-condition use-after-free in tunnel_key_release_params(). The function releases the metadata_dst of the old ...
CVE-2026-68376
- EPSS 0.48%
- Veröffentlicht 10.08.2026 12:03:54
- Zuletzt bearbeitet 19.08.2026 17:20:46
In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a ...
CVE-2026-68373
- EPSS 0.28%
- Veröffentlicht 10.08.2026 12:03:51
- Zuletzt bearbeitet 19.08.2026 17:20:46
In the Linux kernel, the following vulnerability has been resolved: wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() at76_guess_freq() checks only that the received frame is at least a bare 802.11 header (24 bytes) before subtracting...
CVE-2026-68371
- EPSS 0.18%
- Veröffentlicht 10.08.2026 12:03:49
- Zuletzt bearbeitet 23.08.2026 13:16:36
In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Do not put borrowed of_node in probe omap2430_probe() stores pdev->dev.of_node in a local np variable. This is a borrowed pointer and the probe function does n...
CVE-2026-68370
- EPSS 0.14%
- Veröffentlicht 10.08.2026 12:03:48
- Zuletzt bearbeitet 19.08.2026 17:20:46
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds a single shared usb_request (dum->fifo_req) that the "emulated single-request FIFO" fast-path in dum...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:03:46
- Zuletzt bearbeitet 19.08.2026 17:20:46
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: printer: fix infinite loop in printer_read() printer_read() uses the same variable for the requested copy size and the number of bytes actually copied to user space. c...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:03:45
- Zuletzt bearbeitet 19.08.2026 17:20:46
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length against frame_max but does not verify th...