CVE-2026-68354
- EPSS 0.29%
- Veröffentlicht 10.08.2026 12:03:31
- Zuletzt bearbeitet 19.08.2026 17:20:45
In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly fwnet_frag_new() keeps a sorted list of received fragments for a partial datagram. When a new fragment is adjacent to an existing ...
CVE-2026-68353
- EPSS 0.29%
- Veröffentlicht 10.08.2026 12:03:30
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() witho...
CVE-2026-68352
- EPSS 0.42%
- Veröffentlicht 10.08.2026 12:03:29
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx(...
- EPSS 0.22%
- Veröffentlicht 10.08.2026 12:03:28
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read When the firmware sends a command response with a length mismatch, carl9170_cmd_callback() logs the mismatch...
- EPSS 0.18%
- Veröffentlicht 10.08.2026 12:03:27
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix OOB read from off-by-two in TX status handler The bounds check in carl9170_tx_process_status() uses `i > ((cmd->hdr.len / 2) + 1)` which is off by two, allowing...
- EPSS 0.2%
- Veröffentlicht 10.08.2026 12:03:26
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix buffer overflow in rx_stream failover path The failover continuation in carl9170_rx_stream() copies the full tlen from the second USB transfer instead of cappin...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:03:20
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect uea_probe() distinguishes a pre-firmware device from a post-firmware one using the USB id (UEA_IS_PREFIRM...
CVE-2026-68343
- EPSS 0.52%
- Veröffentlicht 10.08.2026 12:03:19
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string ...
CVE-2026-68340
- EPSS 0.15%
- Veröffentlicht 10.08.2026 12:03:16
- Zuletzt bearbeitet 19.08.2026 17:20:43
In the Linux kernel, the following vulnerability has been resolved: hwmon: occ: validate poll response sensor blocks The OCC poll response parser walks a counted list of sensor data blocks. It used the static backing-array capacity as the parse bou...
CVE-2026-68338
- EPSS 0.18%
- Veröffentlicht 10.08.2026 12:03:14
- Zuletzt bearbeitet 19.08.2026 17:20:43
In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the pre...