CVE-2026-68198
- EPSS 0.27%
- Veröffentlicht 10.08.2026 12:00:16
- Zuletzt bearbeitet 23.08.2026 13:16:35
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_state() The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete T...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:00:15
- Zuletzt bearbeitet 19.08.2026 17:20:35
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on bss_desc->bcn_ht_cap being present, b...
CVE-2026-68196
- EPSS 0.42%
- Veröffentlicht 10.08.2026 12:00:14
- Zuletzt bearbeitet 19.08.2026 17:20:35
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: validate assoc response length before subtracting header wilc_parse_assoc_resp_info() computes the trailing IE length as ies_len = buffer_len - sizeof(*res); wit...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:00:13
- Zuletzt bearbeitet 19.08.2026 17:20:35
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and mt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:00:12
- Zuletzt bearbeitet 19.08.2026 17:20:35
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and mt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free...
CVE-2026-68192
- EPSS 0.41%
- Veröffentlicht 10.08.2026 12:00:10
- Zuletzt bearbeitet 19.08.2026 17:20:35
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: make release_scratchbuffers idempotent brcmf_pcie_release_scratchbuffers() frees the shared.scratch and shared.ringupd DMA buffers with dma_free_coherent() but does...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:00:07
- Zuletzt bearbeitet 19.08.2026 17:20:35
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() rtw_get_wps_ie() iterates over IE data from network frames without validating that the IE header and payload fit within the re...
CVE-2026-68189
- EPSS 0.16%
- Veröffentlicht 10.08.2026 12:00:01
- Zuletzt bearbeitet 19.08.2026 17:20:35
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UUID list traversal The hci_sync conversion moved class-of-device and EIR generation from an HCI request built under hdev->lock to asynchronous command...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:00:00
- Zuletzt bearbeitet 19.08.2026 17:20:35
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter der...
- EPSS 0.22%
- Veröffentlicht 10.08.2026 11:59:59
- Zuletzt bearbeitet 19.08.2026 17:20:34
In the Linux kernel, the following vulnerability has been resolved: exec: fix unsigned loop counter wrap in transfer_args_to_stack() The stop value is derived from bprm->p >> PAGE_SHIFT. The index variable is an unsigned long. If bprm->p drops belo...