- EPSS 0.2%
- Veröffentlicht 10.08.2026 11:59:38
- Zuletzt bearbeitet 23.08.2026 13:16:34
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: userspace: fix use-after-free in get_local_id In mptcp_pm_userspace_get_local_id(), the address entry is looked up under spinlock, but its id is read after dropping the ...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 11:59:33
- Zuletzt bearbeitet 19.08.2026 17:20:33
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: validate ranges in damon_set_regions() DAMON core logic assumes zero length regions don't exist. However, a few DAMON API callers including DAMON_SYSFS, DAMON_RECLA...
- EPSS 0.22%
- Veröffentlicht 10.08.2026 11:59:31
- Zuletzt bearbeitet 19.08.2026 17:20:33
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow overlapping input ranges for damon_set_regions() damon_set_regions() assumes the input ranges are sorted by the address and don't overlap each other. Hence...
CVE-2026-68162
- EPSS 0.16%
- Veröffentlicht 10.08.2026 11:59:29
- Zuletzt bearbeitet 23.08.2026 13:16:34
In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP ...
CVE-2026-68161
- EPSS 0.63%
- Veröffentlicht 10.08.2026 11:59:28
- Zuletzt bearbeitet 03.10.2026 11:17:35
In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardown proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when net.sctp.udp_port is set, and stops/restarts them when t...
CVE-2026-68160
- EPSS 0.76%
- Veröffentlicht 10.08.2026 11:59:26
- Zuletzt bearbeitet 19.08.2026 17:20:33
In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() ceph_handle_caps() reads snap_trace_len from the wire-format ceph_mds_caps header and uses it unconditional...
CVE-2026-68159
- EPSS 0.55%
- Veröffentlicht 10.08.2026 11:59:25
- Zuletzt bearbeitet 23.08.2026 13:16:34
In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allo...
CVE-2026-68158
- EPSS 0.7%
- Veröffentlicht 10.08.2026 11:59:24
- Zuletzt bearbeitet 19.08.2026 17:20:33
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode_new_up_state_weight() If a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted osdmap, out-of-bounds memory accesses ...
CVE-2026-68157
- EPSS 0.69%
- Veröffentlicht 10.08.2026 11:59:23
- Zuletzt bearbeitet 19.08.2026 17:20:32
In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_name...
CVE-2026-68156
- EPSS 0.68%
- Veröffentlicht 10.08.2026 11:59:22
- Zuletzt bearbeitet 19.08.2026 17:20:32
In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake....