CVE-2026-64443
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:15
- Zuletzt bearbeitet 03.09.2026 17:27:37
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len...
CVE-2026-64444
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:15
- Zuletzt bearbeitet 03.09.2026 15:41:03
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a mal...
CVE-2026-64442
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:14
- Zuletzt bearbeitet 03.09.2026 17:28:19
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: ...
CVE-2026-64440
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:13
- Zuletzt bearbeitet 03.09.2026 17:48:45
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handler() HT_caps_handler() iterates pIE->length bytes and writes into HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struc...
CVE-2026-64441
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:51:13
- Zuletzt bearbeitet 03.09.2026 17:46:12
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() Three IE/attribute parsing functions have missing bounds checks. rtw_get_sec_ie() ...
CVE-2026-64437
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:51:11
- Zuletzt bearbeitet 03.09.2026 18:04:26
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL") mad...
CVE-2026-64438
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:11
- Zuletzt bearbeitet 03.09.2026 17:55:36
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() The VF2PF interrupt handler queues PF-side response work that stores a raw pointer to per-VF state (struct adf_acc...
CVE-2026-64436
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:10
- Zuletzt bearbeitet 03.09.2026 18:19:24
In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp states pfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by allocating x->calg and copying only the algorithm nam...
CVE-2026-64434
- EPSS 0.26%
- Veröffentlicht 25.07.2026 08:51:09
- Zuletzt bearbeitet 03.09.2026 18:22:07
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref l2cap_chan_timeout() runs asynchronously and accesses chan->conn. If the connection is torn down while the timer is...
CVE-2026-64435
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:09
- Zuletzt bearbeitet 03.09.2026 18:20:28
In the Linux kernel, the following vulnerability has been resolved: audit: Fix data races of skb_queue_len() readers on audit_queue Multiple readers access audit_queue.qlen via skb_queue_len() without holding the queue lock or using READ_ONCE(), wh...