CVE-2026-64359
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:15
- Zuletzt bearbeitet 04.09.2026 15:57:39
In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers Syzbot reported a hung task in nilfs_transaction_begin() where multiple tasks performing chmod() on a nilfs2 m...
CVE-2026-64355
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:13
- Zuletzt bearbeitet 04.09.2026 15:58:46
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_fr...
CVE-2026-64352
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:11
- Zuletzt bearbeitet 03.09.2026 16:03:25
In the Linux kernel, the following vulnerability has been resolved: bpf: Allow LPM map access from sleepable BPF programs trie_lookup_elem() annotates its rcu_dereference_check() walks with only rcu_read_lock_bh_held(). Because rcu_dereference_che...
CVE-2026-64350
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:10
- Zuletzt bearbeitet 03.09.2026 16:03:46
In the Linux kernel, the following vulnerability has been resolved: usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() cdnsp_alloc_stream_info() allocates stream_info->stream_ctx_array with cdnsp_alloc_stream_ctx(). If a later s...
CVE-2026-64351
- EPSS 0.19%
- Veröffentlicht 25.07.2026 08:50:10
- Zuletzt bearbeitet 03.09.2026 16:03:31
In the Linux kernel, the following vulnerability has been resolved: net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() kalmia_rx_fixup() computes usb_packet_length = skb->len - (2 * KALMIA_HEADER_LENGTH) as a u16, guarded only by a pre-lo...
CVE-2026-64347
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:08
- Zuletzt bearbeitet 03.09.2026 16:04:02
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler The OTG branch of composite_setup() falls back to the first configuration when none is selected: if (cdev->...
CVE-2026-64348
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:08
- Zuletzt bearbeitet 03.09.2026 16:03:56
In the Linux kernel, the following vulnerability has been resolved: usb: free iso schedules on failed submit EHCI and FOTG210 isochronous submits build an ehci_iso_sched before linking the URB to the endpoint queue, and keep the staged schedule in ...
CVE-2026-64345
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:07
- Zuletzt bearbeitet 03.09.2026 16:01:24
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_printer: take kref only for successful open printer_open() returns -EBUSY when the character device is already open, but it increments dev->kref regardless of the re...
CVE-2026-64346
- EPSS 0.21%
- Veröffentlicht 25.07.2026 08:50:07
- Zuletzt bearbeitet 03.09.2026 16:04:10
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: Fix use-after-free in gadget_match_driver The udc structure acts as the management structure for the gadget, but their lifecycles are decoupled. A race condition ...
CVE-2026-64344
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:06
- Zuletzt bearbeitet 03.09.2026 16:01:33
In the Linux kernel, the following vulnerability has been resolved: USB: idmouse: fix use-after-free on disconnect race mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of object...