CVE-2026-64333
- EPSS 0.21%
- Veröffentlicht 25.07.2026 08:49:59
- Zuletzt bearbeitet 03.09.2026 16:04:29
In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The digi_write_inb_command() is supposed to wait for the write urb to become available or return an error, but instead it ...
CVE-2026-64331
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:49:58
- Zuletzt bearbeitet 03.09.2026 16:04:40
In the Linux kernel, the following vulnerability has been resolved: usbip: vudc: fix NULL deref in vep_dequeue() vep_alloc_request() wasn't initializing vrequest->udc, so cancellations on the FunctionFS AIO path were arriving in vep_dequeue without...
CVE-2026-64329
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:49:57
- Zuletzt bearbeitet 04.09.2026 14:50:26
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove The threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(), which on a connector-change event calls ucsi_conn...
CVE-2026-64330
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:49:57
- Zuletzt bearbeitet 04.09.2026 14:49:57
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() In svdm_consume_modes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array index without ...
CVE-2026-64324
- EPSS 0.2%
- Veröffentlicht 25.07.2026 08:49:52
- Zuletzt bearbeitet 04.09.2026 14:51:53
In the Linux kernel, the following vulnerability has been resolved: udf: validate free block extents against the partition length udf_free_blocks() checks the logical block number and count against the partition length, but drops the extent offset ...
CVE-2026-64323
- EPSS 0.21%
- Veröffentlicht 25.07.2026 08:49:51
- Zuletzt bearbeitet 04.09.2026 14:52:25
In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it ag...
CVE-2026-64322
- EPSS 0.21%
- Veröffentlicht 25.07.2026 08:49:50
- Zuletzt bearbeitet 04.09.2026 14:52:46
In the Linux kernel, the following vulnerability has been resolved: udf: validate sparing table length as an entry count, not a byte count udf_load_sparable_map() accepts a sparing table when sizeof(*st) + le16_to_cpu(st->reallocationTableLen) > ...
CVE-2026-64319
- EPSS 0.2%
- Veröffentlicht 25.07.2026 08:49:48
- Zuletzt bearbeitet 03.09.2026 15:49:13
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) an...
CVE-2026-64320
- EPSS 0.24%
- Veröffentlicht 25.07.2026 08:49:48
- Zuletzt bearbeitet 03.09.2026 15:49:04
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo...
CVE-2026-64317
- EPSS 0.21%
- Veröffentlicht 25.07.2026 08:49:47
- Zuletzt bearbeitet 08.09.2026 09:18:18
In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink components to the SL record get_symlink_chunk() and the SL handling in parse_rock_ridge_inode_internal() walk the variable-length components of a Ro...