CVE-2026-31715
- EPSS 0.01%
- Veröffentlicht 01.05.2026 14:16:21
- Zuletzt bearbeitet 07.05.2026 06:16:04
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() The xfstests case "generic/107" and syzbot have both reported a NULL pointer dereference. The concurren...
CVE-2026-31716
- EPSS 0.01%
- Veröffentlicht 01.05.2026 14:16:21
- Zuletzt bearbeitet 06.05.2026 21:10:23
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate rec->used in journal-replay file record check check_file_record() validates rec->total against the record size but never validates rec->used. The do_action() jo...
CVE-2026-31701
- EPSS 0.01%
- Veröffentlicht 01.05.2026 14:16:20
- Zuletzt bearbeitet 06.05.2026 18:55:49
In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: take a reference on the USB device in create_card() The caiaq driver stores a pointer to the parent USB device in cdev->chip.dev but never takes a reference on it. The...
CVE-2026-31702
- EPSS 0.01%
- Veröffentlicht 01.05.2026 14:16:20
- Zuletzt bearbeitet 06.05.2026 18:44:52
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() In f2fs_compress_write_end_io(), dec_page_count(sbi, type) can bring the F2FS_WB_CP_DATA counter to zero, unblocking...
CVE-2026-31704
- EPSS 0.01%
- Veröffentlicht 01.05.2026 14:16:20
- Zuletzt bearbeitet 06.05.2026 20:46:54
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use check_add_overflow() to prevent u16 DACL size overflow set_posix_acl_entries_dacl() and set_ntacl_dacl() accumulate ACE sizes in u16 variables. When a file has many POSI...
CVE-2026-31705
- EPSS 0.06%
- Veröffentlicht 01.05.2026 14:16:20
- Zuletzt bearbeitet 06.05.2026 20:45:44
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() applies 4-byte alignment padding via memset() after writing each EA entry. The bounds check on buf_free_l...
CVE-2026-31706
- EPSS 0.05%
- Veröffentlicht 01.05.2026 14:16:20
- Zuletzt bearbeitet 06.05.2026 20:27:43
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() smb_inherit_dacl() trusts the on-disk num_aces value from the parent directory's DACL xattr and uses it to size a...
CVE-2026-31707
- EPSS 0.01%
- Veröffentlicht 01.05.2026 14:16:20
- Zuletzt bearbeitet 06.05.2026 20:26:38
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate response sizes in ipc_validate_msg() ipc_validate_msg() computes the expected message size for each response type by adding (or multiplying) attacker-controlled fie...
CVE-2026-31708
- EPSS 0.04%
- Veröffentlicht 01.05.2026 14:16:20
- Zuletzt bearbeitet 06.05.2026 20:25:14
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL and the default QUERY_INFO path. The QUER...
CVE-2026-31709
- EPSS 0.04%
- Veröffentlicht 01.05.2026 14:16:20
- Zuletzt bearbeitet 07.05.2026 06:16:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and id_mode_to_cifs_acl() derive a DACL pointer from a server-supplied dacloffset and then use ...