- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:16
- Zuletzt bearbeitet 03.10.2026 11:18:06
In the Linux kernel, the following vulnerability has been resolved: fbdev: vfb: defer cleanup until the last reference FBIOGETCMAP takes a shallow snapshot of info->cmap and performs the usercopy after dropping info->lock. vfb_remove() frees the co...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:14
- Zuletzt bearbeitet 03.10.2026 11:18:06
In the Linux kernel, the following vulnerability has been resolved: ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink TUNSETLINK allows a TUN device to change its link-layer type to ARPHRD_IEEE802154 without initializing ieee802154_ptr. l...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:14
- Zuletzt bearbeitet 25.09.2026 11:17:11
In the Linux kernel, the following vulnerability has been resolved: ieee802154: cc2520: fix FIFOP work use-after-free The FIFOP interrupt handler queues cc2520_fifop_irqwork. On removal, cc2520_remove() only flushes the work. The devm-managed FIF...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:13
- Zuletzt bearbeitet 03.10.2026 11:18:06
In the Linux kernel, the following vulnerability has been resolved: ieee802154: hwsim: serialize pib updates to fix double-free hwsim_update_pib() does an unserialized read-swap-free of phy->pib: pib_old = rtnl_dereference(phy->pib); ... rcu_as...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:12
- Zuletzt bearbeitet 03.10.2026 11:18:06
In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: bound automatic table ID allocation fib_empty_table() probes every table ID from 1 until it finds a free one. IPv4 tables are stored in a 256-bucket hash table, so a de...
- EPSS 0.21%
- Veröffentlicht 25.09.2026 10:22:12
- Zuletzt bearbeitet 03.10.2026 11:18:06
In the Linux kernel, the following vulnerability has been resolved: ipv6: flowlabel: cap duplicate leases per socket ipv6_flowlabel_get() allocates an ipv6_fl_socklist entry for every successful GET. The recheck path for a compatible existing flowl...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:11
- Zuletzt bearbeitet 03.10.2026 11:18:06
In the Linux kernel, the following vulnerability has been resolved: ipvs: reject invalid states in connection template sync records IPVS sync receivers validate protocol states before creating or updating a connection. For connection templates, how...
CVE-2026-97594
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:22:10
- Zuletzt bearbeitet 03.10.2026 11:18:05
In the Linux kernel, the following vulnerability has been resolved: landlock: Fix use-after-free of the source's parent directory current_check_refer_path() reads old_dentry->d_parent without holding a reference nor a lock on it, and then dereferen...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:09
- Zuletzt bearbeitet 03.10.2026 11:18:05
In the Linux kernel, the following vulnerability has been resolved: s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm In function ctr_aes_crypt() there is a buffer used to process remaining bytes < AES_BLOCK_SIZE. This b...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:06
- Zuletzt bearbeitet 25.09.2026 11:17:09
In the Linux kernel, the following vulnerability has been resolved: perf: RISC-V: store available counter mask as bitmap The available-counter mask was a single unsigned long, but iteration uses RISCV_MAX_COUNTERS, which is 64. On RV32 that reads p...