CVE-2026-31671
- EPSS 0.02%
- Veröffentlicht 24.04.2026 14:45:18
- Zuletzt bearbeitet 27.04.2026 20:11:39
In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_report() struct xfrm_user_report is a __u8 proto field followed by a struct xfrm_selector which means there is three "empty" bytes of padding, but...
CVE-2026-31669
- EPSS 0.09%
- Veröffentlicht 24.04.2026 14:45:17
- Zuletzt bearbeitet 27.04.2026 20:09:25
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability during RCU re...
CVE-2026-31670
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:45:17
- Zuletzt bearbeitet 27.04.2026 20:10:26
In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill events from being created Userspace can create an unlimited number of rfkill events if the system is so configured, while not consu...
CVE-2026-31668
- EPSS 0.07%
- Veröffentlicht 24.04.2026 14:45:16
- Zuletzt bearbeitet 27.04.2026 20:08:54
In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths in seg6 lwtunnel The seg6 lwtunnel uses a single dst_cache per encap route, shared between seg6_input_core() and seg6_output_cor...
CVE-2026-31667
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:45:15
- Zuletzt bearbeitet 27.04.2026 20:00:40
In the Linux kernel, the following vulnerability has been resolved: Input: uinput - fix circular locking dependency with ff-core A lockdep circular locking dependency warning can be triggered reproducibly when using a force-feedback gamepad with ui...
CVE-2026-31665
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:45:14
- Zuletzt bearbeitet 27.04.2026 20:00:05
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-after-free in timeout object destroy nft_ct_timeout_obj_destroy() frees the timeout object with kfree() immediately after nf_ct_untimeout(), without wait...
CVE-2026-31663
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:45:13
- Zuletzt bearbeitet 27.04.2026 19:59:32
In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto completes, xfrm_input_resume() calls dev_put() immediately on re-entry before the skb reaches transport_f...
CVE-2026-31664
- EPSS 0.02%
- Veröffentlicht 24.04.2026 14:45:13
- Zuletzt bearbeitet 27.04.2026 19:59:44
In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() build_expire() clears the trailing padding bytes of struct xfrm_user_expire after setting the hard field via memset_after(), but t...
CVE-2026-31662
- EPSS 0.07%
- Veröffentlicht 24.04.2026 14:45:12
- Zuletzt bearbeitet 27.04.2026 20:17:55
In the Linux kernel, the following vulnerability has been resolved: tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG The GRP_ACK_MSG handler in tipc_group_proto_rcv() currently decrements bc_ackers on every inbound group ACK, even when the sa...
CVE-2026-31660
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:45:11
- Zuletzt bearbeitet 27.04.2026 20:17:30
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: allocate rx skb before consuming bytes pn532_receive_buf() reports the number of accepted bytes to the serdev core. The current code consumes bytes into recv_skb and ma...