CVE-2026-90093
- EPSS 0.15%
- Veröffentlicht 17.09.2026 16:06:06
- Zuletzt bearbeitet 18.09.2026 18:17:41
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/setsockopt Since commit b66774b48dd9 ("Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref") l2cap_chan::conn has hel...
- EPSS 0.35%
- Veröffentlicht 17.09.2026 16:06:05
- Zuletzt bearbeitet 18.09.2026 18:17:41
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan For L2CAP sockets without owning sk->sk_socket, reading l2cap_pi(sk)->chan may race against concurrent l2cap_soc...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:06:04
- Zuletzt bearbeitet 17.09.2026 17:17:00
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path btmtksdio_tx_packet() rounds the transfer size up to the SDIO block size of 256 bytes, but hands the host controller...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:06:03
- Zuletzt bearbeitet 17.09.2026 17:16:59
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop rfcomm_apply_pn() accepts the MTU value from a remote PN (Parameter Negotiation) frame without checkin...
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:06:02
- Zuletzt bearbeitet 17.09.2026 17:16:59
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: do not leak an hci_conn when a second LE connect is rejected create_le_conn_complete() decides whether the failed connection is still pending by comparing it against hci...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:00
- Zuletzt bearbeitet 17.09.2026 17:16:57
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: Only operate on Ethernet frames act_ife encapsulates/decapsulates the original Ethernet header and uses skb->dev->hard_header_len as the length of that header. ...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:00
- Zuletzt bearbeitet 17.09.2026 17:16:57
In the Linux kernel, the following vulnerability has been resolved: octeontx2-vf: fix workqueue and netdev race in probe/remove Initialize the VF workqueue before register_netdev() so ndo_set_rx_mode does not queue work on a NULL workqueue. Unregis...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:05:58
- Zuletzt bearbeitet 17.09.2026 17:16:57
In the Linux kernel, the following vulnerability has been resolved: net/rds: use wq_has_sleeper() in rds_cong_map_updated() rds_cong_map_updated() runs after a peer's congestion map has been rewritten (by rds_tcp_cong_recv() and rds_ib_cong_recv(),...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:05:56
- Zuletzt bearbeitet 17.09.2026 17:16:57
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbmod: fix length calculations and avoid invalid header warnings syzbot reported a warning in skb_network_header_len() triggered by tcf_skbmod_act(): !skb_transp...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:05:55
- Zuletzt bearbeitet 17.09.2026 17:16:56
In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: add overflow bounds to quantum and initial quantum fq_init() computes quantum = 2 * psched_mtu() and initial_quantum = 10 * psched_mtu() with no overflow check. A de...