CVE-2026-90048
- EPSS 0.51%
- Veröffentlicht 16.09.2026 10:33:44
- Zuletzt bearbeitet 28.09.2026 23:10:00
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() ni_create_attr_list() allocates a fixed buffer of al_aligned(record_size) (== record_size) bytes and then walks ever...
CVE-2026-90045
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:33:42
- Zuletzt bearbeitet 28.09.2026 23:10:00
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data stores a pointer to the submitting task's mm_struct, but does not currently hold a reference to it while async requests are pendi...
CVE-2026-90044
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:33:41
- Zuletzt bearbeitet 28.09.2026 23:10:00
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error path In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io() fails with an error other than -EIOCBQUEUED, the...
CVE-2026-90041
- EPSS 0.3%
- Veröffentlicht 16.09.2026 10:33:39
- Zuletzt bearbeitet 21.09.2026 14:17:28
In the Linux kernel, the following vulnerability has been resolved: HID: sony: clean up device list on probe failure sony_input_configured() adds some controllers to sony_device_list before HID core registers their input devices. input_register_dev...
CVE-2026-90037
- EPSS 0.46%
- Veröffentlicht 16.09.2026 10:33:36
- Zuletzt bearbeitet 21.09.2026 14:17:27
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lru reaping An nfs4_openowner left on nn->close_lru after its final CLOSE keeps its last closed stateid in oo_last_closed_stid, hol...
CVE-2026-90036
- EPSS 0.46%
- Veröffentlicht 16.09.2026 10:33:35
- Zuletzt bearbeitet 21.09.2026 14:17:27
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during blocked-lock reaping A bare lock owner -- its only remaining reference a blocked lock on nn->blocked_locks_lru -- holds a raw pointer to ...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:33:34
- Zuletzt bearbeitet 17.09.2026 10:17:06
In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: change kmalloc() to kzalloc() Change the kmalloc() calls in usb_mdc800_init() for irq_urb_buffer and download_urb_buffer to kzalloc(), avoiding potential stack ...
CVE-2026-90032
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:33:33
- Zuletzt bearbeitet 16.09.2026 15:18:26
In the Linux kernel, the following vulnerability has been resolved: media: usbtv: keep device alive while ALSA card exists The ALSA PCM callbacks store the driver state in pcm->private_data. An open PCM file can outlive USB disconnect because usbtv...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:33:33
- Zuletzt bearbeitet 16.09.2026 11:17:16
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() The snd_usbmidi_us122l_output() picks a count of 2 on anything slower than high speed and never relates it to ep->max_...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:33:32
- Zuletzt bearbeitet 17.09.2026 10:17:06
In the Linux kernel, the following vulnerability has been resolved: usb-storage: ene_ub6250: fix race between scan work and probe ene_ub6250_probe() calls usb_stor_probe2(), which starts the usb-storage infrastructure and schedules the delayed scan...