- EPSS 0.18%
- Veröffentlicht 16.09.2026 10:33:31
- Zuletzt bearbeitet 03.10.2026 11:17:45
In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on disconnect realtek_cr_destructor() calls timer_delete() before the chip containing the timer is freed. The timer callback may still ...
CVE-2026-90025
- EPSS 0.17%
- Veröffentlicht 16.09.2026 10:33:28
- Zuletzt bearbeitet 16.09.2026 15:18:25
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix OOB altmode array index The UCSI displayport driver indexes the connector's port altmode array with the GET_CURRENT_CAM response after checking i...
CVE-2026-90022
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:26
- Zuletzt bearbeitet 17.09.2026 10:17:05
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string attribute show path f_midi2_opts_str_show() takes the string lock internally, but its callers dereference the opts->info.<field> ...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:33:26
- Zuletzt bearbeitet 03.10.2026 11:17:45
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Previously fsg_num_buffers_validate() was removed as it was not necessary due to Kconfig s...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:33:25
- Zuletzt bearbeitet 16.09.2026 11:17:15
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_alloc() f_midi_alloc initializes free_ref to 1 and it can only be incremented when a sound card is registered via f_midi_register_car...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:33:24
- Zuletzt bearbeitet 16.09.2026 11:17:14
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: fix null pointer dereference in usb_put_function_instance() usb_put_function_instance() attempts to dereference fd inside fi struct to get mod in uvc_alloc_inst() erro...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:33:24
- Zuletzt bearbeitet 17.09.2026 10:17:05
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but dev->state is checked after acquiring the lock....
CVE-2026-90018
- EPSS 0.44%
- Veröffentlicht 16.09.2026 10:33:23
- Zuletzt bearbeitet 16.09.2026 15:18:25
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() rtw_get_wps_attr() walks WPS attributes inside a WPS IE taken from a wireless management frame. For each can...
CVE-2026-90016
- EPSS 0.3%
- Veröffentlicht 16.09.2026 10:33:22
- Zuletzt bearbeitet 03.10.2026 11:17:45
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() rtw_restruct_wmm_ie() scans in_ie for a WMM IE with: while (i < in_len) { ... if (i + 5 < in_len && in_ie[i] == 0xDD...
CVE-2026-90017
- EPSS 0.35%
- Veröffentlicht 16.09.2026 10:33:22
- Zuletzt bearbeitet 16.09.2026 15:18:25
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() rtw_action_frame_parse() takes a frame_len parameter but never actually checks it before indexing into the frame body: ...