- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:33:24
- Zuletzt bearbeitet 16.09.2026 11:17:14
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: fix null pointer dereference in usb_put_function_instance() usb_put_function_instance() attempts to dereference fd inside fi struct to get mod in uvc_alloc_inst() erro...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:33:24
- Zuletzt bearbeitet 17.09.2026 10:17:05
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but dev->state is checked after acquiring the lock....
CVE-2026-90018
- EPSS 0.44%
- Veröffentlicht 16.09.2026 10:33:23
- Zuletzt bearbeitet 16.09.2026 15:18:25
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() rtw_get_wps_attr() walks WPS attributes inside a WPS IE taken from a wireless management frame. For each can...
CVE-2026-90016
- EPSS 0.3%
- Veröffentlicht 16.09.2026 10:33:22
- Zuletzt bearbeitet 03.10.2026 11:17:45
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() rtw_restruct_wmm_ie() scans in_ie for a WMM IE with: while (i < in_len) { ... if (i + 5 < in_len && in_ie[i] == 0xDD...
CVE-2026-90017
- EPSS 0.35%
- Veröffentlicht 16.09.2026 10:33:22
- Zuletzt bearbeitet 16.09.2026 15:18:25
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() rtw_action_frame_parse() takes a frame_len parameter but never actually checks it before indexing into the frame body: ...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:33:21
- Zuletzt bearbeitet 16.09.2026 11:17:14
In the Linux kernel, the following vulnerability has been resolved: xhci: fix lost bounce buffers on TDs spanning several ring segments When a TD reaches a link TRB with data that is not aligned to the endpoint's wMaxPacketSize, xhci_align_td() sta...
CVE-2026-90013
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:20
- Zuletzt bearbeitet 03.10.2026 11:17:45
In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening options file The options files do not take the trace_array reference for the options they represent. This could cause a use-after-f...
CVE-2026-90012
- EPSS 0.63%
- Veröffentlicht 16.09.2026 10:33:19
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failure If RX mapping fails after TX mapping succeeds, __spi_map_msg() unmaps TX but leaves tx_sg_mapped set. If TX mapping fails on a...
CVE-2026-90011
- EPSS 0.83%
- Veröffentlicht 16.09.2026 10:33:18
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for the login payload iscsi_target_check_login_request() rejects a login PDU whose DataSegmentLength exceeds MAX_KEY_VALUE_PAIRS, but...
CVE-2026-90007
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:16
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Use rollback index when freeing MSI-X vectors pm8001_request_msix() unwinds previously registered handlers with free_irq() when request_irq() fails. The rollback loop...