Debian

Debian 13 (trixie)

17748 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.6%
  • Veröffentlicht 11.09.2026 19:46:15
  • Zuletzt bearbeitet 14.09.2026 13:19:20

In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This cause...

  • EPSS 0.2%
  • Veröffentlicht 11.09.2026 19:46:13
  • Zuletzt bearbeitet 14.09.2026 13:19:19

In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking owne...

  • EPSS 0.17%
  • Veröffentlicht 11.09.2026 19:46:12
  • Zuletzt bearbeitet 21.09.2026 14:17:25

In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type) block uncond...

  • EPSS 0.13%
  • Veröffentlicht 11.09.2026 19:46:11
  • Zuletzt bearbeitet 13.09.2026 07:17:34

In the Linux kernel, the following vulnerability has been resolved: nfsd: clear opcnt on compound arg release to prevent OOB read nfsd4_release_compoundargs() resets args->ops to the inline iops[8] array when the dynamically-allocated ops buffer is...

  • EPSS 0.16%
  • Veröffentlicht 11.09.2026 19:46:10
  • Zuletzt bearbeitet 13.09.2026 07:17:34

In the Linux kernel, the following vulnerability has been resolved: nfsd: defer vfree of compound ops to fix rpc_status UAF The rpc_status netlink dumpit walks every in-flight svc_rqst under rcu_read_lock and, for NFSv4 requests, reads opnums out o...

  • EPSS 0.61%
  • Veröffentlicht 11.09.2026 19:46:09
  • Zuletzt bearbeitet 13.09.2026 07:17:34

In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry In nfs4_preprocess_seqid_op() the stateid is obtained from nfsd4_lookup_stateid(), which holds a reference on t...

  • EPSS 0.43%
  • Veröffentlicht 11.09.2026 19:46:07
  • Zuletzt bearbeitet 21.09.2026 14:17:25

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but compares it again...

  • EPSS 0.67%
  • Veröffentlicht 11.09.2026 19:46:07
  • Zuletzt bearbeitet 13.09.2026 07:17:34

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding fi_lock when the parent stateid is a d...

  • EPSS 0.45%
  • Veröffentlicht 11.09.2026 19:46:06
  • Zuletzt bearbeitet 14.09.2026 13:19:19

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix cpntf publish race in nfs4_init_cp_state nfs4_alloc_init_cpntf_state() published the new cpntf entry into the s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock se...

  • EPSS 0.18%
  • Veröffentlicht 11.09.2026 19:46:05
  • Zuletzt bearbeitet 11.09.2026 20:19:55

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup nfsd_set_fh_dentry() leaks the dentry reference from exportfs_decode_fh_raw() when the NFS3_FHSIZE or NFS_FHSIZE switch...