CVE-2026-98173
- EPSS 0.33%
- Veröffentlicht 06.10.2026 08:44:17
- Zuletzt bearbeitet 07.10.2026 07:17:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the ...
- EPSS 0.17%
- Veröffentlicht 06.10.2026 08:44:16
- Zuletzt bearbeitet 06.10.2026 09:17:58
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbd_connection leak on cifs_get_tcp_session() error When an RDMA connection is successfully established via smbd_get_connection() but cifs_get_tcp_session() later...
CVE-2026-98171
- EPSS 0.51%
- Veröffentlicht 06.10.2026 08:44:15
- Zuletzt bearbeitet 07.10.2026 07:17:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling...
- EPSS 0.2%
- Veröffentlicht 06.10.2026 08:44:15
- Zuletzt bearbeitet 06.10.2026 09:17:58
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is insufficient. It allows iteration to continu...
CVE-2026-98169
- EPSS 0.43%
- Veröffentlicht 06.10.2026 08:44:14
- Zuletzt bearbeitet 07.10.2026 07:17:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_sna...
- EPSS 0.2%
- Veröffentlicht 06.10.2026 08:44:13
- Zuletzt bearbeitet 06.10.2026 09:17:58
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix reparse buffer bounds in cifs_query_reparse_point() In cifs_query_reparse_point(), the start >= end check before casting to struct reparse_data_buffer * only ensur...
- EPSS 0.22%
- Veröffentlicht 06.10.2026 08:44:12
- Zuletzt bearbeitet 06.10.2026 09:17:58
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix server->total_read for compound encrypted PDUs In receive_encrypted_standard(), server->total_read is left at the full decrypted frame size when walking sub-PDUs o...
CVE-2026-98164
- EPSS 0.19%
- Veröffentlicht 29.09.2026 13:17:53
- Zuletzt bearbeitet 07.10.2026 07:17:03
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are sh...
CVE-2026-98162
- EPSS 0.15%
- Veröffentlicht 25.09.2026 13:06:51
- Zuletzt bearbeitet 02.10.2026 20:43:57
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: smb2_tree_connect ksmbd_tree_conn_connect xa_store(&sess->tree_conns, tree_conn->i...
CVE-2026-98161
- EPSS 0.16%
- Veröffentlicht 25.09.2026 13:06:51
- Zuletzt bearbeitet 03.10.2026 11:18:38
In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the bio data and can later overwrite the error with a successfu...