Debian

Debian 13 (trixie)

17748 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 04.09.2026 15:12:43
  • Zuletzt bearbeitet 04.09.2026 16:18:02

In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: register input device after capabilities are set input_register_device() exposes the device to userspace immediately. In joycon_input_create() it was called before j...

Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 04.09.2026 15:12:42
  • Zuletzt bearbeitet 04.09.2026 16:18:02

In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: stop device IO before hid_hw_stop on probe failure nintendo_hid_probe() calls hid_device_io_start() before joycon_init() and joycon_leds_create(). If either fails, ...

Medienbericht
  • EPSS 0.18%
  • Veröffentlicht 04.09.2026 15:12:40
  • Zuletzt bearbeitet 04.09.2026 16:18:02

In the Linux kernel, the following vulnerability has been resolved: HID: ft260: fix stack-use-after-return write in I2C read race ft260_i2c_read() points dev->read_buf at a caller-supplied buffer (often an on-stack variable), arms a completion and ...

Medienbericht
  • EPSS 0.2%
  • Veröffentlicht 04.09.2026 15:12:39
  • Zuletzt bearbeitet 04.09.2026 16:18:02

In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix use-after-free in enable_sensor enable_sensor_store() can call set_power_report_state(), which dereferences sensor_inst->power_state and sensor_inst->repor...

Medienbericht
  • EPSS 0.18%
  • Veröffentlicht 04.09.2026 15:12:38
  • Zuletzt bearbeitet 04.09.2026 16:18:01

In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: fix use-after-free of inrange_timer on remove uclogic_remove() cancels the pen in-range timer and then stops the device: timer_delete_sync(&drvdata->inrange_timer);...

Medienbericht
  • EPSS 0.2%
  • Veröffentlicht 04.09.2026 15:12:37
  • Zuletzt bearbeitet 04.09.2026 16:18:01

In the Linux kernel, the following vulnerability has been resolved: HID: hyperv: validate initial device info bounds The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO messages that contain a HID descriptor followed by the report...

Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 04.09.2026 15:12:36
  • Zuletzt bearbeitet 04.09.2026 16:18:01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix LE list UAF on reset hci_cc_reset() clears the LE accept and resolving lists without taking hdev->lock. Other command-complete handlers serialize updates ...

Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 04.09.2026 15:12:35
  • Zuletzt bearbeitet 04.09.2026 16:18:01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: validate LE Set CIG Parameters response The Command Complete dispatch validates only the fixed part of the LE Set CIG Parameters response. After that part is ...

Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 04.09.2026 15:12:34
  • Zuletzt bearbeitet 04.09.2026 16:18:01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix accept list UAF during suspend hci_update_event_filter_sync() walks hdev->accept_list while sending a synchronous HCI command for each remote-wakeup device...

Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 04.09.2026 15:12:33
  • Zuletzt bearbeitet 04.09.2026 16:18:01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: zero the sockaddr before returning it in getname iso_sock_getname() fills a struct sockaddr_iso in place and returns its size without clearing it first, so bytes it...