CVE-2026-68392
- EPSS 0.13%
- Veröffentlicht 10.08.2026 12:04:11
- Zuletzt bearbeitet 23.08.2026 13:16:36
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Take hdev->lock for hc...
CVE-2026-68391
- EPSS 0.13%
- Veröffentlicht 10.08.2026 12:04:10
- Zuletzt bearbeitet 03.10.2026 11:17:36
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Use of hci_conn in...
CVE-2026-68389
- EPSS 0.26%
- Veröffentlicht 10.08.2026 12:04:08
- Zuletzt bearbeitet 17.08.2026 06:17:47
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on invalid dump size qca_controller_memdump() allocates qca->qca_memdump before processing the first dump packet. For a sequence-zero packet...
CVE-2026-68388
- EPSS 0.52%
- Veröffentlicht 10.08.2026 12:04:07
- Zuletzt bearbeitet 19.08.2026 17:20:47
In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current f...
- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:04:05
- Zuletzt bearbeitet 19.08.2026 17:20:47
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Reject unhashed UDP sockets on sockmap update UDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means sk_is_refcounted(unbound) = true, while sk_is_refcounted...
CVE-2026-68385
- EPSS 0.5%
- Veröffentlicht 10.08.2026 12:04:04
- Zuletzt bearbeitet 17.08.2026 06:17:47
In the Linux kernel, the following vulnerability has been resolved: s390/checksum: Fix csum_partial() without vector facility Currently csum_partial() calls csum_copy() with copy=false and dst=NULL. On machines without the vector facility, csum_cop...
CVE-2026-68383
- EPSS 0.13%
- Veröffentlicht 10.08.2026 12:04:02
- Zuletzt bearbeitet 17.08.2026 06:17:46
In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Keep scheduler timeline name alive The scheduler keeps a pointer to the timeline name, but q->name is freed with the exec queue while scheduler fences can still referen...
CVE-2026-68382
- EPSS 0.13%
- Veröffentlicht 10.08.2026 12:04:01
- Zuletzt bearbeitet 17.08.2026 06:17:46
In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Hold device ref until queue teardown completes GuC exec queue destruction can run asynchronously. If the final device put happens from a destroy worker, drmm cleanup ca...
CVE-2026-68381
- EPSS 0.46%
- Veröffentlicht 10.08.2026 12:03:59
- Zuletzt bearbeitet 17.08.2026 06:17:46
In the Linux kernel, the following vulnerability has been resolved: ksmbd: pin conn during async oplock break notification smb2_oplock_break_noti() and smb2_lease_break_noti() store a ksmbd_conn pointer in an async ksmbd_work and then queue that wo...
CVE-2026-68377
- EPSS 0.13%
- Veröffentlicht 10.08.2026 12:03:55
- Zuletzt bearbeitet 19.08.2026 17:20:47
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_tunnel_key: Defer dst_release to RCU callback Fix a race-condition use-after-free in tunnel_key_release_params(). The function releases the metadata_dst of the old ...