- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:23:40
- Zuletzt bearbeitet 25.09.2026 11:17:30
In the Linux kernel, the following vulnerability has been resolved: bpf: mark a NULL call argument precise check_func_arg() allows bpf_register_is_null() for nullable arguments w/o marking the underlying scalar register precise. Hence a checkpoint ...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:39
- Zuletzt bearbeitet 25.09.2026 11:17:30
In the Linux kernel, the following vulnerability has been resolved: net: mctp: i3c: serialize probe with bus removal mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free...
CVE-2026-98017
- EPSS 0.13%
- Veröffentlicht 25.09.2026 10:23:39
- Zuletzt bearbeitet 03.10.2026 11:18:24
In the Linux kernel, the following vulnerability has been resolved: net/sched: defer qdisc freeing after failed creation An RTM_NEWQDISC request can make clsact bind a populated shared ingress block during ->init(), publishing an embedded mini_Qdis...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:38
- Zuletzt bearbeitet 03.10.2026 11:18:24
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free race in sample_restore_put() Concurrent teardown of TC sample rules sharing the same restore context may re-read restore->count after dropping restore...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:37
- Zuletzt bearbeitet 03.10.2026 11:18:24
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put In mlx5_eswitch_termtbl_put(), the zero-ref cleanup check reads tt->ref_count after termtbl_mutex has been releas...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:37
- Zuletzt bearbeitet 03.10.2026 11:18:24
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: E-Switch, prevent mc_list repopulation during vport disable In mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead of esw_vport_change_handle_locked() so vport...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:36
- Zuletzt bearbeitet 03.10.2026 11:18:24
In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_pie: clamp quantum in change path fq_pie_change() accepts any quantum value from userspace, including 1. With a crafted size table qdisc_pkt_len reaches ~2 GiB, so qu...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:35
- Zuletzt bearbeitet 03.10.2026 11:18:24
In the Linux kernel, the following vulnerability has been resolved: net/sched: sfq: clamp quantum in change path sfq_change() accepts any non-negative quantum (only rejects (int)ctl->quantum < 0). With a crafted size table qdisc_pkt_len reaches ~2 ...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:35
- Zuletzt bearbeitet 03.10.2026 11:18:24
In the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: clamp quantum in change and init paths hhf_change() accepts any quantum from userspace, including 1. With a crafted size table qdisc_pkt_len reaches ~2 GiB, so quan...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:34
- Zuletzt bearbeitet 03.10.2026 11:18:24
In the Linux kernel, the following vulnerability has been resolved: net/sched: drr: clamp quantum in change class drr_change_class() rejects explicit quantum==0 but falls back to psched_mtu() with no floor. With a crafted size table qdisc_pkt_len r...