CVE-2026-90225
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:34
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: read llcp_sock->local under the socket lock in getsockopt nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and then dereferenced the cached pointer insid...
CVE-2026-90223
- EPSS 0.41%
- Veröffentlicht 17.09.2026 16:07:33
- Zuletzt bearbeitet 18.09.2026 18:17:46
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound SNL TLV parsing to the skb and add length checks nfc_llcp_recv_snl() walked the SNL TLV list using a u16 offset/length pair derived from skb->len, without bounding...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:32
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:32
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: hold a reference to the request skb during send_frame __pn533_send_async() publishes the command and then calls dev->phy_ops->send_frame(). Once dev->cmd is set, an inc...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:31
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Don't leak the extension cell pointer in the bounce payload The bounce_error_event() embeds the failed event in the bounce payload by pointing data.ext.ptr at it. When ...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:30
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix WARNING in res_to_rt syzbot reported a WARN_ON(!res->dev) in res_to_rt() triggered via addr_handler() during asynchronous address resolution: " WARNING: drivers/infi...
- EPSS 0.22%
- Veröffentlicht 17.09.2026 16:07:30
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Free debugfs on registration failure c4iw_alloc() creates the per-device debugfs tree (dev->debugfs_root via setup_debugfs()), but it is removed only in c4iw_remove(), ...
CVE-2026-90217
- EPSS 0.15%
- Veröffentlicht 17.09.2026 16:07:29
- Zuletzt bearbeitet 18.09.2026 18:17:46
In the Linux kernel, the following vulnerability has been resolved: bpf: Compare iterator types during state pruning An iterator stack slot can be MEM_RCU or PTR_UNTRUSTED. These states must not be equal, or the verifier can prune an unsafe path. ...
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:07:28
- Zuletzt bearbeitet 17.09.2026 17:17:16
In the Linux kernel, the following vulnerability has been resolved: mtd: ubi: Release device reference on busy detach ubi_detach_mtd_dev() obtains a device reference through ubi_get_device() before checking whether the UBI device is busy. The busy ...
- EPSS 0.18%
- Veröffentlicht 17.09.2026 16:07:28
- Zuletzt bearbeitet 17.09.2026 17:17:16
In the Linux kernel, the following vulnerability has been resolved: ubi: Fix rollback for explicit UBI device numbers ubi_init_attach() rolls back module initialization failures by scanning ubi_devices[0..i-1], where i is the mtd= parameter index. ...