CVE-2026-90153
- EPSS 0.45%
- Veröffentlicht 17.09.2026 16:06:46
- Zuletzt bearbeitet 18.09.2026 18:17:44
In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size smb_check_perm_dacl() validates that the DACL fits inside the NT security descriptor, but then bounds its two ACE walks by...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:45
- Zuletzt bearbeitet 17.09.2026 17:17:08
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_register() See the procedure below: smb2_sess_setup ksmbd_smb2_session_create __session_create atomic_set(&sess->...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:44
- Zuletzt bearbeitet 17.09.2026 17:17:07
In the Linux kernel, the following vulnerability has been resolved: pnfs/blocklayout: Fix device leaks on parse failure bl_parse_concat() and bl_parse_stripe() allocate a child device array and then parse each child in turn. If parsing a child fai...
CVE-2026-90151
- EPSS 0.74%
- Veröffentlicht 17.09.2026 16:06:44
- Zuletzt bearbeitet 18.09.2026 18:17:44
In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it finishes setting up the client. If any later in...
CVE-2026-90149
- EPSS 0.58%
- Veröffentlicht 17.09.2026 16:06:43
- Zuletzt bearbeitet 18.09.2026 18:17:44
In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers flexfiles accepts NFSv4.0 data servers, but two NFSv4 code paths assume the data server client has a session. Unlike ...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:42
- Zuletzt bearbeitet 17.09.2026 17:17:07
In the Linux kernel, the following vulnerability has been resolved: clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() devm_clk_get_optional_enabled_with_rate() registers its cleanup action before setting the clock rate. If setti...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:42
- Zuletzt bearbeitet 17.09.2026 17:17:07
In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() When nfs4_add_lease() races with a delegation return, it calls nfs4_delete_lease() to clean up. Prev...
CVE-2026-90145
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:06:41
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed Previously, hinic3_send_one_skb() cached the skb fragment count before calling hinic3_tx_offload...
CVE-2026-90146
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:06:41
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: bpf, xdp: move offload check into dev_xdp_install() bpf_xdp_link_update() calls dev_xdp_install() directly and skips dev_xdp_attach(), so the checks in dev_xdp_attach() do not run....
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:06:40
- Zuletzt bearbeitet 17.09.2026 17:17:07
In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL deref in dpll_device_ops() during teardown race When the last owner of a dpll device unregisters while a foreign driver still holds a pin on it via dpll_pin_on_pin_r...