CVE-2026-89626
- EPSS 0.32%
- Veröffentlicht 11.09.2026 19:45:22
- Zuletzt bearbeitet 14.09.2026 13:19:16
In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix field sysfs group cleanup on failure hid_sensor_custom_add_attributes() creates one sysfs group for each custom sensor field. If sysfs_create_group() fails...
CVE-2026-89624
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:45:21
- Zuletzt bearbeitet 21.09.2026 14:17:24
In the Linux kernel, the following vulnerability has been resolved: HID: universal-pidff: stop the device when force-feedback init fails universal_pidff_probe() starts the device with hid_hw_start() and then, if force-feedback initialisation fails,...
CVE-2026-89622
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:45:20
- Zuletzt bearbeitet 21.09.2026 14:17:23
In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes mcp_i2c_smbus_read() stores the caller-supplied buffer pointer in mcp->rxbuf for the duration of a transfer but never c...
- EPSS 0.21%
- Veröffentlicht 11.09.2026 19:45:20
- Zuletzt bearbeitet 14.09.2026 13:19:16
In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: stop device IO before hid_hw_stop Quiesce device IO at the start of the devm cleanup callback mcp2221_hid_unregister() so that incoming HID reports cannot race with h...
- EPSS 0.21%
- Veröffentlicht 11.09.2026 19:45:19
- Zuletzt bearbeitet 14.09.2026 13:19:15
In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: validate report size in mcp2221_raw_event() mcp2221_raw_event() never validates the size of incoming HID reports. In the MCP2221_I2C_GET_DATA path it trusts the devic...
CVE-2026-89619
- EPSS 0.14%
- Veröffentlicht 11.09.2026 19:45:18
- Zuletzt bearbeitet 13.09.2026 07:17:27
In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer quickspi_hid_raw_request() receives the caller's buffer length in len, but quickspi_get_report() ...
CVE-2026-89620
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:45:18
- Zuletzt bearbeitet 13.09.2026 07:17:27
In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-quickspi: validate report size before copy write_cmd_to_txdma() builds an output report in qsdev->report_buf, a heap buffer allocated in quickspi_alloc_re...
- EPSS 0.18%
- Veröffentlicht 11.09.2026 19:45:17
- Zuletzt bearbeitet 14.09.2026 13:19:15
In the Linux kernel, the following vulnerability has been resolved: eventfs: Initialize ei->children and ei->list in init_ei() eventfs_create_dir() allocates the eventfs_inode and initializes it with init_ei(). But this does not initialize the even...
CVE-2026-89616
- EPSS 0.37%
- Veröffentlicht 11.09.2026 19:45:16
- Zuletzt bearbeitet 14.09.2026 13:19:15
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() ni_read_frame() decompresses an LZNT $DATA frame into the vmapped target pages and then trusts decompress_lznt...
CVE-2026-89617
- EPSS 0.14%
- Veröffentlicht 11.09.2026 19:45:16
- Zuletzt bearbeitet 14.09.2026 13:19:15
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate dirty page table on log replay Each DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk lcns_follow field. check_rstbl() validates the table b...