- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:55:09
- Zuletzt bearbeitet 04.09.2026 16:18:14
In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on setattr writeback failure fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate (fault_blocked = true) and releases it at the out:/...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:55:07
- Zuletzt bearbeitet 04.09.2026 16:18:14
In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on open O_TRUNC DAX failure fuse_open() takes filemap_invalidate_lock() for a DAX truncate (dax_truncate = true) and releases it before the out_inode...
- EPSS 0.18%
- Veröffentlicht 04.09.2026 15:55:06
- Zuletzt bearbeitet 04.09.2026 16:18:14
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: keep port count until LUN teardown completes tcm_usbg_drop_nexus() permits session removal once tpg_port_count reaches zero. However, usbg_port_unlink() current...
- EPSS 0.16%
- Veröffentlicht 04.09.2026 15:55:02
- Zuletzt bearbeitet 04.09.2026 16:18:14
In the Linux kernel, the following vulnerability has been resolved: tls: device: fix out-of-bounds write in tls_append_frag() Found with syzkaller and a local syzbot instance running on top of a netdevsim TLS offload emulation; tls_device.c is othe...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:55:01
- Zuletzt bearbeitet 03.10.2026 11:17:40
In the Linux kernel, the following vulnerability has been resolved: gtp: serialize PDP context updates PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP network device is being unregistered. The latter is serialized by RTNL, but t...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:55:00
- Zuletzt bearbeitet 04.09.2026 16:18:13
In the Linux kernel, the following vulnerability has been resolved: tcp: fix AO info use-after-free in tcp_ao_connect_init() tcp_v4_connect() adds a SYN-SENT socket to the ehash before calling tcp_connect(). If TCP-AO is configured, tcp_connect() ...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:54:59
- Zuletzt bearbeitet 04.09.2026 16:18:13
In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free of current_key on reconnect to another peer tcp_inbound_ao_hash() is called before bh_lock_sock_nested() is taken, with only rcu_read_lock() held. On...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:54:58
- Zuletzt bearbeitet 04.09.2026 16:18:13
In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: fix UAF during close ZDI reported and analyzed a race condition during close for espintcp sockets: espintcp_close() frees emsg->skb via kfree_skb() without hol...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:54:57
- Zuletzt bearbeitet 21.09.2026 14:17:20
In the Linux kernel, the following vulnerability has been resolved: tcp: clamp route advmss to TCP_MIN_MSS tcp_select_initial_window() assumes that callers never pass an MSS smaller than 1, but route-derived advmss values can violate that assumptio...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:54:56
- Zuletzt bearbeitet 04.09.2026 16:18:13
In the Linux kernel, the following vulnerability has been resolved: xfrm: drop ESP-in-TCP packets with no ingress device ESP-in-TCP receives records through the TCP strparser. handle_esp() restores skb->dev from the saved skb_iif before passing the...