- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 25.08.2026 06:18:54
In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocate...
- EPSS 0.16%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 22.08.2026 16:16:45
In the Linux kernel, the following vulnerability has been resolved: bnge: Fix NULL pointer dereference in aux device release If allocation of auxr_dev fails during auxiliary device setup, the error path calls auxiliary_device_uninit(), which eventu...
CVE-2026-74707
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 25.08.2026 06:18:55
In the Linux kernel, the following vulnerability has been resolved: xsk: validate metadata when processing requests The zero-copy path validates TX metadata while obtaining the descriptor context, then reads it again later when preparing the hardwa...
CVE-2026-74708
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 25.08.2026 06:18:55
In the Linux kernel, the following vulnerability has been resolved: xsk: validate launch-time metadata size Launch-time metadata extends beyond the first 16 bytes of struct xsk_tx_metadata. Reject the request when the registered metadata area does ...
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 22.08.2026 16:16:45
In the Linux kernel, the following vulnerability has been resolved: xsk: clear metadata pointer when no timestamp is requested User space can change metadata flags after request processing. Rereading them during completion can therefore make the ke...
CVE-2026-74710
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 25.08.2026 06:18:55
In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_XDP accepts a TX metadata length as small as eight bytes, but every supported request needs the flags plus at least one eight-byte ...
CVE-2026-74711
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 25.08.2026 06:18:55
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix type confusion in notification logic Sashiko reports: At the start of the loop in pmbus_notify(), the code unconditionally casts every attribute to a struct sen...
CVE-2026-74712
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 25.08.2026 06:18:56
In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys() We have seen in our CI the following KASAN message: BUG: KASAN: slab-out-of-bounds in cmd_exec+0x550/0xca0 [mlx5_core] Read of ...
CVE-2026-74695
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:44
- Zuletzt bearbeitet 25.08.2026 06:18:53
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() Incoming skbs passing through netfilter flowtable offload hooks (or XFRM offload path) might already carr...
CVE-2026-74696
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:44
- Zuletzt bearbeitet 25.08.2026 06:18:53
In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport migration A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through far more pending Fast Open requests than it was...