CVE-2026-90260
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:58
- Zuletzt bearbeitet 18.09.2026 18:17:51
In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: don't clobber the extent buffer when zeroing it out On a zoned filesystem a freed-but-still-dirty tree block is written out as zeros (EXTENT_BUFFER_ZONED_ZEROOUT) onl...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:58
- Zuletzt bearbeitet 17.09.2026 17:17:22
In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: flush active metadata block group at btree_writepages() start btree_writepages() writes the btree inode's dirty metadata in ascending logical address order. On a zone...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:57
- Zuletzt bearbeitet 17.09.2026 17:17:22
In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data() In that function, we round down the start position and round up the ending position. But during the ca...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:56
- Zuletzt bearbeitet 17.09.2026 17:17:22
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: avoid OOB read of build info string The virtbt_setup_zephyr() sends the Zephyr vendor command 0xfc08 (Read Build Information) and hands the response to bt_dev...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:56
- Zuletzt bearbeitet 17.09.2026 17:17:22
In the Linux kernel, the following vulnerability has been resolved: pinctrl: airoha: add missed IRQ resource helpers Without hooking .irq_request_resources, gpiolib cannot set GPIOD_FLAG_USED_AS_IRQ. This breaks pin direction locking and can allow ...
CVE-2026-90256
- EPSS 0.29%
- Veröffentlicht 17.09.2026 16:07:55
- Zuletzt bearbeitet 18.09.2026 18:17:51
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind hci_conn::l2cap_data is accessed without locks in l2cap_disconn_ind via hci_conn_timeout (disc_work) -> hci...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:54
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths adv_timeout_expire() hands a kmalloc()ed instance byte to hci_cmd_sync_queue() with a NULL destro...
CVE-2026-90255
- EPSS 0.34%
- Veröffentlicht 17.09.2026 16:07:54
- Zuletzt bearbeitet 18.09.2026 18:17:51
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix the SCO setup context lifetime hci_setup_sync() queues a conn_handle_t with a NULL destroy callback, so the context is only freed if hci_enhanced_setup_syn...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:53
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the mesh send cancel command when it is cancelled mesh_send_cancel() queues the pending command with a NULL destroy callback, so it is only freed if send_canc...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:52
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MSFT: validate evt_prefix_len against the response length read_supported_features() only checks that the response covers the fixed part of struct msft_rp_read_supported_...