CVE-2026-90141
- EPSS 0.43%
- Veröffentlicht 17.09.2026 16:06:38
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix integer overflow in ftp helper port/address parsing ip_vs_ftp_get_addrport() accumulates decimal digits into a __u16 (hport) and into unsigned char (p[]) without checking...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:37
- Zuletzt bearbeitet 17.09.2026 17:17:06
In the Linux kernel, the following vulnerability has been resolved: fuse: check for NULL root inode in fuse_fill_super_submount fuse_iget() can return NULL when its inode allocation fails, but fuse_fill_super_submount() passed the result straight t...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:06:37
- Zuletzt bearbeitet 17.09.2026 17:17:06
In the Linux kernel, the following vulnerability has been resolved: cuse: wait for pending RCU callbacks on module exit Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"), fuse_conn_put() frees the fuse_conn through call_rcu() rather than...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:36
- Zuletzt bearbeitet 17.09.2026 17:17:06
In the Linux kernel, the following vulnerability has been resolved: vsock: don't check the listener's sk_err in vsock_accept() Syzbot reported an issue which can be reproduced with these steps: r0 = socket(AF_VSOCK, SOCK_STREAM, 0) bind(r0, {VMAD...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:35
- Zuletzt bearbeitet 17.09.2026 17:17:06
In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/hsmp: Reject negative power cap writes in hwmon hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long and assigns "val / MICROWATT_PER_MILLIWATT"...
CVE-2026-90137
- EPSS 0.18%
- Veröffentlicht 17.09.2026 16:06:35
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix password encoding bounds check The password PSWD_ENCODINGS parser reads password_obj[elem + pos_values] while copying the supported password encodings...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:34
- Zuletzt bearbeitet 17.09.2026 17:17:06
In the Linux kernel, the following vulnerability has been resolved: net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() sashiko is reporting that trying to read /sys/kernel/debug/ref_tracker/* causes use-afer-free crash when either alloc_...
CVE-2026-90133
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:06:33
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib() ntfs_ir_to_ib copies all entries from index_root into a freshly allocated index_block_size-byte buffer without verifying that...
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:06:33
- Zuletzt bearbeitet 17.09.2026 17:17:05
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix kmap_local_page() usage in compress Several compressed I/O paths discard the address returned by kmap_local_page() and later access or unmap the page using page_address()...
CVE-2026-90132
- EPSS 0.15%
- Veröffentlicht 17.09.2026 16:06:32
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: ntfs: reject unprivileged writes to reserved $LX* xattrs Reject setxattr of the reserved $LXUID, $LXGID, $LXMOD and $LXDEV names from userspace unless the caller has CAP_SYS_ADMIN.