CVE-2026-90010
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:33:18
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Cap io_uring sense copy to max_response_len Completion copied scmd->sense_len to the user response buffer without honoring max_response_len. After a valid sense, the mid...
CVE-2026-90011
- EPSS 0.83%
- Veröffentlicht 16.09.2026 10:33:18
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for the login payload iscsi_target_check_login_request() rejects a login PDU whose DataSegmentLength exceeds MAX_KEY_VALUE_PAIRS, but...
CVE-2026-90009
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:33:17
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Fix TOCTOU in io_uring passthrough command setup scsi_bsg_uring_cmd() reads bsg_uring_cmd from the shared mmap'd SQE. Userspace can change a field after we check it and ...
CVE-2026-90007
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:16
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Use rollback index when freeing MSI-X vectors pm8001_request_msix() unwinds previously registered handlers with free_irq() when request_irq() fails. The rollback loop...
CVE-2026-90008
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:16
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame megasas_make_prp_nvme() builds a command's PRP list in cmd->sg_frame, a DMA pool buffer of instance->max_chain_fr...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:33:15
- Zuletzt bearbeitet 16.09.2026 11:17:13
In the Linux kernel, the following vulnerability has been resolved: samples/damon/mtier: handle damon_stop() failure damon_sample_mtier_stop() assumes its damon_stop() call will always successfully stops the two DAMON contexts. Hence it deallocate...
- EPSS 0.19%
- Veröffentlicht 16.09.2026 10:33:14
- Zuletzt bearbeitet 16.09.2026 11:17:12
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: handle region split failure in apply_min_nr_regions() damon_apply_min_nr_regions() repeatedly split each region until its size becomes small enough to meet the user-...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:33:14
- Zuletzt bearbeitet 16.09.2026 11:17:13
In the Linux kernel, the following vulnerability has been resolved: samples/damon/wsse: handle damon_start() failure Patch series "samples/damon: handle damon_{start,stop}() failures". All DAMON sample modules are not correctly handling failures f...
CVE-2026-90003
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:13
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: futex: Prevent rcuwait use-after-free during requeue PI On PREEMPT_RT, FUTEX_CMP_REQUEUE_PI can trigger a KASAN report (slab-out-of-bounds) in futex_requeue_pi_complete() invocatio...
CVE-2026-90001
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:12
- Zuletzt bearbeitet 16.09.2026 15:18:23
In the Linux kernel, the following vulnerability has been resolved: HID: bpf: serialize device reference release in struct_ops destroy path __hid_bpf_ops_destroy_device() and hid_bpf_unreg() can race on the same registration reference, double-putti...