CVE-2026-89970
- EPSS 0.78%
- Veröffentlicht 16.09.2026 10:32:50
- Zuletzt bearbeitet 16.09.2026 15:18:21
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work has already started, cancellation doe...
CVE-2026-89971
- EPSS 0.58%
- Veröffentlicht 16.09.2026 10:32:50
- Zuletzt bearbeitet 03.10.2026 11:17:45
In the Linux kernel, the following vulnerability has been resolved: nvme: skip the zoned limits update if the zone info query failed nvme_query_zone_info() returns either a negative errno or a positive NVMe status code, but nvme_update_ns_info_bloc...
CVE-2026-89969
- EPSS 0.7%
- Veröffentlicht 16.09.2026 10:32:49
- Zuletzt bearbeitet 16.09.2026 15:18:21
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU nvmet_tcp_try_recv_pdu() reads a PDU header into the fixed 128-byte queue->pdu union, then computes the remaining...
CVE-2026-89967
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:32:48
- Zuletzt bearbeitet 16.09.2026 15:18:20
In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: avoid out-of-bounds writes for compound folios migrate_device_range() and migrate_device_pfns() clear the entries following a compound folio so that the PFN arra...
CVE-2026-89968
- EPSS 0.8%
- Veröffentlicht 16.09.2026 10:32:48
- Zuletzt bearbeitet 16.09.2026 15:18:21
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: reject unsolicited H2CData PDUs nvmet_tcp_handle_h2c_data_pdu() accepts an H2CData PDU after only checking that its TTAG is a valid in-range command index and that the c...
- EPSS 0.19%
- Veröffentlicht 16.09.2026 10:32:47
- Zuletzt bearbeitet 16.09.2026 11:17:07
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio alloc_buddy_hugetlb_folio_with_mpol() can pass a NULL nodemask to alloc_fresh_hugetlb_folio() as a f...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:32:46
- Zuletzt bearbeitet 17.09.2026 10:17:05
In the Linux kernel, the following vulnerability has been resolved: parisc: eisa: Fix infinite loop when parsing invalid IRQ value When an invalid value is passed via the "eisa_irq_edge=" kernel command line parameter (e.g. "eisa_irq_edge=16,5"), e...
CVE-2026-89965
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:32:46
- Zuletzt bearbeitet 16.09.2026 15:18:20
In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: reject an arena whose nfree is below the lane count The BTT info block's nfree field, the number of reserve free blocks, is read from the medium without validation. bt...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:32:45
- Zuletzt bearbeitet 16.09.2026 11:17:06
In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec_file: Fix null-ptr-def in extra size calculation A static Sashiko AI review identified a potential NULL pointer dereference in kexec_extra_fdt_size_ppc64(). On platf...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:32:44
- Zuletzt bearbeitet 16.09.2026 11:17:06
In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec_file: Prevent kexec range truncation Sashiko AI review pointed out the following issue. The __merge_memory_ranges() function incorrectly handles overlapping memory r...