CVE-2026-89662
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:45:49
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent lock owner use-after-free during client teardown __destroy_client() releases a client's open owners, but a lock owner whose only reference is a blocked lock (nbl) sta...
CVE-2026-89660
- EPSS 0.59%
- Veröffentlicht 11.09.2026 19:45:48
- Zuletzt bearbeitet 21.09.2026 14:17:24
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it. The client survives ...
CVE-2026-89659
- EPSS 0.44%
- Veröffentlicht 11.09.2026 19:45:47
- Zuletzt bearbeitet 21.09.2026 14:17:24
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegation revoke A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive. The client surviv...
CVE-2026-89657
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:45:46
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: libceph: validate OSD extent maps before cursor advance net/ceph/osd_client.c:osd_sparse_read() validates that the sparse-read data length matches the summed extent lengths, but it...
CVE-2026-89658
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:45:46
- Zuletzt bearbeitet 13.09.2026 07:17:31
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup nfs40_clean_admin_revoked() takes a stateid reference under clp->cl_lock, drops nn->client_lock, and calls ...
CVE-2026-89656
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:45
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids crush_decode() stores bucket data by array slot, and the mapper later derives the per-bucket workspace index from the decoded buck...
CVE-2026-89654
- EPSS 0.41%
- Veröffentlicht 11.09.2026 19:45:44
- Zuletzt bearbeitet 13.09.2026 07:17:30
In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in check_new_map() on session freed during unlock check_new_map() iterates mdsc->sessions[] and for each active session drops mdsc->mutex to perform per-session opera...
CVE-2026-89655
- EPSS 0.63%
- Veröffentlicht 11.09.2026 19:45:44
- Zuletzt bearbeitet 14.09.2026 13:19:17
In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock list_for_each_entry() iterates ci->i_cap_flush_list but drops i_ceph_lock to send cap messages. During the ...
CVE-2026-89653
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:43
- Zuletzt bearbeitet 14.09.2026 13:19:17
In the Linux kernel, the following vulnerability has been resolved: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode MDSMap export_targets entries are monitor controlled. check_new_map() uses each entry as a bit number in a fixed ...
CVE-2026-89652
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:42
- Zuletzt bearbeitet 14.09.2026 13:19:17
In the Linux kernel, the following vulnerability has been resolved: ceph: bound copied dentry name length in NFS export get_name ceph_get_name() copies the MDS-supplied name into the caller's NAME_MAX-sized buffer with memcpy(name, rinfo->dname, ri...