- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:23:24
- Zuletzt bearbeitet 25.09.2026 11:17:27
In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: protect config_ctx from being freed under the config callback vhost_vdpa_config_cb() loads v->config_ctx and signals it without taking a reference and without holding a...
CVE-2026-97990
- EPSS 0.12%
- Veröffentlicht 25.09.2026 10:23:23
- Zuletzt bearbeitet 03.10.2026 11:18:22
In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_net: check TX pull result before RX copy vringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is currently added to the unsigned byte counter and then pa...
CVE-2026-97991
- EPSS 0.12%
- Veröffentlicht 25.09.2026 10:23:23
- Zuletzt bearbeitet 03.10.2026 11:18:22
In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_blk: reject out-of-range sector starts vdpasim_blk_check_range() logs an invalid start sector but continues validating the request. The subsequent unsigned capacity subtr...
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:23:22
- Zuletzt bearbeitet 25.09.2026 11:17:27
In the Linux kernel, the following vulnerability has been resolved: vduse: validate virtqueue alignment vduse_validate_config() only checks the upper bound of vq_align. Invalid values can therefore reach vring_create_virtqueue_map(). The split-ring...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:21
- Zuletzt bearbeitet 03.10.2026 11:18:22
In the Linux kernel, the following vulnerability has been resolved: virtio_input: reset device if input_register_device() fails Probe marks the device DRIVER_OK with virtio_device_ready() before calling input_register_device(). If registration fail...
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:23:21
- Zuletzt bearbeitet 25.09.2026 11:17:26
In the Linux kernel, the following vulnerability has been resolved: vhost: invalidate vring access on IOTLB transitions When VIRTIO_F_ACCESS_PLATFORM changes, cached vring pointers and IOTLB metadata are interpreted in a different address space. Ke...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:20
- Zuletzt bearbeitet 25.09.2026 11:17:26
In the Linux kernel, the following vulnerability has been resolved: af_unix: Update last skb marker in manage_oob(). Fahad Alharbi reported that blocking recv(MSG_PEEK) could hog CPU due to OOB skb. In the following cases, manage_oob() skips OOB s...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:20
- Zuletzt bearbeitet 03.10.2026 11:18:22
In the Linux kernel, the following vulnerability has been resolved: virtio_input: stop callbacks before unregistering input device virtinput_remove() unregisters the input device before resetting the virtio device. virtinput_recv_events() drops vi-...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:19
- Zuletzt bearbeitet 03.10.2026 11:18:22
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: Fix UDP length overflow with PMTU discover and big MTU This commit bounds cork->base.fragsize to IP6_MAX_MTU for UDP sockets to avoid a possible overflow of UDP length t...
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:18
- Zuletzt bearbeitet 03.10.2026 11:18:22
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Fix budget accounting The gmac_rx() function returns the remaining NAPI budget, but its caller treats the return value as the number of packets received. An...