CVE-2026-80955
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:42:23
- Zuletzt bearbeitet 13.09.2026 07:17:02
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() In kset_replay, when key->seg_gen is stale (key->seg_gen < key->cache_pos.cache_seg->gen), cache_key_put(k...
CVE-2026-80953
- EPSS 0.18%
- Veröffentlicht 11.09.2026 19:42:22
- Zuletzt bearbeitet 13.09.2026 07:17:02
In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabling interrupts adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR before the controller's IBI state, transfe...
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:42:21
- Zuletzt bearbeitet 14.09.2026 13:18:50
In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: bound IBI payload to the requested max_payload_len svc_i3c_master_handle_ibi() reads the IBI payload from the RX FIFO into the IBI slot. The loop is bounded by th...
CVE-2026-80952
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:42:21
- Zuletzt bearbeitet 14.09.2026 13:18:50
In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before calling device_unregister(). During device_unregister...
CVE-2026-80950
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:42:20
- Zuletzt bearbeitet 13.09.2026 07:17:02
In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid before accessing it The Renesas I3C driver uses an asynchronous model to transfer data. It prepares a struct renesas_i3c_xfer, enqueu...
- EPSS 0.21%
- Veröffentlicht 11.09.2026 19:42:19
- Zuletzt bearbeitet 13.09.2026 07:17:02
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() In iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses the out_free_eeprom_blob label. Consequentl...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:42:19
- Zuletzt bearbeitet 14.09.2026 13:18:50
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() The memory allocated for buf is not freed in some of the error paths in brcmf_sdio_read_control(). Fix that by adding v...
CVE-2026-80947
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:42:18
- Zuletzt bearbeitet 13.09.2026 07:17:01
In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop rtl8xxxu arms rx_urb_wq from the RX completion path: rtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), whic...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:42:17
- Zuletzt bearbeitet 11.09.2026 20:19:00
In the Linux kernel, the following vulnerability has been resolved: fuse: copy request headers via a stack buffer for io-uring The fuse-io-uring transport copies req->in.h out to the ring in fuse_uring_copy_to_ring() and req->out.h back in fuse_uri...
CVE-2026-80944
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:42:16
- Zuletzt bearbeitet 14.09.2026 13:18:50
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupted wait mwifiex synchronous commands keep the caller-provided data buffer in cmd_node->data_buf. Several callers pass stack-alloca...