- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:12:36
- Zuletzt bearbeitet 04.09.2026 16:18:01
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix LE list UAF on reset hci_cc_reset() clears the LE accept and resolving lists without taking hdev->lock. Other command-complete handlers serialize updates ...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:12:35
- Zuletzt bearbeitet 04.09.2026 16:18:01
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: validate LE Set CIG Parameters response The Command Complete dispatch validates only the fixed part of the LE Set CIG Parameters response. After that part is ...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:12:34
- Zuletzt bearbeitet 04.09.2026 16:18:01
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix accept list UAF during suspend hci_update_event_filter_sync() walks hdev->accept_list while sending a synchronous HCI command for each remote-wakeup device...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:12:33
- Zuletzt bearbeitet 04.09.2026 16:18:01
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: zero the sockaddr before returning it in getname iso_sock_getname() fills a struct sockaddr_iso in place and returns its size without clearing it first, so bytes it...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:12:32
- Zuletzt bearbeitet 04.09.2026 16:18:01
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 mgmt_hci_cmd_sync() checks that the message length agrees with params_len but puts no upper bound on it. params_len is __l...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:12:28
- Zuletzt bearbeitet 04.09.2026 16:18:00
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_aml: validate firmware segment lengths aml_download_firmware() reads two lengths from the firmware header and uses them to build pointers before checking that the he...
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:12:27
- Zuletzt bearbeitet 04.09.2026 16:18:00
In the Linux kernel, the following vulnerability has been resolved: futex: Avoid private hash use-after-free on final put futex_private_hash_put() drops the reference to fph before evaluating fph->mm for wake_up_var(). futex_ref_put() enables preem...
- EPSS 0.21%
- Veröffentlicht 03.09.2026 08:26:35
- Zuletzt bearbeitet 03.09.2026 13:06:15
In the Linux kernel, the following vulnerability has been resolved: selinux: reject a class permission count below its inherited common security_get_permissions() maps an inherited common's permissions into an array sized by the class's own permiss...
- EPSS 0.21%
- Veröffentlicht 03.09.2026 08:26:34
- Zuletzt bearbeitet 03.09.2026 13:06:15
In the Linux kernel, the following vulnerability has been resolved: selinux: do not cancel a policy conversion that never started sel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes() fails, and that helper dereferences the ou...
CVE-2026-80754
- EPSS 0.16%
- Veröffentlicht 03.09.2026 08:26:33
- Zuletzt bearbeitet 04.09.2026 05:17:15
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix F55 transmitter electrode count typo During F55 sensor detection, the transmitter (TX) electrode count was incorrectly assigned the value of the receive...