CVE-2026-64445
- EPSS 0.22%
- Veröffentlicht 25.07.2026 08:51:16
- Zuletzt bearbeitet 03.09.2026 15:39:31
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() OnAuth() has two bugs in the shared-key authentication path. When the Privacy bit is set, rtw_wep_decrypt() i...
CVE-2026-64443
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:15
- Zuletzt bearbeitet 03.09.2026 17:27:37
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len...
CVE-2026-64444
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:15
- Zuletzt bearbeitet 03.09.2026 15:41:03
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a mal...
CVE-2026-64442
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:14
- Zuletzt bearbeitet 03.09.2026 17:28:19
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: ...
CVE-2026-64440
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:13
- Zuletzt bearbeitet 03.09.2026 17:48:45
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handler() HT_caps_handler() iterates pIE->length bytes and writes into HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struc...
CVE-2026-64441
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:51:13
- Zuletzt bearbeitet 03.09.2026 17:46:12
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() Three IE/attribute parsing functions have missing bounds checks. rtw_get_sec_ie() ...
CVE-2026-64439
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:51:12
- Zuletzt bearbeitet 03.09.2026 17:50:14
In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementations at alloc krb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and rfc8009_encrypt(), rfc8009_decrypt() in rfc8009_a...
CVE-2026-64437
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:51:11
- Zuletzt bearbeitet 03.09.2026 18:04:26
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL") mad...
CVE-2026-64438
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:11
- Zuletzt bearbeitet 03.09.2026 17:55:36
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() The VF2PF interrupt handler queues PF-side response work that stores a raw pointer to per-VF state (struct adf_acc...
CVE-2026-64436
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:51:10
- Zuletzt bearbeitet 03.09.2026 18:19:24
In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp states pfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by allocating x->calg and copying only the algorithm nam...