CVE-2026-31612
- EPSS 0.05%
- Veröffentlicht 24.04.2026 14:42:32
- Zuletzt bearbeitet 29.04.2026 17:00:28
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate EaNameLength in smb2_get_ea() smb2_get_ea() reads ea_req->EaNameLength from the client request and passes it directly to strncmp() as the comparison length without ...
CVE-2026-31610
- EPSS 0.02%
- Veröffentlicht 24.04.2026 14:42:31
- Zuletzt bearbeitet 29.04.2026 16:51:02
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc The kernel ASN.1 BER decoder calls action callbacks incrementally as it walks the input. When ksmbd_decode_neg...
CVE-2026-31607
- EPSS 0.07%
- Veröffentlicht 24.04.2026 14:42:29
- Zuletzt bearbeitet 28.04.2026 15:11:28
In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_...
CVE-2026-31605
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:28
- Zuletzt bearbeitet 29.04.2026 19:36:00
In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO Much like commit 19f953e74356 ("fbdev: fb_pm2fb: Avoid potential divide by zero error"), we also need to prevent that same...
CVE-2026-31606
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:28
- Zuletzt bearbeitet 29.04.2026 20:00:34
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: don't call cdev_init while cdev in use When calling unbind, then bind again, cdev_init reinitialized the cdev, even though there may still be references to it. ...
CVE-2026-31602
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:25
- Zuletzt bearbeitet 29.04.2026 20:16:49
In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Limit PTP to a single page Commit 391e69143d0a increased CT_PTP_NUM from 1 to 4 to support 256 playback streams, but the additional pages are not used by the card corr...
CVE-2026-31596
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:22
- Zuletzt bearbeitet 29.04.2026 14:18:43
In the Linux kernel, the following vulnerability has been resolved: ocfs2: handle invalid dinode in ocfs2_group_extend [BUG] kernel BUG at fs/ocfs2/resize.c:308! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:ocfs2_group_extend+0x10aa/0x...
CVE-2026-31597
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:22
- Zuletzt bearbeitet 29.04.2026 14:15:58
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY filemap_fault() may drop the mmap_lock before returning VM_FAULT_RETRY, as documented in mm/filemap.c: "If our ret...
CVE-2026-31588
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:16
- Zuletzt bearbeitet 28.04.2026 20:42:38
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Use scratch field in MMIO fragment to hold small write values When exiting to userspace to service an emulated MMIO write, copy the to-be-written value to a scratch field...
CVE-2026-31580
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:10
- Zuletzt bearbeitet 27.04.2026 20:29:15
In the Linux kernel, the following vulnerability has been resolved: bcache: fix cached_dev.sb_bio use-after-free and crash In our production environment, we have received multiple crash reports regarding libceph, which have caught our attention: `...