CVE-2026-74637
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:36
- Zuletzt bearbeitet 27.08.2026 13:18:35
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix group leader use-after-free after sibling detach perf_group_detach() handles leader and sibling detach differently. When the group leader is detached, all siblings a...
CVE-2026-74626
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:35
- Zuletzt bearbeitet 27.08.2026 13:18:34
In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_netdev: Preserve RX queue depth on allocation failure ntb_netdev_rx_handler() hands the received skb to the network stack before allocating its replacement. If the allocat...
CVE-2026-74628
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:35
- Zuletzt bearbeitet 27.08.2026 13:18:34
In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its timers The x25 timers are armed with mod_timer() and cancelled with timer_delete(), so a pending timer holds no reference on the so...
CVE-2026-74630
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:35
- Zuletzt bearbeitet 25.08.2026 06:18:41
In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent in6_dev_get() from resurrecting inet6_dev in6_dev_get() reads dev->ip6_ptr under RCU and then unconditionally increments its refcount. Device teardown can clear the p...
CVE-2026-74609
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:33
- Zuletzt bearbeitet 25.08.2026 06:18:37
In the Linux kernel, the following vulnerability has been resolved: tipc: read le->link under the node lock in tipc_node_link_down() tipc_node_link_down() caches the link pointer before taking n->lock: struct tipc_link *l = le->link; /* unlocked...
CVE-2026-74597
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:32
- Zuletzt bearbeitet 25.08.2026 06:18:35
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the quoted inner IPv6 packet, and then passes the clone to icmpv6_send()....
CVE-2026-74598
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:32
- Zuletzt bearbeitet 25.08.2026 06:18:35
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix Route Information option length validation rt6_route_rcv() validates the Route Information option (RFC 4191) length against the prefix length, but both checks are off by ...
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:32
- Zuletzt bearbeitet 23.08.2026 13:16:46
In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: always stabilise against page table freeing using init_mm Previous commits have established the invariant that kernel page table freeing is performed while an mmap read ...
CVE-2026-74592
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:31
- Zuletzt bearbeitet 25.08.2026 06:18:34
In the Linux kernel, the following vulnerability has been resolved: ima: Instantiate file_truncate and path_truncate hooks Instantiate the file_truncate and path_truncate LSM hooks to reset the action cache flags (IMA_DONE_MASK) as soon as truncati...
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:30
- Zuletzt bearbeitet 22.08.2026 16:16:30
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound the DROM dual link port number before indexing sw->ports tb_drom_parse_entry_port() validates the device-supplied header->index against sw->config.max_port_numbe...