- EPSS 0.21%
- Veröffentlicht 10.08.2026 12:03:46
- Zuletzt bearbeitet 19.08.2026 17:20:46
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: printer: fix infinite loop in printer_read() printer_read() uses the same variable for the requested copy size and the number of bytes actually copied to user space. c...
- EPSS 0.18%
- Veröffentlicht 10.08.2026 12:03:44
- Zuletzt bearbeitet 23.08.2026 13:16:36
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: synchronize delayed set_alt with teardown The f_tcm set_alt() path defers endpoint setup to a work item and completes the delayed status response from process c...
- EPSS 0.18%
- Veröffentlicht 10.08.2026 12:03:43
- Zuletzt bearbeitet 19.08.2026 17:20:46
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer uvc_send_response() builds the UVC control response from a user-supplied struct uvc_request_data: req->length ...
- EPSS 0.18%
- Veröffentlicht 10.08.2026 12:03:42
- Zuletzt bearbeitet 19.08.2026 17:20:46
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: cap received transmit credits The interrupt-status packet reports transmit credits returned by the device. edge_interrupt_callback() adds the 16-bit value...
- EPSS 0.18%
- Veröffentlicht 10.08.2026 12:03:40
- Zuletzt bearbeitet 19.08.2026 17:20:45
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), p...
CVE-2026-68354
- EPSS 0.29%
- Veröffentlicht 10.08.2026 12:03:31
- Zuletzt bearbeitet 19.08.2026 17:20:45
In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly fwnet_frag_new() keeps a sorted list of received fragments for a partial datagram. When a new fragment is adjacent to an existing ...
CVE-2026-68353
- EPSS 0.29%
- Veröffentlicht 10.08.2026 12:03:30
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() witho...
CVE-2026-68352
- EPSS 0.42%
- Veröffentlicht 10.08.2026 12:03:29
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx(...
- EPSS 0.22%
- Veröffentlicht 10.08.2026 12:03:28
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read When the firmware sends a command response with a length mismatch, carl9170_cmd_callback() logs the mismatch...
- EPSS 0.18%
- Veröffentlicht 10.08.2026 12:03:27
- Zuletzt bearbeitet 19.08.2026 17:20:44
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix OOB read from off-by-two in TX status handler The bounds check in carl9170_tx_process_status() uses `i > ((cmd->hdr.len / 2) + 1)` which is off by two, allowing...