- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:07:22
- Zuletzt bearbeitet 17.09.2026 17:17:15
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix max_qid race between configfs and controller allocation The function nvmet_subsys_attr_qid_max_store() can race against nvmet_alloc_ctrl() when a subsystem's max_qid lim...
CVE-2026-90207
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:22
- Zuletzt bearbeitet 18.09.2026 18:17:46
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize input teardown with event_input snd_midi_input_event() must not be running while a rawmidi substream is closing, since this can lead to the trigger state...
CVE-2026-90205
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:07:21
- Zuletzt bearbeitet 18.09.2026 18:17:46
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate orphan slot during inode read Patch series "ocfs2: validate active orphan slots during inode read". OCFS2 trusts active ordinary and append-DIO orphan slots read f...
CVE-2026-90203
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:07:20
- Zuletzt bearbeitet 18.09.2026 18:17:46
In the Linux kernel, the following vulnerability has been resolved: Squashfs: check block offset is not negative If a negative offset is read off disk (for example the offset into the decompressed fragment block), this will cause squashfs_copy_data...
CVE-2026-90204
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:07:20
- Zuletzt bearbeitet 18.09.2026 18:17:46
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate DIO orphan slot during inode read [BUG] A corrupted append-DIO dinode (high byte at offset 0xa1 corrupted from 0 to 1) can carry an i_dio_orphaned_slot outside the ...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:19
- Zuletzt bearbeitet 17.09.2026 17:17:15
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers _base_release_memory_pools() unconditionally frees every ioc->pcie_sg_lookup[] entry, including ones the setup loop never ...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:18
- Zuletzt bearbeitet 17.09.2026 17:17:14
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix integer overflow in MFT cluster validation In ntfs_init_from_boot(), the boot sector's MFT cluster numbers are validated against the volume size with: if (mlcn * s...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:18
- Zuletzt bearbeitet 17.09.2026 17:17:15
In the Linux kernel, the following vulnerability has been resolved: net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race This bug was discovered while testing the hns3 driver under channel reconfiguration (`ethtool -L` / `et...
CVE-2026-90199
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:07:17
- Zuletzt bearbeitet 18.09.2026 18:17:45
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject out-of-range evcn in mi_enum_attr() In mi_enum_attr(), the start/end VCN validation for non-resident attributes is: if (svcn > evcn + 1) goto out; When evcn is ...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:16
- Zuletzt bearbeitet 17.09.2026 17:17:14
In the Linux kernel, the following vulnerability has been resolved: HID: haptic: don't write an uninitialized value to unhandled usages fill_effect_buf() initializes value only for the four haptic usages handled by its switch, but writes it to fiel...