CVE-2026-31686
- EPSS 0.01%
- Veröffentlicht 27.04.2026 17:30:53
- Zuletzt bearbeitet 06.05.2026 21:04:14
In the Linux kernel, the following vulnerability has been resolved: mm/kasan: fix double free for kasan pXds kasan_free_pxd() assumes the page table is always struct page aligned. But that's not always the case for all architectures. E.g. In cas...
- EPSS 0.01%
- Veröffentlicht 27.04.2026 15:16:04
- Zuletzt bearbeitet 29.04.2026 04:16:38
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
CVE-2026-31685
- EPSS 0.06%
- Veröffentlicht 25.04.2026 08:47:02
- Zuletzt bearbeitet 06.05.2026 21:08:10
In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source address and compares it with the low 64 bits of th...
CVE-2026-31683
- EPSS 0.01%
- Veröffentlicht 25.04.2026 08:47:00
- Zuletzt bearbeitet 06.05.2026 21:14:05
In the Linux kernel, the following vulnerability has been resolved: batman-adv: avoid OGM aggregation when skb tailroom is insufficient When OGM aggregation state is toggled at runtime, an existing forwarded packet may have been allocated with only...
CVE-2026-31682
- EPSS 0.09%
- Veröffentlicht 25.04.2026 08:46:59
- Zuletzt bearbeitet 06.05.2026 21:17:15
In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns->opt[] and assumes that these options are in the linear part of ...
CVE-2026-31681
- EPSS 0.01%
- Veröffentlicht 25.04.2026 08:46:57
- Zuletzt bearbeitet 06.05.2026 21:21:50
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pflags entry as the start of a port range and unconditionally consumes the next ...
CVE-2026-31680
- EPSS 0.01%
- Veröffentlicht 25.04.2026 08:46:56
- Zuletzt bearbeitet 06.05.2026 21:23:31
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the seq-file RCU read-side lock and prints `fl->opt->o...
CVE-2026-31678
- EPSS 0.01%
- Veröffentlicht 25.04.2026 08:46:54
- Zuletzt bearbeitet 06.05.2026 21:28:02
In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already detached the device. Dropping the netdev reference in destro...
CVE-2026-31677
- EPSS 0.01%
- Veröffentlicht 25.04.2026 08:46:53
- Zuletzt bearbeitet 06.05.2026 21:29:38
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive buffer budget Make af_alg_get_rsgl() limit each RX scatterlist extraction to the remaining receive buffer budget. af_alg_get_rsg...
CVE-2026-31676
- EPSS 0.06%
- Veröffentlicht 25.04.2026 08:46:52
- Zuletzt bearbeitet 06.05.2026 21:31:48
In the Linux kernel, the following vulnerability has been resolved: rxrpc: only handle RESPONSE during service challenge Only process RESPONSE packets while the service connection is still in RXRPC_CONN_SERVICE_CHALLENGING. Check that state under s...