CVE-2026-90324
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:08:40
- Zuletzt bearbeitet 18.09.2026 18:17:53
In the Linux kernel, the following vulnerability has been resolved: ublk: check import_ubuf() return value import_ubuf() can fail if the address range (provided by the userspace ublk server) is outside the allowed user address space. Return that 0 ...
CVE-2026-90325
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:08:40
- Zuletzt bearbeitet 18.09.2026 18:17:53
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: skip dying blkg in blkcg_activate_policy() When switching IO schedulers on a block device, blkcg_activate_policy() can race with concurrent blkcg deletion, leading to a...
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:08:39
- Zuletzt bearbeitet 17.09.2026 17:17:30
In the Linux kernel, the following vulnerability has been resolved: ublk: validate auto buf reg before taking uring_cmd With UBLK_F_AUTO_BUF_REG, invalid sqe->addr can fail after ublk_fill_io_cmd() has set UBLK_IO_FLAG_ACTIVE. The uring_cmd is comp...
CVE-2026-90321
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:08:38
- Zuletzt bearbeitet 18.09.2026 18:17:53
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate inline xattrs during inode block validation Patch series "ocfs2: validate xattr entry bounds", v7. This series validates OCFS2 xattr entry name/value bounds when x...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:08:38
- Zuletzt bearbeitet 17.09.2026 17:17:30
In the Linux kernel, the following vulnerability has been resolved: ocfs2/cluster: keep heartbeat local node stable o2nm_node_local_store() handles local=0 by stopping o2net and setting cl_local_node to O2NM_INVALID_NODE_NUM, but it leaves cl_has_l...
CVE-2026-90320
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:08:37
- Zuletzt bearbeitet 18.09.2026 18:17:53
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate external xattr entries when reading metadata ocfs2_validate_xattr_block() checks the xattr block header before the block reaches higher-level xattr users, but it do...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:08:36
- Zuletzt bearbeitet 17.09.2026 17:17:29
In the Linux kernel, the following vulnerability has been resolved: fat: release buffer head after rebuilding parent fat_scan_logstart() leaves the matching directory entry's buffer head in sinfo.bh for the caller to release, just like fat_scan(). ...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:08:36
- Zuletzt bearbeitet 17.09.2026 17:17:29
In the Linux kernel, the following vulnerability has been resolved: rapidio: clear mport->net when rio_add_net() fails rio_alloc_net() stores the newly allocated rio_net in mport->net before rio_scan_alloc_net() registers the device. If rio_add_ne...
CVE-2026-90317
- EPSS 0.15%
- Veröffentlicht 17.09.2026 16:08:35
- Zuletzt bearbeitet 18.09.2026 18:17:53
In the Linux kernel, the following vulnerability has been resolved: bpf: Invalidate RCU pointers after final spin unlock In a sleepable BPF program, a spin lock can provide the only RCU protection for a kptr. The final bpf_spin_unlock() ends that p...
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:08:34
- Zuletzt bearbeitet 17.09.2026 17:17:29
In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers Currently, the legacy I/O and memory sysfs handlers do not check security_locked_down(LOCKDOWN_PCI_ACCESS), leaving...