- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:54
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths adv_timeout_expire() hands a kmalloc()ed instance byte to hci_cmd_sync_queue() with a NULL destro...
CVE-2026-90255
- EPSS 0.34%
- Veröffentlicht 17.09.2026 16:07:54
- Zuletzt bearbeitet 18.09.2026 18:17:51
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix the SCO setup context lifetime hci_setup_sync() queues a conn_handle_t with a NULL destroy callback, so the context is only freed if hci_enhanced_setup_syn...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:53
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the mesh send cancel command when it is cancelled mesh_send_cancel() queues the pending command with a NULL destroy callback, so it is only freed if send_canc...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:52
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MSFT: validate evt_prefix_len against the response length read_supported_features() only checks that the response covers the fixed part of struct msft_rp_read_supported_...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:52
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the HCI command when it is cancelled mgmt_hci_cmd_sync() queues the pending command with a NULL destroy callback, so it is only freed if send_hci_cmd_sync() r...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:51
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix storage null-ptr-deref after replacing prog Syzkaller reported a storage null-ptr-deref issue after replacing prog. This occurs in the following scenario: 1. prog ...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:50
- Zuletzt bearbeitet 17.09.2026 17:17:20
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix teardown of an adopted proto on insert-race loss In tc_new_tfilter() the create branch sets tp_created = 1 before calling tcf_chain_tp_insert_unique(). When...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:50
- Zuletzt bearbeitet 17.09.2026 17:17:21
In the Linux kernel, the following vulnerability has been resolved: iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes The IIO core does not filter duplicate writes to the event enable attribute, so writing the same value twic...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:49
- Zuletzt bearbeitet 17.09.2026 17:17:20
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock leak in irq_work path stack_map_get_build_id_offset() introduced a per-CPU irq_work to defer mmap_read_unlock() from NMI context, and bpf_find_vma() later reused...
CVE-2026-90246
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:48
- Zuletzt bearbeitet 18.09.2026 18:17:50
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix integer overflow in verify_tags() bounds check verify_tags() validates the tagset table unpacked from a policy blob. For each set it reads a count and checks that adv...