- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:41
- Zuletzt bearbeitet 17.09.2026 17:17:19
In the Linux kernel, the following vulnerability has been resolved: NFSD: Release the export reference when reaping open stateids nfs4_put_stid() releases the svc_export tracked in nfs4_stid.sc_export, but free_ol_stateid_reaplist() frees open and ...
CVE-2026-90234
- EPSS 0.47%
- Veröffentlicht 17.09.2026 16:07:40
- Zuletzt bearbeitet 18.09.2026 18:17:48
In the Linux kernel, the following vulnerability has been resolved: NFS: Return a delegation the client fails to record When an NFS server grants a delegation in an OPEN reply, nfs_inode_set_delegation() records it on the client. However, three of ...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:39
- Zuletzt bearbeitet 17.09.2026 17:17:19
In the Linux kernel, the following vulnerability has been resolved: amt: Don't support cross-netns setup. When a lower device is unregistered, amt_device_event() tries to unregister its upper AMT device, but it has two problems. 1. amt_lookup_up...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:39
- Zuletzt bearbeitet 17.09.2026 17:17:19
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: release descriptor pools on probe failure The per-NUMA-node descriptor DMA pools are created lazily from nvme_init_hctx_common() once the admin tag set is allocated, but ...
CVE-2026-90231
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:38
- Zuletzt bearbeitet 18.09.2026 18:17:48
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unconfined user namespace restriction forced stack If a task is already confined by a stack the unprivileged transition restriction on unconfined is not correctly, ap...
CVE-2026-90229
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:37
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Destroy the admin queue on removal The admin queue is allocated with blk_mq_alloc_queue() but never destroyed. nvme_free_ctrl() only drops the last reference and blk_mq...
CVE-2026-90230
- EPSS 0.46%
- Veröffentlicht 17.09.2026 16:07:37
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and han...
CVE-2026-90228
- EPSS 0.67%
- Veröffentlicht 17.09.2026 16:07:36
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() When a host issues an Identify command with CNS 05h (I/O Command Set specific Identify Namespace) and CSI 02h...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:35
- Zuletzt bearbeitet 17.09.2026 17:17:18
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: avoid userspace overflow on invalid optlen nfc_llcp_getsockopt() casts optval to (u32 __user *) for put_user(), so the kernel always stores 4 bytes regardless of the cal...
CVE-2026-90227
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:35
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() Unlike IO_CMD / IO64_CMD, NVME_IOCTL_SUBMIT_IO never calls nvme_cmd_allowed(). Unprivileged callers can thus issue I/O on a part...