CVE-2026-74688
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:43
- Zuletzt bearbeitet 25.08.2026 06:18:51
In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being removed sctp_make_heartbeat_ack() caches the destination transport in chunk->transport without taking a reference. When src_out_o...
CVE-2026-74689
- EPSS 0.2%
- Veröffentlicht 22.08.2026 16:16:43
- Zuletzt bearbeitet 25.08.2026 06:18:51
In the Linux kernel, the following vulnerability has been resolved: net/atm: fix slab-out-of-bounds read in vcc_setsockopt() vcc_setsockopt() contained an ineffective optlen check: if (__SO_LEVEL_MATCH(optname, level) && optlen != __SO_SIZE(optna...
CVE-2026-74690
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:43
- Zuletzt bearbeitet 25.08.2026 06:18:52
In the Linux kernel, the following vulnerability has been resolved: s390/ism: Fix UAF of sba and ieq during ism_dev_exit() A ism interrupt handler can be active in parallel with ism_dev_exit(), accessing freed data structures. No new interrupts wi...
CVE-2026-74691
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:43
- Zuletzt bearbeitet 25.08.2026 06:18:52
In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before stopping the rings tbnet_tear_down() stops both rings and frees their frame buffers before calling tb_xdomain_disable_paths(). tb_ring...
CVE-2026-74692
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:43
- Zuletzt bearbeitet 25.08.2026 06:18:52
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix TOCTOU race between smc_listen_out() and listener close smc_listen_out() reads lsmc->sk.sk_state without the listener lock, then acquires lock_sock_nested() only after...
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:43
- Zuletzt bearbeitet 22.08.2026 16:16:43
In the Linux kernel, the following vulnerability has been resolved: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length ncsi_send_cmd_nl() takes the number of bytes to copy from the attacker-controlled ncsi_pkt_hdr.length field of the i...
- EPSS 0.19%
- Veröffentlicht 22.08.2026 16:16:42
- Zuletzt bearbeitet 22.08.2026 16:16:42
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Use unsigned int for ndp_index The variable ndp_index is declared as a signed integer, but it stores the return value of get_ncm(), which is unsigned. A malici...
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:42
- Zuletzt bearbeitet 22.08.2026 16:16:42
In the Linux kernel, the following vulnerability has been resolved: usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() If cxacru_cm() encounters an error while submitting or waiting for snd_urb, it aborts and returns the error without ...
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:42
- Zuletzt bearbeitet 22.08.2026 16:16:42
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write on Type II inbound URBs data_ep_set_params() sizes each URB transfer buffer before it adds the Format Type II transfer delimiter: u->packets = urb_...
- EPSS 0.19%
- Veröffentlicht 22.08.2026 16:16:42
- Zuletzt bearbeitet 25.08.2026 06:18:51
In the Linux kernel, the following vulnerability has been resolved: Input: evdev - sanitize event type index when fetching event masks The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK ioctls is used to index the static counts ar...