CVE-2026-74540
- EPSS 0.26%
- Veröffentlicht 15.08.2026 12:27:51
- Zuletzt bearbeitet 19.08.2026 17:21:09
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp l2cap_le_connect_rsp() obtains a channel via __l2cap_get_chan_by_ident() but neither holds a reference nor uses l2cap_chan_hold_un...
CVE-2026-74527
- EPSS 0.16%
- Veröffentlicht 15.08.2026 12:27:43
- Zuletzt bearbeitet 17.08.2026 06:19:49
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Block VFs from clobbering special CGX PKIND state PF and VF NIX LFs that share a CGX LMAC reuse the same hardware PKIND programming. When HiGig2 or EDSA parsing is en...
- EPSS 0.18%
- Veröffentlicht 15.08.2026 12:27:42
- Zuletzt bearbeitet 19.08.2026 17:21:09
In the Linux kernel, the following vulnerability has been resolved: net: sxgbe: free TX rings on RX allocation failure When RX descriptor ring allocation fails, init_dma_desc_rings() only frees the partially allocated RX rings and returns. The TX r...
CVE-2026-74519
- EPSS 0.15%
- Veröffentlicht 15.08.2026 12:27:38
- Zuletzt bearbeitet 19.08.2026 17:21:08
In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: don't free uninitialized dev_name on error path dt_remember_or_free_map() duplicates dev_name for each map entry. If kstrdup_const() fails, dt_free_map() frees...
CVE-2026-74512
- EPSS 0.13%
- Veröffentlicht 15.08.2026 12:27:33
- Zuletzt bearbeitet 19.08.2026 17:21:07
In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-free in audit_del_rule() `audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()` before unlinking the rule from RCU-visible filter l...
CVE-2026-74510
- EPSS 0.2%
- Veröffentlicht 15.08.2026 12:27:32
- Zuletzt bearbeitet 23.08.2026 13:16:45
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix UAF in pair command cancellation The pairing completion and authentication failure callbacks look up the pending MGMT_OP_PAIR_DEVICE command by walking hdev->m...
CVE-2026-74508
- EPSS 0.26%
- Veröffentlicht 15.08.2026 12:27:31
- Zuletzt bearbeitet 23.08.2026 13:16:44
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames without a transaction header hidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0] before checking that the L2CAP SDU contains a transa...
CVE-2026-74507
- EPSS 0.24%
- Veröffentlicht 15.08.2026 12:27:30
- Zuletzt bearbeitet 19.08.2026 17:21:07
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payloads When hidp_get_raw_report() waits for a numbered report, hidp_process_data() compares the expected report number with skb->data[0]...
- EPSS 0.18%
- Veröffentlicht 15.08.2026 12:27:29
- Zuletzt bearbeitet 19.08.2026 17:21:07
In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error handling during probe Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB ...
- EPSS 0.18%
- Veröffentlicht 15.08.2026 12:27:25
- Zuletzt bearbeitet 19.08.2026 17:21:07
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set When a USB audio endpoint requests full packet transfers via the fill_max descriptor flag, data_ep_set_para...