CVE-2026-97578
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:22:00
- Zuletzt bearbeitet 03.10.2026 11:18:05
In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer rockchip_vpu981_av1_dec_set_tile_info() divides context_update_tile_id by tile_info->tile_cols and writes one...
CVE-2026-97576
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:21:59
- Zuletzt bearbeitet 03.10.2026 11:18:04
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC tile counts The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from column_width_minus1[] and num_tile_rows_minus1 + 1 from row_h...
CVE-2026-97577
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:21:59
- Zuletzt bearbeitet 03.10.2026 11:18:05
In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity rockchip_vpu981_av1_dec_set_tile_info() indexes the tile group entry array by tile1 * tile_cols + tile0,...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:21:58
- Zuletzt bearbeitet 03.10.2026 11:18:04
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Don't free the live ring's TPA state on queue restart failure bnxt_queue_mem_alloc() shallow copies the live RX ring into the clone: memcpy(clone, rxr, sizeof(*rxr)); ...
CVE-2026-97575
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:21:58
- Zuletzt bearbeitet 03.10.2026 11:18:04
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate AV1 tile counts The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop bounds and as indices into the mi_*_starts[] and *_in_sbs_minus...
CVE-2026-97573
- EPSS 0.53%
- Veröffentlicht 25.09.2026 10:21:57
- Zuletzt bearbeitet 03.10.2026 11:18:04
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() bnxt_rx_ring_reset() frees the ring buffers and then reallocates them, ignoring the result. bnxt_alloc_one_rx_rin...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:21:56
- Zuletzt bearbeitet 03.10.2026 11:18:04
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc() bnxt_alloc_one_tpa_info_data() returns -ENOMEM as soon as one allocation fails. This leaves the remainin...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:21:56
- Zuletzt bearbeitet 03.10.2026 11:18:04
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Propagate RX ring init failures in bnxt_init_nic() bnxt_init_rx_rings() returns an error when bnxt_alloc_one_rx_ring() fails, but bnxt_init_nic() discards that return valu...
CVE-2026-97570
- EPSS 0.44%
- Veröffentlicht 25.09.2026 10:21:55
- Zuletzt bearbeitet 25.09.2026 15:17:59
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Bound SW TPA IDs to prevent crashes FW supports up to 1024 concurrent TPAs, so the FW TPA ID is in the range 0..1023 (see commit ec4d8e7cf024 ("bnxt_en: Add TPA ID mapping...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:21:54
- Zuletzt bearbeitet 03.10.2026 11:18:04
In the Linux kernel, the following vulnerability has been resolved: mptcp: syncookies: remember the request backup flag Instead of using an uninitialised bit when copying the info in subflow_ulp_clone(). To fix this, no need to extend the join_ent...