CVE-2026-23330
- EPSS 0.02%
- Veröffentlicht 25.03.2026 10:27:21
- Zuletzt bearbeitet 27.04.2026 14:16:30
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: complete pending data exchange on device close In nci_close_device(), complete any pending data exchange before closing. The data exchange callback (e.g. rawsock_data_exc...
CVE-2026-23318
- EPSS 0.02%
- Veröffentlicht 25.03.2026 10:27:12
- Zuletzt bearbeitet 23.04.2026 21:05:42
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of the validators table for UAC3 AC header descriptor is defined with the wrong protocol version UAC_VERSI...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:27:07
- Zuletzt bearbeitet 18.04.2026 09:16:18
In the Linux kernel, the following vulnerability has been resolved: net: usb: kaweth: validate USB endpoints The kaweth driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it ...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:27:02
- Zuletzt bearbeitet 18.04.2026 09:16:18
In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message When looking at the data in a USB urb, the actual_length is the size of the buffer passed to the dr...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:59
- Zuletzt bearbeitet 18.04.2026 09:16:18
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() l3mdev_master_dev_rcu() can return NULL when the slave device is being un-slaved from a VRF. All other callers deal with this, ...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:58
- Zuletzt bearbeitet 18.04.2026 09:16:18
In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled, cifs_set_cifscreds() logs the key payload and exposes the plaintext username and p...
- EPSS 0.03%
- Veröffentlicht 25.03.2026 10:26:57
- Zuletzt bearbeitet 27.04.2026 14:16:30
In the Linux kernel, the following vulnerability has been resolved: net: annotate data-races around sk->sk_{data_ready,write_space} skmsg (and probably other layers) are changing these pointers while other cpus might read them concurrently. Add co...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:56
- Zuletzt bearbeitet 18.04.2026 09:16:17
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop When a standalone IPv6 nexthop object is created with a loopback device (e.g., "ip -6 nexthop add id 100 dev l...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:54
- Zuletzt bearbeitet 18.04.2026 09:16:17
In the Linux kernel, the following vulnerability has been resolved: can: ucan: Fix infinite loop from zero-length messages If a broken ucan device gets a message with the message length field set to 0, then the driver will loop for forever in ucan_...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:51
- Zuletzt bearbeitet 18.04.2026 09:16:17
In the Linux kernel, the following vulnerability has been resolved: net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never initialized because inet6_init() exits before nd...