CVE-2026-90137
- EPSS 0.18%
- Veröffentlicht 17.09.2026 16:06:35
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix password encoding bounds check The password PSWD_ENCODINGS parser reads password_obj[elem + pos_values] while copying the supported password encodings...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:34
- Zuletzt bearbeitet 17.09.2026 17:17:06
In the Linux kernel, the following vulnerability has been resolved: net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() sashiko is reporting that trying to read /sys/kernel/debug/ref_tracker/* causes use-afer-free crash when either alloc_...
CVE-2026-90133
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:06:33
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib() ntfs_ir_to_ib copies all entries from index_root into a freshly allocated index_block_size-byte buffer without verifying that...
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:06:33
- Zuletzt bearbeitet 17.09.2026 17:17:05
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix kmap_local_page() usage in compress Several compressed I/O paths discard the address returned by kmap_local_page() and later access or unmap the page using page_address()...
CVE-2026-90132
- EPSS 0.15%
- Veröffentlicht 17.09.2026 16:06:32
- Zuletzt bearbeitet 18.09.2026 18:17:43
In the Linux kernel, the following vulnerability has been resolved: ntfs: reject unprivileged writes to reserved $LX* xattrs Reject setxattr of the reserved $LXUID, $LXGID, $LXMOD and $LXDEV names from userspace unless the caller has CAP_SYS_ADMIN.
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:31
- Zuletzt bearbeitet 17.09.2026 17:17:05
In the Linux kernel, the following vulnerability has been resolved: vdpa_sim: fix cleanup after worker creation failure vdpasim_create() leaves vdpasim->worker as an ERR_PTR when kthread_run_worker() fails. The error path then drops the device refe...
CVE-2026-90131
- EPSS 0.15%
- Veröffentlicht 17.09.2026 16:06:31
- Zuletzt bearbeitet 18.09.2026 18:17:42
In the Linux kernel, the following vulnerability has been resolved: ntfs: serialize resident iomap reads with mrec_lock ntfs_read_iomap_begin_resident() walks the MFT record through ntfs_attr_lookup() -> ntfs_attr_find() without taking ni->mrec_loc...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:30
- Zuletzt bearbeitet 17.09.2026 17:17:05
In the Linux kernel, the following vulnerability has been resolved: virtio_balloon: quiesce balloon work before device shutdown Commit 8bd2fa086a04 ("virtio: break and reset virtio devices on device_shutdown()") added a generic virtio bus .shutdown...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:29
- Zuletzt bearbeitet 17.09.2026 17:17:05
In the Linux kernel, the following vulnerability has been resolved: virtio: rtc: time out alarm requests RTC class operations run with rtc_device.ops_lock held. The virtio RTC alarm requests currently wait without a timeout for the device to return...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:06:29
- Zuletzt bearbeitet 17.09.2026 17:17:05
In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: fix wrong list iterated in add_direct_chain error path In add_direct_chain(), newly allocated direct MR entries are added to the local list 'tmp', which is spliced into ...