CVE-2026-72255
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:54:42
- Zuletzt bearbeitet 14.09.2026 12:17:44
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst The br_netfilter fake rtable is embedded in struct net_bridge and is attached to bridged packets with skb_dst_se...
CVE-2026-72253
- EPSS 0.2%
- Veröffentlicht 15.08.2026 05:54:41
- Zuletzt bearbeitet 23.08.2026 13:16:42
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: validate skb_dst() before accessing it tc ingress and openvswitch do not guarantee routing information to be available. These subsystems use the conntr...
CVE-2026-72252
- EPSS 0.2%
- Veröffentlicht 15.08.2026 05:54:40
- Zuletzt bearbeitet 23.08.2026 13:16:42
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: don't leak bad clone into future transaction On memory allocation failure the cloned nft_pipapo_match can enter a bad state: - some fields can have thei...
CVE-2026-72250
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:54:39
- Zuletzt bearbeitet 17.08.2026 06:18:27
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag nf_ct_frag6_reasm() slides the packet head forward to drop the IPv6 fragment header and then unconditio...
CVE-2026-72251
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:54:39
- Zuletzt bearbeitet 17.08.2026 06:18:27
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: reload possible stale data pointer quoting sashiko: ------------------------------------------------------------------------ [..] noticed a potential memor...
CVE-2026-72247
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:54:35
- Zuletzt bearbeitet 17.08.2026 06:18:26
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix zone comparison in tuple dedup The "already exists" dedup logic in __nf_conncount_add() decides whether a connection has already been counted and can b...
- EPSS 0.23%
- Veröffentlicht 15.08.2026 05:54:32
- Zuletzt bearbeitet 17.08.2026 06:18:26
In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path After device_initialize(), the embedded struct device in struct host1x_device should be released throu...
CVE-2026-72243
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:54:31
- Zuletzt bearbeitet 18.08.2026 07:16:54
In the Linux kernel, the following vulnerability has been resolved: selinux: check connect-related permissions on TCP Fast Open Similar to Landlock, SELinux was not updated when TCP Fast Open support was introduced to ensure connect-related permiss...
CVE-2026-72242
- EPSS 0.2%
- Veröffentlicht 15.08.2026 05:54:30
- Zuletzt bearbeitet 23.08.2026 13:16:42
In the Linux kernel, the following vulnerability has been resolved: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() selinux_sctp_bind_connect() dereferences sk->sk_socket to pass a struct socket * to selinux_socket_bind() and se...
- EPSS 0.22%
- Veröffentlicht 15.08.2026 05:54:29
- Zuletzt bearbeitet 17.08.2026 06:18:25
In the Linux kernel, the following vulnerability has been resolved: leds: uleds: Fix potential buffer overread The name string supplied by userspace is not guaranteed to be null-terminated, so using strchr() on it might result in a buffer overread....