CVE-2026-72133
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:53:08
- Zuletzt bearbeitet 17.08.2026 06:18:13
In the Linux kernel, the following vulnerability has been resolved: spi: uniphier: Fix completion initialization order before devm_request_irq() The driver calls devm_request_irq() before initializing the completion used by the interrupt handler. B...
CVE-2026-72129
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:53:05
- Zuletzt bearbeitet 17.08.2026 06:18:12
In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset into the per-command inline scatterlist. The bounds che...
CVE-2026-72126
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:53:03
- Zuletzt bearbeitet 17.08.2026 06:18:12
In the Linux kernel, the following vulnerability has been resolved: can: isotp: use unconditional synchronize_rcu() in isotp_release() isotp_notify() unregisters the (RCU) CAN filters via can_rx_unregister() and clears so->bound without waiting for...
CVE-2026-72124
- EPSS 0.35%
- Veröffentlicht 15.08.2026 05:53:02
- Zuletzt bearbeitet 19.08.2026 17:20:59
In the Linux kernel, the following vulnerability has been resolved: can: isotp: serialize TX state transitions under so->rx_lock The TX state machine (so->tx.state) is driven from three contexts: sendmsg() claiming and progressing a transfer, the R...
CVE-2026-72125
- EPSS 0.16%
- Veröffentlicht 15.08.2026 05:53:02
- Zuletzt bearbeitet 19.08.2026 17:21:00
In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER isotp_release() looked up the bound network device via dev_get_by_index() using the stored ifindex. During dev...
CVE-2026-72123
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:53:01
- Zuletzt bearbeitet 19.08.2026 17:20:59
In the Linux kernel, the following vulnerability has been resolved: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF Commit f1b4e32aca08 ("can: bcm: use call_rcu() instead of costly synchronize_rcu()") replaced synchronize_rcu() ...
CVE-2026-72122
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:53:00
- Zuletzt bearbeitet 17.08.2026 06:18:11
In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure bcm_sendmsg() reads bo->ifindex and checks bo->bound before taking lock_sock(), while bcm_notify(), bcm_connec...
CVE-2026-72120
- EPSS 0.21%
- Veröffentlicht 15.08.2026 05:52:59
- Zuletzt bearbeitet 17.08.2026 06:18:11
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu list annotations and operations sashiko-bot remarked the missing use of list_add_rcu() in bcm_[rx|tx]_setup() to have a proper initialized bcm_op structur...
CVE-2026-72121
- EPSS 0.35%
- Veröffentlicht 15.08.2026 05:52:59
- Zuletzt bearbeitet 19.08.2026 17:20:59
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking when updating filter and timer values KCSAN detected a simultaneous access to timer values that can be overwritten in bcm_rx_setup() when updating timer and f...
CVE-2026-72119
- EPSS 0.16%
- Veröffentlicht 15.08.2026 05:52:58
- Zuletzt bearbeitet 19.08.2026 17:20:58
In the Linux kernel, the following vulnerability has been resolved: can: bcm: extend bcm_tx_lock usage for data and timer updates Stage new CAN frame content for an existing tx op into a kmalloc()'d buffer and validate it there, mirroring the appro...