Canonical

Ubuntu 22.04 LTS

7957 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 06.05.2026 20:46:54

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use check_add_overflow() to prevent u16 DACL size overflow set_posix_acl_entries_dacl() and set_ntacl_dacl() accumulate ACE sizes in u16 variables. When a file has many POSI...

  • EPSS 0.06%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 06.05.2026 20:45:44

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() applies 4-byte alignment padding via memset() after writing each EA entry. The bounds check on buf_free_l...

  • EPSS 0.05%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 06.05.2026 20:27:43

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() smb_inherit_dacl() trusts the on-disk num_aces value from the parent directory's DACL xattr and uses it to size a...

  • EPSS 0.01%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 06.05.2026 20:26:38

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate response sizes in ipc_validate_msg() ipc_validate_msg() computes the expected message size for each response type by adding (or multiplying) attacker-controlled fie...

  • EPSS 0.04%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 06.05.2026 20:25:14

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL and the default QUERY_INFO path. The QUER...

  • EPSS 0.04%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 07.05.2026 06:16:03

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and id_mode_to_cifs_acl() derive a DACL pointer from a server-supplied dacloffset and then use ...

  • EPSS 0.01%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 06.05.2026 19:23:22

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the dirent into a sing...

  • EPSS 0.01%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 06.05.2026 19:19:51

In the Linux kernel, the following vulnerability has been resolved: wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free Currently we execute `SET_NETDEV_DEV(dev, &priv->lowerdev->dev)` for the virt_wifi net devices. However, unregisterin...

  • EPSS 0.01%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 06.05.2026 19:17:41

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix missing validation of ticket length in non-XDR key preparsing In rxrpc_preparse(), there are two paths for parsing key payloads: the XDR path (for large payloads) and th...

  • EPSS 0.01%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 06.05.2026 19:08:18

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed When retrieving the ID for the CPU, don't attempt to copy the ID blob to userspace if the firmware command ...