CVE-2026-90228
- EPSS 0.67%
- Veröffentlicht 17.09.2026 16:07:36
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() When a host issues an Identify command with CNS 05h (I/O Command Set specific Identify Namespace) and CSI 02h...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:35
- Zuletzt bearbeitet 17.09.2026 17:17:18
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: avoid userspace overflow on invalid optlen nfc_llcp_getsockopt() casts optval to (u32 __user *) for put_user(), so the kernel always stores 4 bytes regardless of the cal...
CVE-2026-90227
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:35
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() Unlike IO_CMD / IO64_CMD, NVME_IOCTL_SUBMIT_IO never calls nvme_cmd_allowed(). Unprivileged callers can thus issue I/O on a part...
CVE-2026-90224
- EPSS 0.3%
- Veröffentlicht 17.09.2026 16:07:34
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix double completion race in nci_data_exchange_complete nci_close_device() and nci_rx_work can both call nci_data_exchange_complete() concurrently. After commit 4527025...
CVE-2026-90225
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:34
- Zuletzt bearbeitet 18.09.2026 18:17:47
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: read llcp_sock->local under the socket lock in getsockopt nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and then dereferenced the cached pointer insid...
CVE-2026-90223
- EPSS 0.41%
- Veröffentlicht 17.09.2026 16:07:33
- Zuletzt bearbeitet 18.09.2026 18:17:46
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound SNL TLV parsing to the skb and add length checks nfc_llcp_recv_snl() walked the SNL TLV list using a u16 offset/length pair derived from skb->len, without bounding...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:32
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:32
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: hold a reference to the request skb during send_frame __pn533_send_async() publishes the command and then calls dev->phy_ops->send_frame(). Once dev->cmd is set, an inc...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:07:31
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Don't leak the extension cell pointer in the bounce payload The bounce_error_event() embeds the failed event in the bounce payload by pointing data.ext.ptr at it. When ...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:07:30
- Zuletzt bearbeitet 17.09.2026 17:17:17
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix WARNING in res_to_rt syzbot reported a WARN_ON(!res->dev) in res_to_rt() triggered via addr_handler() during asynchronous address resolution: " WARNING: drivers/infi...