CVE-2026-90018
- EPSS 0.44%
- Veröffentlicht 16.09.2026 10:33:23
- Zuletzt bearbeitet 16.09.2026 15:18:25
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() rtw_get_wps_attr() walks WPS attributes inside a WPS IE taken from a wireless management frame. For each can...
CVE-2026-90016
- EPSS 0.3%
- Veröffentlicht 16.09.2026 10:33:22
- Zuletzt bearbeitet 03.10.2026 11:17:45
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() rtw_restruct_wmm_ie() scans in_ie for a WMM IE with: while (i < in_len) { ... if (i + 5 < in_len && in_ie[i] == 0xDD...
CVE-2026-90017
- EPSS 0.35%
- Veröffentlicht 16.09.2026 10:33:22
- Zuletzt bearbeitet 16.09.2026 15:18:25
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() rtw_action_frame_parse() takes a frame_len parameter but never actually checks it before indexing into the frame body: ...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:33:21
- Zuletzt bearbeitet 16.09.2026 11:17:14
In the Linux kernel, the following vulnerability has been resolved: xhci: fix lost bounce buffers on TDs spanning several ring segments When a TD reaches a link TRB with data that is not aligned to the endpoint's wMaxPacketSize, xhci_align_td() sta...
CVE-2026-90013
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:20
- Zuletzt bearbeitet 03.10.2026 11:17:45
In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening options file The options files do not take the trace_array reference for the options they represent. This could cause a use-after-f...
CVE-2026-90014
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:33:20
- Zuletzt bearbeitet 16.09.2026 15:18:25
In the Linux kernel, the following vulnerability has been resolved: tracing: Have show_event_filters/triggers files take trace array ref The newly added files show_event_filters and show_event_triggers that show all filters or triggers that are set...
CVE-2026-90012
- EPSS 0.63%
- Veröffentlicht 16.09.2026 10:33:19
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failure If RX mapping fails after TX mapping succeeds, __spi_map_msg() unmaps TX but leaves tx_sg_mapped set. If TX mapping fails on a...
CVE-2026-90010
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:33:18
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Cap io_uring sense copy to max_response_len Completion copied scmd->sense_len to the user response buffer without honoring max_response_len. After a valid sense, the mid...
CVE-2026-90011
- EPSS 0.83%
- Veröffentlicht 16.09.2026 10:33:18
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for the login payload iscsi_target_check_login_request() rejects a login PDU whose DataSegmentLength exceeds MAX_KEY_VALUE_PAIRS, but...
CVE-2026-90009
- EPSS 0.15%
- Veröffentlicht 16.09.2026 10:33:17
- Zuletzt bearbeitet 16.09.2026 15:18:24
In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Fix TOCTOU in io_uring passthrough command setup scsi_bsg_uring_cmd() reads bsg_uring_cmd from the shared mmap'd SQE. Userspace can change a field after we check it and ...