CVE-2026-89637
- EPSS 0.59%
- Veröffentlicht 11.09.2026 19:45:31
- Zuletzt bearbeitet 13.09.2026 07:17:28
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid->resp_buf set, mid->multiRsp t...
CVE-2026-89638
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:45:31
- Zuletzt bearbeitet 13.09.2026 07:17:29
In the Linux kernel, the following vulnerability has been resolved: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions When a file has the setuid or setgid bit set and is written to, the VFS strips those bits an...
CVE-2026-89636
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:45:30
- Zuletzt bearbeitet 14.09.2026 13:19:16
In the Linux kernel, the following vulnerability has been resolved: smb: client: clear ce->tgthint in free_tgts() When free_tgts() frees all structures in ce->tlist, ce->tgthint is left pointing to one of the freed cache_dfs_tgt structures. If ce-...
CVE-2026-89635
- EPSS 0.55%
- Veröffentlicht 11.09.2026 19:45:29
- Zuletzt bearbeitet 13.09.2026 07:17:28
In the Linux kernel, the following vulnerability has been resolved: ksmbd: only rebind the reopened file's own oplock on durable reconnect ksmbd_reopen_durable_fd() walks the inode's m_op_list and rebinds every detached oplock to the reconnecting s...
CVE-2026-89633
- EPSS 0.48%
- Veröffentlicht 11.09.2026 19:45:28
- Zuletzt bearbeitet 13.09.2026 07:17:28
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() coalesce_t2() computes data pointers directly from server-supplied DataOffset fields with no validation...
CVE-2026-89634
- EPSS 0.65%
- Veröffentlicht 11.09.2026 19:45:28
- Zuletzt bearbeitet 14.09.2026 13:19:16
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix ALIGN() overflow in symlink_data() error context loop The check added by commit 7d9a7f1f96cd ("smb/client: fix possible infinite loop and oob read in symlink_data(...
CVE-2026-89632
- EPSS 0.32%
- Veröffentlicht 11.09.2026 19:45:27
- Zuletzt bearbeitet 13.09.2026 07:17:28
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr() reparse_buf_ptr() reads buf->ReparseDataLength before checking that count covers the full fixed header: ...
CVE-2026-89631
- EPSS 0.45%
- Veröffentlicht 11.09.2026 19:45:26
- Zuletzt bearbeitet 13.09.2026 07:17:28
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject a tree connect response whose byte count is too small CIFSTCon() bounds its strnlen() over the byte area with the server's ByteCount minus two, which for ByteCo...
CVE-2026-89630
- EPSS 0.4%
- Veröffentlicht 11.09.2026 19:45:25
- Zuletzt bearbeitet 13.09.2026 07:17:28
In the Linux kernel, the following vulnerability has been resolved: smb: client: restore the data_offset bound in is_valid_oplock_break() Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr") changed the quantity this bound is measur...
- EPSS 0.21%
- Veröffentlicht 11.09.2026 19:45:24
- Zuletzt bearbeitet 14.09.2026 13:19:16
In the Linux kernel, the following vulnerability has been resolved: HID: picolcd: clamp eeprom debugfs read to bytes actually received picolcd_debug_eeprom_read() trusts resp->raw_data[2] -- a length byte supplied by the device in its REPORT_EE_DAT...