CVE-2026-89507
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:43:54
- Zuletzt bearbeitet 13.09.2026 07:17:13
In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Lock the handler in ucma_write_cm_event() ctx->file may only be changed under the handler lock and the xa_lock, which is what stops uevents being queued for a ctx while ...
CVE-2026-89508
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:43:54
- Zuletzt bearbeitet 14.09.2026 13:19:07
In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Lock the handler in ucma_set_ib_path() ucma_set_ib_path() calls ucma_event_handler() straight from the write() path, without the handler lock that keeps ctx->file stable...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:43:53
- Zuletzt bearbeitet 11.09.2026 20:19:32
In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that cannot be passe...
CVE-2026-89504
- EPSS 0.14%
- Veröffentlicht 11.09.2026 19:43:52
- Zuletzt bearbeitet 14.09.2026 13:19:07
In the Linux kernel, the following vulnerability has been resolved: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer In as3722_get_regulator_dt_data(), of_get_child_by_name() acquires a reference o...
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:43:52
- Zuletzt bearbeitet 11.09.2026 20:19:32
In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Guard legacy bundles without method_elm The legacy write() path dispatches through a uverbs_api_write_method, but the uverbs_attr_bundle passed to provider code does n...
CVE-2026-89503
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:43:51
- Zuletzt bearbeitet 03.10.2026 11:17:42
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() ring_buffer_alloc_read_page() is racy with ring_buffer_subbuf_order_set, it can allocate a reader page with a...
CVE-2026-89501
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:43:50
- Zuletzt bearbeitet 13.09.2026 07:17:13
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf Because, ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page, hold cpu_buffer->lock to prevent races with ring_...
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:43:50
- Zuletzt bearbeitet 11.09.2026 20:19:32
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbuf_order When sub-buffers use an order greater than 0, cpu_buffer->free_page is allocated with subbuf_order. Use the correct order ...
CVE-2026-89500
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:43:49
- Zuletzt bearbeitet 03.10.2026 11:17:42
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page Discarding a cached reader page after a concurrent ring buffer resize uses the new global subbuf_order for the free_...
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:43:48
- Zuletzt bearbeitet 14.09.2026 13:19:07
In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdir copy failure On a readdir downcall, orangefs_devreq_write_iter() frees op->downcall.trailer_buf with vfree() when copy_from_iter...