Canonical

Ubuntu 24.04 LTS

10938 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 15.08.2026 12:27:52
  • Zuletzt bearbeitet 17.08.2026 06:19:51

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: clear iso_data always when detaching conn from hcon When setting conn->hcon = NULL, also conn->hcon->iso_data = NULL is necessary, otherwise later iso_conn_free() w...

  • EPSS 0.26%
  • Veröffentlicht 15.08.2026 12:27:51
  • Zuletzt bearbeitet 19.08.2026 17:21:09

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp l2cap_le_connect_rsp() obtains a channel via __l2cap_get_chan_by_ident() but neither holds a reference nor uses l2cap_chan_hold_un...

  • EPSS 0.17%
  • Veröffentlicht 15.08.2026 12:27:50
  • Zuletzt bearbeitet 17.08.2026 06:19:50

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_connect_ind Accessing iso_pi(sk)->conn requires lock_sock, which is not taken in the "ev3" part of iso_connect_ind. It may also be NULL if socket ha...

  • EPSS 0.17%
  • Veröffentlicht 15.08.2026 12:27:49
  • Zuletzt bearbeitet 17.08.2026 06:19:50

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix leaking sk after socket release iso_sock_kill() tests !sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket || sock_flag(sk, SOCK_DEAD) for early return, but this is alw...

  • EPSS 0.17%
  • Veröffentlicht 15.08.2026 12:27:49
  • Zuletzt bearbeitet 17.08.2026 06:19:50

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: hold sk properly in iso_conn_ready sk deref in iso_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk is cu...

  • EPSS 0.17%
  • Veröffentlicht 15.08.2026 12:27:48
  • Zuletzt bearbeitet 17.08.2026 06:19:50

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout iso_sock_timeout() takes lock_sock, so sync disabling the timer while holding that lock may deadlock. iso_sock_timeout() may al...

  • EPSS 0.16%
  • Veröffentlicht 15.08.2026 12:27:47
  • Zuletzt bearbeitet 17.08.2026 06:19:50

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero hci_conn::iso_data is accessed and modified without lock or RCU. This leads to a race [Task hdev->workqueue] ...

  • EPSS 0.17%
  • Veröffentlicht 15.08.2026 12:27:47
  • Zuletzt bearbeitet 17.08.2026 06:19:50

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix refcounting of iso_conn iso_conn_del() and iso_chan_del() have a race that results to double-put of iso_conn: [Task hdev->workqueue] [Task 2] i...

  • EPSS 0.17%
  • Veröffentlicht 15.08.2026 12:27:46
  • Zuletzt bearbeitet 17.08.2026 06:19:50

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Validate length before parsing diagnostics TLV btintel_diagnostics() accesses tlv->val[0] without first validating that the diagnostics VSE is long enough to co...

  • EPSS 0.16%
  • Veröffentlicht 15.08.2026 12:27:45
  • Zuletzt bearbeitet 17.08.2026 06:19:49

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that. Ha...