CVE-2026-31627
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:48
- Zuletzt bearbeitet 27.04.2026 20:43:43
In the Linux kernel, the following vulnerability has been resolved: i2c: s3c24xx: check the size of the SMBUS message before using it The first byte of an i2c SMBUS message is the size, and it should be verified to ensure that it is in the range of...
CVE-2026-31626
- EPSS 0.03%
- Veröffentlicht 24.04.2026 14:42:47
- Zuletzt bearbeitet 27.04.2026 20:49:50
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() Initialize le_tmp64 to zero in rtw_BIP_verify() to prevent using uninitialized data. Smatch warns that only 6 bytes are...
CVE-2026-31625
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:42
- Zuletzt bearbeitet 27.04.2026 21:14:33
In the Linux kernel, the following vulnerability has been resolved: HID: alps: fix NULL pointer dereference in alps_raw_event() Commit ecfa6f34492c ("HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them") attempted to fix up the HI...
CVE-2026-31624
- EPSS 0.02%
- Veröffentlicht 24.04.2026 14:42:41
- Zuletzt bearbeitet 28.04.2026 14:02:38
In the Linux kernel, the following vulnerability has been resolved: HID: core: clamp report_size in s32ton() to avoid undefined shift s32ton() shifts by n-1 where n is the field's report_size, a value that comes directly from a HID device. The HID...
CVE-2026-31623
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:40
- Zuletzt bearbeitet 28.04.2026 14:17:26
In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() A malicious USB device claiming to be a CDC Phonet modem can overflow the skb_shared_info->frags[] array by sending ...
CVE-2026-31622
- EPSS 0.03%
- Veröffentlicht 24.04.2026 14:42:39
- Zuletzt bearbeitet 28.04.2026 14:14:07
In the Linux kernel, the following vulnerability has been resolved: NFC: digital: Bounds check NFC-A cascade depth in SDD response handler The NFC-A anti-collision cascade in digital_in_recv_sdd_res() appends 3 or 4 bytes to target->nfcid1 on each ...
CVE-2026-31618
- EPSS 0.02%
- Veröffentlicht 24.04.2026 14:42:37
- Zuletzt bearbeitet 28.04.2026 14:07:04
In the Linux kernel, the following vulnerability has been resolved: fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO Much like commit 19f953e74356 ("fbdev: fb_pm2fb: Avoid potential divide by zero error"), we also need to prevent that sam...
CVE-2026-31619
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:37
- Zuletzt bearbeitet 28.04.2026 14:09:16
In the Linux kernel, the following vulnerability has been resolved: ALSA: fireworks: bound device-supplied status before string array lookup The status field in an EFW response is a 32-bit value supplied by the firewire device. efr_status_names[] ...
CVE-2026-31617
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:36
- Zuletzt bearbeitet 28.04.2026 17:27:20
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() The block_len read from the host-supplied NTB header is checked against ntb_max but has no lower bound. When bloc...
CVE-2026-31616
- EPSS 0.01%
- Veröffentlicht 24.04.2026 14:42:35
- Zuletzt bearbeitet 28.04.2026 17:21:15
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() A broken/bored/mean USB host can overflow the skb_shared_info->frags[] array on a Linux gadget exposing a Phonet...