Canonical

Ubuntu 24.04 LTS

5749 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 24.04.2026 14:42:34
  • Zuletzt bearbeitet 29.04.2026 18:03:40

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix off-by-8 bounds check in check_wsl_eas() The bounds check uses (u8 *)ea + nlen + 1 + vlen as the end of the EA name and value, but ea_data sits at offset sizeof(st...

  • EPSS 0.02%
  • Veröffentlicht 24.04.2026 14:42:34
  • Zuletzt bearbeitet 28.04.2026 17:29:26

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: renesas_usb3: validate endpoint index in standard request handlers The GET_STATUS and SET/CLEAR_FEATURE handlers extract the endpoint number from the host-supplied wIn...

  • EPSS 0.05%
  • Veröffentlicht 24.04.2026 14:42:33
  • Zuletzt bearbeitet 28.04.2026 15:13:18

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB reads parsing symlink error response When a CREATE returns STATUS_STOPPED_ON_SYMLINK, smb2_check_message() returns success without any length validation, leavi...

  • EPSS 0.07%
  • Veröffentlicht 24.04.2026 14:42:32
  • Zuletzt bearbeitet 29.04.2026 16:56:48

In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on match reads sid.sub_auth[2] as the file mode. If si...

  • EPSS 0.05%
  • Veröffentlicht 24.04.2026 14:42:32
  • Zuletzt bearbeitet 29.04.2026 17:00:28

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate EaNameLength in smb2_get_ea() smb2_get_ea() reads ea_req->EaNameLength from the client request and passes it directly to strncmp() as the comparison length without ...

  • EPSS 0.02%
  • Veröffentlicht 24.04.2026 14:42:31
  • Zuletzt bearbeitet 29.04.2026 16:51:02

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc The kernel ASN.1 BER decoder calls action callbacks incrementally as it walks the input. When ksmbd_decode_neg...

  • EPSS 0.07%
  • Veröffentlicht 24.04.2026 14:42:29
  • Zuletzt bearbeitet 28.04.2026 15:11:28

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_...

  • EPSS 0.01%
  • Veröffentlicht 24.04.2026 14:42:28
  • Zuletzt bearbeitet 29.04.2026 19:36:00

In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO Much like commit 19f953e74356 ("fbdev: fb_pm2fb: Avoid potential divide by zero error"), we also need to prevent that same...

  • EPSS 0.01%
  • Veröffentlicht 24.04.2026 14:42:28
  • Zuletzt bearbeitet 29.04.2026 20:00:34

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: don't call cdev_init while cdev in use When calling unbind, then bind again, cdev_init reinitialized the cdev, even though there may still be references to it. ...

  • EPSS 0.01%
  • Veröffentlicht 24.04.2026 14:42:27
  • Zuletzt bearbeitet 29.04.2026 19:21:26

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix device leak on probe failure Driver core holds a reference to the USB interface and its parent USB device while the interface is bound to a driver and there is no ...