Canonical

Ubuntu 26.04 LTS

1872 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 19.07.2026 14:55:07
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver overrides the maximum transfer size for a specific device which only accepts 16 byte packets for its 32 ...

  • EPSS 0.2%
  • Veröffentlicht 19.07.2026 14:55:06
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling The WebUSB GET_URL handler in composite_setup() narrows landing_page_length to fit the host-supplied wLengt...

  • EPSS 0.21%
  • Veröffentlicht 19.07.2026 14:55:06
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix missing interrupt-in transfer sanity check Add the missing sanity check on the size of interrupt-in transfers to avoid parsing stale or uninitialised sla...

  • EPSS 0.24%
  • Veröffentlicht 19.07.2026 14:55:05
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: copy only received bytes on short ep0 read ffs_ep0_read() allocates its control-OUT data buffer with kmalloc() (not kzalloc) at the Length value from the Setup p...

  • EPSS 0.39%
  • Veröffentlicht 19.07.2026 14:55:04
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() entry->value is u32 and entry->length is u16; the sum is performed in u32 and wraps. A malicious XDomain peer c...

  • EPSS 0.16%
  • Veröffentlicht 19.07.2026 14:55:04
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: serialize DMABUF cancel against request completion ffs_epfile_dmabuf_io_complete() calls usb_ep_free_request() on the completed request but leaves priv->req, the...

  • EPSS 0.22%
  • Veröffentlicht 19.07.2026 14:55:03
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). Two...

  • EPSS 0.21%
  • Veröffentlicht 19.07.2026 14:55:02
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the descriptor cursor by an attacker-supplied...

  • EPSS 0.26%
  • Veröffentlicht 19.07.2026 14:55:02
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() A DIRECTORY entry's value field is used as the dir_offset for a recursive call into __tb_property_parse_dir(...

  • EPSS 0.33%
  • Veröffentlicht 19.07.2026 14:55:01
  • Zuletzt bearbeitet 27.07.2026 17:44:23

In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS frame to an lpfc or qla2xxx Linux initiator can ...