CVE-2026-49426
- EPSS 0.15%
- Veröffentlicht 19.08.2026 06:17:41
- Zuletzt bearbeitet 01.09.2026 20:19:55
When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actual result of the executed system call. As a result, committed audit records f...
CVE-2026-49428
- EPSS 0.34%
- Veröffentlicht 19.08.2026 05:57:04
- Zuletzt bearbeitet 01.09.2026 20:05:56
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged...
CVE-2026-49427
- EPSS 0.34%
- Veröffentlicht 19.08.2026 05:56:53
- Zuletzt bearbeitet 01.09.2026 20:06:01
Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object with the SF_NOCACHE flag, it freed the underlying pages after transmission even though existing mappings still referred to them...
CVE-2026-49422
- EPSS 0.14%
- Veröffentlicht 19.08.2026 05:28:32
- Zuletzt bearbeitet 01.09.2026 20:20:00
The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the lock. After reacquiring, it verifies that the TCP stack had not been switched away, but did not reload its pointer to the stack...
CVE-2026-49421
- EPSS 0.13%
- Veröffentlicht 19.08.2026 05:25:43
- Zuletzt bearbeitet 01.09.2026 20:20:06
The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup. The flag was silently dropped, so path resolution was not actually restricted. A pro...
CVE-2026-49420
- EPSS 0.21%
- Veröffentlicht 19.08.2026 05:20:00
- Zuletzt bearbeitet 01.09.2026 20:20:12
The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer, or whether the result fit back in the original packet. A host sending crafted RTSP traffic from ins...
CVE-2026-49431
- EPSS 0.18%
- Veröffentlicht 19.08.2026 05:15:37
- Zuletzt bearbeitet 01.09.2026 20:05:26
The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream. Any local user ...
CVE-2026-49430
- EPSS 0.2%
- Veröffentlicht 19.08.2026 05:15:29
- Zuletzt bearbeitet 01.09.2026 20:05:45
The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit size as the length for a byteswap operation. A local user with the "receive" delegated ...
CVE-2026-49429
- EPSS 0.21%
- Veröffentlicht 19.08.2026 05:15:21
- Zuletzt bearbeitet 01.09.2026 20:05:50
The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but used the original 64-bit size as the buffer limit when writing records. A local user with the "useru...
CVE-2026-49415
- EPSS 0.12%
- Veröffentlicht 19.08.2026 04:38:24
- Zuletzt bearbeitet 01.09.2026 20:04:26
During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running as the same user can access the target process's memory via procfs or linprocfs, because ...