Количество 20
Количество 20
BDU:2026-11100
Уязвимость функции fst_remove_one() модуля drivers/net/wan/farsync.c драйвера сетевых устройств ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
ROS-20260916-80-0095
Уязвимость kernel-lt
ROS-20260916-73-0089
Уязвимость kernel-lt
CVE-2026-43232
In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00 Read of size 4 at addr ffff88800aad101c by task ksoftirqd/3/32 ... Call Trace: <IRQ> ...
CVE-2026-43232
In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00 Read of size 4 at addr ffff88800aad101c by task ksoftirqd/3/32 ... Call Trace: <IRQ> ...
CVE-2026-43232
In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00
CVE-2026-43232
In the Linux kernel, the following vulnerability has been resolved: n ...
GHSA-84hg-9fjm-pcr7
In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0x...
ALT-PU-2026-7465
ALT-PU-2026-7465: package `kernel-image-rt` update to version 5.10.252-alt1.rt148
ALT-PU-2026-4750
ALT-PU-2026-4750: package `kernel-image-std-def` update to version 5.10.252-alt1
ALT-PU-2026-7309
ALT-PU-2026-7309: package `kernel-image-pine` update to version 6.18.16-alt1
ALT-PU-2026-4126
ALT-PU-2026-4126: package `kernel-image-un-def` update to version 6.1.166-alt1
ALT-PU-2026-4865
ALT-PU-2026-4865: package `kernel-image-6.18` update to version 6.18.19-alt1
ALT-PU-2026-6044
ALT-PU-2026-6044: package `kernel-image-rpi-un` update to version 6.12.79-alt1
ALT-PU-2026-7006
ALT-PU-2026-7006: package `kernel-image-6.12` update to version 6.12.85-alt1
ALT-PU-2026-7004
ALT-PU-2026-7004: package `kernel-image-rt` update to version 6.12.85-alt1
ALT-PU-2026-9924
ALT-PU-2026-9924: package `kernel-image-rpi-un` update to version 6.12.94-alt1
SUSE-SU-2026:3166-1
Security update for the Linux Kernel
SUSE-SU-2026:3130-1
Security update for the Linux Kernel
openSUSE-SU-2026:21555-1
Security update for the Linux Kernel
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-11100 Уязвимость функции fst_remove_one() модуля drivers/net/wan/farsync.c драйвера сетевых устройств ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 8.8 | 0% Низкий | 7 месяцев назад | |
ROS-20260916-80-0095 Уязвимость kernel-lt | CVSS3: 8.8 | 0% Низкий | 9 дней назад | |
ROS-20260916-73-0089 Уязвимость kernel-lt | CVSS3: 8.8 | 0% Низкий | 9 дней назад | |
CVE-2026-43232 In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00 Read of size 4 at addr ffff88800aad101c by task ksoftirqd/3/32 ... Call Trace: <IRQ> ... | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-43232 In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00 Read of size 4 at addr ffff88800aad101c by task ksoftirqd/3/32 ... Call Trace: <IRQ> ... | 0% Низкий | 5 месяцев назад | ||
CVE-2026-43232 In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00 | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-43232 In the Linux kernel, the following vulnerability has been resolved: n ... | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
GHSA-84hg-9fjm-pcr7 In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0x... | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
ALT-PU-2026-7465 ALT-PU-2026-7465: package `kernel-image-rt` update to version 5.10.252-alt1.rt148 | CVSS3: 8.8 | 6 месяцев назад | ||
ALT-PU-2026-4750 ALT-PU-2026-4750: package `kernel-image-std-def` update to version 5.10.252-alt1 | CVSS3: 8.8 | 7 месяцев назад | ||
ALT-PU-2026-7309 ALT-PU-2026-7309: package `kernel-image-pine` update to version 6.18.16-alt1 | CVSS3: 9.8 | 7 месяцев назад | ||
ALT-PU-2026-4126 ALT-PU-2026-4126: package `kernel-image-un-def` update to version 6.1.166-alt1 | CVSS3: 9.8 | 7 месяцев назад | ||
ALT-PU-2026-4865 ALT-PU-2026-4865: package `kernel-image-6.18` update to version 6.18.19-alt1 | CVSS3: 9.8 | 6 месяцев назад | ||
ALT-PU-2026-6044 ALT-PU-2026-6044: package `kernel-image-rpi-un` update to version 6.12.79-alt1 | CVSS3: 9.8 | 6 месяцев назад | ||
ALT-PU-2026-7006 ALT-PU-2026-7006: package `kernel-image-6.12` update to version 6.12.85-alt1 | CVSS3: 9.8 | 5 месяцев назад | ||
ALT-PU-2026-7004 ALT-PU-2026-7004: package `kernel-image-rt` update to version 6.12.85-alt1 | CVSS3: 9.8 | 5 месяцев назад | ||
ALT-PU-2026-9924 ALT-PU-2026-9924: package `kernel-image-rpi-un` update to version 6.12.94-alt1 | CVSS3: 10 | 3 месяца назад | ||
SUSE-SU-2026:3166-1 Security update for the Linux Kernel | 2 месяца назад | |||
SUSE-SU-2026:3130-1 Security update for the Linux Kernel | 2 месяца назад | |||
openSUSE-SU-2026:21555-1 Security update for the Linux Kernel | около 1 месяца назад |
Уязвимостей на страницу