Количество 20
Количество 20
GHSA-j77r-m2hp-2792
In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Resto...
CVE-2026-43236
In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Restoring P...
CVE-2026-43236
In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Restoring P...
CVE-2026-43236
In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Restorin
CVE-2026-43236
In the Linux kernel, the following vulnerability has been resolved: d ...
BDU:2026-11102
Уязвимость функции atmel_hlcdc_plane_atomic_duplicate_state() модуля drivers/gpu/drm/atmel-hlcdc/atmel_hlcdc_plane.c драйвера инфраструктуры прямого рендеринга (DRI) ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
ROS-20260916-80-0093
Уязвимость kernel-lt
ROS-20260916-73-0087
Уязвимость kernel-lt
ALT-PU-2026-7465
ALT-PU-2026-7465: package `kernel-image-rt` update to version 5.10.252-alt1.rt148
ALT-PU-2026-4750
ALT-PU-2026-4750: package `kernel-image-std-def` update to version 5.10.252-alt1
ALT-PU-2026-7309
ALT-PU-2026-7309: package `kernel-image-pine` update to version 6.18.16-alt1
ALT-PU-2026-4126
ALT-PU-2026-4126: package `kernel-image-un-def` update to version 6.1.166-alt1
SUSE-SU-2026:3166-1
Security update for the Linux Kernel
SUSE-SU-2026:3130-1
Security update for the Linux Kernel
openSUSE-SU-2026:21555-1
Security update for the Linux Kernel
ALT-PU-2026-4865
ALT-PU-2026-4865: package `kernel-image-6.18` update to version 6.18.19-alt1
ALT-PU-2026-6044
ALT-PU-2026-6044: package `kernel-image-rpi-un` update to version 6.12.79-alt1
ALT-PU-2026-7006
ALT-PU-2026-7006: package `kernel-image-6.12` update to version 6.12.85-alt1
ALT-PU-2026-7004
ALT-PU-2026-7004: package `kernel-image-rt` update to version 6.12.85-alt1
ALT-PU-2026-9924
ALT-PU-2026-9924: package `kernel-image-rpi-un` update to version 6.12.94-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-j77r-m2hp-2792 In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Resto... | CVSS3: 7.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-43236 In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Restoring P... | CVSS3: 7.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-43236 In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Restoring P... | 0% Низкий | 5 месяцев назад | ||
CVE-2026-43236 In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Restorin | CVSS3: 7.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-43236 In the Linux kernel, the following vulnerability has been resolved: d ... | CVSS3: 7.8 | 0% Низкий | 5 месяцев назад | |
BDU:2026-11102 Уязвимость функции atmel_hlcdc_plane_atomic_duplicate_state() модуля drivers/gpu/drm/atmel-hlcdc/atmel_hlcdc_plane.c драйвера инфраструктуры прямого рендеринга (DRI) ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад | |
ROS-20260916-80-0093 Уязвимость kernel-lt | CVSS3: 7.8 | 0% Низкий | 10 дней назад | |
ROS-20260916-73-0087 Уязвимость kernel-lt | CVSS3: 7.8 | 0% Низкий | 10 дней назад | |
ALT-PU-2026-7465 ALT-PU-2026-7465: package `kernel-image-rt` update to version 5.10.252-alt1.rt148 | CVSS3: 8.8 | 6 месяцев назад | ||
ALT-PU-2026-4750 ALT-PU-2026-4750: package `kernel-image-std-def` update to version 5.10.252-alt1 | CVSS3: 8.8 | 7 месяцев назад | ||
ALT-PU-2026-7309 ALT-PU-2026-7309: package `kernel-image-pine` update to version 6.18.16-alt1 | CVSS3: 9.8 | 7 месяцев назад | ||
ALT-PU-2026-4126 ALT-PU-2026-4126: package `kernel-image-un-def` update to version 6.1.166-alt1 | CVSS3: 9.8 | 7 месяцев назад | ||
SUSE-SU-2026:3166-1 Security update for the Linux Kernel | 2 месяца назад | |||
SUSE-SU-2026:3130-1 Security update for the Linux Kernel | 2 месяца назад | |||
openSUSE-SU-2026:21555-1 Security update for the Linux Kernel | около 1 месяца назад | |||
ALT-PU-2026-4865 ALT-PU-2026-4865: package `kernel-image-6.18` update to version 6.18.19-alt1 | CVSS3: 9.8 | 6 месяцев назад | ||
ALT-PU-2026-6044 ALT-PU-2026-6044: package `kernel-image-rpi-un` update to version 6.12.79-alt1 | CVSS3: 9.8 | 6 месяцев назад | ||
ALT-PU-2026-7006 ALT-PU-2026-7006: package `kernel-image-6.12` update to version 6.12.85-alt1 | CVSS3: 9.8 | 5 месяцев назад | ||
ALT-PU-2026-7004 ALT-PU-2026-7004: package `kernel-image-rt` update to version 6.12.85-alt1 | CVSS3: 9.8 | 5 месяцев назад | ||
ALT-PU-2026-9924 ALT-PU-2026-9924: package `kernel-image-rpi-un` update to version 6.12.94-alt1 | CVSS3: 10 | 3 месяца назад |
Уязвимостей на страницу