Количество 60
Количество 60
GHSA-w5h3-gv63-49vp
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the switch and returned the skb to the caller as if classification had passed. The only qdisc that wires up qevents today is RED, via three call sites (qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop) red_enqueue() was continuing to operate on an skb it no longer owns in this case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF. tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10 tc filter add block 10 ... action ct (with ct defrag enabled and traffic that produces out-of-order fragment...
RLSA-2026:59723
Important: kernel security, bug fix, and enhancement update
ELSA-2026-59723
ELSA-2026-59723: kernel security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3821-1
Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise 15 SP7)
RLSA-2026:49212
Important: kernel security update
ELSA-2026-49212
ELSA-2026-49212: kernel security update (IMPORTANT)
SUSE-SU-2026:3819-1
Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP6)
RLSA-2026:49214
Important: kernel security update
ELSA-2026-49214
ELSA-2026-49214: kernel security update (IMPORTANT)
SUSE-SU-2026:3807-1
Security update for the Linux Kernel (Live Patch 43 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3781-1
Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:3780-1
Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:3778-1
Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:3777-1
Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:3779-1
Security update for the Linux Kernel (Live Patch 15 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:3776-1
Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:3759-1
Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3775-1
Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6)
ELSA-2026-50006
ELSA-2026-50006: Unbreakable Enterprise kernel security update (IMPORTANT)
SUSE-SU-2026:3774-1
Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-w5h3-gv63-49vp In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the switch and returned the skb to the caller as if classification had passed. The only qdisc that wires up qevents today is RED, via three call sites (qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop) red_enqueue() was continuing to operate on an skb it no longer owns in this case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF. tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10 tc filter add block 10 ... action ct (with ct defrag enabled and traffic that produces out-of-order fragment... | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
RLSA-2026:59723 Important: kernel security, bug fix, and enhancement update | 14 дней назад | |||
ELSA-2026-59723 ELSA-2026-59723: kernel security, bug fix, and enhancement update (IMPORTANT) | 16 дней назад | |||
SUSE-SU-2026:3821-1 Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise 15 SP7) | 16 дней назад | |||
RLSA-2026:49212 Important: kernel security update | около 1 месяца назад | |||
ELSA-2026-49212 ELSA-2026-49212: kernel security update (IMPORTANT) | около 1 месяца назад | |||
SUSE-SU-2026:3819-1 Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP6) | 16 дней назад | |||
RLSA-2026:49214 Important: kernel security update | около 1 месяца назад | |||
ELSA-2026-49214 ELSA-2026-49214: kernel security update (IMPORTANT) | около 1 месяца назад | |||
SUSE-SU-2026:3807-1 Security update for the Linux Kernel (Live Patch 43 for SUSE Linux Enterprise 15 SP5) | 16 дней назад | |||
SUSE-SU-2026:3781-1 Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP7) | 17 дней назад | |||
SUSE-SU-2026:3780-1 Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise 15 SP7) | 17 дней назад | |||
SUSE-SU-2026:3778-1 Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7) | 17 дней назад | |||
SUSE-SU-2026:3777-1 Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP6) | 17 дней назад | |||
SUSE-SU-2026:3779-1 Security update for the Linux Kernel (Live Patch 15 for SUSE Linux Enterprise 15 SP7) | 17 дней назад | |||
SUSE-SU-2026:3776-1 Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP6) | 17 дней назад | |||
SUSE-SU-2026:3759-1 Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) | 17 дней назад | |||
SUSE-SU-2026:3775-1 Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6) | 17 дней назад | |||
ELSA-2026-50006 ELSA-2026-50006: Unbreakable Enterprise kernel security update (IMPORTANT) | 8 месяцев назад | |||
SUSE-SU-2026:3774-1 Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7) | 17 дней назад |
Уязвимостей на страницу