Количество 47
Количество 47
CVE-2026-64530
In the Linux kernel, the following vulnerability has been resolved: n ...
CVE-2026-46150
In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group.
CVE-2026-46150
In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group.
CVE-2026-46150
In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group.
CVE-2026-46150
fanotify: fix false positive on permission events
CVE-2026-46150
In the Linux kernel, the following vulnerability has been resolved: f ...
GHSA-w5h3-gv63-49vp
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the switch and returned the skb to the caller as if classification had passed. The only qdisc that wires up qevents today is RED, via three call sites (qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop) red_enqueue() was continuing to operate on an skb it no longer owns in this case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF. tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10 tc filter add block 10 ... action ct (with ct defrag enabled and traffic that produces out-of-order fragment...
GHSA-97pw-xx9j-rg9j
In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group.
RLSA-2026:25217
Important: kernel security update
ELSA-2026-25217
ELSA-2026-25217: kernel security update (IMPORTANT)
RLSA-2026:49212
Important: kernel security update
RLSA-2026:49211
Important: kernel security, bug fix, and enhancement update
ELSA-2026-49212
ELSA-2026-49212: kernel security update (IMPORTANT)
ELSA-2026-49211
ELSA-2026-49211: kernel security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:21557
Important: kernel security update
ELSA-2026-21557
ELSA-2026-21557: kernel security update (IMPORTANT)
RLSA-2026:43307
Important: kernel security, bug fix, and enhancement update
ELSA-2026-43307
ELSA-2026-43307: kernel security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:42919
Important: kernel security, bug fix, and enhancement update
ELSA-2026-42919
ELSA-2026-42919: kernel security, bug fix, and enhancement update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-64530 In the Linux kernel, the following vulnerability has been resolved: n ... | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-46150 In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-46150 In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-46150 In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-46150 fanotify: fix false positive on permission events | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-46150 In the Linux kernel, the following vulnerability has been resolved: f ... | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
GHSA-w5h3-gv63-49vp In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the switch and returned the skb to the caller as if classification had passed. The only qdisc that wires up qevents today is RED, via three call sites (qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop) red_enqueue() was continuing to operate on an skb it no longer owns in this case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF. tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10 tc filter add block 10 ... action ct (with ct defrag enabled and traffic that produces out-of-order fragment... | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
GHSA-97pw-xx9j-rg9j In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
RLSA-2026:25217 Important: kernel security update | 3 месяца назад | |||
ELSA-2026-25217 ELSA-2026-25217: kernel security update (IMPORTANT) | 2 месяца назад | |||
RLSA-2026:49212 Important: kernel security update | около 1 месяца назад | |||
RLSA-2026:49211 Important: kernel security, bug fix, and enhancement update | около 1 месяца назад | |||
ELSA-2026-49212 ELSA-2026-49212: kernel security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-49211 ELSA-2026-49211: kernel security, bug fix, and enhancement update (IMPORTANT) | около 1 месяца назад | |||
RLSA-2026:21557 Important: kernel security update | 3 месяца назад | |||
ELSA-2026-21557 ELSA-2026-21557: kernel security update (IMPORTANT) | около 1 месяца назад | |||
RLSA-2026:43307 Important: kernel security, bug fix, and enhancement update | около 2 месяцев назад | |||
ELSA-2026-43307 ELSA-2026-43307: kernel security, bug fix, and enhancement update (IMPORTANT) | около 2 месяцев назад | |||
RLSA-2026:42919 Important: kernel security, bug fix, and enhancement update | около 2 месяцев назад | |||
ELSA-2026-42919 ELSA-2026-42919: kernel security, bug fix, and enhancement update (IMPORTANT) | около 2 месяцев назад |
Уязвимостей на страницу