Количество 46
Количество 46
CVE-2026-53006
ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-53006
In the Linux kernel, the following vulnerability has been resolved: i ...
CVE-2026-52993
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.
CVE-2026-52993
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.
CVE-2026-52993
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.
CVE-2026-52993
tipc: fix double-free in tipc_buf_append()
CVE-2026-52993
In the Linux kernel, the following vulnerability has been resolved: t ...
RLSA-2026:47040
Important: kernel security, bug fix, and enhancement update
ELSA-2026-47040
ELSA-2026-47040: kernel security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:47011
Important: kernel security update
GHSA-f2fg-xhhc-4m4w
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr when net_dbg_ratelimited() is called in the slow path. - Avoid potential future misuse after pskb_pull() call.
ELSA-2026-47011
ELSA-2026-47011: kernel security update (IMPORTANT)
GHSA-m86q-cgj9-94c8
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.
RLSA-2026:45115
Important: kernel security update
ELSA-2026-45115
ELSA-2026-45115: kernel security update (IMPORTANT)
SUSE-SU-2026:3166-1
Security update for the Linux Kernel
SUSE-SU-2026:3130-1
Security update for the Linux Kernel
RLSA-2026:45192
Important: kernel security, bug fix, and enhancement update
ELSA-2026-45192
ELSA-2026-45192: kernel security, bug fix, and enhancement update (IMPORTANT)
openSUSE-SU-2026:21388-1
Security update for the Linux Kernel
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-53006 ipv6: fix possible UAF in icmpv6_rcv() | CVSS3: 7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53006 In the Linux kernel, the following vulnerability has been resolved: i ... | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-52993 In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-52993 In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations. | CVSS3: 7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-52993 In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-52993 tipc: fix double-free in tipc_buf_append() | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-52993 In the Linux kernel, the following vulnerability has been resolved: t ... | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
RLSA-2026:47040 Important: kernel security, bug fix, and enhancement update | 4 дня назад | |||
ELSA-2026-47040 ELSA-2026-47040: kernel security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
RLSA-2026:47011 Important: kernel security update | 0% Низкий | 6 дней назад | ||
GHSA-f2fg-xhhc-4m4w In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr when net_dbg_ratelimited() is called in the slow path. - Avoid potential future misuse after pskb_pull() call. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
ELSA-2026-47011 ELSA-2026-47011: kernel security update (IMPORTANT) | 0% Низкий | 5 дней назад | ||
GHSA-m86q-cgj9-94c8 In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
RLSA-2026:45115 Important: kernel security update | 8 дней назад | |||
ELSA-2026-45115 ELSA-2026-45115: kernel security update (IMPORTANT) | 6 дней назад | |||
SUSE-SU-2026:3166-1 Security update for the Linux Kernel | 13 дней назад | |||
SUSE-SU-2026:3130-1 Security update for the Linux Kernel | 14 дней назад | |||
RLSA-2026:45192 Important: kernel security, bug fix, and enhancement update | 7 дней назад | |||
ELSA-2026-45192 ELSA-2026-45192: kernel security, bug fix, and enhancement update (IMPORTANT) | 6 дней назад | |||
openSUSE-SU-2026:21388-1 Security update for the Linux Kernel | 14 дней назад |
Уязвимостей на страницу