Количество 52 848
Количество 52 848
CVE-2026-64416
A flaw was found in the Linux kernel's memory management subsystem, specifically within the swap cgroup functionality. When a system is configured without swap, a corrupted page table entry (PTE) can lead to a null pointer dereference during process exit. This vulnerability allows a local attacker to cause a system crash, resulting in a Denial of Service (DoS).
CVE-2026-64415
A flaw was found in the Linux kernel's memory management (mm/swap) component. Under heavy memory and swap stress, a local attacker could trigger a softlockup during large swap cluster reclaim operations. This vulnerability can lead to a Denial of Service (DoS), making the system unresponsive.
CVE-2026-64414
A flaw was found in the Linux kernel's netfilter subsystem. This vulnerability occurs when the u32 module processes network packets containing unreadable fragments, leading to improper handling of these fragments. A remote attacker could exploit this flaw by sending specially crafted network traffic, potentially causing a denial of service (DoS) on the affected system.
CVE-2026-64413
A flaw was found in the Linux kernel's netfilter ebtables component. This vulnerability involves an uninitialized pointer free that can occur when the system's CPU mask is sparse and a memory allocation fails. Under these specific and unlikely conditions, the kernel might attempt to free an uninitialized memory pointer, which could lead to system instability or a denial of service (DoS).
CVE-2026-64412
A flaw was found in the Linux kernel's netfilter ebtables component. A local attacker could exploit this vulnerability by providing a specially crafted module name that is not properly null-terminated. This improper string handling could lead to a buffer over-read when the `request_module()` function processes the string. Successful exploitation could result in information disclosure, allowing an attacker to read sensitive kernel memory, or a denial of service (DoS), causing the system to crash.
CVE-2026-64411
A flaw was found in the Linux kernel's netfilter ebtables component. A local user could exploit this vulnerability by providing a specially crafted table name that is not properly terminated. This improper handling of the table name can lead to a stack-out-of-bounds read, potentially causing a system crash (Denial of Service) or the disclosure of sensitive information from kernel memory.
CVE-2026-64410
A flaw was found in the Linux kernel's netfilter component, specifically concerning the handling of IPIP (IP-in-IP) tunnel hardware offload. The system attempts to utilize hardware offload for IPIP tunnels, a feature not yet supported by existing drivers. A remote attacker could potentially exploit this unsupported operation, leading to a denial of service, compromise of data integrity, or disclosure of sensitive information due to the improper processing of network traffic.
CVE-2026-64409
A flaw was found in the Linux kernel's Bluetooth MTK SDIO (btmtksdio) driver. An incorrect timeout check in the btmtksdio_txrx_work() function can lead to an infinite loop. This prevents the loop from terminating and releasing the SDIO host, resulting in a denial of service (DoS) where the system resource becomes unresponsive.
CVE-2026-64408
A flaw was found in the Bluetooth Network Encapsulation Protocol (BNEP) module of the Linux kernel. The `bnep_add_connection()` function reads the Logical Link Control and Adaptation Protocol (L2CAP) connection without properly holding a channel lock. This can allow a local attacker to trigger a use-after-free vulnerability during network device registration, potentially leading to a system crash and denial of service.
CVE-2026-64407
A flaw was found in the Linux kernel's Bluetooth driver. A malicious Bluetooth controller could send a specially crafted firmware download request that causes an out-of-bounds read. This allows the driver to read memory beyond the intended firmware data and send it back over the Universal Asynchronous Receiver-Transmitter (UART), leading to information disclosure.
CVE-2026-64406
A flaw was found in the Linux kernel's Bluetooth subsystem. This use-after-free (UAF) vulnerability in the `bt_accept_dequeue()` function occurs because a temporary reference is prematurely dropped, leading to `sock_hold()` accessing freed memory. An attacker could potentially exploit this to cause a denial of service (DoS) or other unpredictable system behavior.
CVE-2026-64405
A flaw was found in the Linux kernel's Bluetooth subsystem, specifically within the hci_conn module. This vulnerability occurs when the hci_abort_conn() function attempts to process a pending connection while a critical pointer is unexpectedly null. This can lead to a null pointer dereference, causing a general protection fault and resulting in a system crash. The primary impact is a Denial of Service (DoS), making the system unavailable.
CVE-2026-64404
A flaw was found in the Linux kernel's Bluetooth subsystem. A race condition exists in the iso_conn_big_sync() function where a socket lock is temporarily released and re-acquired. During this window, the Bluetooth connection can be unexpectedly terminated. If the connection is torn down, the subsequent attempt to access connection details can lead to a null pointer dereference, causing the system to crash. This vulnerability can result in a Denial of Service (DoS) for an affected system.
CVE-2026-64403
A flaw was found in the Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) component of the Linux kernel. The `l2cap_get_conf_opt()` function, responsible for processing configuration options, does not properly validate the length of an option before attempting to read its value. This allows an attacker to control the option length, potentially leading to an out-of-bounds read of up to 4 bytes past the end of a buffer. Although current safeguards prevent immediate data leakage, this vulnerability represents a critical validate-after-use ordering bug that could be exploited in future system configurations.
CVE-2026-64402
A flaw was found in the Linux kernel's coresight ultrasoc-smb component. This vulnerability involves an out-of-bounds write in the `smb_sync_perf_buffer()` function. An attacker could potentially exploit this by causing the system to write data beyond the intended memory buffer, which may lead to system instability or a denial of service (DoS). This occurs because a page index is calculated incorrectly before being properly normalized, allowing the system to access memory outside its allocated boundaries.
CVE-2026-64401
A flaw was found in the Linux kernel's Server Message Block (SMB) client. This vulnerability, a use-after-free, occurs when handling witness registrations. Specifically, a second mount for the same network share can cause the system to incorrectly reference a previously freed connection, leading to a use-after-free condition. This can result in system instability or potentially more severe impacts.
CVE-2026-64400
A flaw was found in the Linux kernel's ksmbd component. A vulnerability in the ksmbd component allows a remote authenticated attacker to bypass path restrictions. Specifically, a bug in the caseless retry logic during path resolution fails to properly handle directory traversal attempts. This allows the attacker to create files or directories outside of the intended shared directory boundaries.
CVE-2026-64399
A flaw was found in ksmbd. This vulnerability allows a remote attacker to overwrite data on a shared file system due to insufficient permission checks in the FSCTL_DUPLICATE_EXTENTS_TO_FILE function. Even if a share is configured as read-only or a client has limited write attributes, an attacker can still modify the destination file's data, leading to unauthorized data alteration.
CVE-2026-64398
A flaw was found in the Linux kernel's ksmbd component. An authenticated Server Message Block (SMB) client with only FILE_WRITE_ATTRIBUTES permission can bypass a security check in the FSCTL_SET_ZERO_DATA function. This allows the client to zero out file data, leading to data destruction and a denial of service.
CVE-2026-64397
A flaw was found in the Linux kernel's ksmbd (kernel Server Message Block daemon) component. Concurrent directory query requests using the same file handle can lead to a stack use-after-free vulnerability. This occurs because smb2_query_dir() stores a pointer to stack-allocated data that can be overwritten by another request while still in use. An attacker could exploit this to cause a denial of service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-64416 A flaw was found in the Linux kernel's memory management subsystem, specifically within the swap cgroup functionality. When a system is configured without swap, a corrupted page table entry (PTE) can lead to a null pointer dereference during process exit. This vulnerability allows a local attacker to cause a system crash, resulting in a Denial of Service (DoS). | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64415 A flaw was found in the Linux kernel's memory management (mm/swap) component. Under heavy memory and swap stress, a local attacker could trigger a softlockup during large swap cluster reclaim operations. This vulnerability can lead to a Denial of Service (DoS), making the system unresponsive. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64414 A flaw was found in the Linux kernel's netfilter subsystem. This vulnerability occurs when the u32 module processes network packets containing unreadable fragments, leading to improper handling of these fragments. A remote attacker could exploit this flaw by sending specially crafted network traffic, potentially causing a denial of service (DoS) on the affected system. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64413 A flaw was found in the Linux kernel's netfilter ebtables component. This vulnerability involves an uninitialized pointer free that can occur when the system's CPU mask is sparse and a memory allocation fails. Under these specific and unlikely conditions, the kernel might attempt to free an uninitialized memory pointer, which could lead to system instability or a denial of service (DoS). | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64412 A flaw was found in the Linux kernel's netfilter ebtables component. A local attacker could exploit this vulnerability by providing a specially crafted module name that is not properly null-terminated. This improper string handling could lead to a buffer over-read when the `request_module()` function processes the string. Successful exploitation could result in information disclosure, allowing an attacker to read sensitive kernel memory, or a denial of service (DoS), causing the system to crash. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64411 A flaw was found in the Linux kernel's netfilter ebtables component. A local user could exploit this vulnerability by providing a specially crafted table name that is not properly terminated. This improper handling of the table name can lead to a stack-out-of-bounds read, potentially causing a system crash (Denial of Service) or the disclosure of sensitive information from kernel memory. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64410 A flaw was found in the Linux kernel's netfilter component, specifically concerning the handling of IPIP (IP-in-IP) tunnel hardware offload. The system attempts to utilize hardware offload for IPIP tunnels, a feature not yet supported by existing drivers. A remote attacker could potentially exploit this unsupported operation, leading to a denial of service, compromise of data integrity, or disclosure of sensitive information due to the improper processing of network traffic. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64409 A flaw was found in the Linux kernel's Bluetooth MTK SDIO (btmtksdio) driver. An incorrect timeout check in the btmtksdio_txrx_work() function can lead to an infinite loop. This prevents the loop from terminating and releasing the SDIO host, resulting in a denial of service (DoS) where the system resource becomes unresponsive. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64408 A flaw was found in the Bluetooth Network Encapsulation Protocol (BNEP) module of the Linux kernel. The `bnep_add_connection()` function reads the Logical Link Control and Adaptation Protocol (L2CAP) connection without properly holding a channel lock. This can allow a local attacker to trigger a use-after-free vulnerability during network device registration, potentially leading to a system crash and denial of service. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64407 A flaw was found in the Linux kernel's Bluetooth driver. A malicious Bluetooth controller could send a specially crafted firmware download request that causes an out-of-bounds read. This allows the driver to read memory beyond the intended firmware data and send it back over the Universal Asynchronous Receiver-Transmitter (UART), leading to information disclosure. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64406 A flaw was found in the Linux kernel's Bluetooth subsystem. This use-after-free (UAF) vulnerability in the `bt_accept_dequeue()` function occurs because a temporary reference is prematurely dropped, leading to `sock_hold()` accessing freed memory. An attacker could potentially exploit this to cause a denial of service (DoS) or other unpredictable system behavior. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64405 A flaw was found in the Linux kernel's Bluetooth subsystem, specifically within the hci_conn module. This vulnerability occurs when the hci_abort_conn() function attempts to process a pending connection while a critical pointer is unexpectedly null. This can lead to a null pointer dereference, causing a general protection fault and resulting in a system crash. The primary impact is a Denial of Service (DoS), making the system unavailable. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64404 A flaw was found in the Linux kernel's Bluetooth subsystem. A race condition exists in the iso_conn_big_sync() function where a socket lock is temporarily released and re-acquired. During this window, the Bluetooth connection can be unexpectedly terminated. If the connection is torn down, the subsequent attempt to access connection details can lead to a null pointer dereference, causing the system to crash. This vulnerability can result in a Denial of Service (DoS) for an affected system. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64403 A flaw was found in the Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) component of the Linux kernel. The `l2cap_get_conf_opt()` function, responsible for processing configuration options, does not properly validate the length of an option before attempting to read its value. This allows an attacker to control the option length, potentially leading to an out-of-bounds read of up to 4 bytes past the end of a buffer. Although current safeguards prevent immediate data leakage, this vulnerability represents a critical validate-after-use ordering bug that could be exploited in future system configurations. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64402 A flaw was found in the Linux kernel's coresight ultrasoc-smb component. This vulnerability involves an out-of-bounds write in the `smb_sync_perf_buffer()` function. An attacker could potentially exploit this by causing the system to write data beyond the intended memory buffer, which may lead to system instability or a denial of service (DoS). This occurs because a page index is calculated incorrectly before being properly normalized, allowing the system to access memory outside its allocated boundaries. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64401 A flaw was found in the Linux kernel's Server Message Block (SMB) client. This vulnerability, a use-after-free, occurs when handling witness registrations. Specifically, a second mount for the same network share can cause the system to incorrectly reference a previously freed connection, leading to a use-after-free condition. This can result in system instability or potentially more severe impacts. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64400 A flaw was found in the Linux kernel's ksmbd component. A vulnerability in the ksmbd component allows a remote authenticated attacker to bypass path restrictions. Specifically, a bug in the caseless retry logic during path resolution fails to properly handle directory traversal attempts. This allows the attacker to create files or directories outside of the intended shared directory boundaries. | 0% Низкий | 8 дней назад | ||
CVE-2026-64399 A flaw was found in ksmbd. This vulnerability allows a remote attacker to overwrite data on a shared file system due to insufficient permission checks in the FSCTL_DUPLICATE_EXTENTS_TO_FILE function. Even if a share is configured as read-only or a client has limited write attributes, an attacker can still modify the destination file's data, leading to unauthorized data alteration. | 0% Низкий | 8 дней назад | ||
CVE-2026-64398 A flaw was found in the Linux kernel's ksmbd component. An authenticated Server Message Block (SMB) client with only FILE_WRITE_ATTRIBUTES permission can bypass a security check in the FSCTL_SET_ZERO_DATA function. This allows the client to zero out file data, leading to data destruction and a denial of service. | 0% Низкий | 8 дней назад | ||
CVE-2026-64397 A flaw was found in the Linux kernel's ksmbd (kernel Server Message Block daemon) component. Concurrent directory query requests using the same file handle can lead to a stack use-after-free vulnerability. This occurs because smb2_query_dir() stores a pointer to stack-allocated data that can be overwritten by another request while still in use. An attacker could exploit this to cause a denial of service. | 0% Низкий | 8 дней назад |
Уязвимостей на страницу