Количество 55
Количество 55
CVE-2026-43190
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload).
CVE-2026-43190
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload).
CVE-2026-43190
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload).
CVE-2026-43190
In the Linux kernel, the following vulnerability has been resolved: n ...
GHSA-395h-h5jq-ggp6
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload).
SUSE-SU-2026:3066-1
Security update for the Linux Kernel (Live Patch 78 for SUSE Linux Enterprise 12 SP5)
SUSE-SU-2026:3065-1
Security update for the Linux Kernel (Live Patch 74 for SUSE Linux Enterprise 12 SP5)
SUSE-SU-2026:3011-1
Security update for the Linux Kernel (Live Patch 82 for SUSE Linux Enterprise 12 SP5)
SUSE-SU-2026:2995-1
Security update for the Linux Kernel (Live Patch 69 for SUSE Linux Enterprise 12 SP5)
SUSE-SU-2026:2994-1
Security update for the Linux Kernel (Live Patch 80 for SUSE Linux Enterprise 12 SP5)
SUSE-SU-2026:2992-1
Security update for the Linux Kernel (Live Patch 70 for SUSE Linux Enterprise 12 SP5)
SUSE-SU-2026:2955-1
Security update for the Linux Kernel (Live Patch 71 for SUSE Linux Enterprise 12 SP5)
SUSE-SU-2026:2909-1
Security update for the Linux Kernel (Live Patch 72 for SUSE Linux Enterprise 12 SP5)
SUSE-SU-2026:2317-1
Security update for the Linux Kernel
RLSA-2026:21706
Important: kernel security update
RLSA-2026:21557
Important: kernel security update
ELSA-2026-21706
ELSA-2026-21706: kernel security update (IMPORTANT)
ELSA-2026-21557
ELSA-2026-21557: kernel security update (IMPORTANT)
RLSA-2026:21556
Important: kernel security update
SUSE-SU-2026:2937-1
Security update for the Linux Kernel (Live Patch 51 for SUSE Linux Enterprise 15 SP4)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-43190 In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload). | CVSS3: 8.2 | 0% Низкий | 3 месяца назад | |
CVE-2026-43190 In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload). | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-43190 In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload). | CVSS3: 8.2 | 0% Низкий | 3 месяца назад | |
CVE-2026-43190 In the Linux kernel, the following vulnerability has been resolved: n ... | CVSS3: 8.2 | 0% Низкий | 3 месяца назад | |
GHSA-395h-h5jq-ggp6 In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload). | CVSS3: 8.2 | 0% Низкий | 3 месяца назад | |
SUSE-SU-2026:3066-1 Security update for the Linux Kernel (Live Patch 78 for SUSE Linux Enterprise 12 SP5) | 21 день назад | |||
SUSE-SU-2026:3065-1 Security update for the Linux Kernel (Live Patch 74 for SUSE Linux Enterprise 12 SP5) | 21 день назад | |||
SUSE-SU-2026:3011-1 Security update for the Linux Kernel (Live Patch 82 for SUSE Linux Enterprise 12 SP5) | 22 дня назад | |||
SUSE-SU-2026:2995-1 Security update for the Linux Kernel (Live Patch 69 for SUSE Linux Enterprise 12 SP5) | 22 дня назад | |||
SUSE-SU-2026:2994-1 Security update for the Linux Kernel (Live Patch 80 for SUSE Linux Enterprise 12 SP5) | 22 дня назад | |||
SUSE-SU-2026:2992-1 Security update for the Linux Kernel (Live Patch 70 for SUSE Linux Enterprise 12 SP5) | 22 дня назад | |||
SUSE-SU-2026:2955-1 Security update for the Linux Kernel (Live Patch 71 for SUSE Linux Enterprise 12 SP5) | 23 дня назад | |||
SUSE-SU-2026:2909-1 Security update for the Linux Kernel (Live Patch 72 for SUSE Linux Enterprise 12 SP5) | 23 дня назад | |||
SUSE-SU-2026:2317-1 Security update for the Linux Kernel | около 2 месяцев назад | |||
RLSA-2026:21706 Important: kernel security update | 2 месяца назад | |||
RLSA-2026:21557 Important: kernel security update | 2 месяца назад | |||
ELSA-2026-21706 ELSA-2026-21706: kernel security update (IMPORTANT) | 2 месяца назад | |||
ELSA-2026-21557 ELSA-2026-21557: kernel security update (IMPORTANT) | 9 дней назад | |||
RLSA-2026:21556 Important: kernel security update | 2 месяца назад | |||
SUSE-SU-2026:2937-1 Security update for the Linux Kernel (Live Patch 51 for SUSE Linux Enterprise 15 SP4) | 23 дня назад |
Уязвимостей на страницу