Количество 19
Количество 19
CVE-2026-53195
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space.
CVE-2026-53195
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space.
CVE-2026-53195
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space.
CVE-2026-53195
USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
CVE-2026-53195
In the Linux kernel, the following vulnerability has been resolved: U ...
GHSA-397c-7vfx-vg4x
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space.
BDU:2026-14030
Уязвимость функции build_i2c_fw_hdr() модуля drivers/usb/serial/io_ti.c драйвера устройств шины USB ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
ALT-PU-2026-10474
ALT-PU-2026-10474: package `kernel-image-std-def` update to version 5.10.260-alt1
ALT-PU-2026-10470
ALT-PU-2026-10470: package `kernel-image-un-def` update to version 6.1.177-alt1
ALT-PU-2026-10111
ALT-PU-2026-10111: package `kernel-image-6.18` update to version 6.18.37-alt1
ELBA-2026-500163
ELBA-2026-500163: Unbreakable Enterprise kernel bug fix update (NA)
SUSE-SU-2026:3166-1
Security update for the Linux Kernel
SUSE-SU-2026:3130-1
Security update for the Linux Kernel
ALT-PU-2026-9890
ALT-PU-2026-9890: package `kernel-image-rpi-un` update to version 6.12.94-alt1
openSUSE-SU-2026:21555-1
Security update for the Linux Kernel
ALT-PU-2026-9892
ALT-PU-2026-9892: package `kernel-image-6.12` update to version 6.12.94-alt1
ALT-PU-2026-11671
ALT-PU-2026-11671: package `kernel-image-rt` update to version 6.12.98-alt1
ELSA-2026-500248
ELSA-2026-500248: Unbreakable Enterprise kernel security update (IMPORTANT)
ALT-PU-2026-9924
ALT-PU-2026-9924: package `kernel-image-rpi-un` update to version 6.12.94-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-53195 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-53195 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space. | CVSS3: 7 | 0% Низкий | 3 месяца назад | |
CVE-2026-53195 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-53195 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-53195 In the Linux kernel, the following vulnerability has been resolved: U ... | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
GHSA-397c-7vfx-vg4x In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
BDU:2026-14030 Уязвимость функции build_i2c_fw_hdr() модуля drivers/usb/serial/io_ti.c драйвера устройств шины USB ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
ALT-PU-2026-10474 ALT-PU-2026-10474: package `kernel-image-std-def` update to version 5.10.260-alt1 | CVSS3: 10 | 2 месяца назад | ||
ALT-PU-2026-10470 ALT-PU-2026-10470: package `kernel-image-un-def` update to version 6.1.177-alt1 | CVSS3: 10 | 2 месяца назад | ||
ALT-PU-2026-10111 ALT-PU-2026-10111: package `kernel-image-6.18` update to version 6.18.37-alt1 | CVSS3: 10 | 3 месяца назад | ||
ELBA-2026-500163 ELBA-2026-500163: Unbreakable Enterprise kernel bug fix update (NA) | около 2 месяцев назад | |||
SUSE-SU-2026:3166-1 Security update for the Linux Kernel | 2 месяца назад | |||
SUSE-SU-2026:3130-1 Security update for the Linux Kernel | 2 месяца назад | |||
ALT-PU-2026-9890 ALT-PU-2026-9890: package `kernel-image-rpi-un` update to version 6.12.94-alt1 | CVSS3: 10 | 3 месяца назад | ||
openSUSE-SU-2026:21555-1 Security update for the Linux Kernel | около 1 месяца назад | |||
ALT-PU-2026-9892 ALT-PU-2026-9892: package `kernel-image-6.12` update to version 6.12.94-alt1 | CVSS3: 10 | 3 месяца назад | ||
ALT-PU-2026-11671 ALT-PU-2026-11671: package `kernel-image-rt` update to version 6.12.98-alt1 | CVSS3: 10 | около 2 месяцев назад | ||
ELSA-2026-500248 ELSA-2026-500248: Unbreakable Enterprise kernel security update (IMPORTANT) | 21 день назад | |||
ALT-PU-2026-9924 ALT-PU-2026-9924: package `kernel-image-rpi-un` update to version 6.12.94-alt1 | CVSS3: 10 | 3 месяца назад |
Уязвимостей на страницу