0.0

CVE-2026-43422 - usb: legacy: ncm: Fix NPE in gncm_bind

In the Linux kernel, the following vulnerability has been resolved: usb: legacy: ncm: Fix NPE in gncm_bind Commit 56a512a9b410 ("usb: gadget: f_ncm: align net_device lifecycle with bind/unbind") deferred the allocation of the net_device. This change leads to a NULL pointer dereference in the lega…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.

0.0

CVE-2026-43421 - usb: gadget: f_ncm: Fix net_device lifecycle with device_move

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Fix net_device lifecycle with device_move The network device outlived its parent gadget device during disconnection, resulting in dangling sysfs links and null pointer dereference problems. A prior attempt to…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.

0.0

CVE-2026-43420 - ceph: fix i_nlink underrun during async unlink

In the Linux kernel, the following vulnerability has been resolved: ceph: fix i_nlink underrun during async unlink During async unlink, we drop the `i_nlink` counter before we receive the completion (that will eventually update the `i_nlink`) because "we assume that the unlink will succeed". Tha…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.

8.6

CVSS4.0

CVE-2025-67486 - Dolibarr has an Authenticated Remote Code Execution via eval() injection in user extrafields

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the "computed value" field is pa…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 3:09 p.m.

0.0

CVE-2026-43419 - ceph: fix memory leaks in ceph_mdsc_build_path()

In the Linux kernel, the following vulnerability has been resolved: ceph: fix memory leaks in ceph_mdsc_build_path() Add __putname() calls to error code paths that did not free the "path" pointer obtained by __getname(). If ownership of this pointer is not passed to the caller via path_info.path…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.

0.0

CVE-2026-43418 - sched/mmcid: Prevent CID stalls due to concurrent forks

In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Prevent CID stalls due to concurrent forks A newly forked task is accounted as MMCID user before the task is visible in the process' thread list and the global task list. This creates the following problem: CPU1 …

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.

0.0

CVE-2026-43417 - sched/mmcid: Handle vfork()/CLONE_VM correctly

In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Handle vfork()/CLONE_VM correctly Matthieu and Jiri reported stalls where a task endlessly loops in mm_get_cid() when scheduling in. It turned out that the logic which handles vfork()'ed tasks is broken. It is invok…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.

0.0

CVE-2026-43416 - powerpc, perf: Check that current->mm is alive before getting user callchain

In the Linux kernel, the following vulnerability has been resolved: powerpc, perf: Check that current->mm is alive before getting user callchain It may happen that mm is already released, which leads to kernel panic. This adds the NULL check for current->mm, similarly to commit 20afc60f892d ("x86…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.

0.0

CVE-2026-43415 - scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend In __ufshcd_wl_suspend(), cancel_delayed_work_sync() is called to cancel the UFS RTC work, but it is placed after ufshcd_vops_suspend(hba, pm_op, POST_CHANGE). T…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.

0.0

CVE-2026-43414 - scsi: qla2xxx: Completely fix fcport double free

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is called by qla2x00_sp_release(), when kref_put() releases the first…

πŸ“… Published: May 8, 2026, 2:21 p.m. πŸ”„ Last Modified: May 8, 2026, 2:21 p.m.
Total resulsts: 349182
Page 9 of 34,919
Β« previous page Β» next page
Filters