Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51605
Total
4093
Critical
15302
High
14954
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64405 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() hci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection was … | Jul 25, 2026 |
| CVE-2026-64404 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() iso_conn_big_sync() drops the socket lock to … | Jul 25, 2026 |
| CVE-2026-64403 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length … | Jul 25, 2026 |
| CVE-2026-64402 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() When the SMB sink is used as a … | Jul 25, 2026 |
| CVE-2026-64401 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: resolve SWN tcon from live registrations cifs_swn_notify() looks up a witness registration by … | Jul 25, 2026 |
| CVE-2026-64400 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting caseless retry ksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path … | Jul 25, 2026 |
| CVE-2026-64399 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination file's … | Jul 25, 2026 |
| CVE-2026-64398 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA FSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via ksmbd_vfs_zero_data() … | Jul 25, 2026 |
| CVE-2026-64397 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data … | Jul 25, 2026 |
| CVE-2026-64396 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation When a blocking byte-range lock … | Jul 25, 2026 |
| CVE-2026-64395 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: require source read access for duplicate extents FSCTL_DUPLICATE_EXTENTS_TO_FILE passes the source file directly to … | Jul 25, 2026 |
| CVE-2026-64394 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY commit cc57232cae23 ("ksmbd: fix FSCTL permission … | Jul 25, 2026 |
| CVE-2026-64393 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-based VFS helpers after … | Jul 25, 2026 |
| CVE-2026-64392 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle … | Jul 25, 2026 |
| CVE-2026-64391 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike … | Jul 25, 2026 |
| CVE-2026-64390 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: track the connection owning a byte-range lock SMB2_LOCK adds each granted byte-range lock to … | Jul 25, 2026 |
| CVE-2026-64389 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating session key ksmbd_auth_ntlmv2() derives the NTLMv2 session key into … | Jul 25, 2026 |
| CVE-2026-64388 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb/client: fix chown/chgrp with SMB3 POSIX Extensions Ownership (chown) and group (chgrp) modifications were being … | Jul 25, 2026 |
| CVE-2026-64387 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error … | Jul 25, 2026 |
| CVE-2026-64386 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and … | Jul 25, 2026 |
| CVE-2026-64385 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error … | Jul 25, 2026 |
| CVE-2026-64384 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error … | Jul 25, 2026 |
| CVE-2026-64383 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay … | Jul 25, 2026 |
| CVE-2026-64382 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error … | Jul 25, 2026 |
| CVE-2026-64381 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the … | Jul 25, 2026 |