Zum Hauptinhalt springen
Sicherheitslücken (CVE)Click2Shell: The RCE WordPress 7.1.1 Just Patched(18.09.2026 um 21:47 Uhr)
IT Security NachrichtenMilitary AI Integrity Breach Almost Started U.S. War With China(18.09.2026 um 21:31 Uhr)
Sicherheitslücken (CVE)Cisco Zero-Day Highlights API Endpoint Authentication Issues(18.09.2026 um 21:26 Uhr)
IT Security Nachrichtenyouknow-Masterclass: Vom Use Case zum eigenen KI-Lernassistenten(18.09.2026 um 21:27 Uhr)
Windows Tipps & SecurityWindows 11 26H2 nimmt Kurs auf offiziellen Start, Evaluation-ISO ist da(18.09.2026 um 21:11 Uhr)
IT Security NachrichteniPhone 18 Pro Teardown: Reparaturen werden nun wieder komplizierter(18.09.2026 um 21:58 Uhr)
IT Security NachrichtenThe best iPhone 18 cases in 2026: Expert tested(09.09.2026 um 21:09 Uhr)
Sicherheitslücken (CVE)Click2Shell: The RCE WordPress 7.1.1 Just Patched(18.09.2026 um 21:47 Uhr)
IT Security NachrichtenMilitary AI Integrity Breach Almost Started U.S. War With China(18.09.2026 um 21:31 Uhr)
Sicherheitslücken (CVE)Cisco Zero-Day Highlights API Endpoint Authentication Issues(18.09.2026 um 21:26 Uhr)
IT Security Nachrichtenyouknow-Masterclass: Vom Use Case zum eigenen KI-Lernassistenten(18.09.2026 um 21:27 Uhr)
Windows Tipps & SecurityWindows 11 26H2 nimmt Kurs auf offiziellen Start, Evaluation-ISO ist da(18.09.2026 um 21:11 Uhr)
IT Security NachrichteniPhone 18 Pro Teardown: Reparaturen werden nun wieder komplizierter(18.09.2026 um 21:58 Uhr)
IT Security NachrichtenThe best iPhone 18 cases in 2026: Expert tested(09.09.2026 um 21:09 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

USN-5001-1: Linux kernel (OEM) vulnerabilities

Norbert Slusarek discovered a race condition in the CAN BCM networking protocol of the Linux kernel leading to multiple use-after-free vulnerabilities. A local attacker could use this issue to execute arbitrary code. (CVE-2021-3609) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation did not properly clear received fragments from memory in some situations. A physically proximate attacker could possibly use this issue to inject packets or expose sensitive information. (CVE-2020-24586) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation incorrectly handled encrypted fragments. A physically proximate attacker could possibly use this issue to decrypt fragments. (CVE-2020-24587) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation incorrectly handled certain malformed frames. If a user were tricked into connecting to a malicious server, a physically proximate attacker could use this issue to inject packets. (CVE-2020-24588) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation incorrectly handled EAPOL frames from unauthenticated senders. A physically proximate attacker could inject malicious packets to cause a denial of service (system crash). (CVE-2020-26139) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation did not properly verify certain fragmented frames. A physically proximate attacker could possibly use this issue to inject or decrypt packets. (CVE-2020-26141) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation accepted plaintext fragments in certain situations. A physically proximate attacker could use this issue to inject packets. (CVE-2020-26145) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation could reassemble mixed encrypted and plaintext fragments. A physically proximate attacker could possibly use this issue to inject packets or exfiltrate selected fragments. (CVE-2020-26147) Or Cohen discovered that the SCTP implementation in the Linux kernel contained a race condition in some situations, leading to a use-after-free condition. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-23133) Or Cohen and Nadav Markus discovered a use-after-free vulnerability in the nfc implementation in the Linux kernel. A privileged local attacker could use this issue to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-23134) Manfred Paul discovered that the extended Berkeley Packet Filter (eBPF) implementation in the Linux kernel contained an out-of-bounds vulnerability. A local attacker could use this issue to execute arbitrary code. (CVE-2021-31440) It was discovered that a race condition in the kernel Bluetooth subsystem could lead to use-after-free of slab objects. An attacker could use this issue to possibly execute arbitrary code. (CVE-2021-32399) It was discovered that a use-after-free existed in the Bluetooth HCI driver of the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33034) It was discovered that an out-of-bounds (OOB) memory access flaw existed in the f2fs module of the Linux kernel. A local attacker could use this issue to cause a denial of service (system crash). (CVE-2021-3506) Mathias Krause discovered that a null pointer dereference existed in the Nitro Enclaves kernel driver of the Linux kernel. A local attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2021-3543)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten USN-5001-1: Linux kernel (OEM) vulnerabilities

Thematisch verwandte Begriffe: USN50011, Linux, kernel, vulnerabilities · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Rechts: Artikel Ziehen Links: RSS
Hoch: nächster Artikel Runter: zurück / schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Rechts: Original Links: RSS-Ansicht
↗ Original-Quelle
Social Reaktionen Stimme abgeben (+5 Karma)
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick