Linux: Sicherheitsmeldungen, Schwachstellen & Advisories
Kernel, Distributionen & Open-Source-Basis · CVE-Lage über den EUVD-Pool, Meldungen aus dem Live-Feed.
📡 Aktuelle Linux-Meldungen
Steam Frame CAD files released, plus an update on reservation waiting times
What is Linux?
CVE-2026-98383 | Linux Kernel up to 7.3-rc4 BPF bpf_skb_pull_data/bpf_lwt_seg6_adjust_srh use after free (EUVD-2026-95538 / Nessus ID 364536)
CVE-2026-98380 | Linux Kernel up to 7.3-rc4 net/sched net/sched/act_api.c tcf_action_delete/tcf_idr_delete_index null pointer dereference (EUVD-2026-95535 / Nessus ID 364537)
CVE-2026-98376 | Linux Kernel BPF percpu_array_map_gen_lookup pptrs out-of-bounds (EUVD-2026-95531 / Nessus ID 364540)
Keysharp
Can gaming now be 100% supported in linux based on latest shifts happening in gaming industry?
19 Quick systemd-networkd Config Hacks to Speed Up Your Linux Server
Euro Office has actual releases on their DesktopEditors github
CVE-2026-89675 | Linux Kernel up to 6.18.50/7.2.3 NFSd Async Copy nfsd4_do_async_copy refcount/nf_src/nf_dst/copy_task use after free (Nessus ID 364483)
CVE-2026-89676 | Linux Kernel up to 6.18.49/7.2.3 nfsd nfsd4_copy use after free (Nessus ID 364483)
CVE-2026-89530 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 svcrdma svc_rdma_pull_up_needed buffer overflow (Nessus ID 364483)
🎯 Linux-Schwachstellen (CVE-Radar)
CVE-2026-98383 | Linux Kernel up to 7.3-rc4 BPF bpf_skb_pull_data/bpf_lwt_seg6_adjust_srh use after free (EUVD-2026-95538 / Nessus ID 364536)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.3-rc4. The impacted element is the function bpf_skb_pull_data/bpf_lwt_seg6_adjust_srh of the component BPF. The manipulation results in use after free.
CVE-2026-98380 | Linux Kernel up to 7.3-rc4 net/sched net/sched/act_api.c tcf_action_delete/tcf_idr_delete_index null pointer dereference (EUVD-2026-95535 / Nessus ID 364537)
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 7.3-rc4. Affected by this issue is the function tcf_action_delete/tcf_idr_delete_index of the file net/sched/act_api.c of the component net/sched. The m
CVE-2026-98376 | Linux Kernel BPF percpu_array_map_gen_lookup pptrs out-of-bounds (EUVD-2026-95531 / Nessus ID 364540)
A vulnerability, which was classified as very critical, has been found in Linux Kernel. Affected by this vulnerability is the function percpu_array_map_gen_lookup of the component BPF. The manipulation of the argument pptrs leads to out-of-
CVE-2026-98290 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup rfcomm_sock_cleanup_listen() closes unaccepted child sockets through rfcomm_sock_close(), which takes the child socket lock before rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these locks in reverse order while handling connections and DLC state changes, so lockdep reports a possible deadlock. Close deq
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup rfcomm_sock_cleanup_listen() closes unaccepted child sockets through rfcomm_sock_close(), which takes t
CVE-2026-98283 | In the Linux kernel, the following vulnerability has been resolved: KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops mmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a reference on the kvm_nested_guest pointer obtained from the IDR. A concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race through kvmhv_flush_nested() -> kvmhv_rem
In the Linux kernel, the following vulnerability has been resolved: KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops mmu_lock before calling k
CVE-2026-98282 | In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba(). While doing so, the passed in argument npages is ignored and constant value '1' is used leaving out a possible overflow as the callers can legitimately be using npages > 1 for H_STU
In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across
CVE-2026-98281 | In the Linux kernel, the following vulnerability has been resolved: futex: Also allocate private hash on vfork() As Jann demonstrated, it is entirely feasible to access the mm through vfork(). Therefore we need to allocate a private hash on vfork() as well as any other CLONE_VM user. Specifically, it must be avoided to have (private) futex waiters before allocating the private hash.
In the Linux kernel, the following vulnerability has been resolved: futex: Also allocate private hash on vfork() As Jann demonstrated, it is entirely feasible to access the mm through vfork(). Therefore we need to allocate a private hash
CVE-2026-98276 | In the Linux kernel, the following vulnerability has been resolved: net: lock the socket in sock_gettstamp() sk->sk_flags must only be changed while holding the socket lock, because sock_set_flag() and sock_reset_flag() use non atomic operations (__set_bit() and __clear_bit()). sock_gettstamp() is one of the last places where a bit of sk->sk_flags is changed from a syscall without owning the socket lock, through sock_enable_timestamp(sk, SOCK_TIMESTAMP).
In the Linux kernel, the following vulnerability has been resolved: net: lock the socket in sock_gettstamp() sk->sk_flags must only be changed while holding the socket lock, because sock_set_flag() and sock_reset_flag() use non atomic ope
CVE-2026-98369 | In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): WARNING: suspicious RCU usage in ip6_pkt_drop include/net/addrconf.h:389 suspicious rcu_dereference_check() usage! Call Trace: __in6_dev_get_safely include/net/addrconf.h:389 [inline] ip6_pkt_drop+0x596/0x610 net/ipv6/rou
In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): WARNING:
CVE-2026-98368 | In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutating skb frags On the out-of-place output path (esp->inplace == false) ESP rewrites the skb frag array: esp_output_head() appends a trailer frag and esp_output_tail() replaces the frags with a destination page, both referenced with get_page(). When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the payload frags are owned b
In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutating skb frags On the out-of-place output path (esp->inplace == false) ESP rewrites the skb frag array: esp_output_head()
CVE-2026-98367 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did. Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock is released before the error path cleanup. A concurrent ibv_modify_qp() transitioning the QP to ERROR can race in this window: siw_ac
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_l
CVE-2026-98366 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: validate access flags before swapping the MR's PD rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument: if (flags & IB_MR_REREG_PD) { rxe_put(old_pd); rxe_get(pd); mr->ibmr.pd = ibpd; } if (flags & IB_MR_REREG_ACCESS) { if (access & ~RXE_ACCESS_SUPPORTED_MR) return ERR_PTR(-EOPNOTSUPP); mr->access = access; } B
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: validate access flags before swapping the MR's PD rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument: if
Volltext-Filter & Dossiers: CVE-Radar öffnen ↗
📬 Bei neuem Linux-Advisory alarmiert werden
E-Mail mit Double-Opt-in; Schwelle & KEV-Filter frei wählbar. Abmeldung mit einem Klick (RFC-8058).