Tag

#Kernel

newsHIGH 8.0

Linux Kernel Vulnerability: CVE-2026-64530 - Use-After-Free in net/sched/cls_api.c

A use-after-free vulnerability was discovered in the Linux kernel's net/sched/cls_api.c, specifically in the tcf_qevent_handle function. This vulnerability can be exploited by an attacker to potentially execute arbitrary code or cause a denial-of-service (DoS) condition. Linux kernel versions 5.15.148, 6.1.75, 6.6.14, and 6.7.2 are affected.

1 source
articleMEDIUM 6.5

Linux Kernel Vulnerability: CVE-2024-14040 - Insufficient Weight Representation in Nexthop Group Members

A vulnerability in the Linux kernel's nexthop group member configuration allows for potential issues with weight representation, affecting the ability to configure certain network deployments. The vulnerability has been resolved by increasing the weight representation from u8 to u16. This change impacts the Linux kernel's networking functionality, specifically in CLOS networks where ECMP weights are adjusted. Affected systems should apply patches to ensure proper weight configuration and prevent potential network instability.

1 source
newsHIGH 8.0

Linux Kernel Vulnerability: CVE-2026-64257 - Reject Overlapping Data Areas in SMB2 Responses

A vulnerability in the Linux kernel's SMB2 response handling can allow an attacker to trigger an invalid response that appears to have no data area, potentially leading to security issues. This vulnerability affects various Linux kernel versions. Users should update to the latest version to mitigate the risk.

1 source