help

color

mirror

Atom feed

CVE-2026-64187: xfs: fail recovery on a committed log item with no regions

CVE-2026-64206: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock

CVE-2026-64207: net/sched: dualpi2: fix GSO backlog accounting

CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized

CVE-2026-64205: i2c: i801: fix hardware state machine corruption in error path

CVE-2026-64191: i2c: stub: Reject I2C block transfers with invalid length

CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change

CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize

CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()

CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()

CVE-2026-64173: tracing: Do not call map->ops->elt_free() if elt_alloc() fails

CVE-2026-64172: KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)

CVE-2026-64171: i2c: tegra: fix pm_runtime leak on mutex_lock failure

CVE-2026-64170: spi: qup: fix error pointer deref after DMA setup failure

CVE-2026-64169: spi: ep93xx: fix error pointer deref after DMA setup failure

CVE-2026-64168: spi: sprd: fix error pointer deref after DMA setup failure

CVE-2026-64167: kho: skip KHO for crash kernel

CVE-2026-64186: iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs

CVE-2026-64185: sysfs: don't remove existing directory on update failure

CVE-2026-64184: mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()

CVE-2026-64166: firmware: arm_ffa: Check for NULL FF-A ID table while driver registration

CVE-2026-64183: efi: Allocate runtime workqueue before ACPI init

CVE-2026-64182: drivers/base/memory: fix memory block reference leak in poison accounting

CVE-2026-64181: mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()

CVE-2026-64180: mm/memory_hotplug: fix memory block reference leak on remove

CVE-2026-64179: net: wwan: iosm: fix potential memory leaks in ipc_imem_init()

CVE-2026-64178: Bluetooth: bnep: Fix UAF read of dev->name

CVE-2026-64177: phonet/pep: disable BH around forwarded sk_receive_skb()

CVE-2026-64176: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices

CVE-2026-64175: wifi: iwlwifi: mld: stop TX during firmware restart

CVE-2026-64174: wifi: cfg80211: advance loop vars in cfg80211_merge_profile()

CVE-2026-64165: ARM: integrator: Fix early initialization

CVE-2026-64123: net: hsr: defer node table free until after RCU readers

CVE-2026-64132: ipv6: ioam: refresh hdr pointer before ioam6_event()

CVE-2026-64131: mm/memory: fix spurious warning when unmapping device-private/exclusive pages

CVE-2026-64130: mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free

CVE-2026-64129: mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page

CVE-2026-64128: Bluetooth: ISO: drop ISO_END frames received without prior ISO_START

CVE-2026-64163: test_kprobes: clear kprobes between test runs

CVE-2026-64127: Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer

CVE-2026-64162: idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()

CVE-2026-64161: net: ti: icssm-prueth: fix eth_ports_node leak in probe

CVE-2026-64160: netfs: Fix potential for tearing in ->remote_i_size and ->zero_point

CVE-2026-64159: netfs: Fix zeropoint update where i_size > remote_i_size

CVE-2026-64158: netfs: Fix write streaming disablement if fd open O_RDWR

CVE-2026-64157: netfs: Fix partial invalidation of streaming-write folio

CVE-2026-64156: netfs, afs: Fix write skipping in dir/link writepages

CVE-2026-64155: wifi: ath11k: fix error path leaks in some WMI WOW calls

CVE-2026-64154: drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()

CVE-2026-64153: drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN

CVE-2026-64126: Bluetooth: MGMT: validate Add Extended Advertising Data length

CVE-2026-64152: iommu: Handle unmap error when iommu_debug is enabled

CVE-2026-64151: iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap

CVE-2026-64150: netfilter: nft_inner: release local_lock before re-enabling softirqs

CVE-2026-64149: dma-mapping: move dma_map_resource() sanity check into debug code

CVE-2026-64148: pds_core: fix error handling in pdsc_devcmd_wait

CVE-2026-64147: pds_core: fix debugfs_lookup dentry leak and error handling

CVE-2026-64146: erofs: fix metabuf leak in inode xattr initialization

CVE-2026-64145: wifi: wilc1000: fix dma_buffer leak on bus acquire failure

CVE-2026-64144: Bluetooth: btmtk: fix urb->setup_packet leak in error paths

CVE-2026-64143: platform/x86: uniwill-laptop: Do not enable the charging limit even when forced

CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled

CVE-2026-64142: ksmbd: close durable scavenger races against m_fp_list lookups

CVE-2026-64141: ksmbd: fix null pointer dereference in compare_guid_key()

CVE-2026-64140: ksmbd: fix null pointer dereference in proc_show_files()

CVE-2026-64139: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow

CVE-2026-64138: ksmbd: validate SID in parent security descriptor during ACL inheritance

CVE-2026-64137: smb: client: require net admin for CIFS SWN netlink

CVE-2026-64136: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()

CVE-2026-64135: hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX

CVE-2026-64134: ALSA: pcm: Don't setup bogus iov_iter for silencing

CVE-2026-64133: ALSA: asihpi: Fix potential OOB array access at reading cache

CVE-2026-64124: net: devmem: reject dma-buf bind with non-page-aligned size or SG length

CVE-2026-64084: hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR

CVE-2026-64093: batman-adv: tp_meter: directly shut down timer on cleanup

CVE-2026-64092: batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown

CVE-2026-64091: batman-adv: tt: fix TOCTOU race for reported vlans

CVE-2026-64090: batman-adv: tt: avoid empty VLAN responses

CVE-2026-64089: batman-adv: tt: fix negative last_changeset_len

CVE-2026-64088: batman-adv: tt: fix negative tt_buff_len

CVE-2026-64122: net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover

CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues

CVE-2026-64120: net: ethtool: fix NULL pointer dereference in phy_reply_size

CVE-2026-64119: l2tp: use list_del_rcu in l2tp_session_unhash

CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc()

CVE-2026-64117: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb

CVE-2026-64116: ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()

CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake

CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5

CVE-2026-64087: hwmon: (pmbus/adm1266) reject implausible blackbox record_count

CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning

CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap

CVE-2026-64111: lsm: hold cred_guard_mutex for lsm_set_self_attr()

CVE-2026-64110: igc: fix potential skb leak in igc_fpe_xmit_smd_frame()

CVE-2026-64109: af_unix: Fix UAF read of tail->len in unix_stream_data_wait()

CVE-2026-64108: cifs: Fix busy dentry used after unmounting

CVE-2026-64107: ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put()

CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits

CVE-2026-64105: KVM: arm64: vgic: Free private_irqs when init fails after allocation

CVE-2026-64104: virt: sev-guest: Explicitly leak pages in unknown state

CVE-2026-64086: hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer

CVE-2026-64103: scsi: isci: Fix use-after-free in device removal path

CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math

CVE-2026-64101: fwctl: pds: Validate RPC input size before parsing

CVE-2026-64100: drm/msm: Fix shrinker deadlock

CVE-2026-64099: drm/v3d: Fix use-after-free of CPU job query arrays on error path

CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates

CVE-2026-64097: drm/amd/display: Validate GPIO pin LUT table size before iterating

CVE-2026-64096: batman-adv: mcast: fix use-after-free in orig_node RCU release

CVE-2026-64095: batman-adv: bla: avoid double decrement of bla.num_requests

CVE-2026-64094: batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface

CVE-2026-64085: hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer

CVE-2026-64045: ovpn: tcp - use cached peer pointer in ovpn_tcp_close()

CVE-2026-64054: net: shaper: reject duplicate leaves in GROUP request

CVE-2026-64053: block: don't overwrite bip_vcnt in bio_integrity_copy_user()

CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()

CVE-2026-64051: accel/qaic: Add overflow check to remap_pfn_range during mmap

CVE-2026-64050: drm/msm/dpu: don't mix devm and drmm functions

CVE-2026-64049: drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx

CVE-2026-64083: hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors

CVE-2026-64082: riscv: Fix register corruption from uninitialized cregs on error

CVE-2026-64081: firmware: arm_ffa: Validate framework notification message layout

CVE-2026-64080: firmware: arm_ffa: Snapshot notifier callbacks under lock

CVE-2026-64079: netfilter: x_tables: allocate hook ops while under mutex

CVE-2026-64078: netfilter: x_tables: add and use xtables_unregister_table_exit

CVE-2026-64077: netfilter: ebtables: move to two-stage removal scheme

CVE-2026-64076: netfilter: bridge: eb_tables: close module init race

CVE-2026-64075: fprobe: Fix unregister_fprobe() to wait for RCU grace period

CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot

CVE-2026-64074: fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap

CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT

CVE-2026-64072: nvme: fix bio leak on mapping failure

CVE-2026-64071: nvme-pci: fix use-after-free in nvme_free_host_mem()

CVE-2026-64070: powerpc/hv-gpci: fix preempt count leak in sysfs show paths

CVE-2026-64069: netfs: Fix cancellation of a DIO and single read subrequests

CVE-2026-64068: netfs: Fix missing locking around retry adding new subreqs

CVE-2026-64067: netfs: Fix missing barriers when accessing stream->subrequests locklessly

CVE-2026-64066: netfs: Fix netfs_read_to_pagecache() to pause on subreq failure

CVE-2026-64065: netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call

CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring

CVE-2026-64064: netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone

CVE-2026-64063: netfs: Fix streaming write being overwritten

CVE-2026-64062: netfs: Fix potential deadlock in write-through mode

CVE-2026-64061: netfs: Fix early put of sink folio in netfs_read_gaps()

CVE-2026-64060: netfs: Fix leak of request in netfs_write_begin() error handling

CVE-2026-64059: netfs: Fix folio->private handling in netfs_perform_write()

CVE-2026-64058: netfs: Fix netfs_read_folio() to wait on writeback

CVE-2026-64057: afs: Fix the locking used by afs_get_link()

CVE-2026-64056: net: ethernet: cortina: Make RX SKB per-port

CVE-2026-64055: net: ethernet: cortina: Carry over frag counter

CVE-2026-64046: net: tls: prevent chain-after-chain in plain text SG

CVE-2026-64015: security/keys: fix missed RCU read section on lookup

CVE-2026-64024: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction

CVE-2026-64023: gpio: aggregator: fix a potential use-after-free

CVE-2026-64022: gpio: aggregator: remove the software node when deactivating the aggregator

CVE-2026-64021: drm/xe/oa: Fix exec_queue leak on width check in stream open

CVE-2026-64020: nvme-pci: fix dma_vecs leak on p2p memory

CVE-2026-64019: nvme-pci: fix dma mapping leak on data setup error

CVE-2026-64018: net: mana: validate rx_req_idx to prevent out-of-bounds array access

CVE-2026-64044: ovpn: respect peer refcount in CMD_NEW_PEER error path

CVE-2026-64043: ovpn: fix race between deleting interface and adding new peer

CVE-2026-64042: vfio/pci: Check BAR resources before exporting a DMABUF

CVE-2026-64041: ASoC: codecs: fs210x: fix possible buffer overflow

CVE-2026-64040: cachefiles: Fix error return when vfs_mkdir() fails

CVE-2026-64039: drm/msm/snapshot: fix dumping of the unaligned regions

CVE-2026-64038: hwmon: (lm90) Stop work before releasing hwmon device

CVE-2026-64037: wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled

CVE-2026-64036: cgroup/rstat: validate cpu before css_rstat_cpu() access

CVE-2026-64035: igc: set tx buffer type for SMD frames

CVE-2026-64017: blk-mq: pop cached request if it is usable

CVE-2026-64034: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer

CVE-2026-64033: RDMA/rtrs: Fix use-after-free in path file creation cleanup

CVE-2026-64032: bridge: mcast: Fix a possible use-after-free when removing a bridge port

CVE-2026-64031: erofs: fix managed cache race for unaligned extents

CVE-2026-64030: wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs

CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input

CVE-2026-64028: tracing: Avoid NULL return from hist_field_name() on truncation

CVE-2026-64027: net: shaper: rework the VALID marking (again)

CVE-2026-64026: rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg

CVE-2026-64025: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx

CVE-2026-64016: ksmbd: fix durable reconnect error path file lifetime

CVE-2026-63989: bridge: Fix sleep in atomic context in netlink path

CVE-2026-63998: ethtool: module: call ethnl_ops_complete() on module flash errors

CVE-2026-63997: ethtool: module: avoid leaking a netdev ref on module flash errors

CVE-2026-63996: ethtool: cmis: require exact CDB reply length

CVE-2026-63995: ethtool: cmis: validate start_cmd_payload_size from module

[CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()](2026071905-CVE-2026-63994-97bf@gregkh/T/#u)

CVE-2026-63993: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()

CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()

CVE-2026-64014: Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size

CVE-2026-64013: ACPI: button: Fix ACPI GPE handler leak during removal

CVE-2026-64012: net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked

CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release()

CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()

CVE-2026-64009: xfrm: Check for underflow in xfrm_state_mtu

CVE-2026-63991: Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()

CVE-2026-64008: accel/rocket: fix UAF via dangling GEM handle in create_bo

CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable

CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation

CVE-2026-64005: net/smc: Do not re-initialize smc hashtables

next (older)

topics (new)

topics (active)

mirroring instructions