public inbox for [email protected]
 help / color / mirror / Atom feed
This is experimental automated Linux kernel CVE triage research. Results are heuristic and may be incorrect. This site is not an official vendor advisory or severity source.
[CVE-2026-53000][IMPORTANT] netfilter: nat: use kfree_rcu to release ops [ Upstream
 2026-06-25 14:00 UTC 

[CVE-2026-53261][LOW] devlink: Release nested relation on devlink free [ Upstream
 2026-06-25 13:58 UTC 

[CVE-2026-53258][LOW] wifi: fix leak if split 6 GHz scanning fails [ Upstream
 2026-06-25 13:55 UTC 

[CVE-2026-53266][IMPORTANT] netfilter: bridge: make ebt_snat ARP rewrite writable [ Upstream
 2026-06-25 13:51 UTC 

[CVE-2026-53245][MODERATE REGULAR] net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr [ Upstream
 2026-06-25 13:46 UTC 

[CVE-2026-53274][LOW] net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
 2026-06-25 13:42 UTC 

[CVE-2026-53007][LOW] ice: fix potential NULL pointer deref in error path of ice_set_ringparam() [ Upstream
 2026-06-25 13:39 UTC 

[CVE-2026-53241][MODERATE REGULAR] ALSA: seq: dummy: fix UMP event stack overread [ Upstream
 2026-06-25 13:34 UTC 

[CVE-2026-53228][MODERATE 7.0] ipv6: sit: reload inner IPv6 header after GSO offloads [ Upstream
 2026-06-25 13:31 UTC 

[CVE-2026-53227][MODERATE REGULAR] net: openvswitch: fix possible kfree_skb of ERR_PTR [ Upstream
 2026-06-25 13:26 UTC 

[CVE-2026-53232][MODERATE 7.0] net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events. This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves. Reviewed-by: Nicolai Buchwitz <[email protected]> Fixes: 298e54f ("net: phy: add core phylib sfp support") Signed-off-by: Maxime Chevallier <[email protected]> Link: https://patch.msgid.link/[email protected] Signed-off-by: Jakub Kicinski <[email protected]>
 2026-06-25 13:21 UTC 

[CVE-2026-53249][MODERATE 7.0] ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options [ Upstream
 2026-06-25 13:18 UTC 

[CVE-2026-53102][LOW] wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() [ Upstream
 2026-06-25 13:18 UTC 

[CVE-2026-53270][MODERATE 7.0] ipvs: clear the svc scheduler ptr early on edit [ Upstream
 2026-06-25 13:13 UTC 

[CVE-2026-53250][MODERATE 7.0] xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() [ Upstream
 2026-06-25 13:09 UTC 

[CVE-2026-53257][MODERATE REGULAR] wifi: cfg80211: enforce HE/EHT cap/oper consistency [ Upstream
 2026-06-25 13:05 UTC 

[CVE-2026-52965][LOW] drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure
 2026-06-25 13:03 UTC 

[CVE-2026-53256][MODERATE 7.0] Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() [ Upstream
 2026-06-25 13:02 UTC 

[CVE-2026-53116][MODERATE 7.0] s390/ap: use generic driver_override infrastructure [ Upstream
 2026-06-25 12:57 UTC 

[CVE-2026-53275][MODERATE 7.0] ipv6: mcast: Fix use-after-free when processing MLD queries
 2026-06-25 12:57 UTC 

[CVE-2026-53260][MODERATE 7.0] tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). [ Upstream
 2026-06-25 12:51 UTC 

[CVE-2026-53050][MODERATE 7.0] quota: Fix race of dquot_scan_active() with quota deactivation [ Upstream
 2026-06-25 12:50 UTC 

[CVE-2026-52964][MODERATE REGULAR] ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
 2026-06-25 12:41 UTC 

[CVE-2026-53218][MODERATE 7.0] netfilter: nft_exthdr: fix register tracking for F_PRESENT flag [ Upstream
 2026-06-25 11:58 UTC 

[CVE-2026-53188][MODERATE 7.0] RDMA/core: Validate the passed in fops for ib_get_ucaps()
 2026-06-25 11:50 UTC 

[CVE-2026-53193][MODERATE 7.0] ALSA: timer: Forcibly close timer instances at closing
 2026-06-25 11:45 UTC 

[CVE-2026-53194][IMPORTANT] USB: serial: kl5kusb105: fix bulk-out buffer overflow
 2026-06-25 11:41 UTC 

[CVE-2026-53192][MODERATE 7.0] ALSA: timer: Fix UAF at snd_timer_user_params()
 2026-06-25 11:35 UTC 

[CVE-2026-53238][MODERATE REGULAR] netlabel: validate unlabeled address and mask attribute lengths [ Upstream
 2026-06-25 11:29 UTC 

[CVE-2026-53224][MODERATE 7.0] sctp: validate embedded INIT chunk and address list lengths in cookie [ Upstream
 2026-06-25 11:23 UTC 

[CVE-2026-53189][MODERATE 7.0] mm/huge_memory: update file PMD counter before folio_put() [ Upstream
 2026-06-25 11:19 UTC 

[CVE-2026-53223][MODERATE 7.0] net: guard timestamp cmsgs to real error queue skbs [ Upstream
 2026-06-25 11:13 UTC 

[CVE-2026-53236][MODERATE 7.0] tcp: restrict SO_ATTACH_FILTER to priv users [ Upstream
 2026-06-25 11:08 UTC 

[CVE-2026-53212][MODERATE 7.0] netfilter: nft_tunnel: fix use-after-free on object destroy
 2026-06-25 11:04 UTC 

[CVE-2026-53196][IMPORTANT] USB: serial: io_ti: fix heap overflow in get_manuf_info()
 2026-06-25 10:58 UTC 

[CVE-2026-53187][MODERATE REGULAR] RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
 2026-06-25 10:53 UTC 

[CVE-2026-53185][IMPORTANT] zram: fix use-after-free in zram_bvec_write_partial()
 2026-06-25 10:49 UTC 

[CVE-2026-53219][MODERATE REGULAR] netfilter: x_tables: avoid leaking percpu counter pointers [ Upstream
 2026-06-25 10:41 UTC 

[CVE-2026-53191][MODERATE REGULAR] io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries
 2026-06-25 10:37 UTC 

[CVE-2026-53221][MODERATE 7.0] ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() [ Upstream
 2026-06-25 10:32 UTC 

[CVE-2026-53209][MODERATE 7.0] Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
 2026-06-25 10:26 UTC 

[CVE-2026-53195][MODERATE 7.0] USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
 2026-06-25 10:20 UTC 

[CVE-2026-53208][MODERATE 7.0] Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
 2026-06-25 10:12 UTC 

[CVE-2026-53220][MODERATE 7.0] netfilter: revalidate bridge ports [ Upstream
 2026-06-25 10:09 UTC 

[CVE-2026-53199][MODERATE REGULAR] hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf [ Upstream
 2026-06-25 10:02 UTC 

[CVE-2026-53207][LOW] mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison [ Upstream
 2026-06-25  9:58 UTC 

[CVE-2026-53151][MODERATE REGULAR] rxrpc: Fix the ACK parser to extract the SACK table for parsing
 2026-06-25  9:38 UTC 

[CVE-2026-53168][MODERATE 7.0] fuse: reject fuse_notify() pagecache ops on directories
 2026-06-25  9:34 UTC 

[CVE-2026-53182][MODERATE 7.0] wifi: nl80211: reject oversized EMA RNR lists
 2026-06-25  9:30 UTC 

[CVE-2026-53115][MODERATE 7.0] bus: fsl-mc: use generic driver_override infrastructure [ Upstream
 2026-06-25  9:28 UTC 

[CVE-2026-53167][MODERATE 7.0] fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
 2026-06-25  9:26 UTC 

[CVE-2026-53183][MODERATE REGULAR] mptcp: allow subflow rcv wnd to shrink
 2026-06-25  9:22 UTC 

[CVE-2026-52989][IMPORTANT] nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers [ Upstream
 2026-06-25  9:21 UTC 

[CVE-2026-53154][LOW] mm/hugetlb: restore reservation on error in hugetlb folio copy paths
 2026-06-25  9:17 UTC 

[CVE-2026-53131][MODERATE 7.0] netfilter: require Ethernet MAC header before using eth_hdr() [ Upstream
 2026-06-25  9:13 UTC 

[CVE-2026-53156][MODERATE 7.0] nvmem: core: fix use-after-free bugs in error paths
 2026-06-25  9:06 UTC 

[CVE-2026-53073][MODERATE 7.0] Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error [ Upstream
 2026-06-25  9:04 UTC 

[CVE-2026-53134][MODERATE 7.0] netfilter: nft_fib: fix stale stack leak via the OIFNAME register [ Upstream
 2026-06-25  9:02 UTC 

[CVE-2026-53132][MODERATE 7.0] vsock/virtio: fix potential unbounded skb queue
 2026-06-25  8:57 UTC 

[CVE-2026-52988][MODERATE 7.0] netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase [ Upstream
 2026-06-25  8:57 UTC 

[CVE-2026-53164][MODERATE REGULAR] iommu/dma: Do not try to iommu_map a 0 length region in swiotlb
 2026-06-25  8:53 UTC 

[CVE-2026-53058][LOW] drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() [ Upstream
 2026-06-25  8:52 UTC 

[CVE-2026-53026][MODERATE 7.0] NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg [ Upstream
 2026-06-25  8:32 UTC 

[CVE-2026-52958][MODERATE 7.0] libceph: Fix potential out-of-bounds access in osdmap_decode()
 2026-06-25  7:53 UTC 

[CVE-2026-53022][MODERATE 7.0] platform/x86: dell-wmi-sysman: bound enumeration string aggregation [ Upstream
 2026-06-24 20:13 UTC 

[CVE-2026-53061][MODERATE 7.0] dm cache: fix dirty mapping checking in passthrough mode switching [ Upstream
 2026-06-24 20:09 UTC 

[CVE-2026-53074][MODERATE 7.0] bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb [ Upstream
 2026-06-24 20:04 UTC 

[CVE-2026-53122][MODERATE REGULAR] btrfs: fix deadlock between reflink and transaction commit when using flushoncommit [ Upstream
 2026-06-24 20:00 UTC 

[CVE-2026-53120][MODERATE 7.0] PCI: use generic driver_override infrastructure [ Upstream
 2026-06-24 19:56 UTC 

[CVE-2026-53106][LOW] bpf: Do not allow deleting local storage in NMI [ Upstream
 2026-06-24 19:53 UTC 

[CVE-2026-53124][LOW] ublk: reset per-IO canceled flag on each fetch [ Upstream
 2026-06-24 19:50 UTC 

[CVE-2026-52945][MODERATE 7.0] Revert "wireguard: device: enable threaded NAPI" This reverts commit 933466f which is
 2026-06-24 19:50 UTC 

[CVE-2026-52970][MODERATE 7.0] netfilter: nft_ct: fix missing expect put in obj eval
 2026-06-24 19:47 UTC 

[CVE-2026-53095][IMPORTANT] bpf: Fix abuse of kprobe_write_ctx via freplace [ Upstream
 2026-06-24 19:44 UTC 

[CVE-2026-52955][IMPORTANT] libceph: Fix potential out-of-bounds access in crush_decode()
 2026-06-24 19:39 UTC 

[CVE-2026-53076][MODERATE REGULAR] bpf: Fix OOB in pcpu_init_value [ Upstream
 2026-06-24 19:36 UTC 

[CVE-2026-52968][IMPORTANT] KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
 2026-06-24 19:32 UTC 

[CVE-2026-52967][MODERATE 7.0] smb/client: fix possible infinite loop and oob read in symlink_data()
 2026-06-24 19:27 UTC 

[CVE-2026-53071][IMPORTANT] Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp [ Upstream
 2026-06-24 19:24 UTC 

[CVE-2026-53100][LOW] wifi: mt76: fix deadlock in remain-on-channel [ Upstream
 2026-06-24 19:23 UTC 

[CVE-2026-52963][MODERATE REGULAR] ALSA: usb-audio: Bound MIDI endpoint descriptor scans
 2026-06-24 19:17 UTC 

[CVE-2026-53091][IMPORTANT] net: pull headers in qdisc_pkt_len_segs_init() [ Upstream
 2026-06-24 19:14 UTC 

[CVE-2026-52954][MODERATE REGULAR] libceph: handle rbtree insertion error in decode_choose_args()
 2026-06-24 19:13 UTC 

[CVE-2026-53126][LOW] blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() [ Upstream
 2026-06-24 19:10 UTC 

[CVE-2026-52998][MODERATE 7.0] netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check [ Upstream
 2026-06-24 19:10 UTC 

[CVE-2026-53086][MODERATE REGULAR] net: bcmgenet: fix racing timeout handler [ Upstream
 2026-06-24 18:57 UTC 

[CVE-2026-53127][LOW] block: fix zones_cond memory leak on zone revalidation error paths [ Upstream
 2026-06-24 18:54 UTC 

[CVE-2026-53011][MODERATE 7.0] net/sched: taprio: fix use-after-free in advance_sched() on schedule switch [ Upstream
 2026-06-24 18:53 UTC 

[CVE-2026-53004][MODERATE REGULAR] sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks [ Upstream
 2026-06-24 18:49 UTC 

[CVE-2026-52956][MODERATE 7.0] libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
 2026-06-24 18:42 UTC 

[CVE-2026-53084][MODERATE REGULAR] bpf: return VMA snapshot from task_vma iterator [ Upstream
 2026-06-24 18:40 UTC 

[CVE-2026-52974][LOW] net: tls: fix strparser anchor skb leak on offload RX setup failure [ Upstream
 2026-06-24 18:34 UTC 

[CVE-2026-53123][LOW] md: wake raid456 reshape waiters before suspend [ Upstream
 2026-06-24 18:30 UTC 

[CVE-2026-53083][LOW] bpf: Fix RCU stall in bpf_fd_array_map_clear() [ Upstream
 2026-06-24 18:25 UTC 

[CVE-2026-53005][MODERATE 7.0] af_unix: Drop all SCM attributes for SOCKMAP. [ Upstream
 2026-06-24 18:21 UTC 

[CVE-2026-53096][MODERATE 7.0] bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path [ Upstream
 2026-06-24 18:18 UTC 

[CVE-2026-52961][MODERATE REGULAR] ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
 2026-06-24 18:13 UTC 

[CVE-2026-53118][MODERATE REGULAR] vdpa: use generic driver_override infrastructure [ Upstream
 2026-06-24 18:09 UTC 

[CVE-2026-53053][MODERATE 7.0] iommu/amd: Fix clone_alias() to use the original device's devid [ Upstream
 2026-06-24 18:06 UTC 

[CVE-2026-53125][LOW] md: fix array_state=clear sysfs deadlock [ Upstream
 2026-06-24 18:05 UTC 

[CVE-2026-52984][LOW] net/sched: netem: fix queue limit check to include reordered packets [ Upstream
 2026-06-24 18:02 UTC 

[CVE-2026-53129][MODERATE REGULAR] fs/mbcache: cancel shrink work before destroying the cache [ Upstream
 2026-06-24 17:57 UTC 

[CVE-2026-53014][MODERATE 7.0] net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir [ Upstream
 2026-06-24 17:54 UTC 

[CVE-2026-52985][LOW] netdevsim: zero initialize struct iphdr in dummy sk_buff [ Upstream
 2026-06-24 17:50 UTC 

[CVE-2026-53110][MODERATE 7.0] s390/bpf: Zero-extend bpf prog return values and kfunc arguments [ Upstream
 2026-06-24 17:46 UTC 

[CVE-2026-53059][IMPORTANT] dm log: fix out-of-bounds write due to region_count overflow [ Upstream
 2026-06-24 17:42 UTC 

[CVE-2026-53109][MODERATE REGULAR] powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy [ Upstream
 2026-06-24 17:38 UTC 

[CVE-2026-52999][MODERATE 7.0] netfilter: nfnetlink_osf: fix out-of-bounds read on option matching [ Upstream
 2026-06-24 17:35 UTC 

[CVE-2026-53081][IMPORTANT] bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars [ Upstream
 2026-06-24 17:30 UTC 

[CVE-2026-53075][MODERATE 7.0] ppp: require CAP_NET_ADMIN in target netns for unattached ioctls [ Upstream
 2026-06-24 17:24 UTC 

[CVE-2026-53062][MODERATE 7.0] dm cache policy smq: fix missing locks in invalidating cache blocks [ Upstream
 2026-06-24 17:20 UTC 

[CVE-2026-53048][LOW] gfs2: prevent NULL pointer dereference during unmount [ Upstream
 2026-06-24 17:14 UTC 

[CVE-2026-53069][MODERATE REGULAR] net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master [ Upstream
 2026-06-24 17:10 UTC 

[CVE-2026-52975][MODERATE REGULAR] bonding: 3ad: implement proper RCU rules for port->aggregator [ Upstream
 2026-06-24 17:06 UTC 

[CVE-2026-52982][MODERATE REGULAR] net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() [ Upstream
 2026-06-24 17:02 UTC 

[CVE-2026-53009][IMPORTANT] ice: fix double-free of tx_buf skb [ Upstream
 2026-06-24 16:57 UTC 

[CVE-2026-53092][IMPORTANT] bpf: Fix linked reg delta tracking when src_reg == dst_reg [ Upstream
 2026-06-24 16:54 UTC 

[CVE-2026-53013][LOW] macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF [ Upstream
 2026-06-24 16:51 UTC 

[CVE-2026-52943][IMPORTANT] net: skbuff: fix missing zerocopy reference in pskb_carve helpers [ Upstream
 2026-06-24  9:52 UTC 

[CVE-2026-52940][MODERATE 7.0] tun: zero the whole vnet header in tun_put_user() [ Upstream
 2026-06-24  9:36 UTC 

[CVE-2026-52941][LOW] net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint [ Upstream
 2026-06-24  9:29 UTC 

[CVE-2026-52939][MODERATE REGULAR] net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion [ Upstream
 2026-06-24  9:13 UTC 

[CVE-2026-52923][IMPORTANT] ipc: limit next_id allocation to the valid ID range
 2026-06-24  9:09 UTC 

[CVE-2026-52924][IMPORTANT] sctp: purge outqueue on stale COOKIE-ECHO handling [ Upstream
 2026-06-24  9:05 UTC 

[CVE-2026-52915][MODERATE 7.0] netfilter: ip6t_hbh: reject oversized option lists
 2026-06-24  9:00 UTC 

[CVE-2026-52937][MODERATE REGULAR] tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR [ Upstream
 2026-06-24  8:56 UTC 

[CVE-2026-52912][MODERATE 7.0] netfilter: nf_queue: hold bridge skb->dev while queued [ Upstream
 2026-06-24  8:52 UTC 

[CVE-2026-52930][MODERATE 7.0] ipc/shm: serialize orphan cleanup with shm_nattch updates
 2026-06-24  8:46 UTC 

[CVE-2026-52921][LOW] netfilter: ipset: stop hash:* range iteration at end
 2026-06-24  8:42 UTC 

[CVE-2026-52936][LOW] crypto: jitterentropy - replace long-held spinlock with mutex [ Upstream
 2026-06-24  8:38 UTC 

[CVE-2026-52935][MODERATE 7.0] xfrm: espintcp: do not reuse an in-progress partial send
 2026-06-24  8:34 UTC 

[CVE-2026-52918][MODERATE 7.0] Bluetooth: serialize accept_q access [ Upstream
 2026-06-24  8:30 UTC 

[CVE-2026-52928][LOW] af_unix: Reject SIOCATMARK on non-stream sockets
 2026-06-24  8:23 UTC 

[CVE-2026-52917][MODERATE 7.0] sctp: diag: reject stale associations in dump_one path
 2026-06-24  8:19 UTC 

[CVE-2026-52933][MODERATE 7.0] io_uring/poll: fix signed comparison in io_poll_get_ownership()
 2026-06-24  8:14 UTC 

[CVE-2026-52929][MODERATE 7.0] sctp: stream: fully roll back denied add-stream state
 2026-06-24  8:11 UTC 

[CVE-2026-52925][MODERATE REGULAR] vrf: Fix a potential NPD when removing a port from a VRF [ Upstream
 2026-06-24  8:06 UTC 

[CVE-2026-52942][MODERATE 7.0] netfilter: nf_log: validate MAC header was set before dumping it [ Upstream
 2026-06-24  8:01 UTC 

[CVE-2026-52920][MODERATE 7.0] netfilter: xt_policy: fix strict mode inbound policy matching [ Upstream
 2026-06-24  7:56 UTC 

[CVE-2026-52927][MODERATE 7.0] netfilter: ebtables: fix OOB read in compat_mtw_from_user [ Upstream
 2026-06-24  7:52 UTC 

[CVE-2026-52910][IMPORTANT] bpf: Free reuseport cBPF prog after RCU grace period. [ Upstream
 2026-06-22 13:21 UTC 

[CVE-2026-52908][IMPORTANT] RDMA: During rereg_mr ensure that REREG_ACCESS is compatible [ Upstream
 2026-06-19 14:58 UTC 

[CVE-2026-52909][MODERATE 7.0] ip6_vti: set netns_immutable on the fallback device. [ Upstream
 2026-06-19 14:53 UTC 

[CVE-2026-46331][IMPORTANT] net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined. Fixes: 8b79647 ("net/sched: act_pedit: really ensure the skb is writable") Reported-by: Yiming Qian <[email protected]> Reported-by: Keenan Dong <[email protected]> Reported-by: Han Guidong <[email protected]> Reported-by: Zhang Cen <[email protected]> Reviewed-by: Han Guidong <[email protected]> Tested-by: Han Guidong <[email protected]> Reviewed-by: Davide Caratti <[email protected]> Tested-by: Davide Caratti <[email protected]> Reviewed-by: Toke Høiland-Jørgensen <[email protected]> Tested-by: Toke Høiland-Jørgensen <[email protected]> Reviewed-by: Victor Nogueira <[email protected]> Tested-by: Victor Nogueira <[email protected]> Acked-by: Jamal Hadi Salim <[email protected]> Signed-off-by: Rajat Gupta <[email protected]> Link: https://patch.msgid.link/[email protected] Signed-off-by: Jakub Kicinski <[email protected]>
 2026-06-16  6:51 UTC 

[CVE-2026-43284][IMPORTANT] xfrm: esp: avoid in-place decrypt on shared skb frags
 2026-06-09 22:28 UTC 

[CVE-2026-43186][IMPORTANT] ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() [ Upstream
 2026-06-09 22:23 UTC 

[CVE-2026-43078][MODERATE 7.0] crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
 2026-06-09 22:17 UTC 

[CVE-2026-43110][MODERATE 7.0] wifi: brcmfmac: validate bsscfg indices in IF events [ Upstream
 2026-06-09 22:12 UTC 

[CVE-2026-43158][MODERATE 7.0] xfs: fix freemap adjustments when adding xattrs to leaf blocks [ Upstream
 2026-06-09 22:04 UTC 

[CVE-2026-31532][MODERATE 7.0] can: raw: fix ro->uniq use-after-free in raw_rcv()
 2026-06-09 22:00 UTC 

[CVE-2026-31586][IMPORTANT] mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
 2026-06-09 21:55 UTC 

[CVE-2026-43063][MODERATE 7.0] xfs: don't irele after failing to iget in xfs_attri_recover_work
 2026-06-09 21:51 UTC 

[CVE-2026-43066][LOW] ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths [ Upstream
 2026-06-09 21:46 UTC 

[CVE-2026-43068][MODERATE REGULAR] ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal()
 2026-06-09 21:42 UTC 

[CVE-2026-46318][LOW] Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare"
 2026-06-09 16:53 UTC 

[CVE-2026-46329][MODERATE 7.0] erofs: handle end of filesystem properly for file-backed mounts [ Upstream
 2026-06-09 16:27 UTC 

[CVE-2026-46325][MODERATE 7.0] RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE [ Upstream
 2026-06-09 13:40 UTC 

[CVE-2026-46327][LOW] dm: fix unlocked test for dm_suspended_md [ Upstream
 2026-06-09 13:36 UTC 

[CVE-2026-46320][MODERATE REGULAR] tap: free page on error paths in tap_get_user_xdp() [ Upstream
 2026-06-09 13:32 UTC 

[CVE-2026-46330][IMPORTANT] Revert "net/smc: Introduce TCP ULP support" [ Upstream
 2026-06-09 13:28 UTC 

[CVE-2026-46322][MODERATE REGULAR] tun: free page on build_skb failure in tun_xdp_one() [ Upstream
 2026-06-09 13:24 UTC 

[CVE-2026-46321][MODERATE REGULAR] tun: free page on short-frame rejection in tun_xdp_one() [ Upstream
 2026-06-09 13:18 UTC 

[CVE-2026-46323][IMPORTANT] net: gro: don't merge zcopy skbs [ Upstream
 2026-06-09 13:13 UTC 

[CVE-2026-46324][MODERATE 7.0] netfilter: nf_tables: use list_del_rcu for netlink hooks [ Upstream
 2026-06-09 13:08 UTC 

[CVE-2026-46317][MODERATE 7.0] KVM: arm64: Reassign nested_mmus array behind mmu_lock
 2026-06-09 13:02 UTC 

[CVE-2026-46316][MODERATE 7.0] KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
 2026-06-09 12:53 UTC 

[CVE-2026-46315][MODERATE REGULAR] io_uring/waitid: clear waitid info before copying it to userspace
 2026-06-09  7:51 UTC 

[CVE-2026-46281][MODERATE 7.0] vmalloc: fix buffer overflow in vrealloc_node_align()
 2026-06-08 19:57 UTC 

[CVE-2026-46283][MODERATE REGULAR] tpm: Use kfree_sensitive() to free auth session in tpm_dev_release()
 2026-06-08 19:50 UTC 

[CVE-2026-46284][LOW] mm/hugetlb: fix early boot crash on parameters without '=' separator
 2026-06-08 19:46 UTC 

[CVE-2026-46289][MODERATE 7.0] lib/scatterlist: fix length calculations in extract_kvec_to_sg
 2026-06-08 19:33 UTC 

[CVE-2026-46291][MODERATE REGULAR] crypto: caam - guard HMAC key hex dumps in hash_digest_key [ Upstream
 2026-06-08 19:27 UTC 

[CVE-2026-46292][LOW] pmdomain: core: Fix detach procedure for virtual devices in genpd [ Upstream
 2026-06-08 19:23 UTC 

[CVE-2026-46294][MODERATE 7.0] dm: fix a buffer overflow in ioctl processing
 2026-06-08 19:16 UTC 

[CVE-2026-46295][MODERATE REGULAR] KVM: x86: Do IRR scan in __kvm_apic_update_irr even if PIR is empty
 2026-06-08 19:12 UTC 

[CVE-2026-46298][LOW] pseries/papr-hvpipe: Fix race with interrupt handler
 2026-06-08 19:04 UTC 

[CVE-2026-46299][LOW] hfsplus: fix held lock freed on hfsplus_fill_super() [ Upstream
 2026-06-08 19:01 UTC 

[CVE-2026-46302][LOW] selinux: allow multiple opens of /sys/fs/selinux/policy
 2026-06-08 18:55 UTC 

[CVE-2026-46303][MODERATE REGULAR] isofs: validate Rock Ridge CE continuation extent against volume size
 2026-06-08 18:52 UTC 

[CVE-2026-46304][MODERATE REGULAR] nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
 2026-06-08 18:45 UTC 

[CVE-2026-46306][MODERATE 7.0] flow_dissector: do not dissect PPPoE PFC frames [ Upstream
 2026-06-08 18:38 UTC 

[CVE-2026-46307][MODERATE REGULAR] wifi: ath5k: do not access array OOB
 2026-06-08 18:34 UTC 

[CVE-2026-46309][IMPORTANT] drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise
 2026-06-08 18:24 UTC 

[CVE-2026-46312][MODERATE REGULAR] media: videobuf2: Set vma_flags in vb2_dma_sg_mmap
 2026-06-08 18:17 UTC 

[CVE-2026-46313][LOW] media: intel/ipu6: fix error pointer dereference
 2026-06-08 18:13 UTC 

[CVE-2026-46280][MODERATE 7.0] lib: test_hmm: evict device pages on file close to avoid use-after-free [ Upstream
 2026-06-08 15:56 UTC 

[CVE-2026-46275][MODERATE 7.0] Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
 2026-06-08 14:59 UTC 

[CVE-2026-46274][IMPORTANT] io-wq: check that the predecessor is hashed in io_wq_remove_pending()
 2026-06-08 14:52 UTC 

[CVE-2026-46260][MODERATE REGULAR] ipv6: Fix out-of-bound access in fib6_add_rt2node(). [ Upstream
 2026-06-03 20:22 UTC 

[CVE-2026-46273][MODERATE REGULAR] ibmveth: Disable GSO for packets with small MSS
 2026-06-03 20:17 UTC 

[CVE-2026-46271][LOW] wifi: ath12k: do WoW offloads only on primary link [ Upstream
 2026-06-03 20:03 UTC 

[CVE-2026-43279][MODERATE 7.0] ALSA: usb-audio: Add sanity check for OOB writes at silencing [ Upstream
 2026-06-03 20:00 UTC 

[CVE-2026-46268][LOW] PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning condition [ Upstream
 2026-06-03 19:59 UTC 

[CVE-2026-46262][LOW] ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr_mode_put() [ Upstream
 2026-06-03 19:54 UTC 

[CVE-2026-46244][IMPORTANT] netfilter: nft_inner: Fix IPv6 inner_thoff desync
 2026-06-03 19:47 UTC 

[CVE-2026-46266][MODERATE 7.0] inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP [ Upstream
 2026-06-03 19:38 UTC 

[CVE-2026-46252][MODERATE REGULAR] regulator: core: fix locking in regulator_resolve_supply() error path [ Upstream
 2026-06-03 19:34 UTC 

[CVE-2026-46256][LOW] NFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages [ Upstream
 2026-06-03 19:30 UTC 

[CVE-2026-46247][LOW] clk: qcom: gfx3d: add parent to parent request map [ Upstream
 2026-06-03 19:26 UTC 

[CVE-2026-46251][MODERATE 7.0] btrfs: fix block_group_tree dirty_list corruption [ Upstream
 2026-06-03 19:20 UTC 

page:  |  | latest

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox