[CVE-2026-68214][MODERATE 7.0] media: rtl2832: fix use-after-free in rtl2832_remove()
2026-08-10 16:57 UTC
[CVE-2026-68109][LOW] drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
2026-08-10 16:52 UTC
[CVE-2026-68138][MODERATE 7.0] net/sched: serialize qdisc_rtab_list against concurrent get/put
2026-08-10 16:52 UTC
[CVE-2026-68217][LOW] media: pwc: Drain fill_buf on start_streaming() failure
2026-08-10 16:49 UTC
[CVE-2026-68100][MODERATE 7.0] ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
2026-08-10 16:45 UTC
[CVE-2026-68086][MODERATE 7.0] mm/khugepaged: write all dirty file folios when collapsing [There is no upstream commit, as this code was removed by upstream
2026-08-10 16:45 UTC
[CVE-2026-68146][MODERATE REGULAR] ftrace: Add global mutex to serialize trace_parser access
2026-08-10 16:41 UTC
[CVE-2026-68425][MODERATE REGULAR] IB/mad: Drop unmatched RMPP responses before reassembly [ Upstream
2026-08-10 16:37 UTC
[CVE-2026-68289][MODERATE 7.0] tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() [ Upstream
2026-08-10 16:32 UTC
[CVE-2026-68234][LOW] drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
2026-08-10 16:28 UTC
[CVE-2026-68092][LOW] time/jiffies: Register jiffies clocksource before usage [ Upstream
2026-08-10 16:28 UTC
[CVE-2026-68129][MODERATE REGULAR] gve: fix Rx queue stall on alloc failure
2026-08-10 16:26 UTC
[CVE-2026-68415][MODERATE 7.0] xfrm: clear mode callbacks after failed mode setup [ Upstream
2026-08-10 16:22 UTC
[CVE-2026-68136][IMPORTANT] net: gro: fix double aggregation of flush-marked skbs
2026-08-10 16:20 UTC
[CVE-2026-68398][MODERATE 7.0] ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF [ Upstream
2026-08-10 16:15 UTC
[CVE-2026-68412][LOW] wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() [ Upstream
2026-08-10 16:11 UTC
[CVE-2026-68312][MODERATE REGULAR] cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths [ Upstream
2026-08-10 16:07 UTC
[CVE-2026-68308][MODERATE REGULAR] wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() [ Upstream
2026-08-10 16:04 UTC
[CVE-2026-68422][LOW] btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() [ Upstream
2026-08-10 16:04 UTC
[CVE-2026-68139][MODERATE REGULAR] net/mlx5e: Use sender devcom for MPV master-up
2026-08-10 16:00 UTC
[CVE-2026-68254][LOW] drm/i915/vrr: require valid min/max vfreq for VRR [ Upstream
2026-08-10 16:00 UTC
[CVE-2026-68260][MODERATE REGULAR] drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
2026-08-10 15:56 UTC
[CVE-2026-68200][IMPORTANT] ALSA: timer: don't re-enter an instance callback that is still running
2026-08-10 15:56 UTC
[CVE-2026-68235][LOW] drm/amd/display: dce100: skip non-DP stream encoders for DP MST
2026-08-10 15:52 UTC
[CVE-2026-68401][MODERATE 7.0] firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() [ Upstream
2026-08-10 15:52 UTC
[CVE-2026-68378][LOW] dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
2026-08-10 15:52 UTC
[CVE-2026-68266][MODERATE 7.0] drm/xe: Hold a dma-buf reference for imported BOs [ Upstream
2026-08-10 15:48 UTC
[CVE-2026-68400][MODERATE 7.0] firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation [ Upstream
2026-08-10 15:44 UTC
[CVE-2026-68262][MODERATE 7.0] drm/imagination: Fix user array stride in pvr_set_uobj_array()
2026-08-10 15:44 UTC
[CVE-2026-68188][MODERATE 7.0] Bluetooth: RFCOMM: Fix session UAF in set_termios
2026-08-10 15:44 UTC
[CVE-2026-68090][LOW] debugobjects: Plug race against a concurrent OOM disable
2026-08-10 15:40 UTC
[CVE-2026-68296][MODERATE REGULAR] net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM [ Upstream
2026-08-10 15:36 UTC
[CVE-2026-68250][LOW] drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
2026-08-10 15:32 UTC
[CVE-2026-68387][LOW] can: raw: add locking for raw flags bitfield [ Upstream
2026-08-10 15:32 UTC
[CVE-2026-68187][MODERATE REGULAR] exec: fix unsigned loop counter wrap in transfer_args_to_stack()
2026-08-10 15:30 UTC
[CVE-2026-68297][MODERATE REGULAR] tipc: fix u16 MTU truncation in media and bearer MTU validation [ Upstream
2026-08-10 15:26 UTC
[CVE-2026-68291][LOW] idpf: fix max_vport related crash on allocation error during init [ Upstream
2026-08-10 15:20 UTC
[CVE-2026-68375][LOW] bnxt_en: Handle partially initialized auxiliary devices [ Upstream
2026-08-10 15:17 UTC
[CVE-2026-68390][MODERATE 7.0] Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups [ Upstream
2026-08-10 15:13 UTC
[CVE-2026-68428][MODERATE 7.0] KVM: x86/mmu: Fix use-after-free on vendor module reload
2026-08-10 15:12 UTC
[CVE-2026-68140][IMPORTANT] net/iucv: fix use-after-free of a severed iucv_path
2026-08-10 15:08 UTC
[CVE-2026-68365][MODERATE 7.0] USB: serial: io_edgeport: cap received transmit credits
2026-08-10 15:03 UTC
[CVE-2026-68102][LOW] drm/amdgpu: fix aperture mapping leak
2026-08-10 14:59 UTC
[CVE-2026-68218][LOW] media: pci: dm1105: Free allocated workqueue
2026-08-10 14:59 UTC
[CVE-2026-68236][IMPORTANT] drm/amd/display: set new_stream to NULL after release
2026-08-10 14:54 UTC
[CVE-2026-68363][MODERATE 7.0] wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request [ Upstream
2026-08-10 14:54 UTC
[CVE-2026-68099][IMPORTANT] ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
2026-08-10 14:50 UTC
[CVE-2026-68246][MODERATE REGULAR] drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
2026-08-10 14:50 UTC
[CVE-2026-68156][IMPORTANT] libceph: refresh auth->authorizer_buf{,_len} after authorizer update
2026-08-10 14:50 UTC
[CVE-2026-68427][MODERATE 7.0] gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings [ Upstream
2026-08-10 14:46 UTC
[CVE-2026-68159][IMPORTANT] libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
2026-08-10 14:43 UTC
[CVE-2026-68121][MODERATE 7.0] pppoe: reload header pointer after dev_hard_header()
2026-08-10 14:39 UTC
[CVE-2026-68278][IMPORTANT] drm/dp/mst: fix buffer overflows in sideband chunk accumulation
2026-08-10 14:34 UTC
[CVE-2026-68128][IMPORTANT] ice: reject out-of-range ptype in ice_parser_profile_init
2026-08-10 14:30 UTC
[CVE-2026-68416][MODERATE 7.0] mtd: fix double free and WARN_ON in add_mtd_device() error paths [ Upstream
2026-08-10 14:26 UTC
[CVE-2026-68131][MODERATE 7.0] rbd: Reset positive result codes to zero in object map update path
2026-08-10 14:24 UTC
[CVE-2026-68384][MODERATE 7.0] drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves [ Upstream
2026-08-10 14:20 UTC
[CVE-2026-68419][MODERATE 7.0] RDMA/irdma: Prevent rereg_mr for non-mem regions [ Upstream
2026-08-10 14:18 UTC
[CVE-2026-68255][MODERATE 7.0] drm/virtio: bound EDID block reads to the response buffer
2026-08-10 14:14 UTC
[CVE-2026-68148][MODERATE 7.0] fscrypt: Add missing superblock check in find_or_insert_direct_key()
2026-08-10 14:10 UTC
[CVE-2026-68167][LOW] btrfs: do not try compression for data reloc inodes
2026-08-10 14:06 UTC
[CVE-2026-68118][MODERATE 7.0] tcp: challenge ACK for non-exact RST in SYN-RECEIVED
2026-08-10 14:06 UTC
[CVE-2026-68242][MODERATE REGULAR] drm/i915/gt: Fix NULL deref on sched_engine alloc failure
2026-08-10 14:03 UTC
[CVE-2026-68372][MODERATE REGULAR] usb: core: port: Deattach Type-C connector on component unbind
2026-08-10 14:03 UTC
[CVE-2026-68106][MODERATE REGULAR] drm/amdgpu: fix division by zero with invalid uvd dimensions
2026-08-10 13:57 UTC
[CVE-2026-68409][IMPORTANT] wifi: mac80211: defer link RX stats percpu free to RCU [ Upstream
2026-08-10 13:57 UTC
[CVE-2026-68239][MODERATE 7.0] drm/ttm: Account for NULL and handle pages in ttm_pool_backup
2026-08-10 13:53 UTC
[CVE-2026-68125][MODERATE 7.0] mac802154: llsec: reject frames shorter than the authentication tag
2026-08-10 13:51 UTC
[CVE-2026-68368][MODERATE 7.0] usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
2026-08-10 13:48 UTC
[CVE-2026-68376][IMPORTANT] sctp: fix auth_hmacs array size in struct sctp_cookie [ Upstream
2026-08-10 13:34 UTC
[CVE-2026-68108][MODERATE 7.0] drm/amdgpu/vce: fix integer overflow in image size
2026-08-10 13:34 UTC
[CVE-2026-68161][MODERATE 7.0] sctp: close UDP tunnel sockets during netns teardown [ Upstream
2026-08-10 13:34 UTC
[CVE-2026-68304][LOW] wifi: brcmfmac: fix 802.1X-SHA256 call trace warning [ Upstream
2026-08-10 13:30 UTC
[CVE-2026-68227][LOW] media: cx231xx: fix devres lifetime
2026-08-10 13:26 UTC
[CVE-2026-68391][MODERATE 7.0] Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds [ Upstream
2026-08-10 13:23 UTC
[CVE-2026-68364][MODERATE REGULAR] drm/amd/display: Fix ISM dc_lock deadlock during suspend [ Upstream
2026-08-10 13:19 UTC
[CVE-2026-68157][MODERATE 7.0] libceph: guard missing CRUSH type name lookup
2026-08-10 13:19 UTC
[CVE-2026-68133][LOW] ice: fix PTP Call Trace during PTP release
2026-08-10 13:15 UTC
[CVE-2026-68406][LOW] wifi: cfg80211: validate PMSR FTM preamble range [ Upstream
2026-08-10 13:11 UTC
[CVE-2026-68103][MODERATE 7.0] drm/amdgpu: reject mapping a reserved doorbell to a new queue
2026-08-10 13:07 UTC
[CVE-2026-68169][MODERATE 7.0] mptcp: pm: userspace: fix use-after-free in get_local_id [ Upstream
2026-08-10 13:07 UTC
[CVE-2026-68202][IMPORTANT] ALSA: seq: close a re-opened queue timer in the destructor
2026-08-10 13:02 UTC
[CVE-2026-68194][MODERATE REGULAR] wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
2026-08-10 12:59 UTC
[CVE-2026-68349][MODERATE 7.0] wifi: carl9170: fix buffer overflow in rx_stream failover path [ Upstream
2026-08-10 12:55 UTC
[CVE-2026-68316][MODERATE 7.0] accel: ethosu: Fix element size accounting for cmd stream validation [ Upstream
2026-08-10 12:51 UTC
[CVE-2026-68331][LOW] dpaa2-eth: put MAC endpoint device on disconnect [ Upstream
2026-08-10 12:51 UTC
[CVE-2026-68322][MODERATE REGULAR] rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled [ Upstream
2026-08-10 12:43 UTC
[CVE-2026-68082][MODERATE 7.0] libceph: fix two unsafe bare decodes in decode_lockers()
2026-08-08 9:54 UTC
[CVE-2026-68081][MODERATE 7.0] KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
2026-08-08 9:51 UTC
[CVE-2026-31669][IMPORTANT] mptcp: fix slab-use-after-free in __inet_lookup_established
2026-08-07 16:00 UTC
[CVE-2026-46082][MODERATE REGULAR] KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0
2026-08-07 14:09 UTC
[CVE-2026-68480][MODERATE REGULAR] x86/bugs: Make Safe-RET robust against interrupt injection
2026-08-06 17:51 UTC
[CVE-2026-64590][LOW] dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning [ Upstream
2026-08-06 8:22 UTC
[CVE-2026-64601][MODERATE 7.0] ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
2026-08-06 8:19 UTC
[CVE-2026-64598][MODERATE REGULAR] smb/client: Fix error code in smb2_aead_req_alloc()
2026-08-06 8:15 UTC
[CVE-2026-64597][IMPORTANT] smb: client: fix double-free in SMB2_close() replay
2026-08-06 8:11 UTC
[CVE-2026-64603][LOW] platform/x86: intel-hid: Protect ACPI notify handler against recursion
2026-08-06 8:07 UTC
[CVE-2026-64591][LOW] iommu/vt-d: Avoid WARNING in sva unbind path
2026-08-06 8:07 UTC
[CVE-2026-64604][MODERATE REGULAR] KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
2026-08-06 8:03 UTC
[CVE-2026-64593][LOW] btrfs: do not trim a device which is not writeable [ Upstream
2026-08-06 8:00 UTC
[CVE-2026-64586][MODERATE 7.0] wifi: brcmfmac: drain bus_reset work on device removal
2026-08-06 7:55 UTC
[CVE-2026-64596][MODERATE REGULAR] libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()
2026-08-06 7:45 UTC
[CVE-2026-64582][IMPORTANT] RDMA/rxe: Fix a use-after-free problem in rxe_mmap [ Upstream
2026-08-05 11:51 UTC
[CVE-2026-64572][MODERATE 7.0] ipv4: fib: free fib_alias with kfree_rcu() on insert error path [ Upstream
2026-08-05 9:29 UTC
[CVE-2026-64569][MODERATE REGULAR] mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n [ Upstream
2026-08-05 9:25 UTC
[CVE-2026-64570][MODERATE 7.0] wifi: mac80211: fix fils_discovery double free on alloc failure [ Upstream
2026-08-05 9:22 UTC
[CVE-2026-64577][MODERATE 7.0] gtp: check skb_pull_data() return in gtp1u_send_echo_resp() [ Upstream
2026-08-05 9:17 UTC
[CVE-2026-64579][MODERATE 7.0] xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert [ Upstream
2026-08-05 9:17 UTC
[CVE-2026-64573][MODERATE 7.0] Bluetooth: qca: fix NVM tag length underflow in TLV parser [ Upstream
2026-08-05 9:13 UTC
[CVE-2026-64580][MODERATE 7.0] xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() [ Upstream
2026-08-05 9:13 UTC
[CVE-2026-64581][MODERATE 7.0] xfrm: fix sk_dst_cache double-free in xfrm_user_policy() [ Upstream
2026-08-05 9:09 UTC
[CVE-2026-64567][MODERATE 7.0] btrfs: reject free space cache with more entries than pages [ Upstream
2026-08-05 9:06 UTC
[CVE-2026-64568][MODERATE 7.0] wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure [ Upstream
2026-08-05 9:02 UTC
[CVE-2026-64576][MODERATE REGULAR] nexthop: initialize extack in nh_res_bucket_migrate() [ Upstream
2026-08-05 8:58 UTC
[CVE-2026-64575][MODERATE 7.0] bpf: tcp: fix double sock release on batch realloc [ Upstream
2026-08-05 8:53 UTC
[CVE-2026-64574][MODERATE 7.0] wifi: mac80211: tear down new links on vif update error path [ Upstream
2026-08-05 8:52 UTC
[CVE-2026-64564][IMPORTANT] sctp: don't free the ASCONF's own transport in DEL-IP processing
2026-08-04 7:02 UTC
[CVE-2026-64563][MODERATE 7.0] rhashtable: clear stale iter->p on table restart
2026-08-04 6:59 UTC
[CVE-2026-64562][MODERATE 7.0] KVM: nVMX: Hide shadow VMCS right after VMCLEAR
2026-08-04 6:55 UTC
[CVE-2026-64561][IMPORTANT] KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
2026-08-04 6:51 UTC
[CVE-2026-64549][MODERATE REGULAR] Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() [ Upstream
2026-08-02 13:03 UTC
[CVE-2025-71130][MODERATE 7.0] drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
2026-08-02 11:49 UTC
[CVE-2026-31540][LOW] drm/i915/gt: Check set_default_submission() before deferencing [ Upstream
2026-08-02 11:40 UTC
[CVE-2025-68793][MODERATE 7.0] drm/amdgpu: fix a job->pasid access race in gpu recovery [ Upstream
2026-08-01 18:06 UTC
[CVE-2026-23034][MODERATE REGULAR] drm/amdgpu/userq: Fix fence reference leak on queue teardown v2 [ Upstream
2026-08-01 18:01 UTC
[CVE-2026-23051][LOW] drm/amdgpu: fix drm panic null pointer when driver not support atomic [ Upstream
2026-08-01 17:55 UTC
[CVE-2026-23163][MODERATE REGULAR] drm/amdgpu: fix NULL pointer dereference in amdgpu_gmc_filter_faults_remove [ Upstream
2026-08-01 17:50 UTC
[CVE-2026-31765][MODERATE REGULAR] drm/amdgpu: Change AMDGPU_VA_RESERVED_TRAP_SIZE to 64KB
2026-08-01 17:22 UTC
[CVE-2026-31766][IMPORTANT] drm/amdgpu: validate doorbell_offset in user queue creation
2026-08-01 17:16 UTC
[CVE-2026-43131][LOW] drm/amd/pm: Fix null pointer dereference issue [ Upstream
2026-08-01 17:10 UTC
[CVE-2026-43191][LOW] drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 [ Upstream
2026-08-01 17:07 UTC
[CVE-2026-43195][MODERATE REGULAR] drm/amdgpu: validate user queue size constraints [ Upstream
2026-08-01 17:02 UTC
[CVE-2026-43243][LOW] drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src [ Upstream
2026-08-01 16:58 UTC
[CVE-2025-71293][MODERATE 7.0] drm/amdgpu/ras: Move ras data alloc before bad page check [ Upstream
2026-08-01 16:54 UTC
[CVE-2025-71294][LOW] drm/amdgpu: fix NULL pointer issue buffer funcs [ Upstream
2026-08-01 16:49 UTC
[CVE-2026-43298][LOW] drm/amdgpu: Skip vcn poison irq release on VF [ Upstream
2026-08-01 16:45 UTC
[CVE-2026-43305][LOW] drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path [ Upstream
2026-08-01 16:41 UTC
[CVE-2026-43318][MODERATE REGULAR] drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify [ Upstream
2026-08-01 16:37 UTC
[CVE-2026-43320][LOW] drm/amd/display: Fix dsc eDP issue [ Upstream
2026-08-01 16:33 UTC
[CVE-2026-43367][LOW] drm/amd: Fix a few more NULL pointer dereference in device cleanup
2026-08-01 16:29 UTC
[CVE-2026-43369][LOW] drm/amd: Fix NULL pointer dereference in device cleanup
2026-08-01 16:25 UTC
[CVE-2026-43398][MODERATE REGULAR] drm/amdgpu: add upper bound check on user inputs in wait ioctl
2026-08-01 16:21 UTC
[CVE-2026-43399][MODERATE REGULAR] drm/amdgpu/userq: Fix reference leak in amdgpu_userq_wait_ioctl
2026-08-01 16:17 UTC
[CVE-2026-43400][MODERATE REGULAR] drm/amdgpu: add upper bound check on user inputs in signal ioctl
2026-08-01 16:12 UTC
[CVE-2026-43444][LOW] drm/amdkfd: Unreserve bo if queue update failed [ Upstream
2026-08-01 16:07 UTC
[CVE-2026-45878][IMPORTANT] drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 [ Upstream
2026-08-01 15:54 UTC
[CVE-2026-45853][MODERATE 7.0] drm/amdgpu: Use kvfree instead of kfree in amdgpu_gmc_get_nps_memranges() [ Upstream
2026-08-01 15:47 UTC
[CVE-2026-45947][LOW] drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc() [ Upstream
2026-08-01 15:41 UTC
[CVE-2026-45979][LOW] drm/amdgpu: clean up the amdgpu_cs_parser_bos [ Upstream
2026-08-01 15:35 UTC
[CVE-2026-45976][LOW] drm/amdgpu: Fix memory leak in amdgpu_ras_init() [ Upstream
2026-08-01 15:29 UTC
[CVE-2026-46199][MODERATE 7.0] drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
2026-08-01 14:17 UTC
[CVE-2026-46220][MODERATE REGULAR] drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
2026-08-01 14:06 UTC
[CVE-2026-46229][MODERATE 7.0] drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
2026-08-01 14:00 UTC
[CVE-2026-46204][MODERATE 7.0] drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
2026-08-01 13:54 UTC
[CVE-2026-46197][MODERATE 7.0] drm/amdkfd: validate SVM ioctl nattr against buffer size
2026-08-01 13:51 UTC
[CVE-2026-46230][MODERATE 7.0] drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
2026-08-01 13:41 UTC
[CVE-2026-46245][LOW] drm/amd/display: Fix dc_link NULL handling in HPD init [ Upstream
2026-08-01 13:37 UTC
[CVE-2026-46263][MODERATE REGULAR] drm/amd/display: Fix out-of-bounds stream encoder index v3 [ Upstream
2026-08-01 13:33 UTC
[CVE-2026-46276][LOW] drm/amdgpu: fix zero-size GDS range init on RDNA4
2026-08-01 13:27 UTC
[CVE-2026-46311][MODERATE 7.0] drm/amdgpu/userq: fix access to stale wptr mapping
2026-08-01 13:21 UTC
[CVE-2026-53135][LOW] drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
2026-07-31 20:53 UTC
[CVE-2026-53136][IMPORTANT] drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
2026-07-31 20:39 UTC
[CVE-2026-53137][MODERATE 7.0] drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
2026-07-31 20:32 UTC
[CVE-2026-53138][MODERATE 7.0] drm/amd/display: Bound VBIOS record-chain walk loops
2026-07-31 20:27 UTC
[CVE-2026-43368][MODERATE 7.0] drm/i915: Fix potential overflow of shmem scatterlist length
2026-07-30 17:18 UTC
[CVE-2026-31656][MODERATE 7.0] drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
2026-07-30 17:11 UTC
[CVE-2026-43237][IMPORTANT] drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 [ Upstream
2026-07-30 17:00 UTC
[CVE-2026-43206][IMPORTANT] drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() [ Upstream
2026-07-30 16:50 UTC
[CVE-2026-31566][IMPORTANT] drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib [ Upstream
2026-07-30 16:34 UTC
[CVE-2026-43370][MODERATE 7.0] drm/amdgpu: Fix use-after-free race in VM acquire
2026-07-30 16:21 UTC
[CVE-2022-4994][LOW] KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that __emulator_pio_in() fills "val" when handling in-kernel PIO. vcpu->arch.pio.count is guaranteed to be '0', so this a pure nop. emulator_pio_in_emulated is now the last caller of emulator_pio_in. No functional change intended. Signed-off-by: Paolo Bonzini <[email protected]>
2026-07-30 9:49 UTC
[CVE-2026-63886][IMPORTANT] scsi: target: iscsi: Validate CHAP_R length before base64 decode
2026-07-29 23:56 UTC (3+ messages)
` [CVE-2026-63886] scsi
[CVE-2026-64560][MODERATE 7.0] posix-cpu-timers: Prevent UAF caused by non-leader exec() race
2026-07-29 17:51 UTC
[CVE-2026-64559][MODERATE 7.0] s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
2026-07-29 16:56 UTC
[CVE-2026-64558][IMPORTANT] s390/pkey: Check length in pkey_pckmo handler implementation
2026-07-29 16:51 UTC
[CVE-2026-64556][IMPORTANT] perf/core: Detach event groups during remove_on_exec [ Upstream
2026-07-29 8:55 UTC
[CVE-2026-64557][MODERATE 7.0] Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() [ Upstream
2026-07-29 8:51 UTC
[CVE-2026-64544][LOW] crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents [ Upstream
2026-07-29 6:26 UTC
[CVE-2026-64543][MODERATE 7.0] tipc: fix use-after-free of the discoverer in tipc_disc_rcv() [ Upstream
2026-07-29 6:03 UTC
[CVE-2026-64553][MODERATE REGULAR] net: psample: fix info leak in PSAMPLE_ATTR_DATA [ Upstream
2026-07-29 5:38 UTC
[CVE-2026-64539][MODERATE 7.0] Bluetooth: eir: Fix stack OOB write when prepending the Flags AD [ Upstream
2026-07-29 5:35 UTC
[CVE-2026-64547][MODERATE REGULAR] net: usb: net1080: validate packet_len before pad-byte access in rx_fixup [ Upstream
2026-07-29 5:21 UTC
[CVE-2026-64551][MODERATE 7.0] sctp: validate STALE_COOKIE cause length before reading staleness
2026-07-29 5:09 UTC
[CVE-2026-64540][MODERATE REGULAR] usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() [ Upstream
2026-07-29 5:06 UTC
[CVE-2026-64548][MODERATE 7.0] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() [ Upstream
2026-07-28 2:31 UTC
[CVE-2026-64554][IMPORTANT] netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
2026-07-28 2:27 UTC
[CVE-2026-64545][MODERATE REGULAR] net, bpf: check master for NULL in xdp_master_redirect() [ Upstream
2026-07-28 2:23 UTC
[CVE-2026-64555][MODERATE 7.0] KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
2026-07-28 2:18 UTC
[CVE-2026-64537][LOW] bridge: cfm: reject invalid CCM interval at configuration time [ Upstream
2026-07-28 2:18 UTC
[CVE-2026-64541][MODERATE 7.0] net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket [ Upstream
2026-07-28 2:18 UTC
[CVE-2026-43097][LOW] PCI: hv: Fix double ida_free in hv_pci_probe error path [ Upstream
2026-07-28 2:15 UTC
[CVE-2026-64546][MODERATE REGULAR] drm/edid: fix OOB read in drm_parse_tiled_block() [ Upstream
2026-07-28 2:14 UTC
[CVE-2026-64538][MODERATE 7.0] ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). [ Upstream
2026-07-28 2:10 UTC
[CVE-2026-64552][IMPORTANT] virtio-net: fix len check in receive_big() [ Upstream
2026-07-27 22:42 UTC
[CVE-2026-64542][MODERATE REGULAR] ipv6: ndisc: fix NULL deref in accept_untracked_na() [ Upstream
2026-07-27 22:03 UTC
[CVE-2026-64535][IMPORTANT] nvmet-tcp: Fix potential UAF when ddgst mismatch
2026-07-27 6:58 UTC
[CVE-2026-64531][MODERATE 7.0] net: openvswitch: reject oversized nested action attrs
2026-07-27 6:55 UTC
[CVE-2026-64534][IMPORTANT] nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
2026-07-27 6:51 UTC
[CVE-2024-14040][LOW] net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. With high fan-out of the involved nodes, and overall high number of nodes, a (non-)ECMP weight ratio that we would like to configure does not fit into 8 bits. Instead of, say, 255:254, we might like to configure something like 1000:999. For these deployments, the 8-bit weight may not be enough. To that end, in this patch increase the next hop weight from u8 to u16. Increasing the width of an integral type can be tricky, because while the code still compiles, the types may not check out anymore, and numerical errors come up. To prevent this, the conversion was done in two steps. First the type was changed from u8 to a single-member structure, which invalidated all uses of the field. This allowed going through them one by one and audit for type correctness. Then the structure was replaced with a vanilla u16 again. This should ensure that no place was missed. The UAPI for configuring nexthop group members is that an attribute NHA_GROUP carries an array of struct nexthop_grp entries: struct nexthop_grp { __u32 id; /* nexthop id - must exist */ __u8 weight; /* weight of this nexthop */ __u8 resvd1; __u16 resvd2; }; The field resvd1 is currently validated and required to be zero. We can lift this requirement and carry high-order bits of the weight in the reserved field: struct nexthop_grp { __u32 id; /* nexthop id - must exist */ __u8 weight; /* weight of this nexthop */ __u8 weight_high; __u16 resvd2; }; Keeping the fields split this way was chosen in case an existing userspace makes assumptions about the width of the weight field, and to sidestep any endianness issues. The weight field is currently encoded as the weight value minus one, because weight of 0 is invalid. This same trick is impossible for the new weight_high field, because zero must mean actual zero. With this in place: - Old userspace is guaranteed to carry weight_high of 0, therefore configuring 8-bit weights as appropriate. When dumping nexthops with 16-bit weight, it would only show the lower 8 bits. But configuring such nexthops implies existence of userspace aware of the extension in the first place. - New userspace talking to an old kernel will work as long as it only attempts to configure 8-bit weights, where the high-order bits are zero. Old kernel will bounce attempts at configuring >8-bit weights. Renaming reserved fields as they are allocated for some purpose is commonly done in Linux. Whoever touches a reserved field is doing so at their own risk. nexthop_grp::resvd1 in particular is currently used by at least strace, however they carry an own copy of UAPI headers, and the conversion should be trivial. A helper is provided for decoding the weight out of the two fields. Forcing a conversion seems preferable to bending backwards and introducing anonymous unions or whatever. Signed-off-by: Petr Machata <[email protected]> Reviewed-by: Ido Schimmel <[email protected]> Reviewed-by: David Ahern <[email protected]> Reviewed-by: Przemek Kitszel <[email protected]> Link: https://patch.msgid.link/483e2fcf4beb0d9135d62e7d27b46fa2685479d4.1723036486.git.petrm@nvidia.com Signed-off-by: Jakub Kicinski <[email protected]>
2026-07-26 6:53 UTC
page: next (older) | prev (newer) | latest
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox