public inbox for [email protected]
 help / color / mirror / Atom feed
This is experimental automated Linux kernel CVE triage research. Results are heuristic and may be incorrect. This site is not an official vendor advisory or severity source.
[CVE-2026-64562][MODERATE 7.0] KVM: nVMX: Hide shadow VMCS right after VMCLEAR
 2026-08-04  6:55 UTC 

[CVE-2026-64561][IMPORTANT] KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
 2026-08-04  6:51 UTC 

[CVE-2026-64549][MODERATE REGULAR] Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() [ Upstream
 2026-08-02 13:03 UTC 

[CVE-2025-71130][MODERATE 7.0] drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
 2026-08-02 11:49 UTC 

[CVE-2026-31540][LOW] drm/i915/gt: Check set_default_submission() before deferencing [ Upstream
 2026-08-02 11:40 UTC 

[CVE-2025-68793][MODERATE 7.0] drm/amdgpu: fix a job->pasid access race in gpu recovery [ Upstream
 2026-08-01 18:06 UTC 

[CVE-2026-23034][MODERATE REGULAR] drm/amdgpu/userq: Fix fence reference leak on queue teardown v2 [ Upstream
 2026-08-01 18:01 UTC 

[CVE-2026-23051][LOW] drm/amdgpu: fix drm panic null pointer when driver not support atomic [ Upstream
 2026-08-01 17:55 UTC 

[CVE-2026-23163][MODERATE REGULAR] drm/amdgpu: fix NULL pointer dereference in amdgpu_gmc_filter_faults_remove [ Upstream
 2026-08-01 17:50 UTC 

[CVE-2026-31765][MODERATE REGULAR] drm/amdgpu: Change AMDGPU_VA_RESERVED_TRAP_SIZE to 64KB
 2026-08-01 17:22 UTC 

[CVE-2026-31766][IMPORTANT] drm/amdgpu: validate doorbell_offset in user queue creation
 2026-08-01 17:16 UTC 

[CVE-2026-43131][LOW] drm/amd/pm: Fix null pointer dereference issue [ Upstream
 2026-08-01 17:10 UTC 

[CVE-2026-43191][LOW] drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 [ Upstream
 2026-08-01 17:07 UTC 

[CVE-2026-43195][MODERATE REGULAR] drm/amdgpu: validate user queue size constraints [ Upstream
 2026-08-01 17:02 UTC 

[CVE-2026-43243][LOW] drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src [ Upstream
 2026-08-01 16:58 UTC 

[CVE-2025-71293][MODERATE 7.0] drm/amdgpu/ras: Move ras data alloc before bad page check [ Upstream
 2026-08-01 16:54 UTC 

[CVE-2025-71294][LOW] drm/amdgpu: fix NULL pointer issue buffer funcs [ Upstream
 2026-08-01 16:49 UTC 

[CVE-2026-43298][LOW] drm/amdgpu: Skip vcn poison irq release on VF [ Upstream
 2026-08-01 16:45 UTC 

[CVE-2026-43305][LOW] drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path [ Upstream
 2026-08-01 16:41 UTC 

[CVE-2026-43318][MODERATE REGULAR] drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify [ Upstream
 2026-08-01 16:37 UTC 

[CVE-2026-43320][LOW] drm/amd/display: Fix dsc eDP issue [ Upstream
 2026-08-01 16:33 UTC 

[CVE-2026-43367][LOW] drm/amd: Fix a few more NULL pointer dereference in device cleanup
 2026-08-01 16:29 UTC 

[CVE-2026-43369][LOW] drm/amd: Fix NULL pointer dereference in device cleanup
 2026-08-01 16:25 UTC 

[CVE-2026-43398][MODERATE REGULAR] drm/amdgpu: add upper bound check on user inputs in wait ioctl
 2026-08-01 16:21 UTC 

[CVE-2026-43399][MODERATE REGULAR] drm/amdgpu/userq: Fix reference leak in amdgpu_userq_wait_ioctl
 2026-08-01 16:17 UTC 

[CVE-2026-43400][MODERATE REGULAR] drm/amdgpu: add upper bound check on user inputs in signal ioctl
 2026-08-01 16:12 UTC 

[CVE-2026-43444][LOW] drm/amdkfd: Unreserve bo if queue update failed [ Upstream
 2026-08-01 16:07 UTC 

[CVE-2026-45878][IMPORTANT] drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 [ Upstream
 2026-08-01 15:54 UTC 

[CVE-2026-45853][MODERATE 7.0] drm/amdgpu: Use kvfree instead of kfree in amdgpu_gmc_get_nps_memranges() [ Upstream
 2026-08-01 15:47 UTC 

[CVE-2026-45947][LOW] drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc() [ Upstream
 2026-08-01 15:41 UTC 

[CVE-2026-45979][LOW] drm/amdgpu: clean up the amdgpu_cs_parser_bos [ Upstream
 2026-08-01 15:35 UTC 

[CVE-2026-45976][LOW] drm/amdgpu: Fix memory leak in amdgpu_ras_init() [ Upstream
 2026-08-01 15:29 UTC 

[CVE-2026-46199][MODERATE 7.0] drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
 2026-08-01 14:17 UTC 

[CVE-2026-46220][MODERATE REGULAR] drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
 2026-08-01 14:06 UTC 

[CVE-2026-46229][MODERATE 7.0] drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
 2026-08-01 14:00 UTC 

[CVE-2026-46204][MODERATE 7.0] drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
 2026-08-01 13:54 UTC 

[CVE-2026-46197][MODERATE 7.0] drm/amdkfd: validate SVM ioctl nattr against buffer size
 2026-08-01 13:51 UTC 

[CVE-2026-46230][MODERATE 7.0] drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
 2026-08-01 13:41 UTC 

[CVE-2026-46245][LOW] drm/amd/display: Fix dc_link NULL handling in HPD init [ Upstream
 2026-08-01 13:37 UTC 

[CVE-2026-46263][MODERATE REGULAR] drm/amd/display: Fix out-of-bounds stream encoder index v3 [ Upstream
 2026-08-01 13:33 UTC 

[CVE-2026-46276][LOW] drm/amdgpu: fix zero-size GDS range init on RDNA4
 2026-08-01 13:27 UTC 

[CVE-2026-46311][MODERATE 7.0] drm/amdgpu/userq: fix access to stale wptr mapping
 2026-08-01 13:21 UTC 

[CVE-2026-53135][LOW] drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
 2026-07-31 20:53 UTC 

[CVE-2026-53136][IMPORTANT] drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
 2026-07-31 20:39 UTC 

[CVE-2026-53137][MODERATE 7.0] drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
 2026-07-31 20:32 UTC 

[CVE-2026-53138][MODERATE 7.0] drm/amd/display: Bound VBIOS record-chain walk loops
 2026-07-31 20:27 UTC 

[CVE-2026-43368][MODERATE 7.0] drm/i915: Fix potential overflow of shmem scatterlist length
 2026-07-30 17:18 UTC 

[CVE-2026-31656][MODERATE 7.0] drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
 2026-07-30 17:11 UTC 

[CVE-2026-43237][IMPORTANT] drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 [ Upstream
 2026-07-30 17:00 UTC 

[CVE-2026-43206][IMPORTANT] drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() [ Upstream
 2026-07-30 16:50 UTC 

[CVE-2026-31566][IMPORTANT] drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib [ Upstream
 2026-07-30 16:34 UTC 

[CVE-2026-43370][MODERATE 7.0] drm/amdgpu: Fix use-after-free race in VM acquire
 2026-07-30 16:21 UTC 

[CVE-2022-4994][LOW] KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that __emulator_pio_in() fills "val" when handling in-kernel PIO. vcpu->arch.pio.count is guaranteed to be '0', so this a pure nop. emulator_pio_in_emulated is now the last caller of emulator_pio_in. No functional change intended. Signed-off-by: Paolo Bonzini <[email protected]>
 2026-07-30  9:49 UTC 

[CVE-2026-63886][IMPORTANT] scsi: target: iscsi: Validate CHAP_R length before base64 decode
 2026-07-29 23:56 UTC  (3+ messages)
` [CVE-2026-63886] scsi

[CVE-2026-64560][MODERATE 7.0] posix-cpu-timers: Prevent UAF caused by non-leader exec() race
 2026-07-29 17:51 UTC 

[CVE-2026-64559][MODERATE 7.0] s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
 2026-07-29 16:56 UTC 

[CVE-2026-64558][IMPORTANT] s390/pkey: Check length in pkey_pckmo handler implementation
 2026-07-29 16:51 UTC 

[CVE-2026-64556][IMPORTANT] perf/core: Detach event groups during remove_on_exec [ Upstream
 2026-07-29  8:55 UTC 

[CVE-2026-64557][MODERATE 7.0] Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() [ Upstream
 2026-07-29  8:51 UTC 

[CVE-2026-64544][LOW] crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents [ Upstream
 2026-07-29  6:26 UTC 

[CVE-2026-64543][MODERATE 7.0] tipc: fix use-after-free of the discoverer in tipc_disc_rcv() [ Upstream
 2026-07-29  6:03 UTC 

[CVE-2026-64553][MODERATE REGULAR] net: psample: fix info leak in PSAMPLE_ATTR_DATA [ Upstream
 2026-07-29  5:38 UTC 

[CVE-2026-64539][MODERATE 7.0] Bluetooth: eir: Fix stack OOB write when prepending the Flags AD [ Upstream
 2026-07-29  5:35 UTC 

[CVE-2026-64547][MODERATE REGULAR] net: usb: net1080: validate packet_len before pad-byte access in rx_fixup [ Upstream
 2026-07-29  5:21 UTC 

[CVE-2026-64551][MODERATE 7.0] sctp: validate STALE_COOKIE cause length before reading staleness
 2026-07-29  5:09 UTC 

[CVE-2026-64540][MODERATE REGULAR] usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() [ Upstream
 2026-07-29  5:06 UTC 

[CVE-2026-64548][MODERATE 7.0] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() [ Upstream
 2026-07-28  2:31 UTC 

[CVE-2026-64554][IMPORTANT] netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
 2026-07-28  2:27 UTC 

[CVE-2026-64545][MODERATE REGULAR] net, bpf: check master for NULL in xdp_master_redirect() [ Upstream
 2026-07-28  2:23 UTC 

[CVE-2026-64555][MODERATE 7.0] KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
 2026-07-28  2:18 UTC 

[CVE-2026-64537][LOW] bridge: cfm: reject invalid CCM interval at configuration time [ Upstream
 2026-07-28  2:18 UTC 

[CVE-2026-64541][MODERATE 7.0] net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket [ Upstream
 2026-07-28  2:18 UTC 

[CVE-2026-43097][LOW] PCI: hv: Fix double ida_free in hv_pci_probe error path [ Upstream
 2026-07-28  2:15 UTC 

[CVE-2026-64546][MODERATE REGULAR] drm/edid: fix OOB read in drm_parse_tiled_block() [ Upstream
 2026-07-28  2:14 UTC 

[CVE-2026-64538][MODERATE 7.0] ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). [ Upstream
 2026-07-28  2:10 UTC 

[CVE-2026-64552][IMPORTANT] virtio-net: fix len check in receive_big() [ Upstream
 2026-07-27 22:42 UTC 

[CVE-2026-64542][MODERATE REGULAR] ipv6: ndisc: fix NULL deref in accept_untracked_na() [ Upstream
 2026-07-27 22:03 UTC 

[CVE-2026-64535][IMPORTANT] nvmet-tcp: Fix potential UAF when ddgst mismatch
 2026-07-27  6:58 UTC 

[CVE-2026-64531][MODERATE 7.0] net: openvswitch: reject oversized nested action attrs
 2026-07-27  6:55 UTC 

[CVE-2026-64534][IMPORTANT] nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
 2026-07-27  6:51 UTC 

[CVE-2024-14040][LOW] net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. With high fan-out of the involved nodes, and overall high number of nodes, a (non-)ECMP weight ratio that we would like to configure does not fit into 8 bits. Instead of, say, 255:254, we might like to configure something like 1000:999. For these deployments, the 8-bit weight may not be enough. To that end, in this patch increase the next hop weight from u8 to u16. Increasing the width of an integral type can be tricky, because while the code still compiles, the types may not check out anymore, and numerical errors come up. To prevent this, the conversion was done in two steps. First the type was changed from u8 to a single-member structure, which invalidated all uses of the field. This allowed going through them one by one and audit for type correctness. Then the structure was replaced with a vanilla u16 again. This should ensure that no place was missed. The UAPI for configuring nexthop group members is that an attribute NHA_GROUP carries an array of struct nexthop_grp entries: struct nexthop_grp { __u32 id; /* nexthop id - must exist */ __u8 weight; /* weight of this nexthop */ __u8 resvd1; __u16 resvd2; }; The field resvd1 is currently validated and required to be zero. We can lift this requirement and carry high-order bits of the weight in the reserved field: struct nexthop_grp { __u32 id; /* nexthop id - must exist */ __u8 weight; /* weight of this nexthop */ __u8 weight_high; __u16 resvd2; }; Keeping the fields split this way was chosen in case an existing userspace makes assumptions about the width of the weight field, and to sidestep any endianness issues. The weight field is currently encoded as the weight value minus one, because weight of 0 is invalid. This same trick is impossible for the new weight_high field, because zero must mean actual zero. With this in place: - Old userspace is guaranteed to carry weight_high of 0, therefore configuring 8-bit weights as appropriate. When dumping nexthops with 16-bit weight, it would only show the lower 8 bits. But configuring such nexthops implies existence of userspace aware of the extension in the first place. - New userspace talking to an old kernel will work as long as it only attempts to configure 8-bit weights, where the high-order bits are zero. Old kernel will bounce attempts at configuring >8-bit weights. Renaming reserved fields as they are allocated for some purpose is commonly done in Linux. Whoever touches a reserved field is doing so at their own risk. nexthop_grp::resvd1 in particular is currently used by at least strace, however they carry an own copy of UAPI headers, and the conversion should be trivial. A helper is provided for decoding the weight out of the two fields. Forcing a conversion seems preferable to bending backwards and introducing anonymous unions or whatever. Signed-off-by: Petr Machata <[email protected]> Reviewed-by: Ido Schimmel <[email protected]> Reviewed-by: David Ahern <[email protected]> Reviewed-by: Przemek Kitszel <[email protected]> Link: https://patch.msgid.link/483e2fcf4beb0d9135d62e7d27b46fa2685479d4.1723036486.git.petrm@nvidia.com Signed-off-by: Jakub Kicinski <[email protected]>
 2026-07-26  6:53 UTC 

[CVE-2026-64530][IMPORTANT] net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle [ Upstream
 2026-07-26  6:51 UTC 

[CVE-2026-64383][IMPORTANT] smb: client: fix double-free in SMB2_flush() replay
 2026-07-25 19:44 UTC 

[CVE-2026-64340][MODERATE 7.0] USB: legousbtower: fix use-after-free on disconnect race
 2026-07-25 19:41 UTC 

[CVE-2026-64516][MODERATE 7.0] drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets [ Upstream
 2026-07-25 19:37 UTC 

[CVE-2026-64486][LOW] ALSA: cmipci: check snd_ctl_new1() return value
 2026-07-25 19:37 UTC 

[CVE-2026-64463][MODERATE 7.0] usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
 2026-07-25 19:33 UTC 

[CVE-2026-64315][MODERATE REGULAR] crypto: caam - use print_hex_dump_devel to guard key hex dumps again
 2026-07-25 19:30 UTC 

[CVE-2026-64364][IMPORTANT] HID: multitouch: fix out-of-bounds bit access on mt_io_flags [ Upstream
 2026-07-25 19:24 UTC 

[CVE-2026-64357][MODERATE REGULAR] xfs: fix exchmaps reservation limit check
 2026-07-25 19:22 UTC 

[CVE-2026-64369][MODERATE REGULAR] s390: Revert support for DCACHE_WORD_ACCESS
 2026-07-25 19:18 UTC 

[CVE-2026-64515][MODERATE 7.0] wifi: mac80211: fix MLE defragmentation [ Upstream
 2026-07-25 19:14 UTC 

[CVE-2026-64265][IMPORTANT] fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
 2026-07-25 19:11 UTC 

[CVE-2026-64419][LOW] mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() [ Upstream
 2026-07-25 19:09 UTC 

[CVE-2026-64316][MODERATE REGULAR] crypto: caam - use print_hex_dump_devel to guard key hex dumps
 2026-07-25 19:09 UTC 

[CVE-2026-64522][LOW] net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA [ Upstream
 2026-07-25 19:05 UTC 

[CVE-2026-64309][MODERATE 7.0] crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
 2026-07-25 19:05 UTC 

[CVE-2026-64320][IMPORTANT] nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
 2026-07-25 19:01 UTC 

[CVE-2026-64307][MODERATE 7.0] crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) [ Upstream
 2026-07-25 18:58 UTC 

[CVE-2026-64323][MODERATE 7.0] udf: validate VAT header length against the VAT inode size
 2026-07-25 18:54 UTC 

[CVE-2026-64276][IMPORTANT] Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
 2026-07-25 18:50 UTC 

[CVE-2026-64404][MODERATE REGULAR] Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
 2026-07-25 18:46 UTC 

[CVE-2026-64346][MODERATE 7.0] usb: gadget: udc: Fix use-after-free in gadget_match_driver
 2026-07-25 18:43 UTC 

[CVE-2026-64525][MODERATE 7.0] xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit [ Upstream
 2026-07-25 18:40 UTC 

[CVE-2026-64523][MODERATE 7.0] net/handshake: Take a long-lived file reference at submit [ Upstream
 2026-07-25 18:38 UTC 

[CVE-2026-64360][MODERATE REGULAR] hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
 2026-07-25 18:35 UTC 

[CVE-2026-64382][IMPORTANT] smb: client: fix double-free in SMB2_open() replay
 2026-07-25 18:33 UTC 

[CVE-2026-64460][MODERATE 7.0] PCI/IOV: Skip VF Resizable BAR restore on read error
 2026-07-25 18:30 UTC 

[CVE-2026-64470][MODERATE 7.0] Bluetooth: btusb: fix use-after-free on marvell probe failure [ Upstream
 2026-07-25 18:27 UTC 

[CVE-2026-64452][MODERATE 7.0] 6lowpan: fix NHC entry use-after-free on error path
 2026-07-25 18:23 UTC 

[CVE-2026-64365][MODERATE 7.0] HID: letsketch: fix UAF on inrange_timer at driver unbind
 2026-07-25 18:19 UTC 

[CVE-2026-64481][MODERATE 7.0] ALSA: hda/cs35l41: Fix firmware load work teardown [ Upstream
 2026-07-25 18:15 UTC 

[CVE-2026-64384][IMPORTANT] smb: client: fix change notify replay double-free
 2026-07-25 18:12 UTC 

[CVE-2026-64428][LOW] gpio: sch: use raw_spinlock_t in the irq startup path [ Upstream
 2026-07-25 18:08 UTC 

[CVE-2026-64266][MODERATE 7.0] fuse: re-lock request before returning from fuse_ref_folio()
 2026-07-25 18:08 UTC 

[CVE-2026-64424][MODERATE 7.0] netpoll: fix a use-after-free on shutdown path
 2026-07-25 18:04 UTC 

[CVE-2026-64356][LOW] xfs: fix memory leak in xfs_dqinode_metadir_create()
 2026-07-25 18:01 UTC 

[CVE-2026-64388][LOW] smb/client: fix chown/chgrp with SMB3 POSIX Extensions
 2026-07-25 17:58 UTC 

[CVE-2026-64325][MODERATE REGULAR] wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon [ Upstream
 2026-07-25 17:55 UTC 

[CVE-2026-64275][LOW] Input: elan_i2c - prevent division by zero and arithmetic underflow
 2026-07-25 17:53 UTC 

[CVE-2026-64336][MODERATE REGULAR] USB: serial: keyspan_pda: fix information leak
 2026-07-25 17:48 UTC 

[CVE-2026-64313][MODERATE 7.0] crypto: ecc - Fix carry overflow in vli multiplication
 2026-07-25 17:45 UTC 

[CVE-2026-64451][LOW] tracing: Fix NULL pointer dereference in func_set_flag()
 2026-07-25 17:40 UTC 

[CVE-2026-64453][MODERATE 7.0] usb: misc: usbio: fix disconnect UAF in client teardown
 2026-07-25 17:39 UTC 

[CVE-2026-64342][MODERATE 7.0] USB: iowarrior: fix use-after-free on disconnect
 2026-07-25 17:37 UTC 

[CVE-2026-64479][MODERATE REGULAR] ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
 2026-07-25 17:33 UTC 

[CVE-2026-64308][MODERATE REGULAR] crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
 2026-07-25 17:29 UTC 

[CVE-2026-64507][MODERATE REGULAR] x86/bugs: Enable IBPB flush on BPF JIT allocation
 2026-07-25 17:26 UTC 

[CVE-2026-64529][MODERATE REGULAR] crypto: qat - remove unused character device and IOCTLs [ Upstream
 2026-07-25 17:23 UTC 

[CVE-2026-64317][MODERATE 7.0] isofs: bound Rock Ridge symlink components to the SL record
 2026-07-25 17:18 UTC 

[CVE-2026-64490][IMPORTANT] ALSA: virtio: Validate control metadata from the device
 2026-07-25 17:14 UTC 

[CVE-2026-64283][MODERATE 7.0] KVM: guest_memfd: Treat memslot binding offset+size as unsigned values
 2026-07-25 17:10 UTC 

[CVE-2026-64319][MODERATE 7.0] nvmet-auth: validate reply message payload bounds against transfer length [ Upstream
 2026-07-25 17:10 UTC 

[CVE-2026-64344][MODERATE 7.0] USB: idmouse: fix use-after-free on disconnect race
 2026-07-25 17:07 UTC 

[CVE-2026-64289][MODERATE REGULAR] iommufd: Set upper bounds on cache invalidation entry_num and entry_len
 2026-07-25 17:03 UTC 

[CVE-2026-64435][LOW] audit: Fix data races of skb_queue_len() readers on audit_queue
 2026-07-25 17:00 UTC 

[CVE-2026-64385][IMPORTANT] smb: client: fix double-free in SMB2_ioctl() replay
 2026-07-25 16:55 UTC 

[CVE-2026-64477][MODERATE REGULAR] x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled
 2026-07-25 16:52 UTC 

[CVE-2026-64292][MODERATE REGULAR] iommufd: Move vevent memory allocation outside spinlock [ Upstream
 2026-07-25 16:48 UTC 

[CVE-2026-64415][LOW] mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup
 2026-07-25 16:45 UTC 

[CVE-2026-64279][MODERATE REGULAR] i2c: core: fix adapter deregistration race
 2026-07-25 16:41 UTC 

[CVE-2026-64376][LOW] firmware_loader: fix device reference leak in firmware_upload_register()
 2026-07-25 16:37 UTC 

[CVE-2026-64354][MODERATE 7.0] bpf: Validate BTF repeated field counts before expansion
 2026-07-25 16:34 UTC 

[CVE-2026-64422][MODERATE 7.0] net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
 2026-07-25 16:30 UTC 

[CVE-2026-64402][MODERATE 7.0] coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
 2026-07-25 16:26 UTC 

[CVE-2026-64375][IMPORTANT] proc: protect ptrace_may_access() with exec_update_lock (FD links) [ Upstream
 2026-07-25 16:26 UTC 

[CVE-2026-64339][MODERATE REGULAR] usb: misc: usbio: bound bulk IN response length to the received transfer
 2026-07-25 16:22 UTC 

[CVE-2026-64312][MODERATE 7.0] crypto: pcrypt - restore callback for non-parallel fallback
 2026-07-25 16:20 UTC 

[CVE-2026-64510][MODERATE 7.0] ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup [ Upstream
 2026-07-25 16:16 UTC 

[CVE-2026-64305][MODERATE 7.0] crypto: qat - protect service table iterations with service_lock
 2026-07-25 16:12 UTC 

[CVE-2026-64271][IMPORTANT] Input: touchwin - reset the packet index on every complete packet
 2026-07-25 16:08 UTC 

[CVE-2026-64303][IMPORTANT] spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
 2026-07-25 16:08 UTC 

[CVE-2026-64351][MODERATE REGULAR] net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
 2026-07-25 16:04 UTC 

[CVE-2026-64268][IMPORTANT] RDMA/siw: bound Read Response placement to the RREAD length
 2026-07-25 16:00 UTC 

[CVE-2026-64465][LOW] usb: xhci: Fix sleep in atomic context in xhci_free_streams()
 2026-07-25 15:56 UTC 

[CVE-2026-64413][MODERATE REGULAR] netfilter: ebtables: zero chainstack array [ Upstream
 2026-07-25 15:52 UTC 

[CVE-2026-64296][IMPORTANT] exfat: bound uniname advance in exfat_find_dir_entry()
 2026-07-25 15:48 UTC 

[CVE-2026-64363][MODERATE REGULAR] HID: appleir: fix UAF on pending key_up_timer in remove() [ Upstream
 2026-07-25 15:44 UTC 

[CVE-2026-64416][MODERATE REGULAR] mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host [ Upstream
 2026-07-25 15:39 UTC 

[CVE-2026-64418][MODERATE 7.0] mm: shrinker: fix shrinker_info teardown race with expansion
 2026-07-25 15:37 UTC 

[CVE-2026-64456][MODERATE 7.0] hwrng: virtio: clamp device-reported used.len at copy_data()
 2026-07-25 15:36 UTC 

[CVE-2026-64288][MODERATE REGULAR] KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB
 2026-07-25 15:33 UTC 

[CVE-2026-64330][MODERATE REGULAR] usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
 2026-07-25 15:31 UTC 

[CVE-2026-64322][MODERATE 7.0] udf: validate sparing table length as an entry count, not a byte count
 2026-07-25 15:27 UTC 

[CVE-2026-64512][LOW] Revert "ACPI: CPPC: Use access_width over bit_width for system memory accesses" This reverts commit 4949aff which is
 2026-07-25 15:23 UTC 

[CVE-2026-64411][MODERATE REGULAR] netfilter: ebtables: terminate table name before find_table_lock()
 2026-07-25 15:19 UTC 

[CVE-2026-64514][LOW] userfaultfd: gate must_wait writability check on pte_present() [ Upstream
 2026-07-25 15:14 UTC 

[CVE-2026-64483][IMPORTANT] ALSA: firewire: isight: bound the sample count to the packet payload
 2026-07-25 15:11 UTC 

[CVE-2026-64371][MODERATE 7.0] proc: protect ptrace_may_access() with exec_update_lock (part 1) [ Upstream
 2026-07-25 15:07 UTC 

[CVE-2026-64366][IMPORTANT] HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
 2026-07-25 15:03 UTC 

[CVE-2026-64380][MODERATE 7.0] smb: client: harden POSIX SID length parsing [ Upstream
 2026-07-25 14:59 UTC 

[CVE-2026-64476][LOW] vfio/pci: Latch disable_idle_d3 per device [ Upstream
 2026-07-25 14:55 UTC 

[CVE-2026-64280][MODERATE 7.0] fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
 2026-07-25 14:52 UTC 

[CVE-2026-64300][IMPORTANT] perf/aux: Fix page UAF in map_range()
 2026-07-25 14:52 UTC 

[CVE-2026-64374][MODERATE REGULAR] sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
 2026-07-25 14:50 UTC 

[CVE-2026-64297][LOW] module: decompress: check return value of module_extend_max_pages()
 2026-07-25 14:50 UTC 

[CVE-2026-64406][MODERATE REGULAR] Bluetooth: fix UAF in bt_accept_dequeue()
 2026-07-25 14:45 UTC 

[CVE-2026-64519][LOW] NFSD: Fix infinite loop in layout state revocation [ Upstream
 2026-07-25 14:42 UTC 

[CVE-2026-64513][LOW] KVM: x86: Unconditionally recompute CR8 intercept on PPR update [ Upstream
 2026-07-25 14:39 UTC 

[CVE-2026-64256][LOW] xfs: don't wrap around quota ids in dqiterate
 2026-07-25 14:36 UTC 

[CVE-2026-64436][MODERATE 7.0] net: af_key: initialize alg_key_len for IPComp states
 2026-07-25 14:33 UTC 

[CVE-2026-64306][MODERATE 7.0] crypto: drbg - Fix returning success on failure in CTR_DRBG
 2026-07-25 14:28 UTC 

[CVE-2026-64473][MODERATE 7.0] vfio: Remove device debugfs before releasing devres
 2026-07-25 14:26 UTC 

[CVE-2026-64426][MODERATE REGULAR] io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE
 2026-07-25 14:22 UTC 

[CVE-2026-64281][MODERATE REGULAR] svcrdma: wake sq waiters when the transport closes
 2026-07-25 14:19 UTC 

[CVE-2026-64286][MODERATE 7.0] KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
 2026-07-25 14:18 UTC 

[CVE-2026-64343][MODERATE REGULAR] USB: ldusb: fix use-after-free on disconnect race
 2026-07-25 14:18 UTC 

[CVE-2026-64324][MODERATE 7.0] udf: validate free block extents against the partition length
 2026-07-25 14:13 UTC 

[CVE-2026-64487][MODERATE REGULAR] ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
 2026-07-25 14:11 UTC 

[CVE-2026-64352][LOW] bpf: Allow LPM map access from sleepable BPF programs [ Upstream
 2026-07-25 14:07 UTC 

[CVE-2026-64448][MODERATE 7.0] smb: client: restrict implied bcc[0] exemption to responses without data area [ Upstream
 2026-07-25 14:03 UTC 

[CVE-2026-64430][LOW] NTB: epf: Avoid calling pci_irq_vector() from hardirq context
 2026-07-25 13:59 UTC 

[CVE-2026-64332][LOW] USB: ulpi: fix memory leak on registration failure
 2026-07-25 13:59 UTC 

[CVE-2026-64496][MODERATE REGULAR] iio: event: Fix event FIFO reset race
 2026-07-25 13:55 UTC 

[CVE-2026-64475][MODERATE 7.0] vfio/pci: Release the VGA arbiter client on register_device() failure [ Upstream
 2026-07-25 13:51 UTC 

[CVE-2026-64387][IMPORTANT] smb: client: fix query directory replay double-free
 2026-07-25 13:47 UTC 

[CVE-2026-64372][MODERATE 7.0] cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
 2026-07-25 13:43 UTC 

[CVE-2026-64338][MODERATE 7.0] USB: misc: uss720: unregister parport on probe failure
 2026-07-25 13:39 UTC 

[CVE-2026-64471][MODERATE 7.0] Bluetooth: btusb: fix use-after-free on registration failure
 2026-07-25 13:35 UTC 

page:  |  | latest

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox