public inbox for [email protected]
 help / color / mirror / Atom feed
This is experimental automated Linux kernel CVE triage research. Results are heuristic and may be incorrect. This site is not an official vendor advisory or severity source.
[CVE-2026-74614][MODERATE 7.0] vsock/virtio: read virtqueues under worker locks
 2026-08-22 18:01 UTC 

[CVE-2026-74630][IMPORTANT] ipv6: prevent in6_dev_get() from resurrecting inet6_dev
 2026-08-22 17:57 UTC 

[CVE-2026-74721][MODERATE 7.0] accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() [ Upstream
 2026-08-22 17:57 UTC 

[CVE-2026-74699][LOW] drm/xe: Fix memory leak in exec_queue_set_hang_replay_state() [ Upstream
 2026-08-22 17:56 UTC 

[CVE-2026-74689][MODERATE REGULAR] net/atm: fix slab-out-of-bounds read in vcc_setsockopt() [ Upstream
 2026-08-22 17:55 UTC 

[CVE-2026-74682][MODERATE 7.0] ALSA: usb-audio: fix OOB write on Type II inbound URBs
 2026-08-22 17:53 UTC 

[CVE-2026-74733][LOW] gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock [ Upstream
 2026-08-22 17:48 UTC 

[CVE-2026-74595][MODERATE 7.0] fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
 2026-08-22 17:45 UTC 

[CVE-2026-74690][MODERATE 7.0] s390/ism: Fix UAF of sba and ieq during ism_dev_exit() [ Upstream
 2026-08-22 17:41 UTC 

[CVE-2026-74732][LOW] drm/amd/display: Check for tg ops in dce110_set_avmute [ Upstream
 2026-08-22 17:37 UTC 

[CVE-2026-74589][MODERATE 7.0] bpf, sockmap: Fix sk_redir use-after-free in send verdict
 2026-08-22 17:37 UTC 

[CVE-2026-74709][LOW] xsk: clear metadata pointer when no timestamp is requested [ Upstream
 2026-08-22 17:30 UTC 

[CVE-2026-74678][LOW] net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
 2026-08-22 17:26 UTC 

[CVE-2026-74674][MODERATE 7.0] mm: fix incorrect flush address in direct page table reclaim
 2026-08-22 17:23 UTC 

[CVE-2026-74669][IMPORTANT] ipvs: clear IPv4 options after rebasing tunnel ICMP errors
 2026-08-22 17:21 UTC 

[CVE-2026-74730][MODERATE 7.0] NFS: Pin the 'struct nfs_server' during a FREE_STATEID call [ Upstream
 2026-08-22 17:19 UTC 

[CVE-2026-74718][LOW] devlink: fix net namespace reference leak in reload [ Upstream
 2026-08-22 17:14 UTC 

[CVE-2026-74728][LOW] xfs: handle NULL b_addr in xfs_buf_free [ Upstream
 2026-08-22 17:11 UTC 

[CVE-2026-74621][MODERATE 7.0] net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
 2026-08-22 17:08 UTC 

[CVE-2026-74624][MODERATE 7.0] netfilter: nf_conntrack: defer invalid log until after unlock
 2026-08-22 17:04 UTC 

[CVE-2026-74611][IMPORTANT] tls: rx: restore msg_iter before TLS 1.3 optimistic retry
 2026-08-22 17:00 UTC 

[CVE-2026-74636][LOW] tracing: Fix race between update_event_fields and, event_define_fields
 2026-08-22 16:57 UTC 

[CVE-2026-74713][MODERATE REGULAR] vhost_iotlb: bound map allocation in add_range [ Upstream
 2026-08-22 16:54 UTC 

[CVE-2026-74663][LOW] net/sched: reject overly deep qdisc hierarchies
 2026-08-22 16:51 UTC 

[CVE-2026-74620][MODERATE 7.0] net/sched: act_gact, act_police: range check the fallback control action
 2026-08-22 16:49 UTC 

[CVE-2026-74704][MODERATE REGULAR] net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter [ Upstream
 2026-08-22 16:45 UTC 

[CVE-2026-74612][MODERATE 7.0] veth: fix skb length accounting after XDP frag adjustment
 2026-08-22 16:41 UTC 

[CVE-2026-74659][MODERATE REGULAR] net: bridge: mrp: fix uninitialised bytes on the wire
 2026-08-22 16:37 UTC 

[CVE-2026-74712][MODERATE 7.0] vdpa/mlx5: Fix buffer length in create_direct_keys() [ Upstream
 2026-08-22 16:37 UTC 

[CVE-2026-74725][MODERATE 7.0] enic: fix tx_hang_reset use-after-free on device removal [ Upstream
 2026-08-22 16:35 UTC 

[CVE-2026-74633][LOW] tracing: Fix NULL pointer dereference in module event cache removal
 2026-08-22 16:31 UTC 

[CVE-2026-74617][MODERATE REGULAR] dibs: initialise dibs->lock in dibs_dev_alloc()
 2026-08-22 16:30 UTC 

[CVE-2026-74686][LOW] rqspinlock: Reset tail when preserving queue on deadlock [ Upstream
 2026-08-22 16:28 UTC 

[CVE-2026-74664][LOW] net: openvswitch: reallocate update replies for mismatched IDs
 2026-08-22 16:26 UTC 

[CVE-2026-74594][MODERATE 7.0] sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
 2026-08-22 16:22 UTC 

[CVE-2026-74618][MODERATE REGULAR] binfmt_misc: don't warn when the mount is completed from another user namespace
 2026-08-22 16:18 UTC 

[CVE-2026-74675][MODERATE 7.0] vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
 2026-08-22 16:16 UTC 

[CVE-2026-74679][MODERATE REGULAR] usb: gadget: f_ncm: Use unsigned int for ndp_index
 2026-08-22 16:12 UTC 

[CVE-2026-74606][MODERATE 7.0] eventfs: Fix use-after-free in eventfs_remove_rec()
 2026-08-22 16:08 UTC 

[CVE-2026-74599][MODERATE REGULAR] mm/ptdump: always stabilise against page table freeing using init_mm
 2026-08-22 16:06 UTC 

[CVE-2026-74707][MODERATE 7.0] xsk: validate metadata when processing requests [ Upstream
 2026-08-22 16:02 UTC 

[CVE-2026-74720][MODERATE 7.0] bpf: Preserve pointer state for commuted arithmetic [ Upstream
 2026-08-22 15:58 UTC 

[CVE-2026-74634][MODERATE 7.0] ring-buffer: Prevent subbuf order change when resizing is disabled
 2026-08-22 15:54 UTC 

[CVE-2026-74653][LOW] serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
 2026-08-22 15:52 UTC 

[CVE-2026-74591][MODERATE 7.0] mm/filemap: __filemap_add_folio() restore index before retrying
 2026-08-22 15:46 UTC 

[CVE-2026-74584][MODERATE REGULAR] RDMA/bnxt_re: zero shared page before exposing to userspace
 2026-08-22 14:51 UTC 

[CVE-2026-74583][MODERATE 7.0] net/sched: cls_route: fix fastmap use-after-free on filter [ Upstream
 2026-08-21 17:08 UTC 

[CVE-2026-74581][MODERATE 7.0] net: ipv6: clear suppressed fib6 rule result
 2026-08-21 17:03 UTC 

[CVE-2026-74582][IMPORTANT] packet: use consistent hard_header_len in non-ring send paths
 2026-08-21 16:57 UTC 

[CVE-2026-74580][MODERATE 7.0] vhost: reset the vring metadata cache on vring reconfiguration
 2026-08-21 16:53 UTC 

[CVE-2026-74579][LOW] netfilter: nft_payload: fix mask build for partial field offload [ Upstream
 2026-08-17  5:51 UTC 

[CVE-2026-72054][IMPORTANT] net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
 2026-08-16 13:21 UTC 

[CVE-2026-74346][MODERATE REGULAR] RDMA/irdma: Fix OOB read during CQ MR registration [ Upstream
 2026-08-16 13:16 UTC 

[CVE-2026-72398][IMPORTANT] sctp: add INIT verification after cookie unpacking [ Upstream
 2026-08-16 13:12 UTC 

[CVE-2026-72363][MODERATE REGULAR] netfs: Fix folio state after ENOMEM whilst under writeback iteration [ Upstream
 2026-08-16 13:09 UTC 

[CVE-2026-72102][MODERATE 7.0] dm_early_create: fix freeing used table on dm_resume failure
 2026-08-16 13:07 UTC 

[CVE-2026-72348][IMPORTANT] netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop [ Upstream
 2026-08-16 13:03 UTC 

[CVE-2026-72091][MODERATE REGULAR] accel/amdxdna: reject user command submission without a command BO commit 261c1fe3327ad24508f54552c6366e3e4db82c15 upstream
 2026-08-16 12:59 UTC 

[CVE-2026-72242][MODERATE 7.0] selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() [ Upstream
 2026-08-16 12:59 UTC 

[CVE-2026-72100][LOW] dm-integrity: fix a bug if the bio is out of limits
 2026-08-16 12:55 UTC 

[CVE-2026-72286][MODERATE 7.0] KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
 2026-08-16 12:51 UTC 

[CVE-2026-72101][MODERATE REGULAR] dm-integrity: fix leaking uninitialized kernel memory [ Upstream
 2026-08-16 12:47 UTC 

[CVE-2026-72298][IMPORTANT] net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
 2026-08-16 12:43 UTC 

[CVE-2026-72253][MODERATE 7.0] netfilter: nf_conntrack_sip: validate skb_dst() before accessing it [ Upstream
 2026-08-16 12:38 UTC 

[CVE-2026-74267][MODERATE 7.0] net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen [ Upstream
 2026-08-16 12:35 UTC 

[CVE-2026-72256][MODERATE REGULAR] netfilter: xt_cluster: reject template conntracks in hash match
 2026-08-16 12:30 UTC 

[CVE-2026-72424][LOW] rtc: msc313: fix NULL deref in shared IRQ handler at probe [ Upstream
 2026-08-16 12:25 UTC 

[CVE-2026-74377][MODERATE 7.0] RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path [ Upstream
 2026-08-16 12:25 UTC 

[CVE-2026-72407][MODERATE 7.0] geneve: validate inner network offset in geneve_gro_complete() [ Upstream
 2026-08-16 12:22 UTC 

[CVE-2026-72480][MODERATE REGULAR] iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling [ Upstream
 2026-08-16 12:20 UTC 

[CVE-2026-72325][MODERATE REGULAR] perf/x86/amd/core: Avoid enabling BRS from the SVM reload path [ Upstream
 2026-08-16 12:20 UTC 

[CVE-2026-74283][IMPORTANT] tipc: require net admin for TIPCv2 netlink mutators [ Upstream
 2026-08-16 12:17 UTC 

[CVE-2026-72377][MODERATE REGULAR] afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints [ Upstream
 2026-08-16 12:13 UTC 

[CVE-2026-72142][LOW] i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) [ Upstream
 2026-08-16 12:12 UTC 

[CVE-2026-72243][MODERATE 7.0] selinux: check connect-related permissions on TCP Fast Open
 2026-08-16 12:08 UTC 

[CVE-2026-72118][LOW] can: bcm: fix CAN frame rx/tx statistics
 2026-08-16 12:05 UTC 

[CVE-2026-72038][LOW] net: liquidio: fix BAR resource leak on PF number failure commit c63ee62a3c4ac1a1542f4c1a4b87e2f41df5a496 upstream
 2026-08-16 12:01 UTC 

[CVE-2026-72240][LOW] mfd: sm501: Fix reference leak on failed device registration
 2026-08-16 12:01 UTC 

[CVE-2026-72251][IMPORTANT] netfilter: nf_nat_sip: reload possible stale data pointer
 2026-08-16 11:57 UTC 

[CVE-2026-72452][MODERATE 7.0] drm/i915: clear CRTC color blob pointers after dropping refs [ Upstream
 2026-08-16 11:52 UTC 

[CVE-2026-74300][MODERATE REGULAR] Bluetooth: hci: validate codec capability element length [ Upstream
 2026-08-16 11:51 UTC 

[CVE-2026-72135][MODERATE 7.0] tpm: Make the TPM character devices non-seekable
 2026-08-16 11:47 UTC 

[CVE-2026-72446][IMPORTANT] ALSA: usb-audio: qcom: reject stream disable with no active interface [ Upstream
 2026-08-16 11:43 UTC 

[CVE-2026-72445][LOW] ALSA: usb-audio: qcom: clear opened when stream enable fails [ Upstream
 2026-08-16 11:43 UTC 

[CVE-2026-74375][LOW] md/raid1,raid10: fix deadlock in read error recovery path [ Upstream
 2026-08-16 11:42 UTC 

[CVE-2026-74347][MODERATE 7.0] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount [ Upstream
 2026-08-16 11:40 UTC 

[CVE-2026-74345][IMPORTANT] RDMA/siw: Fix endpoint/socket association handling [ Upstream
 2026-08-16 11:36 UTC 

[CVE-2026-72404][MODERATE 7.0] tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy() [ Upstream
 2026-08-16 11:33 UTC 

[CVE-2026-74301][LOW] Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path [ Upstream
 2026-08-16 11:29 UTC 

[CVE-2026-72254][LOW] netfilter: nft_fib: reject fib expression on the netdev egress hook [ Upstream
 2026-08-16 11:26 UTC 

[CVE-2026-74362][LOW] ext2: fix ignored return value of generic_write_sync() [ Upstream
 2026-08-16 11:22 UTC 

[CVE-2026-74387][MODERATE REGULAR] ALSA: seq: midi: Serialize output teardown with event_input [ Upstream
 2026-08-16 11:22 UTC 

[CVE-2026-72178][LOW] mm/damon/core: always put unsuccessfully committed target pids
 2026-08-16 11:19 UTC 

[CVE-2026-74430][MODERATE 7.0] rxrpc: Fix ACKALL packet handling
 2026-08-16 11:17 UTC 

[CVE-2026-72356][MODERATE REGULAR] cifs: Fix missing credit release on failure in cifs_issue_read() [ Upstream
 2026-08-16 11:15 UTC 

[CVE-2026-68469][LOW] wifi: mwifiex: fix permanently busy scans after multiple roam iterations
 2026-08-16 11:13 UTC 

[CVE-2026-72237][MODERATE REGULAR] perf/x86/amd/brs: Fix kernel address leakage
 2026-08-16 11:09 UTC 

[CVE-2026-72061][IMPORTANT] net: sit: require CAP_NET_ADMIN in the device netns for changelink
 2026-08-16 11:06 UTC 

[CVE-2026-72432][LOW] tpm_crb: Check ACPI_COMPANION() against NULL during probe [ Upstream
 2026-08-16 11:02 UTC 

[CVE-2026-74379][LOW] dax/kmem: account for partial discontiguous resource upon removal [ Upstream
 2026-08-16 11:00 UTC 

[CVE-2026-72143][LOW] platform/x86: ISST: Restore SST-PP control to all domains
 2026-08-16 10:56 UTC 

[CVE-2026-72400][MODERATE REGULAR] seg6: validate SRH length before reading fixed fields [ Upstream
 2026-08-16 10:54 UTC 

[CVE-2026-72130][MODERATE 7.0] nvmet-auth: reject short AUTH_RECEIVE buffers [ Upstream
 2026-08-16 10:49 UTC 

[CVE-2026-72024][MODERATE REGULAR] mac802154: remove interfaces with RCU list deletion
 2026-08-16 10:45 UTC 

[CVE-2026-72068][LOW] posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
 2026-08-16 10:41 UTC 

[CVE-2026-72275][LOW] fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
 2026-08-16 10:37 UTC 

[CVE-2026-72266][LOW] fbdev: vesafb: fix memory leak in vesafb_probe()
 2026-08-16 10:37 UTC 

[CVE-2026-74317][MODERATE 7.0] ixgbe: do not configure xps for XDP queues [ Upstream
 2026-08-16 10:34 UTC 

[CVE-2026-72308][LOW] mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
 2026-08-16 10:31 UTC 

[CVE-2026-74314][MODERATE 7.0] bpf: Cancel special fields on map value recycle [ Upstream
 2026-08-16 10:28 UTC 

[CVE-2026-74376][LOW] md/raid10: reset read_slot when reusing r10bio for discard [ Upstream
 2026-08-16 10:25 UTC 

[CVE-2026-74288][MODERATE REGULAR] net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). [ Upstream
 2026-08-16 10:21 UTC 

[CVE-2026-72495][MODERATE REGULAR] RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
 2026-08-16 10:17 UTC 

[CVE-2026-74268][MODERATE 7.0] tcp: clear sock_ops cb flags before force-closing a child socket [ Upstream
 2026-08-16 10:15 UTC 

[CVE-2026-74425][MODERATE REGULAR] afs: handle CB.InitCallBackState3 requests without a server record
 2026-08-16 10:12 UTC 

[CVE-2026-72034][MODERATE REGULAR] fhandle: reject detached mounts in capable_wrt_mount()
 2026-08-16 10:10 UTC 

[CVE-2026-72157][MODERATE 7.0] net: thunderbolt: Fix frags[] overflow by bounding frame_count
 2026-08-16 10:07 UTC 

[CVE-2026-72037][LOW] net: lan743x: Initialize eth_syslock spinlock before use commit 39139b1c1c2b614096519b526112c726adb12ff0 upstream
 2026-08-16 10:03 UTC 

[CVE-2026-72436][MODERATE 7.0] netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types [ Upstream
 2026-08-16 10:01 UTC 

[CVE-2026-72073][MODERATE 7.0] mmc: vub300: fix use-after-free on probe failure [ Upstream
 2026-08-16 10:01 UTC 

[CVE-2026-72365][MODERATE REGULAR] netfs: Fix writethrough to use collection offload [ Upstream
 2026-08-16  9:58 UTC 

[CVE-2026-74282][MODERATE REGULAR] tipc: prevent snt_unacked underflow on CONN_ACK [ Upstream
 2026-08-16  9:56 UTC 

[CVE-2026-72381][MODERATE 7.0] ksmbd: fix use-after-free of fp->owner.name in durable handle owner check [ Upstream
 2026-08-16  9:53 UTC 

[CVE-2026-72023][LOW] octeontx2-pf: fix SQB pointer leak on init failure [ Upstream
 2026-08-16  9:52 UTC 

[CVE-2026-72410][LOW] octeontx2-af: Validate NIX maximum LFs correctly [ Upstream
 2026-08-16  9:49 UTC 

[CVE-2026-72313][LOW] drm/fb-helper: Only consider active CRTCs for vblank sync [ Upstream
 2026-08-16  9:46 UTC 

[CVE-2026-72053][MODERATE 7.0] net: ipip: require CAP_NET_ADMIN in the device netns for changelink
 2026-08-16  9:44 UTC 

[CVE-2026-72501][MODERATE REGULAR] RDMA/bnxt_re: Initialize dpi variable to zero
 2026-08-16  9:40 UTC 

[CVE-2026-74420][MODERATE REGULAR] drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges [ Upstream
 2026-08-16  9:40 UTC 

[CVE-2026-72350][LOW] netfilter: xt_u32: reject invalid shift counts [ Upstream
 2026-08-16  9:39 UTC 

[CVE-2026-72366][LOW] netfs: Fix netfs_create_write_req() to handle async cache object creation [ Upstream
 2026-08-16  9:35 UTC 

[CVE-2026-72402][MODERATE REGULAR] bpf: Mask pseudo pointer values in verifier logs [ Upstream
 2026-08-16  9:33 UTC 

[CVE-2026-74275][MODERATE 7.0] cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach() [ Upstream
 2026-08-16  9:31 UTC 

[CVE-2026-72217][IMPORTANT] SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
 2026-08-16  9:29 UTC 

[CVE-2026-74332][MODERATE REGULAR] ASoC: amd: acp-sdw-sof: Bound DAI link iteration [ Upstream
 2026-08-16  9:27 UTC 

[CVE-2026-72262][IMPORTANT] ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
 2026-08-16  9:24 UTC 

[CVE-2026-72248][IMPORTANT] netfilter: flowtable: support IPIP tunnel with direct xmit
 2026-08-16  9:20 UTC 

[CVE-2026-72036][MODERATE REGULAR] net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
 2026-08-16  9:19 UTC 

[CVE-2026-72369][MODERATE REGULAR] minix: avoid overflow in bitmap block count calculation [ Upstream
 2026-08-16  9:15 UTC 

[CVE-2026-72388][MODERATE REGULAR] drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock [ Upstream
 2026-08-16  9:15 UTC 

[CVE-2026-74397][LOW] IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier [ Upstream
 2026-08-16  9:15 UTC 

[CVE-2026-74263][LOW] net: wwan: t7xx: check skb_clone in control TX [ Upstream
 2026-08-16  9:12 UTC 

[CVE-2026-68458][MODERATE 7.0] binder: cache secctx size before release zeroes it [ Upstream
 2026-08-16  9:12 UTC 

[CVE-2026-74292][MODERATE REGULAR] ASoC: tegra: tegra210_ahub: Validate written enum value [ Upstream
 2026-08-16  9:12 UTC 

[CVE-2026-72373][MODERATE REGULAR] afs: Fix missing NULL pointer check in afs_break_some_callbacks() [ Upstream
 2026-08-16  9:12 UTC 

[CVE-2026-72141][LOW] i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
 2026-08-16  9:08 UTC 

[CVE-2026-72326][LOW] net/sched: cake: reject overhead values that underflow length [ Upstream
 2026-08-16  9:06 UTC 

[CVE-2026-74396][LOW] RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure [ Upstream
 2026-08-16  9:03 UTC 

[CVE-2026-72367][MODERATE 7.0] iomap: guard io_size EOF trim against concurrent truncate underflow [ Upstream
 2026-08-16  9:00 UTC 

[CVE-2026-74363][MODERATE 7.0] bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs [ Upstream
 2026-08-16  8:58 UTC 

[CVE-2026-72305][MODERATE REGULAR] VDUSE: avoid leaking information to userspace [ Upstream
 2026-08-16  8:56 UTC 

[CVE-2026-74578][MODERATE 7.0] crypto: algif_skcipher - force synchronous processing on trees without ctx->state The AIO/async path in skcipher_recvmsg() passes the socket-wide ctx->iv directly into the skcipher request. After io_submit() the socket lock is dropped and the request is processed asynchronously, so a concurrent sendmsg(ALG_SET_IV) can overwrite ctx->iv and make the in-flight request run under an attacker-controlled IV. For CTR/stream modes this is IV/keystream reuse and lets an unprivileged user recover the plaintext of a concurrent operation. Snapshotting ctx->iv into per-request storage for the async path is not sufficient. For ciphers with statesize == 0 - which includes cbc and ctr - the MSG_MORE inter-chunk IV chaining is carried solely by the in-place req->iv writeback, which a snapshot redirects into per-request memory that af_alg_free_resources() releases on completion, silently producing wrong output. Writing the IV back from the completion callback instead is not possible either: that would require lock_sock() there, but the callback can run in softirq/atomic context, so it must not sleep. Make the operation synchronous instead, which removes both the IV race and any writeback race. This is equivalent to the upstream resolution,
 2026-08-16  8:53 UTC 

[CVE-2026-68479][MODERATE 7.0] Bluetooth: btrtl: validate firmware patch bounds
 2026-08-16  8:41 UTC 

[CVE-2026-72110][MODERATE 7.0] bpf,fork: wipe ->bpf_storage before bailouts that access it
 2026-08-16  8:37 UTC 

[CVE-2026-74431][MODERATE REGULAR] rxrpc: Fix potential infinite loop in rxrpc_recvmsg()
 2026-08-16  8:33 UTC 

[CVE-2026-72430][LOW] net/sched: act_ct: fix nf_connlabels leak on two error paths [ Upstream
 2026-08-16  8:31 UTC 

[CVE-2026-72321][LOW] ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer() [ Upstream
 2026-08-16  8:28 UTC 

[CVE-2026-72272][LOW] fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
 2026-08-16  8:25 UTC 

[CVE-2026-72362][MODERATE REGULAR] drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() [ Upstream
 2026-08-16  8:21 UTC 

[CVE-2026-74354][MODERATE 7.0] bpf: Take mmap_lock in zap_pages() [ Upstream
 2026-08-16  8:18 UTC 

[CVE-2026-72493][MODERATE 7.0] net: serialize netif_running() check in enqueue_to_backlog() [ Upstream
 2026-08-16  8:14 UTC 

[CVE-2026-72383][MODERATE 7.0] sctp: fix addr_wq_timer race in sctp_free_addr_wq() [ Upstream
 2026-08-16  8:11 UTC 

[CVE-2026-74338][LOW] bpf: Reject sleepable BPF_LSM_CGROUP programs at load time [ Upstream
 2026-08-16  8:08 UTC 

[CVE-2026-72345][MODERATE REGULAR] net/mlx5: LAG, Fix off-by-one in single-FDB error rollback [ Upstream
 2026-08-16  8:05 UTC 

[CVE-2026-72434][MODERATE 7.0] netfilter: ipset: make sure gc is properly stopped [ Upstream
 2026-08-16  8:05 UTC 

[CVE-2026-74361][MODERATE 7.0] nvme: fix FDP fdpcidx bounds check [ Upstream
 2026-08-16  8:05 UTC 

[CVE-2026-72492][MODERATE 7.0] ksmbd: fix use-after-free in same_client_has_lease() [ Upstream
 2026-08-16  8:01 UTC 

[CVE-2026-72423][MODERATE 7.0] bpf: Guard conntrack opts error writes [ Upstream
 2026-08-16  8:01 UTC 

[CVE-2026-72418][MODERATE REGULAR] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct [ Upstream
 2026-08-16  7:57 UTC 

[CVE-2026-72444][MODERATE 7.0] flow_dissector: check device type before reading ETH_ADDRS [ Upstream
 2026-08-16  7:55 UTC 

[CVE-2026-74435][MODERATE 7.0] rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
 2026-08-16  7:51 UTC 

[CVE-2026-74427][MODERATE 7.0] afs: Fix netns teardown to cancel the preallocation charger
 2026-08-16  7:49 UTC 

[CVE-2026-72439][LOW] md/raid10: fix writes_pending leak on write request failures [ Upstream
 2026-08-16  7:45 UTC 

[CVE-2026-68456][MODERATE REGULAR] usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() [ Upstream
 2026-08-16  7:42 UTC 

[CVE-2026-72040][LOW] ipmi: fix refcount leak in i_ipmi_request() [ Upstream commit a3f3859cecacb64f18fd446271ece9a3b3f2d4de ]
 2026-08-16  7:38 UTC 

[CVE-2026-72150][MODERATE 7.0] sunrpc: fix uninitialized xprt_create_args structure
 2026-08-16  7:38 UTC 

[CVE-2026-72173][LOW] fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
 2026-08-16  7:35 UTC 

[CVE-2026-72144][MODERATE REGULAR] platform/x86: dell-laptop: fix missing cleanups in init error path [ Upstream
 2026-08-16  7:34 UTC 

[CVE-2026-74308][LOW] ext4: fix kernel BUG in ext4_write_inline_data_end [ Upstream
 2026-08-16  7:32 UTC 

[CVE-2026-72103][MODERATE 7.0] dm: avoid leaking the caller's thread keyring via the table device file [ Upstream
 2026-08-16  7:28 UTC 

[CVE-2026-72099][MODERATE REGULAR] dm-integrity: don't increment hash_offset twice commit edf025f083854f80032b73a1aad69a3c90db236f upstream
 2026-08-16  7:25 UTC 

[CVE-2026-74428][MODERATE REGULAR] rxrpc: Fix double unlock in rxrpc_recvmsg()
 2026-08-16  7:23 UTC 

[CVE-2026-74408][MODERATE 7.0] wifi: ath9k: fix OOB access from firmware tx status queue ID [ Upstream
 2026-08-16  7:22 UTC 

[CVE-2026-72132][MODERATE 7.0] NFS: Charge unstable writes by request size, not folio size [ Upstream
 2026-08-16  7:18 UTC 

[CVE-2026-74410][MODERATE 7.0] wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer [ Upstream
 2026-08-16  7:14 UTC 

[CVE-2026-74255][MODERATE 7.0] tipc: fix UAF in tipc_l2_send_msg() [ Upstream
 2026-08-16  7:10 UTC 

[CVE-2026-72375][MODERATE 7.0] afs: Fix reinitialisation of the inode, in particular ->lock_work [ Upstream
 2026-08-16  7:06 UTC 

[CVE-2026-72020][MODERATE 7.0] ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
 2026-08-16  7:03 UTC 

[CVE-2026-72107][MODERATE 7.0] dm era: fix out-of-bounds memory access for non-zero start sector
 2026-08-16  6:59 UTC 

[CVE-2026-74326][LOW] wifi: mt76: mt7921: fix resource leak in probe error path [ Upstream
 2026-08-16  6:54 UTC 

[CVE-2026-74385][MODERATE 7.0] nvmet-tcp: check return value of nvmet_tcp_set_queue_sock [ Upstream
 2026-08-16  6:52 UTC 

[CVE-2026-74365][MODERATE 7.0] nvdimm/btt: Handle preemption in BTT lane acquisition [ Upstream
 2026-08-16  6:49 UTC 

[CVE-2026-72443][MODERATE 7.0] ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints [ Upstream
 2026-08-16  6:46 UTC 

[CVE-2026-72301][MODERATE 7.0] ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
 2026-08-16  6:42 UTC 

[CVE-2026-74422][MODERATE REGULAR] drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() [ Upstream
 2026-08-16  6:38 UTC 

[CVE-2026-72072][MODERATE 7.0] net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete commit de74d8fd10291763d97b218f09adcc7513c975e4 upstream
 2026-08-16  6:38 UTC 

[CVE-2026-72438][MODERATE REGULAR] md/raid10: fix writes_pending and barrier reference leaks on discard failures [ Upstream
 2026-08-16  6:36 UTC 

[CVE-2026-72319][IMPORTANT] ipvs: ensure inner headers in ICMP errors are in headroom [ Upstream
 2026-08-16  6:33 UTC 

[CVE-2026-74399][MODERATE REGULAR] evm: terminate and bound the evm_xattrs read buffer [ Upstream
 2026-08-16  6:29 UTC 

[CVE-2026-74429][MODERATE REGULAR] rxrpc: Fix the reception of a reply packet before data transmission
 2026-08-16  6:25 UTC 

page:  |  | latest

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox