public inbox for [email protected]
 help / color / mirror / Atom feed
This is experimental automated Linux kernel CVE triage research. Results are heuristic and may be incorrect. This site is not an official vendor advisory or severity source.
[CVE-2026-80670][MODERATE REGULAR] perf tools: Use perf_env__get_cpu_topology() in machine__resolve() [ Upstream
 2026-08-28  9:57 UTC 

[CVE-2026-80593][LOW] hwmon: (asus_atk0110) Check package count before accessing element
 2026-08-28  9:57 UTC 

[CVE-2026-80630][MODERATE 7.0] net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen [ Upstream
 2026-08-28  9:52 UTC 

[CVE-2026-80716][MODERATE 7.0] ALSA: pcm: wake linked drain waiters on unlink
 2026-08-28  9:47 UTC 

[CVE-2026-80663][MODERATE 7.0] tools/power/x86/intel-speed-select: Harden daemon pidfile open
 2026-08-28  9:42 UTC 

[CVE-2026-80721][MODERATE 7.0] Bluetooth: ISO: ensure no dangling hcon references in iso_conn [ Upstream
 2026-08-28  9:42 UTC 

[CVE-2026-80719][MODERATE REGULAR] mm: mglru: fix stale batch updates after memcg reparenting
 2026-08-28  9:38 UTC 

[CVE-2026-80723][MODERATE 7.0] of: reserved_mem: prevent OOB when too many dynamic regions are defined [ Upstream
 2026-08-28  9:36 UTC 

[CVE-2026-80704][LOW] drm/amd/display: use proper context for logging
 2026-08-28  9:34 UTC 

[CVE-2026-80703][MODERATE 7.0] drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
 2026-08-28  9:34 UTC 

[CVE-2026-80669][LOW] bpf: Disable xfrm_decode_session hook attachment [ Upstream
 2026-08-28  9:34 UTC 

[CVE-2026-80676][MODERATE 7.0] Drivers: hv: vmbus: use generic driver_override infrastructure [ Upstream
 2026-08-28  9:30 UTC 

[CVE-2026-80707][MODERATE REGULAR] can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
 2026-08-28  9:26 UTC 

[CVE-2026-80705][LOW] drm/amd/display: check if dml21_add_phantom_plane() is successful
 2026-08-28  9:21 UTC 

[CVE-2026-80675][MODERATE 7.0] libbpf: Reject non-exclusive metadata maps in the signed loader [ Upstream
 2026-08-28  9:21 UTC 

[CVE-2026-80717][MODERATE REGULAR] sctp: validate Adaptation Indication parameter length
 2026-08-28  9:19 UTC 

[CVE-2026-80692][MODERATE 7.0] Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks [ Upstream
 2026-08-28  9:17 UTC 

[CVE-2026-80698][MODERATE 7.0] dmaengine: idxd: fix double free of wq, engine, and group structs [ Upstream
 2026-08-28  9:13 UTC 

[CVE-2026-80678][MODERATE 7.0] i2c: imx: Fix slave registration race and error handling [ Upstream
 2026-08-28  9:10 UTC 

[CVE-2026-80603][MODERATE 7.0] netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
 2026-08-28  9:04 UTC 

[CVE-2026-80639][LOW] cxl/test: Fix __fortify_panic [ Upstream
 2026-08-28  9:01 UTC 

[CVE-2026-80622][MODERATE 7.0] char: tlclk: fix use-after-free in tlclk_cleanup() [ Upstream
 2026-08-28  9:01 UTC 

[CVE-2026-80634][MODERATE 7.0] netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag [ Upstream
 2026-08-28  8:57 UTC 

[CVE-2026-80624][MODERATE REGULAR] mfd: cs42l43: Sanity check firmware size [ Upstream
 2026-08-28  8:52 UTC 

[CVE-2026-80637][MODERATE REGULAR] netfilter: synproxy: fix unaligned memory access in timestamp adjustment [ Upstream
 2026-08-28  8:48 UTC 

[CVE-2026-80613][MODERATE 7.0] veth: fix NAPI leak in XDP enable error path [ Upstream
 2026-08-28  8:45 UTC 

[CVE-2026-80701][MODERATE REGULAR] drm/vmwgfx: enforce cursor size limits for MOB cursors
 2026-08-28  8:41 UTC 

[CVE-2026-80662][MODERATE REGULAR] cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size [ Upstream
 2026-08-28  8:38 UTC 

[CVE-2026-80602][MODERATE REGULAR] perf/x86/amd/lbr: Fix kernel address leakage
 2026-08-28  8:37 UTC 

[CVE-2026-80653][LOW] scsi: hisi_sas: Add slave_destroy interface for v3 hw [ Upstream
 2026-08-28  8:34 UTC 

[CVE-2026-80681][MODERATE 7.0] vxlan: re-fetch eth header after route_shortcircuit()
 2026-08-28  8:31 UTC 

[CVE-2026-80706][MODERATE 7.0] can: softing: fw_parse(): validate firmware record spans
 2026-08-28  8:25 UTC 

[CVE-2026-80641][LOW] wifi: wlcore: enable the right set of ciphers [ Upstream
 2026-08-28  8:21 UTC 

[CVE-2026-80688][LOW] riscv: drop __init from vec_check_unaligned_access_speed_all_cpus [ Upstream
 2026-08-28  8:21 UTC 

[CVE-2026-80657][LOW] accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer [ Upstream
 2026-08-28  8:21 UTC 

[CVE-2026-80691][MODERATE 7.0] scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE [ Upstream
 2026-08-28  8:20 UTC 

[CVE-2026-80710][MODERATE 7.0] s390/dasd: Fix undersized format-check buffer
 2026-08-28  8:18 UTC 

[CVE-2026-80611][LOW] ACPI: processor_idle: Mark LPI enter functions as __cpuidle [ Upstream
 2026-08-28  8:14 UTC 

[CVE-2026-80687][LOW] iommufd/viommu: Release the igroup lock on the vdevice_size error path
 2026-08-28  8:10 UTC 

[CVE-2026-80700][MODERATE 7.0] drm/vmwgfx: validate external BO copy bounds for both stride paths
 2026-08-28  8:07 UTC 

[CVE-2026-80640][LOW] cxl/fwctl: Fix __fortify_panic [ Upstream
 2026-08-28  8:03 UTC 

[CVE-2026-80652][LOW] crypto: ccp - Treat zero-length cert chain as query for blob lengths [ Upstream
 2026-08-28  8:03 UTC 

[CVE-2026-80715][LOW] igc: remove napi_synchronize() in igc_down() [ Upstream
 2026-08-28  7:58 UTC 

[CVE-2026-80606][LOW] drm/xe/userptr: Hold notifier_lock for write on inject test path [ Upstream
 2026-08-28  7:54 UTC 

[CVE-2026-80683][MODERATE 7.0] Bluetooth: SCO: give the socket its own sco_conn reference
 2026-08-28  7:51 UTC 

[CVE-2026-80590][IMPORTANT] inet: frags: strip GSO state from fragments before reassembly
 2026-08-28  6:47 UTC 

[CVE-2026-80544][MODERATE 7.0] s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing
 2026-08-26 18:09 UTC 

[CVE-2026-80585][MODERATE 7.0] mptcp: fastopen: only mark MPTFO subflows with SYN data
 2026-08-26 18:07 UTC 

[CVE-2026-74744][IMPORTANT] ipvlan: inherit needed_headroom and needed_tailroom from phy_dev [ Upstream
 2026-08-26 18:03 UTC 

[CVE-2026-80529][MODERATE REGULAR] xfs: don't swallow dquot recovery verification errors
 2026-08-26 17:58 UTC 

[CVE-2026-80579][MODERATE 7.0] fbdev: clear fb_info->mode before deleting a videomode
 2026-08-26 17:58 UTC 

[CVE-2026-74753][MODERATE 7.0] perf: Reject exited events as group leaders [ Upstream
 2026-08-26 17:55 UTC 

[CVE-2026-80576][MODERATE 7.0] drm/amdgpu: reject oversized IBs with per-ring packet limits
 2026-08-26 17:54 UTC 

[CVE-2026-80535][LOW] xfs: don't double-lock when deleting a self-referential directory
 2026-08-26 17:53 UTC 

[CVE-2026-80530][MODERATE 7.0] xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
 2026-08-26 17:53 UTC 

[CVE-2026-80538][MODERATE REGULAR] xfs: propagate errors from xfs_rtginode_load
 2026-08-26 17:53 UTC 

[CVE-2026-80561][MODERATE 7.0] libceph: fix multiple unsafe decodes in decode_locker()
 2026-08-26 17:53 UTC 

[CVE-2026-80577][LOW] drm/panthor: skip zero-sized firmware sections
 2026-08-26 17:49 UTC 

[CVE-2026-80557][MODERATE 7.0] libceph: fix OOB read in decode_watchers() via missing bounds check
 2026-08-26 17:49 UTC 

[CVE-2026-80548][MODERATE 7.0] s390/vfio_ccw: Selectively expand io_mutex
 2026-08-26 17:45 UTC 

[CVE-2026-74752][IMPORTANT] sctp: validate cookie AUTH state before use [ Upstream
 2026-08-26 17:41 UTC 

[CVE-2026-80541][MODERATE REGULAR] drm/amdgpu: validate GEM_CREATE domain combinations
 2026-08-26 17:37 UTC 

[CVE-2026-80558][MODERATE 7.0] libceph: Avoid using invalid osd indices from primary_temp
 2026-08-26 17:37 UTC 

[CVE-2026-74748][MODERATE 7.0] netfilter: ipset: fix refcount race between list:set GC and swap [ Upstream
 2026-08-26 17:32 UTC 

[CVE-2026-74747][MODERATE REGULAR] ipvs: revalidate ihl to prevent out-of-bounds access [ Upstream
 2026-08-26 17:28 UTC 

[CVE-2026-74735][MODERATE REGULAR] l2tp: fix tunnel and session refcount leak on seq_file release [ Upstream
 2026-08-26 17:27 UTC 

[CVE-2026-80580][MODERATE 7.0] fbdev: bound mode sysfs output to the sysfs buffer
 2026-08-26 17:21 UTC 

[CVE-2026-80564][LOW] gve: fix NULL dereference due to missing ptp adjfine
 2026-08-26 17:16 UTC 

[CVE-2026-80552][MODERATE 7.0] s390/vfio_ccw: Ensure index for read/write regions are within range
 2026-08-26 17:14 UTC 

[CVE-2026-80584][MODERATE 7.0] s390/qeth: validate user buffer length in SNMP and ARP query ioctls
 2026-08-26 17:09 UTC 

[CVE-2026-80536][MODERATE 7.0] xfs: bounds-check buffer log item's dirty bitmap
 2026-08-26 17:04 UTC 

[CVE-2026-80547][MODERATE 7.0] s390/vfio_ccw: Implement a crw lock
 2026-08-26 17:04 UTC 

[CVE-2026-74738][MODERATE REGULAR] regmap: sdw-mbq: don't call an unset readable_reg callback [ Upstream
 2026-08-26 17:00 UTC 

[CVE-2026-80523][LOW] clk: spacemit: k3: set hdma clock as critical [ Upstream
 2026-08-26 16:57 UTC 

[CVE-2026-80542][MODERATE REGULAR] drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
 2026-08-26 16:55 UTC 

[CVE-2026-80527][MODERATE REGULAR] ceph: fix hanging __ceph_get_caps() with stale mds_wanted [ Upstream
 2026-08-26 16:55 UTC 

[CVE-2026-74740][MODERATE REGULAR] net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain [ Upstream
 2026-08-26 16:50 UTC 

[CVE-2026-74745][LOW] eth: bnxt: avoid deadlock when canceling IRQ affinity notifier [ Upstream
 2026-08-26 16:47 UTC 

[CVE-2026-80531][MODERATE 7.0] xfs: avoid UAF on sc->tempip in xrep_tempfile_create
 2026-08-26 16:47 UTC 

[CVE-2026-74736][MODERATE REGULAR] net/sched: cls_bpf: reject dev-bound programs bound to a different device [ Upstream
 2026-08-26 16:45 UTC 

[CVE-2026-74739][MODERATE 7.0] net/sched: cls_u32: skip hash tables in u32_bind_class() [ Upstream
 2026-08-26 16:42 UTC 

[CVE-2026-80589][MODERATE 7.0] block: stop the timeout timer when releasing a never added disk [ Upstream
 2026-08-26 16:37 UTC 

[CVE-2026-74754][LOW] scsi: core: pair EH runtime PM get and put [ Upstream
 2026-08-26 16:32 UTC 

[CVE-2026-80522][IMPORTANT] crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() [ Upstream
 2026-08-26 16:28 UTC 

[CVE-2026-80540][MODERATE 7.0] drm/amdgpu: Fix UVD decode image min size calculation
 2026-08-26 16:24 UTC 

[CVE-2026-80586][IMPORTANT] mptcp: options: reset DSS fields in case of unexpected size
 2026-08-26 16:24 UTC 

[CVE-2026-80537][MODERATE 7.0] xfs: fix off-by-one in rtrefcount btree root level validation
 2026-08-26 16:19 UTC 

[CVE-2026-80571][MODERATE 7.0] powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
 2026-08-26 16:18 UTC 

[CVE-2026-80572][MODERATE 7.0] Input: byd - synchronize timer deletion before freeing private data
 2026-08-26 16:14 UTC 

[CVE-2026-80534][LOW] xfs: fix ilock leak on error in xfs_dq_get_next_id
 2026-08-26 16:11 UTC 

[CVE-2026-80582][MODERATE 7.0] drm/shmem_helper: Check VMA boundaries for PMD mappings
 2026-08-26 16:07 UTC 

[CVE-2026-80551][MODERATE 7.0] s390/vfio_ccw: Ensure first IDAW remains constant
 2026-08-26 16:05 UTC 

[CVE-2026-80521][MODERATE 7.0] af_unix: Unlink scc_entry in unix_del_edge(). [ Upstream
 2026-08-26 16:02 UTC 

[CVE-2026-80588][MODERATE REGULAR] mptcp: reclaim forward-allocated memory on RX path errors
 2026-08-26 16:00 UTC 

[CVE-2026-80532][LOW] xfs: fix another iunlink infinite loop bug in online fsck
 2026-08-26 15:59 UTC 

[CVE-2026-80587][MODERATE REGULAR] mptcp: avoid combining some incoming suboptions
 2026-08-26 15:55 UTC 

[CVE-2026-80554][MODERATE 7.0] s390/vfio_ccw: Limit the number of channel program segments
 2026-08-26 15:51 UTC 

[CVE-2026-80525][LOW] ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
 2026-08-26 15:47 UTC 

[CVE-2026-74734][LOW] firewire: ohci: fix NULL pointer dereference in ar_context_release [ Upstream
 2026-08-26 15:44 UTC 

[CVE-2026-80549][LOW] s390/vfio_ccw: Move cp cleanup out of not operational
 2026-08-26 15:42 UTC 

[CVE-2026-80539][MODERATE REGULAR] drm/amdgpu: disallow multiple FENCE chunks in one submit
 2026-08-26 15:38 UTC 

[CVE-2026-80555][MODERATE REGULAR] s390/vfio_ccw: Free all memory if cp_init() fails
 2026-08-26 15:38 UTC 

[CVE-2026-80578][MODERATE REGULAR] fbdev: core: Fix pointer desynchronization in fb_io_read()
 2026-08-26 15:35 UTC 

[CVE-2026-80574][MODERATE 7.0] Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
 2026-08-26 15:31 UTC 

[CVE-2026-80533][LOW] xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
 2026-08-26 15:24 UTC 

[CVE-2026-74737][MODERATE 7.0] net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG [ Upstream
 2026-08-26 15:20 UTC 

[CVE-2026-74742][MODERATE REGULAR] veth: fix queue index used to wake the peer txq in veth_poll [ Upstream
 2026-08-26 15:16 UTC 

[CVE-2026-80528][MODERATE 7.0] ceph: avoid fs reclaim while using current->journal_info [ Upstream
 2026-08-26 15:14 UTC 

[CVE-2026-74743][IMPORTANT] macvlan: inherit needed_headroom and needed_tailroom from lowerdev [ Upstream
 2026-08-26 15:09 UTC 

[CVE-2026-80550][MODERATE 7.0] s390/vfio_ccw: Fix out of bounds check on CCW array
 2026-08-26 15:04 UTC 

[CVE-2026-80553][MODERATE 7.0] s390/vfio_ccw: Cancel existing workqueues
 2026-08-26 15:00 UTC 

[CVE-2026-74746][IMPORTANT] netfilter: flowtable: publish GC-visible tuple last [ Upstream
 2026-08-26 14:56 UTC 

[CVE-2026-80581][LOW] ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
 2026-08-26 14:50 UTC 

[CVE-2026-74751][MODERATE REGULAR] riscv: lib: Fix ZBB strnlen reading past count boundary [ Upstream
 2026-08-26 14:43 UTC 

[CVE-2026-74705][MODERATE 7.0] udp: fix potential use-after-free in tunnel segmentation [ Upstream
 2026-08-22 22:32 UTC 

[CVE-2026-74654][LOW] serial: 8250_dma: Clear stale RX state on shutdown
 2026-08-22 22:27 UTC 

[CVE-2026-74676][LOW] vt: add permission check for KDSKBMETA ioctl
 2026-08-22 22:23 UTC 

[CVE-2026-74658][MODERATE REGULAR] futex: Prevent robust futex exit race some more
 2026-08-22 22:20 UTC 

[CVE-2026-74586][IMPORTANT] sctp: clear new_transport when removing a peer
 2026-08-22 22:16 UTC 

[CVE-2026-74631][MODERATE 7.0] net: smc: fix splice entry lifetime imbalance in smc_rx_splice
 2026-08-22 22:11 UTC 

[CVE-2026-74640][IMPORTANT] ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
 2026-08-22 22:07 UTC 

[CVE-2026-74639][MODERATE 7.0] ALSA: us144mkii: re-anchor capture URBs on resubmission
 2026-08-22 22:04 UTC 

[CVE-2026-74670][MODERATE 7.0] ipvs: stop estimator after disabled calc phase
 2026-08-22 22:02 UTC 

[CVE-2026-74673][MODERATE REGULAR] Input: evdev - fix information leak in evdev_pass_values()
 2026-08-22 22:00 UTC 

[CVE-2026-74719][MODERATE REGULAR] net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() [ Upstream
 2026-08-22 21:57 UTC 

[CVE-2026-74629][MODERATE 7.0] net/dibs: Correct freeing of dmb_clientid_arr
 2026-08-22 21:53 UTC 

[CVE-2026-74637][MODERATE 7.0] perf/core: Fix group leader use-after-free after sibling detach
 2026-08-22 21:51 UTC 

[CVE-2026-74585][MODERATE 7.0] thunderbolt: Bound the DROM dual link port number before indexing sw->ports
 2026-08-22 21:47 UTC 

[CVE-2026-74701][MODERATE REGULAR] net/openvswitch: check Ethernet header length in key_extract() [ Upstream
 2026-08-22 21:43 UTC 

[CVE-2026-74711][MODERATE REGULAR] hwmon: (pmbus) Fix type confusion in notification logic [ Upstream
 2026-08-22 21:39 UTC 

[CVE-2026-74724][MODERATE 7.0] ipvs: avoid out-of-bounds write in ip_vs_nat_icmp [ Upstream
 2026-08-22 21:37 UTC 

[CVE-2026-74695][MODERATE 7.0] netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() [ Upstream
 2026-08-22 21:35 UTC 

[CVE-2026-74610][MODERATE 7.0] tls: don't leave a full plaintext sk_msg ring unpushed
 2026-08-22 21:32 UTC 

[CVE-2026-74623][LOW] net: atlantic: free stranded TX buffers on ring deinit
 2026-08-22 21:30 UTC 

[CVE-2026-74625][MODERATE 7.0] netfilter: bridge: release template ct on non-IP path
 2026-08-22 21:26 UTC 

[CVE-2026-74698][LOW] net/mlx5e: fix BQL reset on SQ re-activation [ Upstream
 2026-08-22 21:22 UTC 

[CVE-2026-74622][LOW] net: atlantic: free RX pages of consumed but not refilled buffers
 2026-08-22 21:22 UTC 

[CVE-2026-74655][MODERATE 7.0] serial: qcom-geni: fix TX DMA buffer flush
 2026-08-22 21:18 UTC 

[CVE-2026-74688][MODERATE 7.0] sctp: clear control chunk transport if it is being removed [ Upstream
 2026-08-22 21:14 UTC 

[CVE-2026-74681][MODERATE 7.0] usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
 2026-08-22 21:10 UTC 

[CVE-2026-74700][MODERATE 7.0] net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers [ Upstream
 2026-08-22 21:08 UTC 

[CVE-2026-74716][MODERATE REGULAR] accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages() [ Upstream
 2026-08-22 21:04 UTC 

[CVE-2026-74613][MODERATE 7.0] vsock/virtio: avoid refilling the RX queue after teardown
 2026-08-22 21:04 UTC 

[CVE-2026-74604][MODERATE 7.0] Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
 2026-08-22 20:59 UTC 

[CVE-2026-74608][MODERATE 7.0] smb: client: Fix use-after-free in cifs_try_adding_channels()
 2026-08-22 20:56 UTC 

[CVE-2026-74667][MODERATE 7.0] net/packet: reset the MAC header on the packet-socket transmit path
 2026-08-22 20:51 UTC 

[CVE-2026-74615][IMPORTANT] vxlan: do not arm the ageing timer on a device that is down
 2026-08-22 20:47 UTC 

[CVE-2026-74723][MODERATE REGULAR] btrfs: lzo: reject inline extents without valid headers [ Upstream
 2026-08-22 20:42 UTC 

[CVE-2026-74619][MODERATE REGULAR] ovl: don't warn when the mount is completed from another user namespace
 2026-08-22 20:39 UTC 

[CVE-2026-74588][IMPORTANT] sctp: keep chunk->transport in step with the list it is queued on
 2026-08-22 20:36 UTC 

[CVE-2026-74684][MODERATE 7.0] net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
 2026-08-22 20:33 UTC 

[CVE-2026-74632][MODERATE 7.0] mm/huge_memory: fix huge_zero_pfn race
 2026-08-22 20:30 UTC 

[CVE-2026-74726][MODERATE REGULAR] bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor [ Upstream
 2026-08-22 20:26 UTC 

[CVE-2026-74665][MODERATE 7.0] net: fix skb length accounting after generic XDP frag adjustment
 2026-08-22 20:22 UTC 

[CVE-2026-74635][MODERATE REGULAR] fbdev: bitblit: bound-check glyph index in bit_cursor()
 2026-08-22 20:20 UTC 

[CVE-2026-74641][IMPORTANT] ALSA: usx2y: bound the hwdep mmap fault offset
 2026-08-22 20:16 UTC 

[CVE-2026-74677][MODERATE 7.0] net: usb: ipheth: fix carrier_work UAF on disconnect
 2026-08-22 20:13 UTC 

[CVE-2026-74722][LOW] btrfs: fix memory leak in btrfs_do_encoded_write() [ Upstream
 2026-08-22 20:10 UTC 

[CVE-2026-74708][LOW] xsk: validate launch-time metadata size [ Upstream
 2026-08-22 20:07 UTC 

[CVE-2026-74607][MODERATE 7.0] KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
 2026-08-22 20:04 UTC 

[CVE-2026-74598][MODERATE 7.0] ipv6: fix Route Information option length validation
 2026-08-22 20:01 UTC 

[CVE-2026-74662][IMPORTANT] inet: frags: publish queues before arming timer
 2026-08-22 19:56 UTC 

[CVE-2026-74683][MODERATE REGULAR] Input: evdev - sanitize event type index when fetching event masks
 2026-08-22 19:53 UTC 

[CVE-2026-74692][MODERATE 7.0] net/smc: fix TOCTOU race between smc_listen_out() and listener close [ Upstream
 2026-08-22 19:50 UTC 

[CVE-2026-74596][MODERATE 7.0] fs,fsverity: remove check for fsverity being enabled in setattr_prepare()
 2026-08-22 19:46 UTC 

[CVE-2026-74587][IMPORTANT] sctp: fix use-after-free of cached ASCONF chunk
 2026-08-22 19:44 UTC 

[CVE-2026-74672][MODERATE 7.0] mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
 2026-08-22 19:39 UTC 

[CVE-2026-74600][MODERATE REGULAR] mm/page_table_check: skip special zero mappings
 2026-08-22 19:35 UTC 

[CVE-2026-74696][MODERATE REGULAR] tcp: fix TFO max_qlen accounting across reuseport migration [ Upstream
 2026-08-22 19:33 UTC 

[CVE-2026-74656][MODERATE 7.0] ipv4: fix use-after-free in fib_nhc_update_mtu()
 2026-08-22 19:29 UTC 

[CVE-2026-74592][MODERATE 7.0] ima: Instantiate file_truncate and path_truncate hooks
 2026-08-22 19:25 UTC 

[CVE-2026-74666][MODERATE 7.0] packet: synchronize pressure clearing with ring reconfiguration
 2026-08-22 19:22 UTC 

[CVE-2026-74697][MODERATE 7.0] bnxt_en: Disable EOP for TPA on all chips to prevent data corruption [ Upstream
 2026-08-22 19:18 UTC 

[CVE-2026-74642][MODERATE REGULAR] ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
 2026-08-22 19:14 UTC 

[CVE-2026-74605][MODERATE 7.0] eventfs: Use children field for rcu head and add memory barriers
 2026-08-22 19:12 UTC 

[CVE-2026-74601][LOW] ring-buffer: Use current_context for safe per-CPU buffer swap
 2026-08-22 19:10 UTC 

[CVE-2026-74714][MODERATE 7.0] bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() [ Upstream
 2026-08-22 19:07 UTC 

[CVE-2026-74680][LOW] usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
 2026-08-22 19:03 UTC 

[CVE-2026-74661][MODERATE 7.0] mac802154: fix netdev use-after-free in beacon worker
 2026-08-22 18:59 UTC 

[CVE-2026-74616][IMPORTANT] xdp: reject clones that overrun skb_shared_info tailroom
 2026-08-22 18:57 UTC 

[CVE-2026-74657][MODERATE 7.0] ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
 2026-08-22 18:52 UTC 

[CVE-2026-74602][MODERATE REGULAR] ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
 2026-08-22 18:48 UTC 

[CVE-2026-74609][MODERATE 7.0] tipc: read le->link under the node lock in tipc_node_link_down()
 2026-08-22 18:45 UTC 

[CVE-2026-74715][MODERATE 7.0] bpf: Fix netns reference imbalance in conntrack kfuncs [ Upstream
 2026-08-22 18:40 UTC 

[CVE-2026-74644][LOW] mm/damon/ops-common: putback folios on invalid migrate nid
 2026-08-22 18:37 UTC 

[CVE-2026-74710][MODERATE REGULAR] xsk: require at least 16 bytes of TX metadata [ Upstream
 2026-08-22 18:35 UTC 

[CVE-2026-74668][MODERATE 7.0] packet: use consistent hard_header_len in TX_RING send path
 2026-08-22 18:31 UTC 

[CVE-2026-74660][MODERATE 7.0] netfilter: ebt_nflog: pin the NFLOG backend
 2026-08-22 18:27 UTC 

[CVE-2026-74691][MODERATE REGULAR] net: thunderbolt: Tear down DMA paths before stopping the rings [ Upstream
 2026-08-22 18:23 UTC 

[CVE-2026-74597][IMPORTANT] ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
 2026-08-22 18:18 UTC 

[CVE-2026-74627][MODERATE 7.0] net: devmem: prevent net-iov / page mixing
 2026-08-22 18:14 UTC 

[CVE-2026-74626][MODERATE REGULAR] NTB: ntb_netdev: Preserve RX queue depth on allocation failure
 2026-08-22 18:13 UTC 

[CVE-2026-74717][LOW] net/mlx5: fw_tracer, return NULL on create error [ Upstream
 2026-08-22 18:10 UTC 

[CVE-2026-74671][MODERATE 7.0] ima: fix out-of-bounds read in xattr_verify() [ Upstream
 2026-08-22 18:10 UTC 

[CVE-2026-74590][MODERATE REGULAR] fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
 2026-08-22 18:05 UTC 

[CVE-2026-74614][MODERATE 7.0] vsock/virtio: read virtqueues under worker locks
 2026-08-22 18:01 UTC 

[CVE-2026-74630][IMPORTANT] ipv6: prevent in6_dev_get() from resurrecting inet6_dev
 2026-08-22 17:57 UTC 

[CVE-2026-74721][MODERATE 7.0] accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() [ Upstream
 2026-08-22 17:57 UTC 

[CVE-2026-74699][LOW] drm/xe: Fix memory leak in exec_queue_set_hang_replay_state() [ Upstream
 2026-08-22 17:56 UTC 

[CVE-2026-74689][MODERATE REGULAR] net/atm: fix slab-out-of-bounds read in vcc_setsockopt() [ Upstream
 2026-08-22 17:55 UTC 

page:  |  | latest

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox