org.kernel.vger.linux-cve-announce archive
603 archived articles, newest first (page 2 of 7). Latest articles →
CVE-2026-74560: xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
Sat, 15 Aug 2026 21:27:21 +0900CVE-2026-74559: xsk: drain continuation descs after overflow in xsk_build_skb()
Sat, 15 Aug 2026 21:27:20 +0900CVE-2026-74558: xsk: reclaim invalid Tx descriptors in ZC batch path
Sat, 15 Aug 2026 21:27:19 +0900CVE-2026-74557: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
Sat, 15 Aug 2026 21:27:18 +0900CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
Sat, 15 Aug 2026 21:27:17 +0900CVE-2026-74547: hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
Sat, 15 Aug 2026 21:27:08 +0900CVE-2026-74505: ALSA: 6fire: Fix UAF at error handling during probe
Sat, 15 Aug 2026 21:26:26 +0900CVE-2026-74514: KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
Sat, 15 Aug 2026 21:26:35 +0900CVE-2026-74513: dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
Sat, 15 Aug 2026 21:26:34 +0900CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule()
Sat, 15 Aug 2026 21:26:33 +0900CVE-2026-74511: Bluetooth: mgmt: fix pending command UAF in EIR updates
Sat, 15 Aug 2026 21:26:32 +0900CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation
Sat, 15 Aug 2026 21:26:31 +0900CVE-2026-74545: rtase: fix double free of multi-frag skb on DMA map failure
Sat, 15 Aug 2026 21:27:06 +0900CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs
Sat, 15 Aug 2026 21:26:30 +0900CVE-2026-74544: net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
Sat, 15 Aug 2026 21:27:05 +0900CVE-2026-74543: net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
Sat, 15 Aug 2026 21:27:04 +0900CVE-2026-74542: netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
Sat, 15 Aug 2026 21:27:03 +0900CVE-2026-74541: Bluetooth: ISO: clear iso_data always when detaching conn from hcon
Sat, 15 Aug 2026 21:27:02 +0900CVE-2026-74540: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
Sat, 15 Aug 2026 21:27:01 +0900CVE-2026-74539: Bluetooth: ISO: lock sk in iso_sock_getname
Sat, 15 Aug 2026 21:27:00 +0900CVE-2026-74538: Bluetooth: ISO: lock sk in iso_connect_ind
Sat, 15 Aug 2026 21:26:59 +0900CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready
Sat, 15 Aug 2026 21:26:58 +0900CVE-2026-68465: mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
Sat, 15 Aug 2026 15:01:07 +0900CVE-2026-68456: usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
Sat, 15 Aug 2026 15:00:58 +0900CVE-2026-68451: s390/zcrypt: Validate length for CCA ECC private key requests
Thu, 13 Aug 2026 22:58:29 +0900CVE-2026-68454: KVM: s390: pci: Fix handling of AIF enable without AISB
Thu, 13 Aug 2026 22:58:32 +0900CVE-2026-68453: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
Thu, 13 Aug 2026 22:58:31 +0900CVE-2026-68452: s390/zcrypt: Validate length for CCA AES cipher key requests
Thu, 13 Aug 2026 22:58:30 +0900CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert
Wed, 12 Aug 2026 09:50:26 +0900CVE-2026-68449: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
Wed, 12 Aug 2026 09:50:25 +0900CVE-2026-68447: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
Wed, 12 Aug 2026 09:50:23 +0900CVE-2026-68448: ovl: check access to copy_file_range source with src mounter creds
Wed, 12 Aug 2026 09:50:24 +0900CVE-2026-68438: smp: Make CSD lock acquisition atomic for debug mode
Wed, 12 Aug 2026 09:06:01 +0900CVE-2026-68437: drm/imagination: Fit paired fragment job in the correct CCCB
Wed, 12 Aug 2026 09:06:00 +0900CVE-2026-68436: drm/amd/display: use kvzalloc to allocate struct dc
Wed, 12 Aug 2026 09:05:59 +0900CVE-2026-68435: LoongArch: Fix address space mismatch in kexec command line lookup
Wed, 12 Aug 2026 09:05:58 +0900CVE-2026-68434: serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
Wed, 12 Aug 2026 09:05:57 +0900CVE-2026-68433: libceph: bound get_version reply decode to front len
Wed, 12 Aug 2026 09:05:56 +0900CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink
Wed, 12 Aug 2026 09:05:55 +0900CVE-2026-68431: ksmbd: validate minimum PDU size for transform requests
Wed, 12 Aug 2026 09:05:54 +0900CVE-2026-68446: drm/vmwgfx: Validate vmw_surface_metadata::array_size
Wed, 12 Aug 2026 09:06:09 +0900CVE-2026-68445: drm/vc4: Prevent shader BO mappings from becoming writable
Wed, 12 Aug 2026 09:06:08 +0900CVE-2026-68444: firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
Wed, 12 Aug 2026 09:06:07 +0900CVE-2026-68443: hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
Wed, 12 Aug 2026 09:06:06 +0900CVE-2026-68442: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
Wed, 12 Aug 2026 09:06:05 +0900CVE-2026-68441: net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
Wed, 12 Aug 2026 09:06:04 +0900CVE-2026-68440: net: txgbe: fix heap overflow when reading module EEPROM
Wed, 12 Aug 2026 09:06:03 +0900CVE-2026-68439: wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
Wed, 12 Aug 2026 09:06:02 +0900CVE-2026-68429: drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
Wed, 12 Aug 2026 09:05:52 +0900CVE-2026-68430: drm/amdgpu/gfx8: drop unecessary BUG_ON()
Wed, 12 Aug 2026 09:05:53 +0900REJECTED: CVE-2026-31404: NFSD: Defer sub-object cleanup in export put callbacks
Tue, 11 Aug 2026 11:15:05 +0900REJECTED: CVE-2026-46194: f2fs: fix node_cnt race between extent node destroy and writeback
Tue, 11 Aug 2026 11:13:29 +0900REJECTED: CVE-2026-63872: esp: fix page frag reference leak on skb_to_sgvec failure
Tue, 11 Aug 2026 11:08:44 +0900REJECTED: CVE-2026-68171: arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
Tue, 11 Aug 2026 11:07:22 +0900REJECTED: CVE-2021-47504: io_uring: ensure task_work gets run as part of cancelations
Tue, 11 Aug 2026 11:05:12 +0900CVE-2026-68394: Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
Mon, 10 Aug 2026 14:01:51 +0200CVE-2026-68403: wifi: brcmfmac: initialize SDIO data work before cleanup
Mon, 10 Aug 2026 14:02:00 +0200CVE-2026-68402: wifi: cfg80211: bound element ID read when checking non-inheritance
Mon, 10 Aug 2026 14:01:59 +0200CVE-2026-68401: firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
Mon, 10 Aug 2026 14:01:58 +0200CVE-2026-68400: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation
Mon, 10 Aug 2026 14:01:57 +0200CVE-2026-68399: bpf: Fix UAF in sock clone early bailouts
Mon, 10 Aug 2026 14:01:56 +0200CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
Mon, 10 Aug 2026 14:01:55 +0200CVE-2026-68428: KVM: x86/mmu: Fix use-after-free on vendor module reload
Mon, 10 Aug 2026 14:02:25 +0200CVE-2026-68427: gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
Mon, 10 Aug 2026 14:02:24 +0200CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment
Mon, 10 Aug 2026 14:02:23 +0200CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly
Mon, 10 Aug 2026 14:02:22 +0200CVE-2026-68424: mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins()
Mon, 10 Aug 2026 14:02:21 +0200CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv()
Mon, 10 Aug 2026 14:01:54 +0200CVE-2026-68423: mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy()
Mon, 10 Aug 2026 14:02:20 +0200CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
Mon, 10 Aug 2026 14:02:19 +0200CVE-2026-68421: sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
Mon, 10 Aug 2026 14:02:18 +0200CVE-2026-68420: xfrm: reject optional IPTFS templates in outbound policies
Mon, 10 Aug 2026 14:02:17 +0200CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions
Mon, 10 Aug 2026 14:02:16 +0200CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create
Mon, 10 Aug 2026 14:02:15 +0200CVE-2026-68417: RDMA/siw: publish QP after initialization
Mon, 10 Aug 2026 14:02:14 +0200CVE-2026-68416: mtd: fix double free and WARN_ON in add_mtd_device() error paths
Mon, 10 Aug 2026 14:02:13 +0200CVE-2026-68415: xfrm: clear mode callbacks after failed mode setup
Mon, 10 Aug 2026 14:02:12 +0200CVE-2026-68414: wifi: cfg80211: cancel sched scan results work on unregister
Mon, 10 Aug 2026 14:02:11 +0200CVE-2026-68396: scsi: core: wake eh reliably when using scsi_schedule_eh
Mon, 10 Aug 2026 14:01:53 +0200CVE-2026-68413: wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
Mon, 10 Aug 2026 14:02:10 +0200CVE-2026-68412: wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
Mon, 10 Aug 2026 14:02:09 +0200CVE-2026-68411: wifi: mac80211_hwsim: clamp virtio RX length before skb_put
Mon, 10 Aug 2026 14:02:08 +0200CVE-2026-68410: wifi: libertas: fix memory leak in helper_firmware_cb()
Mon, 10 Aug 2026 14:02:07 +0200CVE-2026-68409: wifi: mac80211: defer link RX stats percpu free to RCU
Mon, 10 Aug 2026 14:02:06 +0200CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
Mon, 10 Aug 2026 14:02:05 +0200CVE-2026-68407: wifi: nl80211: free RNR data on MBSSID mismatch
Mon, 10 Aug 2026 14:02:04 +0200CVE-2026-68406: wifi: cfg80211: validate PMSR FTM preamble range
Mon, 10 Aug 2026 14:02:03 +0200CVE-2026-68405: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
Mon, 10 Aug 2026 14:02:02 +0200CVE-2026-68404: wifi: cfg80211: use wiphy work for socket owner autodisconnect
Mon, 10 Aug 2026 14:02:01 +0200CVE-2026-68395: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
Mon, 10 Aug 2026 14:01:52 +0200CVE-2026-68354: firewire: net: Fix fragmented datagram reassembly
Mon, 10 Aug 2026 14:01:11 +0200CVE-2026-68363: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
Mon, 10 Aug 2026 14:01:20 +0200CVE-2026-68362: wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
Mon, 10 Aug 2026 14:01:19 +0200CVE-2026-68361: hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
Mon, 10 Aug 2026 14:01:18 +0200CVE-2026-68360: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
Mon, 10 Aug 2026 14:01:17 +0200CVE-2026-68359: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
Mon, 10 Aug 2026 14:01:16 +0200CVE-2026-68358: hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
Mon, 10 Aug 2026 14:01:15 +0200CVE-2026-68393: Bluetooth: hci_sync: extend conn_hash lookup critical sections
Mon, 10 Aug 2026 14:01:50 +0200CVE-2026-68392: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Mon, 10 Aug 2026 14:01:49 +0200CVE-2026-68391: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
Mon, 10 Aug 2026 14:01:48 +0200
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.