org.kernel.vger.linux-cve-announce archive

605 archived articles, newest first (page 4 of 7). Latest articles →

CVE-2026-64518: tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().
Sat, 25 Jul 2026 11:13:39 +0200
Greg Kroah-Hartman <[email protected]> • #14049
CVE-2026-64517: drm/xe/gsc: Fix double-free of managed BO in error path
Sat, 25 Jul 2026 11:13:38 +0200
Greg Kroah-Hartman <[email protected]> • #14048
CVE-2026-64516: drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets
Sat, 25 Jul 2026 11:13:37 +0200
Greg Kroah-Hartman <[email protected]> • #14047
CVE-2026-64513: KVM: x86: Unconditionally recompute CR8 intercept on PPR update
Sat, 25 Jul 2026 10:52:10 +0200
Greg Kroah-Hartman <[email protected]> • #14046
CVE-2026-64514: userfaultfd: gate must_wait writability check on pte_present()
Sat, 25 Jul 2026 10:52:11 +0200
Greg Kroah-Hartman <[email protected]> • #14045
CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout
Sat, 25 Jul 2026 10:51:29 +0200
Greg Kroah-Hartman <[email protected]> • #14044
CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown
Sat, 25 Jul 2026 10:51:38 +0200
Greg Kroah-Hartman <[email protected]> • #14043
CVE-2026-64480: ALSA: ice1712: check snd_ctl_new1() return value
Sat, 25 Jul 2026 10:51:37 +0200
Greg Kroah-Hartman <[email protected]> • #14042
CVE-2026-64479: ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
Sat, 25 Jul 2026 10:51:36 +0200
Greg Kroah-Hartman <[email protected]> • #14041
CVE-2026-64478: ALSA: usb-audio: avoid kobject path lookup in DualSense match
Sat, 25 Jul 2026 10:51:35 +0200
Greg Kroah-Hartman <[email protected]> • #14040
CVE-2026-64477: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled
Sat, 25 Jul 2026 10:51:34 +0200
Greg Kroah-Hartman <[email protected]> • #14039
CVE-2026-64512: ACPI: CPPC: Suppress UBSAN warning caused by field misuse
Sat, 25 Jul 2026 10:52:09 +0200
Greg Kroah-Hartman <[email protected]> • #14038
CVE-2026-64476: vfio/pci: Latch disable_idle_d3 per device
Sat, 25 Jul 2026 10:51:33 +0200
Greg Kroah-Hartman <[email protected]> • #14037
CVE-2026-64511: ACPI: NFIT: core: Fix possible NULL pointer dereference
Sat, 25 Jul 2026 10:52:08 +0200
Greg Kroah-Hartman <[email protected]> • #14036
CVE-2026-64510: ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
Sat, 25 Jul 2026 10:52:07 +0200
Greg Kroah-Hartman <[email protected]> • #14035
CVE-2026-64509: rust: block: fix GenDisk cleanup paths
Sat, 25 Jul 2026 10:52:06 +0200
Greg Kroah-Hartman <[email protected]> • #14034
CVE-2026-64508: bpf: Support for hardening against JIT spraying
Sat, 25 Jul 2026 10:52:05 +0200
Greg Kroah-Hartman <[email protected]> • #14033
CVE-2026-64507: x86/bugs: Enable IBPB flush on BPF JIT allocation
Sat, 25 Jul 2026 10:52:04 +0200
Greg Kroah-Hartman <[email protected]> • #14032
CVE-2026-64506: wifi: rtw89: correct drop logic for malformed AMPDU frames
Sat, 25 Jul 2026 10:52:03 +0200
Greg Kroah-Hartman <[email protected]> • #14031
CVE-2026-64505: usb: gadget: function: rndis: add length check for header
Sat, 25 Jul 2026 10:52:02 +0200
Greg Kroah-Hartman <[email protected]> • #14030
CVE-2026-64504: iio: accel: bmc150: clamp the device-reported FIFO frame count
Sat, 25 Jul 2026 10:52:01 +0200
Greg Kroah-Hartman <[email protected]> • #14029
CVE-2026-64503: iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
Sat, 25 Jul 2026 10:52:00 +0200
Greg Kroah-Hartman <[email protected]> • #14028
CVE-2026-64502: iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices
Sat, 25 Jul 2026 10:51:59 +0200
Greg Kroah-Hartman <[email protected]> • #14027
CVE-2026-64475: vfio/pci: Release the VGA arbiter client on register_device() failure
Sat, 25 Jul 2026 10:51:32 +0200
Greg Kroah-Hartman <[email protected]> • #14026
CVE-2026-64501: iio: adc: ad_sigma_delta: fix CS held asserted and state leaks
Sat, 25 Jul 2026 10:51:58 +0200
Greg Kroah-Hartman <[email protected]> • #14025
CVE-2026-64500: iio: adc: lpc32xx: Initialize completion before requesting IRQ
Sat, 25 Jul 2026 10:51:57 +0200
Greg Kroah-Hartman <[email protected]> • #14024
CVE-2026-64499: iio: adc: ti-ads1119: fix PM reference leak in buffer preenable
Sat, 25 Jul 2026 10:51:56 +0200
Greg Kroah-Hartman <[email protected]> • #14023
CVE-2026-64498: iio: buffer: hw-consumer: free scan_mask on buffer release
Sat, 25 Jul 2026 10:51:55 +0200
Greg Kroah-Hartman <[email protected]> • #14022
CVE-2026-64497: iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
Sat, 25 Jul 2026 10:51:54 +0200
Greg Kroah-Hartman <[email protected]> • #14021
CVE-2026-64496: iio: event: Fix event FIFO reset race
Sat, 25 Jul 2026 10:51:53 +0200
Greg Kroah-Hartman <[email protected]> • #14020
CVE-2026-64495: iio: gyro: bmg160: bail out when bandwidth/filter is not in table
Sat, 25 Jul 2026 10:51:52 +0200
Greg Kroah-Hartman <[email protected]> • #14019
CVE-2026-64494: iio: light: gp2ap002: fix runtime PM leak on read error
Sat, 25 Jul 2026 10:51:51 +0200
Greg Kroah-Hartman <[email protected]> • #14018
CVE-2026-64493: iio: pressure: mpl115: fix runtime PM leak on read error
Sat, 25 Jul 2026 10:51:50 +0200
Greg Kroah-Hartman <[email protected]> • #14017
CVE-2026-64492: iio: temperature: tmp006: use devm_iio_trigger_register
Sat, 25 Jul 2026 10:51:49 +0200
Greg Kroah-Hartman <[email protected]> • #14016
CVE-2026-64474: vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
Sat, 25 Jul 2026 10:51:31 +0200
Greg Kroah-Hartman <[email protected]> • #14015
CVE-2026-64491: ALSA: usx2y: us144mkii: fix work UAF on disconnect
Sat, 25 Jul 2026 10:51:48 +0200
Greg Kroah-Hartman <[email protected]> • #14014
CVE-2026-64490: ALSA: virtio: Validate control metadata from the device
Sat, 25 Jul 2026 10:51:47 +0200
Greg Kroah-Hartman <[email protected]> • #14013
CVE-2026-64489: ALSA: ymfpci: check snd_ctl_new1() return value
Sat, 25 Jul 2026 10:51:46 +0200
Greg Kroah-Hartman <[email protected]> • #14012
CVE-2026-64488: ALSA: aoa: check snd_ctl_new1() return value
Sat, 25 Jul 2026 10:51:45 +0200
Greg Kroah-Hartman <[email protected]> • #14011
CVE-2026-64487: ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
Sat, 25 Jul 2026 10:51:44 +0200
Greg Kroah-Hartman <[email protected]> • #14010
CVE-2026-64486: ALSA: cmipci: check snd_ctl_new1() return value
Sat, 25 Jul 2026 10:51:43 +0200
Greg Kroah-Hartman <[email protected]> • #14009
CVE-2026-64485: ALSA: compress: Fix task creation error unwind
Sat, 25 Jul 2026 10:51:42 +0200
Greg Kroah-Hartman <[email protected]> • #14008
CVE-2026-64484: ALSA: es1938: check snd_ctl_new1() return value
Sat, 25 Jul 2026 10:51:41 +0200
Greg Kroah-Hartman <[email protected]> • #14007
CVE-2026-64483: ALSA: firewire: isight: bound the sample count to the packet payload
Sat, 25 Jul 2026 10:51:40 +0200
Greg Kroah-Hartman <[email protected]> • #14006
CVE-2026-64482: ALSA: gus: check snd_ctl_new1() return value
Sat, 25 Jul 2026 10:51:39 +0200
Greg Kroah-Hartman <[email protected]> • #14005
CVE-2026-64473: vfio: Remove device debugfs before releasing devres
Sat, 25 Jul 2026 10:51:30 +0200
Greg Kroah-Hartman <[email protected]> • #14004
CVE-2026-64432: fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
Sat, 25 Jul 2026 10:50:49 +0200
Greg Kroah-Hartman <[email protected]> • #14003
CVE-2026-64441: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
Sat, 25 Jul 2026 10:50:58 +0200
Greg Kroah-Hartman <[email protected]> • #14002
CVE-2026-64440: staging: rtl8723bs: fix OOB write in HT_caps_handler()
Sat, 25 Jul 2026 10:50:57 +0200
Greg Kroah-Hartman <[email protected]> • #14001
CVE-2026-64439: crypto: krb5 - filter out async aead implementations at alloc
Sat, 25 Jul 2026 10:50:56 +0200
Greg Kroah-Hartman <[email protected]> • #14000
CVE-2026-64438: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
Sat, 25 Jul 2026 10:50:55 +0200
Greg Kroah-Hartman <[email protected]> • #13999
CVE-2026-64437: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
Sat, 25 Jul 2026 10:50:54 +0200
Greg Kroah-Hartman <[email protected]> • #13998
CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states
Sat, 25 Jul 2026 10:50:53 +0200
Greg Kroah-Hartman <[email protected]> • #13997
CVE-2026-64471: Bluetooth: btusb: fix use-after-free on registration failure
Sat, 25 Jul 2026 10:51:28 +0200
Greg Kroah-Hartman <[email protected]> • #13996
CVE-2026-64470: Bluetooth: btusb: fix use-after-free on marvell probe failure
Sat, 25 Jul 2026 10:51:27 +0200
Greg Kroah-Hartman <[email protected]> • #13995
CVE-2026-64469: binder: fix UAF in binder_thread_release()
Sat, 25 Jul 2026 10:51:26 +0200
Greg Kroah-Hartman <[email protected]> • #13994
CVE-2026-64468: binder: fix UAF in binder_free_transaction()
Sat, 25 Jul 2026 10:51:25 +0200
Greg Kroah-Hartman <[email protected]> • #13993
CVE-2026-64467: rust_binder: use a u64 stride when cleaning up the offsets array
Sat, 25 Jul 2026 10:51:24 +0200
Greg Kroah-Hartman <[email protected]> • #13992
CVE-2026-64466: rust_binder: clear freeze listener on node removal
Sat, 25 Jul 2026 10:51:23 +0200
Greg Kroah-Hartman <[email protected]> • #13991
CVE-2026-64465: usb: xhci: Fix sleep in atomic context in xhci_free_streams()
Sat, 25 Jul 2026 10:51:22 +0200
Greg Kroah-Hartman <[email protected]> • #13990
CVE-2026-64464: xhci: sideband: fix ring sg table pages leak
Sat, 25 Jul 2026 10:51:21 +0200
Greg Kroah-Hartman <[email protected]> • #13989
CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
Sat, 25 Jul 2026 10:51:20 +0200
Greg Kroah-Hartman <[email protected]> • #13988
CVE-2026-64462: PCI: altera: Fix resource leaks on probe failure
Sat, 25 Jul 2026 10:51:19 +0200
Greg Kroah-Hartman <[email protected]> • #13987
CVE-2026-64435: audit: Fix data races of skb_queue_len() readers on audit_queue
Sat, 25 Jul 2026 10:50:52 +0200
Greg Kroah-Hartman <[email protected]> • #13986
CVE-2026-64461: PCI: mediatek: Fix IRQ domain leak when port fails to enable
Sat, 25 Jul 2026 10:51:18 +0200
Greg Kroah-Hartman <[email protected]> • #13985
CVE-2026-64460: PCI/IOV: Skip VF Resizable BAR restore on read error
Sat, 25 Jul 2026 10:51:17 +0200
Greg Kroah-Hartman <[email protected]> • #13984
CVE-2026-64459: tcp: restore RCU grace period in tcp_ao_destroy_sock
Sat, 25 Jul 2026 10:51:16 +0200
Greg Kroah-Hartman <[email protected]> • #13983
CVE-2026-64458: mm/damon/ops-common: handle extreme intervals in damon_hot_score()
Sat, 25 Jul 2026 10:51:15 +0200
Greg Kroah-Hartman <[email protected]> • #13982
CVE-2026-64457: virtio_pci: fix vq info pointer lookup via wrong index
Sat, 25 Jul 2026 10:51:14 +0200
Greg Kroah-Hartman <[email protected]> • #13981
CVE-2026-64456: hwrng: virtio: clamp device-reported used.len at copy_data()
Sat, 25 Jul 2026 10:51:13 +0200
Greg Kroah-Hartman <[email protected]> • #13980
CVE-2026-64455: USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
Sat, 25 Jul 2026 10:51:12 +0200
Greg Kroah-Hartman <[email protected]> • #13979
CVE-2026-64454: usb: dwc3: run gadget disconnect from sleepable suspend context
Sat, 25 Jul 2026 10:51:11 +0200
Greg Kroah-Hartman <[email protected]> • #13978
CVE-2026-64453: usb: misc: usbio: fix disconnect UAF in client teardown
Sat, 25 Jul 2026 10:51:10 +0200
Greg Kroah-Hartman <[email protected]> • #13977
CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path
Sat, 25 Jul 2026 10:51:09 +0200
Greg Kroah-Hartman <[email protected]> • #13976
CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
Sat, 25 Jul 2026 10:50:51 +0200
Greg Kroah-Hartman <[email protected]> • #13975
CVE-2026-64451: tracing: Fix NULL pointer dereference in func_set_flag()
Sat, 25 Jul 2026 10:51:08 +0200
Greg Kroah-Hartman <[email protected]> • #13974
CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks
Sat, 25 Jul 2026 10:51:07 +0200
Greg Kroah-Hartman <[email protected]> • #13973
CVE-2026-64449: staging: vme_user: bound slave read/write to the kern_buf size
Sat, 25 Jul 2026 10:51:06 +0200
Greg Kroah-Hartman <[email protected]> • #13972
CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area
Sat, 25 Jul 2026 10:51:05 +0200
Greg Kroah-Hartman <[email protected]> • #13971
CVE-2026-64447: staging: media: ipu7: fix double-free and use-after-free in error paths
Sat, 25 Jul 2026 10:51:04 +0200
Greg Kroah-Hartman <[email protected]> • #13970
CVE-2026-64446: staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
Sat, 25 Jul 2026 10:51:03 +0200
Greg Kroah-Hartman <[email protected]> • #13969
CVE-2026-64445: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
Sat, 25 Jul 2026 10:51:02 +0200
Greg Kroah-Hartman <[email protected]> • #13968
CVE-2026-64444: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
Sat, 25 Jul 2026 10:51:01 +0200
Greg Kroah-Hartman <[email protected]> • #13967
CVE-2026-64443: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
Sat, 25 Jul 2026 10:51:00 +0200
Greg Kroah-Hartman <[email protected]> • #13966
CVE-2026-64442: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
Sat, 25 Jul 2026 10:50:59 +0200
Greg Kroah-Hartman <[email protected]> • #13965
CVE-2026-64433: Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
Sat, 25 Jul 2026 10:50:50 +0200
Greg Kroah-Hartman <[email protected]> • #13964
CVE-2026-64392: ksmbd: use opener credentials for delete-on-close
Sat, 25 Jul 2026 10:50:09 +0200
Greg Kroah-Hartman <[email protected]> • #13963
CVE-2026-64401: smb: client: resolve SWN tcon from live registrations
Sat, 25 Jul 2026 10:50:18 +0200
Greg Kroah-Hartman <[email protected]> • #13962
CVE-2026-64400: ksmbd: prevent path traversal bypass by restricting caseless retry
Sat, 25 Jul 2026 10:50:17 +0200
Greg Kroah-Hartman <[email protected]> • #13961
CVE-2026-64399: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
Sat, 25 Jul 2026 10:50:16 +0200
Greg Kroah-Hartman <[email protected]> • #13960
CVE-2026-64398: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
Sat, 25 Jul 2026 10:50:15 +0200
Greg Kroah-Hartman <[email protected]> • #13959
CVE-2026-64397: ksmbd: serialize QUERY_DIRECTORY requests per file
Sat, 25 Jul 2026 10:50:14 +0200
Greg Kroah-Hartman <[email protected]> • #13958
CVE-2026-64396: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
Sat, 25 Jul 2026 10:50:13 +0200
Greg Kroah-Hartman <[email protected]> • #13957
CVE-2026-64431: ntfs: avoid calling post_write_mst_fixup() for invalid index_block
Sat, 25 Jul 2026 10:50:48 +0200
Greg Kroah-Hartman <[email protected]> • #13956
CVE-2026-64430: NTB: epf: Avoid calling pci_irq_vector() from hardirq context
Sat, 25 Jul 2026 10:50:47 +0200
Greg Kroah-Hartman <[email protected]> • #13955
CVE-2026-64429: gpio: eic-sprd: use raw_spinlock_t in the irq startup path
Sat, 25 Jul 2026 10:50:46 +0200
Greg Kroah-Hartman <[email protected]> • #13954
CVE-2026-64428: gpio: sch: use raw_spinlock_t in the irq startup path
Sat, 25 Jul 2026 10:50:45 +0200
Greg Kroah-Hartman <[email protected]> • #13953
CVE-2026-64427: HID: logitech-dj: Fix maxfield check in DJ short report validation
Sat, 25 Jul 2026 10:50:44 +0200
Greg Kroah-Hartman <[email protected]> • #13952
CVE-2026-64426: io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE
Sat, 25 Jul 2026 10:50:43 +0200
Greg Kroah-Hartman <[email protected]> • #13951
CVE-2026-64425: io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
Sat, 25 Jul 2026 10:50:42 +0200
Greg Kroah-Hartman <[email protected]> • #13950
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.