[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2qwI4Ds3BhklXyb5yo7CdCyFpA2b1mdn8dKLKk5RBW4":3},{"product":4,"cycleMajor":14,"releases":15,"cves":36,"nextMajor":11870},{"id":5,"slug":6,"name":7,"category":8,"vendor":9,"description":10,"logo_url":11,"official_url":9,"synced_at":12,"created_at":13},"c4eb95d1-e6ca-4014-b92e-4d0f71e8b8e0","linux","Linux","other",null,"Developers rely on operating systems that provide a stable and secure foundation for their applications, which is why Linux has been a popular choice since its initial release on 17 September 1991 by Linus Torvalds. Linux is a family of free-and-open-source Unix-like operating systems based on the Linux kernel, offering a flexible and customizable platform for a wide range of use cases. The Linux kernel is maintained by a community of developers led by Linus Torvalds, ensuring that the operating system stays up-to-date with the latest security patches and features. This community-driven approach has contributed to Linux's widespread adoption, with many developers using it as the basis for their projects.\n\nThe end-of-life landscape for Linux is complex, with a total of 35 versions released to date, of which 28 have reached their end-of-life. Currently, 7 versions remain active, with the latest stable version being 6.1.175. Looking ahead, the next version to reach its end-of-life is 5.15, which is scheduled to expire on 31 December 2026. This means that developers still using version 5.15 should start planning their migration to a newer version to ensure they continue to receive security updates and support. The most recent end-of-life date was 22 April 2026, when version 6.19 reached the end of its life cycle.\n\nIn terms of security, Linux has a strong track record, with no known Common Vulnerabilities and Exposures (CVEs) currently tracked. This means that there are no critical vulnerabilities to be concerned about, and no specific version is more affected than others. As a result, developers can focus on using Linux as a secure foundation for their applications without worrying about known security risks. However, it is still essential for developers to stay up-to-date with the latest versions and security patches to ensure the long-term security and stability of their projects. By doing so, they can take advantage of the many benefits that Linux has to offer, including its flexibility, customizability, and community-driven development model.","https:\u002F\u002Fcdn.simpleicons.org\u002Flinux","2026-08-06T02:01:26.182+00:00","2026-05-30T16:23:55.904463+00:00","4",[16,24,30],{"id":17,"product_id":5,"cycle":18,"release_date":19,"eol":20,"eol_boolean":9,"latest":21,"latest_release_date":20,"lts":22,"support":9,"created_at":23},"21e0ad09-43e7-4e3c-83e8-552e3d557878","4.19","2018-10-22","2024-12-05","4.19.325",true,"2026-05-30T16:26:16.905757+00:00",{"id":25,"product_id":5,"cycle":26,"release_date":27,"eol":28,"eol_boolean":9,"latest":29,"latest_release_date":28,"lts":22,"support":9,"created_at":23},"d421d1ee-c172-4be7-9680-d0b9c01eb456","4.14","2017-11-12","2024-01-10","4.14.336",{"id":31,"product_id":5,"cycle":32,"release_date":33,"eol":34,"eol_boolean":9,"latest":35,"latest_release_date":34,"lts":22,"support":9,"created_at":23},"131e858e-1172-4d64-bc23-8f778898f393","4.9","2016-12-11","2023-01-07","4.9.337",[37,45,46,47,53,54,55,62,63,64,70,71,72,77,82,83,84,89,90,91,96,97,98,105,106,107,113,114,115,120,121,122,127,128,129,134,135,136,141,142,147,152,153,154,159,160,161,167,168,169,174,175,176,181,182,183,188,189,190,195,196,197,202,203,204,209,210,211,217,218,219,224,225,226,231,237,242,243,244,249,250,251,256,261,262,263,268,269,270,275,276,277,282,287,288,289,294,295,296,301,302,303,308,309,310,315,316,317,322,323,324,329,330,331,336,337,338,344,345,346,351,352,353,358,359,364,365,366,371,372,373,379,380,381,386,387,388,394,395,396,401,402,403,408,409,410,415,416,417,422,423,424,429,430,431,436,437,442,443,444,450,451,452,457,458,459,464,465,466,472,473,474,479,480,481,486,487,492,493,494,499,500,501,506,507,508,513,514,519,520,521,526,531,532,533,538,539,540,546,547,548,553,554,555,560,561,562,567,572,573,574,579,580,585,586,587,592,597,598,599,604,605,606,611,612,613,618,623,628,633,638,643,648,653,654,660,661,662,667,668,669,674,675,676,681,682,683,688,689,690,695,696,697,702,703,704,709,710,711,716,721,722,727,728,729,734,735,736,741,742,743,748,749,750,755,756,757,762,767,768,769,774,775,780,781,786,787,792,793,794,799,800,801,806,807,808,813,818,819,824,825,826,831,832,833,838,839,840,845,846,847,852,853,854,859,860,861,866,867,868,873,874,875,880,881,882,887,888,889,894,899,900,901,906,907,908,913,918,919,920,925,926,927,932,933,934,939,940,941,946,951,952,953,958,959,960,965,970,971,972,977,978,979,984,985,986,991,992,993,998,999,1000,1005,1006,1007,1012,1013,1014,1019,1020,1025,1026,1027,1032,1033,1034,1039,1040,1045,1046,1047,1052,1053,1054,1059,1060,1061,1066,1067,1068,1073,1074,1075,1080,1081,1082,1087,1088,1089,1094,1095,1096,1101,1102,1103,1108,1109,1110,1115,1120,1121,1122,1127,1128,1129,1134,1135,1140,1145,1146,1147,1152,1153,1154,1159,1160,1166,1167,1168,1173,1174,1175,1180,1181,1182,1187,1188,1189,1194,1195,1196,1201,1202,1203,1208,1209,1210,1215,1216,1217,1222,1223,1224,1229,1230,1231,1236,1237,1238,1243,1249,1250,1255,1260,1261,1262,1267,1268,1269,1274,1275,1276,1281,1282,1283,1288,1289,1290,1295,1296,1297,1302,1303,1304,1309,1310,1311,1316,1321,1322,1323,1328,1329,1334,1340,1341,1342,1347,1348,1349,1354,1355,1356,1361,1362,1363,1368,1369,1370,1375,1376,1381,1382,1383,1388,1389,1390,1395,1396,1397,1402,1403,1404,1409,1414,1415,1416,1421,1422,1423,1428,1429,1430,1435,1436,1437,1442,1443,1444,1449,1450,1451,1456,1461,1462,1463,1468,1469,1470,1475,1476,1481,1482,1483,1488,1489,1490,1495,1496,1501,1502,1503,1508,1509,1510,1515,1516,1521,1522,1523,1528,1529,1530,1535,1536,1541,1542,1543,1548,1549,1550,1555,1556,1561,1562,1563,1568,1569,1570,1575,1576,1577,1582,1583,1584,1589,1590,1591,1596,1597,1598,1603,1604,1605,1610,1611,1612,1617,1618,1619,1624,1625,1626,1631,1632,1633,1638,1639,1640,1645,1646,1647,1652,1653,1654,1659,1660,1661,1666,1667,1668,1673,1674,1675,1680,1681,1686,1687,1688,1693,1694,1695,1700,1701,1702,1707,1708,1713,1714,1715,1720,1725,1726,1731,1732,1733,1738,1743,1744,1745,1750,1751,1752,1757,1758,1759,1764,1765,1766,1771,1772,1773,1778,1783,1784,1785,1790,1791,1792,1797,1798,1799,1804,1805,1806,1811,1812,1813,1818,1823,1824,1825,1830,1835,1836,1837,1842,1847,1848,1849,1854,1855,1856,1861,1862,1863,1868,1873,1874,1875,1880,1881,1886,1887,1888,1893,1898,1899,1900,1905,1906,1907,1912,1913,1914,1919,1920,1921,1926,1927,1928,1933,1934,1939,1940,1941,1946,1947,1952,1953,1954,1959,1964,1965,1966,1971,1976,1977,1978,1983,1984,1985,1990,1991,1992,1997,1998,1999,2004,2005,2006,2011,2012,2013,2018,2019,2020,2025,2026,2031,2032,2033,2038,2039,2040,2045,2046,2051,2052,2057,2058,2059,2064,2065,2066,2071,2072,2073,2078,2083,2084,2085,2090,2091,2096,2097,2098,2103,2104,2105,2110,2111,2116,2117,2118,2123,2124,2125,2130,2131,2136,2137,2138,2143,2144,2145,2150,2151,2152,2157,2158,2159,2164,2165,2166,2171,2172,2173,2178,2179,2180,2185,2186,2187,2192,2193,2194,2199,2200,2205,2206,2207,2212,2217,2218,2219,2224,2225,2226,2231,2236,2237,2238,2243,2244,2245,2250,2251,2256,2257,2258,2263,2264,2265,2270,2271,2272,2277,2278,2279,2284,2285,2286,2291,2296,2297,2298,2303,2304,2305,2310,2311,2312,2317,2318,2319,2324,2325,2326,2331,2332,2333,2338,2339,2340,2345,2350,2351,2352,2357,2358,2359,2364,2365,2366,2371,2372,2373,2378,2379,2380,2385,2386,2391,2392,2397,2398,2399,2404,2405,2406,2411,2412,2413,2418,2419,2420,2425,2426,2431,2432,2433,2438,2443,2444,2445,2450,2451,2452,2457,2458,2459,2464,2465,2466,2471,2476,2477,2478,2483,2484,2485,2490,2491,2496,2497,2498,2503,2504,2505,2510,2515,2516,2517,2522,2523,2524,2529,2530,2535,2540,2541,2546,2551,2556,2561,2562,2563,2568,2573,2574,2575,2580,2585,2590,2591,2592,2597,2598,2599,2604,2605,2606,2611,2612,2613,2618,2619,2620,2625,2626,2627,2632,2633,2634,2639,2644,2645,2646,2651,2652,2657,2658,2659,2664,2665,2666,2671,2672,2673,2678,2679,2680,2685,2686,2691,2692,2693,2698,2699,2700,2705,2706,2707,2712,2713,2714,2719,2720,2721,2726,2727,2728,2733,2734,2739,2744,2745,2746,2751,2752,2753,2758,2759,2760,2765,2766,2767,2772,2773,2774,2779,2780,2781,2786,2787,2788,2793,2794,2795,2800,2801,2802,2807,2808,2809,2814,2815,2816,2821,2822,2823,2828,2829,2830,2835,2836,2837,2842,2843,2844,2849,2854,2855,2856,2861,2862,2863,2868,2869,2870,2875,2876,2877,2882,2883,2884,2889,2890,2891,2896,2897,2898,2903,2904,2905,2910,2911,2912,2917,2918,2919,2924,2925,2926,2931,2932,2933,2938,2943,2944,2945,2950,2951,2952,2957,2958,2959,2964,2965,2966,2971,2972,2973,2978,2979,2980,2985,2990,2991,2996,2997,2998,3003,3004,3009,3010,3011,3016,3017,3018,3023,3024,3025,3030,3031,3032,3037,3038,3039,3044,3045,3046,3051,3052,3053,3058,3059,3060,3065,3066,3071,3072,3073,3078,3079,3080,3085,3086,3087,3092,3093,3094,3099,3100,3101,3106,3111,3116,3117,3118,3123,3124,3125,3130,3131,3132,3137,3138,3139,3144,3145,3146,3151,3152,3153,3158,3159,3160,3165,3166,3167,3172,3173,3174,3179,3180,3181,3186,3187,3188,3193,3194,3195,3200,3201,3202,3207,3208,3213,3214,3215,3220,3221,3222,3227,3228,3229,3234,3235,3236,3241,3242,3243,3248,3249,3250,3255,3256,3257,3262,3263,3264,3269,3270,3271,3276,3277,3278,3283,3284,3285,3290,3291,3292,3297,3298,3299,3304,3309,3310,3311,3316,3317,3322,3323,3324,3329,3330,3335,3336,3337,3342,3347,3348,3349,3354,3355,3356,3361,3366,3367,3368,3373,3378,3383,3388,3393,3398,3399,3400,3405,3410,3411,3412,3417,3418,3419,3424,3425,3430,3431,3432,3437,3442,3443,3444,3449,3450,3451,3456,3457,3458,3463,3464,3465,3470,3471,3472,3477,3478,3479,3484,3485,3486,3491,3492,3493,3498,3503,3504,3505,3510,3511,3512,3517,3518,3519,3524,3525,3526,3531,3532,3533,3538,3539,3544,3545,3546,3551,3552,3553,3558,3559,3560,3565,3570,3571,3572,3577,3578,3583,3584,3585,3590,3591,3592,3597,3598,3599,3604,3605,3606,3611,3612,3617,3618,3619,3624,3625,3626,3631,3632,3633,3638,3639,3640,3645,3650,3651,3656,3661,3662,3663,3668,3669,3670,3675,3676,3677,3682,3683,3688,3689,3690,3695,3700,3705,3706,3707,3712,3713,3714,3719,3720,3721,3726,3727,3728,3733,3734,3735,3740,3741,3742,3747,3748,3753,3754,3755,3760,3761,3762,3767,3768,3773,3774,3775,3780,3785,3786,3787,3792,3793,3794,3799,3800,3801,3806,3807,3808,3813,3814,3815,3820,3821,3822,3827,3832,3833,3834,3839,3840,3841,3846,3847,3848,3853,3858,3859,3860,3865,3866,3867,3872,3873,3874,3879,3880,3881,3886,3887,3892,3893,3894,3899,3900,3901,3906,3911,3912,3913,3918,3919,3920,3925,3926,3927,3932,3933,3934,3939,3940,3941,3946,3947,3948,3953,3958,3959,3960,3965,3966,3967,3974,3975,3976,3981,3982,3983,3988,3989,3990,3995,3996,4001,4002,4007,4008,4009,4014,4015,4016,4021,4022,4023,4028,4033,4034,4035,4040,4041,4042,4047,4048,4049,4054,4059,4064,4065,4066,4071,4072,4073,4078,4079,4084,4085,4086,4091,4092,4093,4098,4099,4100,4105,4106,4107,4112,4113,4118,4123,4128,4129,4130,4135,4136,4137,4142,4143,4148,4149,4150,4155,4156,4157,4162,4163,4164,4169,4170,4171,4176,4177,4178,4183,4184,4185,4190,4191,4192,4197,4202,4203,4204,4209,4214,4219,4220,4221,4226,4231,4232,4233,4238,4239,4240,4245,4246,4247,4252,4253,4254,4259,4260,4261,4266,4271,4272,4273,4278,4279,4280,4285,4286,4287,4292,4293,4294,4299,4300,4301,4306,4307,4308,4313,4314,4315,4320,4321,4322,4327,4328,4329,4334,4339,4340,4341,4346,4347,4348,4353,4358,4363,4364,4365,4370,4371,4372,4377,4378,4383,4384,4385,4390,4391,4392,4397,4398,4399,4404,4405,4406,4411,4412,4413,4418,4419,4420,4425,4426,4427,4432,4433,4434,4439,4440,4441,4446,4447,4448,4453,4454,4455,4460,4465,4470,4471,4472,4477,4478,4479,4484,4485,4486,4491,4496,4497,4502,4503,4504,4509,4510,4511,4516,4517,4518,4523,4528,4529,4530,4535,4536,4537,4542,4543,4544,4549,4550,4551,4556,4557,4558,4563,4564,4565,4570,4571,4572,4577,4578,4579,4584,4585,4586,4591,4592,4593,4598,4599,4600,4605,4606,4607,4612,4613,4614,4619,4620,4621,4626,4627,4628,4633,4634,4635,4640,4641,4642,4647,4648,4649,4654,4659,4660,4661,4666,4667,4672,4673,4674,4679,4680,4681,4686,4687,4688,4693,4694,4695,4700,4705,4706,4707,4712,4713,4714,4719,4720,4721,4726,4727,4728,4733,4734,4735,4740,4741,4742,4747,4748,4749,4754,4759,4760,4761,4766,4767,4768,4773,4774,4775,4780,4785,4790,4791,4796,4797,4798,4803,4804,4805,4810,4815,4816,4817,4822,4823,4824,4829,4830,4831,4836,4841,4842,4843,4848,4849,4854,4855,4860,4861,4866,4867,4872,4873,4874,4879,4880,4885,4886,4887,4892,4893,4894,4899,4904,4909,4910,4911,4916,4917,4918,4923,4924,4925,4930,4931,4932,4937,4938,4939,4944,4945,4946,4951,4952,4953,4958,4959,4960,4965,4966,4967,4972,4973,4974,4979,4980,4981,4986,4987,4988,4993,4994,4995,5000,5001,5006,5007,5008,5013,5014,5019,5020,5025,5026,5031,5032,5033,5038,5039,5040,5045,5046,5047,5052,5053,5054,5059,5060,5061,5066,5067,5068,5073,5078,5079,5084,5085,5086,5091,5092,5093,5098,5099,5100,5105,5106,5107,5112,5113,5114,5119,5120,5121,5126,5127,5128,5133,5134,5135,5140,5141,5142,5147,5148,5149,5154,5155,5156,5161,5162,5163,5168,5169,5174,5175,5176,5181,5182,5183,5188,5189,5190,5195,5196,5197,5202,5203,5204,5209,5210,5211,5216,5217,5218,5223,5224,5225,5230,5231,5232,5237,5238,5239,5244,5245,5246,5251,5252,5253,5258,5263,5264,5265,5270,5271,5272,5277,5278,5279,5284,5285,5286,5291,5292,5297,5298,5299,5304,5309,5310,5311,5316,5321,5322,5323,5328,5329,5330,5335,5340,5341,5342,5347,5348,5349,5354,5355,5356,5361,5362,5363,5368,5369,5370,5375,5376,5377,5382,5383,5384,5389,5390,5391,5396,5397,5398,5403,5404,5405,5410,5411,5412,5417,5422,5423,5424,5429,5430,5431,5436,5437,5438,5443,5444,5445,5450,5451,5452,5457,5458,5459,5464,5465,5466,5471,5476,5477,5478,5483,5488,5489,5490,5495,5496,5497,5502,5503,5504,5509,5510,5511,5516,5517,5518,5523,5524,5525,5530,5531,5532,5537,5538,5539,5544,5549,5550,5551,5556,5557,5558,5563,5568,5569,5570,5575,5576,5577,5582,5583,5588,5589,5590,5595,5596,5597,5602,5603,5608,5613,5614,5615,5620,5621,5622,5627,5628,5629,5634,5639,5640,5641,5646,5647,5648,5653,5654,5655,5660,5665,5666,5667,5672,5673,5674,5679,5680,5681,5686,5687,5688,5693,5698,5699,5700,5705,5706,5707,5712,5713,5714,5719,5720,5721,5726,5727,5728,5733,5734,5735,5740,5741,5742,5747,5748,5749,5754,5755,5756,5761,5762,5763,5768,5769,5770,5775,5780,5781,5782,5787,5788,5789,5794,5795,5796,5801,5802,5803,5808,5809,5810,5815,5816,5821,5822,5823,5828,5833,5838,5839,5840,5845,5846,5847,5852,5853,5854,5859,5860,5861,5866,5867,5868,5873,5874,5875,5880,5881,5882,5887,5888,5889,5894,5895,5896,5901,5902,5903,5908,5909,5910,5915,5916,5917,5922,5923,5924,5929,5930,5931,5936,5937,5938,5943,5944,5945,5950,5951,5952,5957,5962,5963,5964,5969,5970,5971,5976,5977,5982,5983,5984,5989,5990,5991,5996,5997,5998,6003,6004,6005,6010,6011,6012,6017,6022,6023,6024,6029,6030,6031,6036,6037,6038,6043,6044,6045,6050,6051,6052,6057,6058,6059,6064,6065,6066,6071,6072,6073,6078,6079,6084,6085,6090,6091,6092,6097,6098,6099,6104,6105,6106,6111,6112,6117,6118,6123,6128,6133,6134,6135,6140,6141,6142,6147,6148,6149,6154,6155,6156,6161,6162,6163,6168,6169,6170,6175,6176,6177,6182,6183,6184,6189,6190,6191,6196,6197,6202,6203,6204,6209,6210,6211,6216,6217,6218,6223,6224,6225,6230,6231,6232,6237,6238,6239,6244,6245,6246,6251,6252,6253,6258,6263,6264,6265,6270,6271,6272,6277,6278,6279,6284,6285,6286,6291,6296,6297,6298,6304,6305,6306,6311,6312,6313,6318,6319,6320,6325,6330,6331,6332,6337,6338,6339,6344,6345,6346,6351,6352,6357,6362,6363,6364,6369,6374,6379,6384,6385,6386,6391,6392,6393,6398,6399,6404,6405,6406,6411,6412,6413,6418,6423,6424,6425,6430,6431,6432,6437,6438,6439,6444,6445,6446,6451,6452,6453,6458,6463,6464,6465,6470,6471,6472,6477,6478,6483,6484,6485,6490,6491,6492,6497,6498,6499,6504,6505,6510,6511,6512,6517,6518,6519,6524,6525,6526,6531,6532,6533,6538,6539,6540,6545,6546,6547,6552,6553,6554,6559,6560,6565,6566,6567,6572,6573,6574,6579,6584,6585,6586,6591,6592,6593,6598,6599,6604,6605,6606,6611,6612,6613,6618,6619,6620,6625,6626,6627,6632,6633,6634,6639,6640,6641,6646,6647,6648,6653,6654,6655,6660,6661,6662,6667,6668,6669,6674,6679,6680,6681,6686,6687,6688,6693,6694,6695,6700,6701,6702,6707,6708,6709,6714,6715,6720,6721,6722,6727,6728,6729,6734,6735,6736,6741,6742,6743,6748,6749,6750,6755,6760,6761,6766,6767,6768,6773,6774,6775,6780,6781,6782,6787,6788,6789,6794,6795,6796,6801,6806,6807,6808,6813,6814,6815,6820,6821,6822,6827,6828,6829,6834,6835,6836,6841,6842,6843,6848,6849,6850,6855,6856,6857,6862,6863,6864,6869,6870,6875,6876,6877,6882,6883,6884,6889,6890,6891,6896,6897,6902,6903,6904,6909,6910,6911,6916,6917,6918,6923,6924,6925,6930,6931,6932,6937,6938,6939,6944,6945,6946,6951,6956,6957,6958,6963,6964,6965,6970,6971,6972,6977,6978,6979,6984,6985,6986,6991,6992,6993,6998,7003,7004,7005,7010,7015,7020,7021,7022,7027,7028,7029,7034,7039,7044,7045,7046,7051,7052,7053,7058,7059,7060,7065,7066,7067,7072,7073,7074,7079,7084,7085,7086,7091,7096,7097,7098,7103,7104,7105,7110,7111,7112,7117,7118,7119,7124,7125,7126,7131,7132,7133,7138,7139,7140,7145,7146,7147,7152,7157,7162,7168,7169,7170,7175,7176,7177,7182,7183,7184,7189,7190,7191,7196,7197,7198,7203,7204,7205,7210,7211,7212,7217,7218,7219,7224,7229,7230,7231,7236,7237,7238,7243,7244,7245,7250,7251,7256,7261,7262,7263,7268,7269,7274,7275,7280,7281,7286,7287,7292,7293,7294,7299,7300,7301,7306,7307,7312,7317,7318,7319,7324,7325,7326,7331,7332,7333,7338,7339,7340,7345,7346,7347,7352,7353,7354,7359,7360,7361,7366,7367,7368,7373,7374,7375,7380,7385,7386,7391,7392,7393,7398,7403,7404,7405,7410,7411,7412,7417,7418,7419,7424,7425,7426,7431,7432,7433,7439,7440,7441,7446,7447,7448,7453,7454,7455,7460,7461,7462,7467,7468,7469,7474,7475,7476,7481,7482,7483,7488,7493,7498,7499,7500,7505,7506,7507,7512,7513,7514,7519,7520,7521,7526,7527,7528,7533,7534,7535,7540,7541,7542,7547,7548,7549,7554,7555,7556,7561,7562,7567,7568,7569,7574,7575,7576,7581,7582,7583,7588,7589,7590,7595,7596,7597,7602,7603,7604,7609,7610,7611,7616,7617,7618,7623,7624,7625,7630,7631,7636,7637,7638,7643,7644,7645,7650,7651,7652,7657,7658,7659,7664,7665,7666,7671,7672,7673,7678,7679,7680,7685,7686,7687,7692,7693,7694,7699,7704,7705,7706,7711,7712,7713,7718,7719,7724,7725,7726,7731,7732,7733,7738,7739,7740,7745,7746,7751,7752,7753,7758,7759,7760,7765,7766,7767,7772,7773,7774,7779,7780,7781,7786,7791,7792,7793,7798,7799,7800,7805,7806,7807,7812,7813,7814,7819,7820,7825,7826,7827,7832,7833,7834,7839,7840,7841,7846,7847,7848,7853,7854,7855,7860,7861,7862,7867,7868,7869,7874,7879,7880,7881,7886,7887,7888,7893,7894,7895,7900,7901,7902,7907,7908,7909,7914,7915,7916,7921,7922,7923,7928,7929,7930,7935,7936,7941,7942,7943,7948,7949,7950,7955,7956,7957,7962,7963,7964,7969,7970,7971,7976,7977,7978,7983,7984,7985,7990,7995,7996,8001,8002,8003,8008,8009,8010,8015,8016,8017,8022,8023,8024,8029,8030,8031,8036,8037,8038,8043,8044,8045,8050,8051,8052,8057,8058,8059,8064,8065,8066,8071,8072,8073,8078,8079,8080,8085,8086,8087,8092,8093,8094,8099,8100,8101,8106,8107,8108,8113,8114,8115,8120,8125,8126,8127,8132,8133,8134,8139,8140,8141,8146,8147,8148,8153,8154,8155,8160,8161,8162,8167,8168,8169,8174,8175,8176,8181,8182,8183,8188,8193,8194,8195,8200,8201,8202,8207,8208,8209,8214,8215,8216,8221,8222,8223,8228,8229,8234,8235,8236,8241,8242,8243,8248,8249,8250,8255,8260,8261,8262,8267,8268,8269,8274,8275,8276,8281,8282,8283,8288,8289,8290,8295,8296,8297,8302,8303,8304,8309,8310,8311,8316,8317,8318,8323,8324,8325,8330,8331,8332,8337,8338,8339,8344,8349,8350,8351,8356,8357,8358,8363,8364,8365,8370,8371,8372,8377,8378,8379,8384,8385,8386,8391,8392,8393,8398,8399,8400,8405,8406,8407,8412,8413,8414,8419,8420,8421,8426,8427,8428,8433,8434,8435,8440,8441,8442,8447,8448,8449,8454,8455,8456,8461,8462,8463,8468,8473,8474,8475,8480,8481,8482,8487,8488,8489,8494,8499,8500,8501,8506,8507,8508,8513,8514,8515,8520,8521,8522,8527,8528,8529,8534,8535,8536,8541,8542,8543,8548,8549,8550,8555,8556,8557,8562,8563,8564,8569,8570,8571,8576,8577,8578,8583,8584,8585,8590,8591,8592,8597,8602,8607,8608,8609,8614,8615,8616,8621,8622,8623,8628,8629,8630,8635,8636,8637,8642,8643,8644,8649,8650,8651,8656,8657,8658,8663,8664,8665,8670,8671,8672,8677,8678,8679,8684,8685,8686,8691,8692,8693,8698,8699,8700,8705,8706,8707,8712,8713,8714,8719,8720,8721,8726,8727,8728,8733,8734,8739,8740,8741,8746,8747,8748,8753,8754,8755,8760,8761,8762,8767,8768,8769,8774,8779,8780,8781,8786,8787,8788,8793,8794,8795,8800,8805,8806,8811,8812,8813,8818,8819,8824,8825,8826,8831,8832,8833,8838,8839,8840,8845,8846,8847,8852,8853,8854,8859,8860,8861,8866,8867,8868,8873,8874,8875,8880,8881,8882,8887,8888,8889,8894,8895,8896,8901,8902,8903,8908,8909,8910,8915,8916,8917,8922,8923,8924,8929,8930,8935,8936,8937,8942,8943,8944,8949,8950,8951,8956,8961,8962,8963,8968,8969,8970,8975,8976,8977,8982,8983,8984,8989,8990,8991,8996,8997,8998,9003,9004,9005,9010,9011,9012,9017,9018,9019,9024,9025,9026,9031,9032,9033,9038,9039,9040,9045,9046,9047,9052,9053,9054,9059,9064,9065,9070,9071,9072,9077,9078,9083,9084,9085,9090,9091,9092,9097,9098,9099,9104,9105,9106,9111,9112,9113,9118,9119,9120,9125,9126,9127,9132,9133,9134,9139,9140,9141,9146,9147,9148,9153,9154,9155,9160,9161,9162,9167,9168,9169,9174,9175,9176,9181,9182,9183,9188,9189,9190,9195,9196,9197,9202,9203,9204,9209,9210,9211,9216,9217,9218,9223,9224,9225,9230,9231,9232,9237,9238,9239,9244,9245,9246,9251,9252,9253,9258,9259,9260,9265,9266,9267,9272,9273,9278,9279,9280,9285,9286,9287,9292,9297,9298,9299,9304,9305,9306,9311,9312,9313,9318,9319,9320,9325,9326,9327,9332,9333,9334,9339,9340,9341,9346,9347,9348,9354,9355,9356,9361,9362,9363,9368,9369,9374,9379,9380,9381,9386,9387,9388,9393,9394,9399,9400,9401,9406,9407,9408,9413,9414,9415,9420,9425,9426,9427,9432,9433,9434,9439,9440,9441,9446,9447,9448,9453,9454,9455,9460,9461,9462,9467,9468,9469,9474,9479,9480,9481,9486,9487,9488,9493,9494,9495,9500,9505,9506,9507,9512,9513,9518,9519,9524,9529,9534,9535,9536,9541,9542,9543,9548,9549,9550,9555,9556,9557,9562,9563,9564,9569,9574,9575,9576,9581,9582,9583,9588,9589,9590,9595,9600,9601,9602,9607,9612,9613,9618,9619,9620,9625,9626,9627,9632,9633,9634,9639,9640,9641,9646,9647,9652,9653,9658,9659,9660,9665,9670,9671,9672,9677,9678,9679,9684,9685,9686,9691,9692,9693,9698,9699,9704,9709,9710,9711,9716,9717,9722,9723,9728,9729,9730,9735,9736,9737,9742,9743,9744,9749,9750,9751,9756,9757,9762,9763,9768,9769,9774,9775,9776,9781,9782,9783,9788,9789,9790,9795,9800,9801,9802,9807,9808,9809,9815,9816,9817,9822,9827,9828,9833,9834,9835,9840,9841,9842,9847,9848,9849,9854,9855,9856,9861,9866,9867,9868,9873,9874,9875,9880,9881,9882,9887,9892,9893,9894,9899,9900,9901,9906,9907,9908,9913,9914,9915,9920,9921,9922,9927,9928,9933,9934,9935,9940,9945,9946,9947,9952,9953,9954,9959,9964,9965,9966,9971,9972,9973,9978,9979,9980,9985,9986,9987,9992,9993,9994,9999,10000,10001,10006,10007,10008,10013,10018,10019,10024,10029,10034,10035,10036,10041,10042,10043,10049,10050,10051,10056,10057,10058,10063,10064,10065,10070,10071,10072,10077,10078,10079,10084,10085,10086,10091,10096,10097,10098,10103,10104,10105,10110,10111,10112,10117,10118,10119,10124,10125,10126,10131,10132,10133,10138,10139,10140,10145,10146,10147,10152,10153,10154,10159,10160,10161,10166,10167,10168,10173,10174,10175,10180,10181,10182,10187,10188,10189,10194,10195,10196,10201,10202,10203,10208,10209,10210,10215,10216,10217,10222,10223,10224,10229,10230,10231,10236,10237,10242,10243,10244,10249,10250,10251,10256,10257,10258,10263,10264,10265,10270,10271,10272,10277,10282,10283,10284,10289,10290,10291,10296,10301,10302,10307,10308,10309,10314,10315,10316,10321,10322,10323,10328,10329,10330,10335,10340,10345,10346,10347,10352,10353,10358,10359,10364,10365,10366,10371,10372,10373,10378,10383,10384,10385,10390,10391,10392,10397,10398,10399,10404,10405,10406,10411,10412,10413,10418,10419,10420,10425,10426,10427,10432,10433,10434,10439,10440,10441,10446,10447,10448,10453,10458,10459,10460,10465,10470,10471,10472,10477,10478,10479,10484,10485,10486,10491,10492,10493,10498,10499,10500,10505,10506,10511,10512,10513,10518,10519,10520,10525,10526,10527,10532,10537,10538,10539,10544,10545,10546,10551,10552,10553,10558,10559,10560,10565,10566,10567,10572,10573,10574,10579,10584,10585,10590,10591,10596,10597,10598,10603,10608,10609,10610,10615,10616,10621,10622,10623,10628,10629,10634,10639,10640,10641,10646,10647,10648,10653,10654,10655,10660,10661,10662,10667,10672,10673,10678,10679,10680,10685,10686,10687,10692,10693,10694,10699,10700,10701,10706,10707,10708,10713,10714,10715,10720,10721,10726,10727,10728,10733,10734,10735,10740,10741,10742,10747,10748,10749,10754,10759,10760,10761,10766,10767,10768,10773,10774,10775,10780,10781,10786,10787,10788,10793,10794,10795,10800,10801,10802,10807,10808,10809,10814,10819,10820,10821,10826,10827,10832,10833,10834,10839,10840,10841,10846,10847,10848,10853,10854,10855,10860,10861,10862,10867,10868,10869,10874,10879,10880,10881,10886,10887,10888,10893,10894,10895,10900,10901,10902,10907,10908,10909,10914,10919,10920,10921,10926,10927,10928,10933,10934,10939,10940,10941,10946,10947,10948,10953,10954,10955,10960,10961,10962,10967,10968,10969,10974,10975,10976,10981,10982,10983,10988,10989,10990,10995,10996,10997,11002,11007,11008,11009,11014,11015,11016,11021,11022,11023,11028,11029,11030,11035,11036,11037,11042,11043,11044,11049,11050,11051,11056,11061,11062,11063,11068,11073,11078,11083,11084,11085,11090,11091,11092,11097,11098,11099,11104,11105,11106,11111,11112,11113,11118,11119,11120,11125,11130,11131,11132,11137,11138,11139,11144,11145,11146,11151,11152,11153,11158,11159,11160,11165,11166,11167,11172,11173,11174,11179,11180,11181,11186,11187,11188,11193,11194,11195,11200,11201,11202,11207,11212,11213,11214,11219,11220,11221,11226,11227,11228,11233,11234,11235,11240,11241,11242,11247,11248,11249,11254,11255,11256,11261,11266,11267,11268,11273,11274,11279,11284,11285,11286,11291,11292,11293,11298,11299,11300,11305,11306,11311,11312,11313,11318,11319,11320,11325,11326,11327,11332,11333,11334,11339,11340,11341,11346,11347,11348,11353,11354,11355,11360,11361,11362,11367,11368,11369,11374,11375,11376,11381,11386,11387,11388,11393,11394,11395,11400,11401,11402,11407,11408,11409,11414,11415,11416,11421,11422,11427,11428,11429,11434,11435,11436,11441,11442,11443,11448,11449,11450,11455,11456,11457,11462,11463,11464,11469,11470,11471,11476,11477,11478,11483,11484,11485,11490,11491,11496,11497,11498,11503,11508,11513,11514,11515,11520,11525,11530,11531,11536,11541,11542,11547,11548,11549,11554,11555,11556,11561,11562,11563,11568,11569,11574,11575,11580,11585,11586,11587,11592,11593,11594,11599,11600,11601,11606,11607,11608,11613,11614,11615,11620,11625,11626,11627,11632,11637,11638,11639,11644,11649,11654,11655,11656,11661,11662,11663,11668,11669,11670,11675,11676,11677,11682,11683,11688,11689,11690,11695,11696,11697,11702,11703,11708,11709,11710,11716,11717,11718,11723,11724,11725,11730,11731,11732,11737,11738,11739,11744,11745,11746,11751,11756,11757,11758,11763,11764,11769,11770,11775,11776,11777,11782,11783,11784,11789,11790,11791,11796,11797,11798,11803,11804,11805,11811,11812,11813,11818,11819,11820,11825,11826,11827,11832,11833,11834,11839,11840,11841,11846,11847,11848,11853,11854,11855,11860,11861,11862,11868,11869],{"cveId":38,"releaseId":31,"cycle":32,"description":39,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":43,"url":44},"CVE-2026-63806","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()\n\nDrop a BUG_ON() that has been reachable since it was first added, way back\nin 2009, and instead use get_unaligned() to perform potentially-unaligned\naccesses.\n\nFor a given store, KVM x86's emulator tracks the entire value in the\ndestination operand, x86_emulate_ctxt.dst.  If the destination is memory,\nand the target splits multiple pages and\u002For","HIGH",7.1,false,"2026-07-19T12:16:53.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-63806",{"cveId":38,"releaseId":17,"cycle":18,"description":39,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":43,"url":44},{"cveId":38,"releaseId":25,"cycle":26,"description":39,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":43,"url":44},{"cveId":48,"releaseId":31,"cycle":32,"description":49,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":51,"url":52},"CVE-2026-63803","In the Linux kernel, the following vulnerability has been resolved:\n\nhdlc_ppp: sync per-proto timers before freeing hdlc state\n\nEach PPP control protocol (LCP\u002FIPCP\u002FIPV6CP) embedded in struct ppp\nregisters a timer via timer_setup(). That struct ppp is the\nhdlc->state allocation, which detach_hdlc_protocol() frees with kfree()\nin both teardown paths: unregister_hdlc_device() and the re-attach inside\nattach_hdlc_protocol().\n\nThe ppp proto never registered a .detach callback, so\ndetach_hdlc_protocol",7.8,"2026-07-19T12:16:52.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-63803",{"cveId":48,"releaseId":17,"cycle":18,"description":49,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":51,"url":52},{"cveId":48,"releaseId":25,"cycle":26,"description":49,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":51,"url":52},{"cveId":56,"releaseId":31,"cycle":32,"description":57,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":60,"url":61},"CVE-2026-63798","In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip\u002Fimgpdc: Fix resource leak, add missing chained handler cleanup on remove\n\nThe driver allocates domain generic chips using\nirq_alloc_domain_generic_chips() during probe and sets up chained\nhandlers using irq_set_chained_handler_and_data(). However, on driver\nremoval, the generic chips are not freed and the chained handlers are\nnot removed.\n\nThe generic chips remain on the global gc_list and may later be accessed by\ngener","MEDIUM",5.5,"2026-07-19T12:16:52.303+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-63798",{"cveId":56,"releaseId":17,"cycle":18,"description":57,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":60,"url":61},{"cveId":56,"releaseId":25,"cycle":26,"description":57,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":60,"url":61},{"cveId":65,"releaseId":31,"cycle":32,"description":66,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":68,"url":69},"CVE-2026-63796","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reject oversized group bitmap descriptors\n\nocfs2_validate_gd_parent() only bounds bg_bits against the parent\nallocator's chain geometry.  A malicious descriptor can still claim a\nbg_size\u002Fbg_bits pair that exceeds the bitmap bytes that physically fit in\nthe group descriptor block, so later bitmap scans and bit updates can run\npast bg_bitmap.\n\nAdd a physical-cap check based on ocfs2_group_bitmap_size() for the parent\nalloc",8.8,"2026-07-19T12:16:52.033+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-63796",{"cveId":65,"releaseId":17,"cycle":18,"description":66,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":68,"url":69},{"cveId":65,"releaseId":25,"cycle":26,"description":66,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":68,"url":69},{"cveId":73,"releaseId":17,"cycle":18,"description":74,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":75,"url":76},"CVE-2026-63794","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path\n\nIn sev_dbg_crypt(), the per-iteration transfer length is bounded by\nthe source page offset (PAGE_SIZE - s_off) but not by the destination\npage offset (PAGE_SIZE - d_off).  When d_off > s_off, the encrypt\npath (__sev_dbg_encrypt_user) performs a read-modify-write using a\nsingle-page intermediate buffer (dst_tpage):\n\n  1. __sev_dbg_decrypt() expands the size to roun","2026-07-19T12:16:51.757+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-63794",{"cveId":78,"releaseId":31,"cycle":32,"description":79,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":80,"url":81},"CVE-2026-53403","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var\n\ninfo->var, a framebuffer's current mode, is expected to have a matching\nentry in info->modelist. var_to_display() relies on this and treats a\nfailed fb_match_mode() as \"This should not happen\". fb_set_var() keeps it\ntrue by adding the mode to the list on every change, and\ndo_register_framebuffer() does the same at registration.\n\nstore_modes() replaces ","2026-07-19T12:16:51.51+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53403",{"cveId":78,"releaseId":17,"cycle":18,"description":79,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":80,"url":81},{"cveId":78,"releaseId":25,"cycle":26,"description":79,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":80,"url":81},{"cveId":85,"releaseId":31,"cycle":32,"description":86,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":87,"url":88},"CVE-2026-53401","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: omap2: fix use-after-free in omapfb_mmap\n\nomapfb_mmap() has a race condition with OMAPFB_SETUP_PLANE ioctl that\ncan lead to use-after-free:\n\nThe fb_mmap() entry point holds mm_lock but not lock (fb_info->lock),\nwhile ioctl handlers like OMAPFB_SETUP_PLANE hold lock but not mm_lock.\nThis allows concurrent execution.\n\nIn omapfb_mmap():\n1. rg = omapfb_get_mem_region(ofbi->region);      \u002F\u002F Get old region ref\n2. start = omapf","2026-07-19T12:16:51.287+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53401",{"cveId":85,"releaseId":17,"cycle":18,"description":86,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":87,"url":88},{"cveId":85,"releaseId":25,"cycle":26,"description":86,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":87,"url":88},{"cveId":92,"releaseId":31,"cycle":32,"description":93,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":94,"url":95},"CVE-2026-53400","In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter registration race\n\nAdapters can be looked up based on their id using i2c_get_adapter()\nwhich takes a reference to the embedded struct device.\n\nMake sure that the adapter (including its struct device) has been\ninitialised before adding it to the IDR to avoid accessing uninitialised\ndata which could, for example, lead to NULL-pointer dereferences or\nuse-after-free.\n\nNote that the i2c-dev chardev, which is r","2026-07-19T12:16:51.177+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53400",{"cveId":92,"releaseId":17,"cycle":18,"description":93,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":94,"url":95},{"cveId":92,"releaseId":25,"cycle":26,"description":93,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":94,"url":95},{"cveId":99,"releaseId":31,"cycle":32,"description":100,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":103,"url":104},"CVE-2026-53399","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: release layout stid on setlease failure\n\nnfs4_alloc_stid() publishes the new stid into cl->cl_stateids via\nidr_alloc_cyclic() under cl_lock before returning to\nnfsd4_alloc_layout_stateid(). When nfsd4_layout_setlease() then\nfails, the error path frees the layout stateid directly with\nkmem_cache_free() without ever calling idr_remove(), leaving the\nIDR slot pointing at freed slab memory. Any subsequent IDR walker\n(states_s","CRITICAL",9.8,"2026-07-19T12:16:51.063+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53399",{"cveId":99,"releaseId":17,"cycle":18,"description":100,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":103,"url":104},{"cveId":99,"releaseId":25,"cycle":26,"description":100,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":103,"url":104},{"cveId":108,"releaseId":31,"cycle":32,"description":109,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":111,"url":112},"CVE-2026-53397","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix posix_acl leak on SETACL decode failure\n\nnfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() each\ncall nfs_stream_decode_acl() twice, first for NFS_ACL and then for\nNFS_DFACL.  Each successful call transfers ownership of a freshly\nallocated posix_acl into argp->acl_access or argp->acl_default.  If\nthe first call succeeds but the second fails, the decoder returns\nfalse and argp->acl_access is left dangling.\n\n",7.5,"2026-07-19T12:16:50.793+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53397",{"cveId":108,"releaseId":17,"cycle":18,"description":109,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":111,"url":112},{"cveId":108,"releaseId":25,"cycle":26,"description":109,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":111,"url":112},{"cveId":116,"releaseId":31,"cycle":32,"description":117,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":118,"url":119},"CVE-2026-53392","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4\u002Fflexfiles: reject zero filehandle version count\n\nff_layout_alloc_lseg() decodes the filehandle-version array count\nfrom the flexfiles layout body. The value is used as the count for\nkzalloc_objs(), and the current code only rejects NULL.\n\nA zero count yields ZERO_SIZE_PTR, which can be stored in\ndss_info->fh_versions even though later flexfiles paths assume that at\nleast one filehandle version exists.\n\nReject fh_count == ","2026-07-19T12:16:50.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53392",{"cveId":116,"releaseId":17,"cycle":18,"description":117,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":118,"url":119},{"cveId":116,"releaseId":25,"cycle":26,"description":117,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":118,"url":119},{"cveId":123,"releaseId":31,"cycle":32,"description":124,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":125,"url":126},"CVE-2026-53391","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4\u002FpNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr\n\nnfs4_decode_mp_ds_addr() decodes the r_netid and r_addr opaques of a\nnetaddr4 from a GETDEVICEINFO multipath-DS body, then immediately\ncalls strrchr(buf, '.') to locate the port separator. Both decodes\nuse xdr_stream_decode_string_dup(), and the current code checks only\n\"nlen \u003C 0\" \u002F \"rlen \u003C 0\" before dereferencing the returned string.\n\nWhen the on-wire opaque has ","2026-07-19T12:16:50.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53391",{"cveId":123,"releaseId":17,"cycle":18,"description":124,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":125,"url":126},{"cveId":123,"releaseId":25,"cycle":26,"description":124,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":125,"url":126},{"cveId":130,"releaseId":31,"cycle":32,"description":131,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":132,"url":133},"CVE-2026-53388","In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before replacing page cache folio\n\nfuse_try_move_folio() unlocks the request on entry but does not\nre-lock it on the success path. This means fuse_chan_abort() can end the\nrequest and free the fuse_io_args (eg fuse_readpages_end()) while the\nsubsequent copy chain logic after fuse_try_move_folio() accesses the\nfuse_io_args, leading to use-after-free issues.\n\nFix this by calling lock_request() before replace","2026-07-19T12:16:49.757+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53388",{"cveId":130,"releaseId":17,"cycle":18,"description":131,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":132,"url":133},{"cveId":130,"releaseId":25,"cycle":26,"description":131,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":132,"url":133},{"cveId":137,"releaseId":25,"cycle":26,"description":138,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":139,"url":140},"CVE-2026-53385","In the Linux kernel, the following vulnerability has been resolved:\n\nvc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write\n\nA KASAN null-ptr-deref was observed in vcs_notifier():\n\nBUG: KASAN: null-ptr-deref in vcs_notifier+0x98\u002F0x130\nRead of size 2 at addr qmp_cmd_name: qmp_capabilities, arguments: {}\n\nThe issue is a race condition in vcs_write(). When the console_lock is\ntemporarily dropped (to copy data from userspace), the vc_data pointer\nobtained from vcs_vc() may becom","2026-07-19T12:16:49.387+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53385",{"cveId":137,"releaseId":17,"cycle":18,"description":138,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":139,"url":140},{"cveId":143,"releaseId":17,"cycle":18,"description":144,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":145,"url":146},"CVE-2026-53376","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdkfd: Add upper bound check for num_of_nodes\n\ndrm\u002Famdkfd: Add upper bound check for num_of_nodes\nin kfd_ioctl_get_process_apertures_new.\n\n(cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)","2026-07-19T11:16:38.74+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53376",{"cveId":148,"releaseId":31,"cycle":32,"description":149,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":150,"url":151},"CVE-2026-53375","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu\u002Fvce: Prevent partial address patches\n\nIn the case that only one of lo\u002Fhi is valid, the patching could result\nin a bad address written to in FW.","2026-07-19T11:16:38.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53375",{"cveId":148,"releaseId":17,"cycle":18,"description":149,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":150,"url":151},{"cveId":148,"releaseId":25,"cycle":26,"description":149,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":150,"url":151},{"cveId":155,"releaseId":31,"cycle":32,"description":156,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":157,"url":158},"CVE-2026-53374","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: zero-initialize GART table on allocation\n\nGART TLB is flushed after unmapping but not after mapping. Since\namdgpu_bo_create_kernel() does not zero-initialize the buffer, when a\nsingle PTE is written the TLB may speculatively load other uninitialized\nentries from the same cacheline. Those garbage entries can appear valid,\nand a subsequent write to another PTE in the same cacheline may cause the\nGPU to use a stale gar","2026-07-19T11:16:38.5+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53374",{"cveId":155,"releaseId":17,"cycle":18,"description":156,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":157,"url":158},{"cveId":155,"releaseId":25,"cycle":26,"description":156,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":157,"url":158},{"cveId":162,"releaseId":31,"cycle":32,"description":163,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":165,"url":166},"CVE-2026-53369","In the Linux kernel, the following vulnerability has been resolved:\n\nudf: reject descriptors with oversized CRC length\n\nudf_read_tagged() skips CRC verification when descCRCLength +\nsizeof(struct tag) exceeds the block size.  A crafted UDF image can\nset descCRCLength to an oversized value to bypass CRC validation\nentirely; the descriptor is then accepted based solely on the 8-bit\ntag checksum, which is trivially recomputable.\n\nReject such descriptors instead of silently accepting them.  A\nlegiti",8.4,"2026-07-19T09:17:02.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53369",{"cveId":162,"releaseId":17,"cycle":18,"description":163,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":165,"url":166},{"cveId":162,"releaseId":25,"cycle":26,"description":163,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":165,"url":166},{"cveId":170,"releaseId":31,"cycle":32,"description":171,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":172,"url":173},"CVE-2026-53368","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage\n\nf2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion\nwith the checkpoint path, which can result in an incorrect inode block\nmarking state. The scenario is as follows:\n\ncreate & write & fsync 'file A'                 write checkpoint\n- f2fs_do_sync_file \u002F\u002F inline inode\n - f2fs_write_inode \u002F\u002F inode folio is dirty\n                             ","2026-07-19T09:17:01.903+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53368",{"cveId":170,"releaseId":17,"cycle":18,"description":171,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":172,"url":173},{"cveId":170,"releaseId":25,"cycle":26,"description":171,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":172,"url":173},{"cveId":177,"releaseId":31,"cycle":32,"description":178,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":179,"url":180},"CVE-2026-53359","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Fix shadow paging use-after-free due to unexpected role\n\nCommit 0cb2af2ea66ad (\"KVM: x86: Fix shadow paging use-after-free due\nto unexpected GFN\") fixed a shadow paging mismatch between stored and\ncomputed GFNs; the bug could be triggered by changing a PDE mapping from\noutside the guest, and then deleting a memslot.  The rmap_remove()\ncall would miss entries created after the PDE change because the GFN\nof the leaf SPT","2026-07-04T12:17:01.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53359",{"cveId":177,"releaseId":17,"cycle":18,"description":178,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":179,"url":180},{"cveId":177,"releaseId":25,"cycle":26,"description":178,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":179,"url":180},{"cveId":184,"releaseId":31,"cycle":32,"description":185,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":186,"url":187},"CVE-2026-53358","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: use chan timer to close channels in cleanup_listen()\n\nl2cap_chan_close() removes the channel from conn->chan_l, which\nmust be done under conn->lock.  cleanup_listen() runs under the\nparent sk_lock, so acquiring conn->lock would invert the\nestablished conn->lock -> chan->lock -> sk_lock order.\n\nInstead of calling l2cap_chan_close() directly, schedule\nl2cap_chan_timeout with delay 0 to close the channel\nasynchro","2026-07-02T15:17:03.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53358",{"cveId":184,"releaseId":17,"cycle":18,"description":185,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":186,"url":187},{"cveId":184,"releaseId":25,"cycle":26,"description":185,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":186,"url":187},{"cveId":191,"releaseId":31,"cycle":32,"description":192,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":193,"url":194},"CVE-2026-53355","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rds: clear i_sends on setup unwind\n\nThe RDS IB connection teardown path is written so it can run during\npartial startup and on repeated shutdown attempts. It uses NULL\npointers to distinguish resources that are still owned from resources\nthat have already been released.\n\nWhen rds_ib_setup_qp() fails after allocating i_sends but before\nallocating i_recvs, the sends_out path frees i_sends without clearing\nthe pointer. A late","2026-07-01T14:16:43.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53355",{"cveId":191,"releaseId":17,"cycle":18,"description":192,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":193,"url":194},{"cveId":191,"releaseId":25,"cycle":26,"description":192,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":193,"url":194},{"cveId":198,"releaseId":31,"cycle":32,"description":199,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":200,"url":201},"CVE-2026-53354","In the Linux kernel, the following vulnerability has been resolved:\n\narm64: errata: Mitigate TLBI errata on various Arm CPUs\n\nA number of CPUs developed by Arm suffer from errata whereby a broadcast\nTLBI;DSB sequence may complete before the global observation of writes\nwhich are translated by an affected TLB entry.\n\nThese errata ONLY affect the completion of memory accesses which have\nbeen translated by an invalidated TLB entry, and these errata DO NOT\naffect the actual invalidation of TLB entri","2026-07-01T14:16:43.627+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53354",{"cveId":198,"releaseId":17,"cycle":18,"description":199,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":200,"url":201},{"cveId":198,"releaseId":25,"cycle":26,"description":199,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":200,"url":201},{"cveId":205,"releaseId":31,"cycle":32,"description":206,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":207,"url":208},"CVE-2026-53353","In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: Remove WARN_ONCE() in hsr_addr_is_self().\n\nsyzbot reported the warning [0] in hsr_addr_is_self(),\nwhose assumption is simply wrong.\n\nhsr->self_node is cleared in hsr_del_self_node(), which\nis called from hsr_dellink().\n\nSince dev->rtnl_link_ops->dellink() is called before\nunregister_netdevice_many(), there is a window when\nuser can find the device but without hsr->self_node.\n\nLet's remove WARN_ONCE() in hsr_addr_is_self().","2026-07-01T14:16:43.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53353",{"cveId":205,"releaseId":17,"cycle":18,"description":206,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":207,"url":208},{"cveId":205,"releaseId":25,"cycle":26,"description":206,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":207,"url":208},{"cveId":212,"releaseId":31,"cycle":32,"description":213,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":215,"url":216},"CVE-2026-53352","In the Linux kernel, the following vulnerability has been resolved:\n\nsignal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()\n\nWhen a multi-threaded process receives a stop signal (e.g., SIGSTOP),\ndo_signal_stop() sets JOBCTL_STOP_PENDING and JOBCTL_STOP_CONSUME on all\nthreads and sets signal->group_stop_count to the number of threads. If\none of the threads concurrently calls execve(), de_thread() invokes\nzap_other_threads() to kill all other threads. zap_other_threads()\naborts the pe",4.7,"2026-07-01T14:16:43.347+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53352",{"cveId":212,"releaseId":17,"cycle":18,"description":213,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":215,"url":216},{"cveId":212,"releaseId":25,"cycle":26,"description":213,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":215,"url":216},{"cveId":220,"releaseId":31,"cycle":32,"description":221,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":222,"url":223},"CVE-2026-53349","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack: destroy stale expectfn expectations on unregister\n\nNAT helpers such as nf_nat_h323 store a raw pointer to module text in\nexp->expectfn (e.g. ip_nat_q931_expect). nf_ct_helper_expectfn_unregister()\nonly unlinks the callback descriptor and never walks the expectation table,\nso an expectation pending at module removal survives with a dangling\nexp->expectfn into freed module text.\n\nWhen the expected connect","2026-07-01T14:16:43.003+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53349",{"cveId":220,"releaseId":17,"cycle":18,"description":221,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":222,"url":223},{"cveId":220,"releaseId":25,"cycle":26,"description":221,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":222,"url":223},{"cveId":227,"releaseId":17,"cycle":18,"description":228,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":229,"url":230},"CVE-2026-53332","In the Linux kernel, the following vulnerability has been resolved:\n\nslimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd\n\nWhen the remoteproc starts in parallel with the NGD driver being probed,\nor the remoteproc is already up when the PDR lookup is being registered,\nor in the theoretical event that we get an interrupt from the hardware,\nthese callbacks will operate on uninitialized data. This result in\nissues to boot the affected boards.\n\nOne such example can be seen in the follow","2026-07-01T14:16:41.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53332",{"cveId":232,"releaseId":17,"cycle":18,"description":233,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":235,"url":236},"CVE-2026-53329","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Use krealloc_array() in dal_vector_reserve()\n\n[Why & How]\ndal_vector_reserve() computes the allocation size as\n\"capacity * vector->struct_size\" using uint32_t arithmetic, which can\nsilently wrap to a small value on overflow. This would cause krealloc to\nreturn a smaller buffer than expected, leading to heap overflows on\nsubsequent vector appends.\n\nReplace krealloc() with krealloc_array() which performs an inter",7,"2026-07-01T14:16:40.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53329",{"cveId":238,"releaseId":31,"cycle":32,"description":239,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":240,"url":241},"CVE-2026-53325","In the Linux kernel, the following vulnerability has been resolved:\n\nagp\u002Famd64: Fix broken error propagation in agp_amd64_probe()\n\nA NULL pointer dereference was observed in the AMD64 AGP driver when\nrunning in a virtualized environment (e.g. qemu\u002Fkvm) without a physical\nAMD northbridge. The crash occurs in amd64_fetch_size() when attempting\nto dereference the pointer returned by node_to_amd_nb(0).\n\nThe root cause of this crash is broken error propagation in\nagp_amd64_probe(): When no AMD northb","2026-06-29T06:16:33.167+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53325",{"cveId":238,"releaseId":17,"cycle":18,"description":239,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":240,"url":241},{"cveId":238,"releaseId":25,"cycle":26,"description":239,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":240,"url":241},{"cveId":245,"releaseId":31,"cycle":32,"description":246,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":247,"url":248},"CVE-2026-53320","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()\n\nnilfs_ioctl_mark_blocks_dirty() uses bd_oblocknr to detect dead blocks\nby comparing it with the current block number bd_blocknr. If they differ,\nthe block is considered dead and skipped.\n\nHowever, bd_oblocknr should never be 0 since block 0 typically stores the\nprimary superblock and is never a valid GC target block. A corrupted ioctl\nrequest with bd_oblocknr s","2026-06-26T20:17:25.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53320",{"cveId":245,"releaseId":17,"cycle":18,"description":246,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":247,"url":248},{"cveId":245,"releaseId":25,"cycle":26,"description":246,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":247,"url":248},{"cveId":252,"releaseId":17,"cycle":18,"description":253,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":254,"url":255},"CVE-2026-53314","In the Linux kernel, the following vulnerability has been resolved:\n\npadata: Put CPU offline callback in ONLINE section to allow failure\n\nsyzbot reported the following warning:\n\n    DEAD callback error for CPU1\n    WARNING: kernel\u002Fcpu.c:1463 at _cpu_down+0x759\u002F0x1020 kernel\u002Fcpu.c:1463, CPU#0: syz.0.1960\u002F14614\n\nat commit 4ae12d8bd9a8 (\"Merge tag 'kbuild-fixes-7.0-2' of git:\u002F\u002Fgit.kernel.org\u002Fpub\u002Fscm\u002Flinux\u002Fkernel\u002Fgit\u002Fkbuild\u002Flinux\")\nwhich tglx traced to padata_cpu_dead() given it's the only\nsub-CPUHP","2026-06-26T20:17:24.717+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53314",{"cveId":257,"releaseId":31,"cycle":32,"description":258,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":259,"url":260},"CVE-2026-53309","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2\u002Fdlm: fix off-by-one in dlm_match_regions() region comparison\n\nThe local-vs-remote region comparison loop uses '\u003C=' instead of '\u003C',\ncausing it to read one entry past the valid range of qr_regions.  The\nother loops in the same function correctly use '\u003C'.\n\nFix the loop condition to use '\u003C' for consistency and correctness.","2026-06-26T20:17:24.203+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53309",{"cveId":257,"releaseId":17,"cycle":18,"description":258,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":259,"url":260},{"cveId":257,"releaseId":25,"cycle":26,"description":258,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":259,"url":260},{"cveId":264,"releaseId":31,"cycle":32,"description":265,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":266,"url":267},"CVE-2026-53306","In the Linux kernel, the following vulnerability has been resolved:\n\ntty: hvc_iucv: fix off-by-one in number of supported devices\n\nMAX_HVC_IUCV_LINES == HVC_ALLOC_TTY_ADAPTERS == 8.\nThis is the number of entries in:\n  static struct hvc_iucv_private *hvc_iucv_table[MAX_HVC_IUCV_LINES];\n\nSometimes hvc_iucv_table[] is limited by:\n(a)\tif (num > hvc_iucv_devices) \u002F\u002F for error detection\nor\n(b)\tfor (i = 0; i \u003C hvc_iucv_devices; i++) \u002F\u002F in 2 places\n(so these 2 don't agree; second one appears to be corre","2026-06-26T20:17:23.877+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53306",{"cveId":264,"releaseId":17,"cycle":18,"description":265,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":266,"url":267},{"cveId":264,"releaseId":25,"cycle":26,"description":265,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":266,"url":267},{"cveId":271,"releaseId":31,"cycle":32,"description":272,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":273,"url":274},"CVE-2026-53304","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: sg: Resolve soft lockup issue when opening \u002Fdev\u002FsgX\n\nThe parameter def_reserved_size defines the default buffer size reserved\nfor each Sg_fd and should be restricted to a range between 0 and 1,048,576\n(see https:\u002F\u002Ftldp.org\u002FHOWTO\u002FSCSI-Generic-HOWTO\u002Fproc.html).  Although the\nfunction sg_proc_write_dressz enforces this limit, it is possible to bypass\nit by directly modifying the module parameter as shown below, which then\nca","2026-06-26T20:17:23.637+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53304",{"cveId":271,"releaseId":17,"cycle":18,"description":272,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":273,"url":274},{"cveId":271,"releaseId":25,"cycle":26,"description":272,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":273,"url":274},{"cveId":278,"releaseId":17,"cycle":18,"description":279,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":280,"url":281},"CVE-2026-53303","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()\n\nIn f2fs_sbi_show(), the extension_list, extension_count and\nhot_ext_count are read without holding sbi->sb_lock. If a concurrent\nsysfs store modifies the extension list via f2fs_update_extension_list(),\nthe show path may read inconsistent count and array contents, potentially\nleading to out-of-bounds access or displaying stale data.\n\nFix this by holding sb_lo","2026-06-26T20:17:23.527+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53303",{"cveId":283,"releaseId":31,"cycle":32,"description":284,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":285,"url":286},"CVE-2026-53296","In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mailbox-test: free channels on probe error\n\nOn probe error, free the previously obtained channels. This not only\nprevents a leak, but also UAF scenarios because the client structure\nwill be removed nonetheless because it was allocated with devm.","2026-06-26T20:17:22.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53296",{"cveId":283,"releaseId":17,"cycle":18,"description":284,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":285,"url":286},{"cveId":283,"releaseId":25,"cycle":26,"description":284,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":285,"url":286},{"cveId":290,"releaseId":31,"cycle":32,"description":291,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":292,"url":293},"CVE-2026-53295","In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: add sanity check for channel array\n\nFail gracefully if there is no channel array attached to the mailbox\ncontroller. Otherwise the later dereference will cause an OOPS which\nmight not be seen because mailbox controllers might instantiate very\nearly. Remove the comment explaining the obvious while here.","2026-06-26T20:17:22.427+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53295",{"cveId":290,"releaseId":17,"cycle":18,"description":291,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":292,"url":293},{"cveId":290,"releaseId":25,"cycle":26,"description":291,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":292,"url":293},{"cveId":297,"releaseId":31,"cycle":32,"description":298,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":299,"url":300},"CVE-2026-53294","In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mailbox-test: don't free the reused channel\n\nThe RX channel can be aliased to the TX channel if it has a different\nMMIO. This special case needs to be handled when freeing the channels\notherwise a double-free occurs.","2026-06-26T20:17:22.31+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53294",{"cveId":297,"releaseId":17,"cycle":18,"description":298,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":299,"url":300},{"cveId":297,"releaseId":25,"cycle":26,"description":298,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":299,"url":300},{"cveId":304,"releaseId":31,"cycle":32,"description":305,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":306,"url":307},"CVE-2026-53292","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind\n\nsyzbot reported a kernel BUG triggered from pn_socket_sendmsg() via\npn_socket_autobind():\n\n  kernel BUG at net\u002Fphonet\u002Fsocket.c:213!\n  RIP: 0010:pn_socket_autobind net\u002Fphonet\u002Fsocket.c:213 [inline]\n  RIP: 0010:pn_socket_sendmsg+0x240\u002F0x250 net\u002Fphonet\u002Fsocket.c:421\n  Call Trace:\n   sock_sendmsg_nosec+0x112\u002F0x150 net\u002Fsocket.c:797\n   __sock_sendmsg net\u002Fsocket.c:812 ","2026-06-26T20:17:22.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53292",{"cveId":304,"releaseId":17,"cycle":18,"description":305,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":306,"url":307},{"cveId":304,"releaseId":25,"cycle":26,"description":305,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":306,"url":307},{"cveId":311,"releaseId":31,"cycle":32,"description":312,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":313,"url":314},"CVE-2026-53287","In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix incorrect inheritable capability in CAPSET records\n\n__audit_log_capset() records the effective capability set into the\ninheritable field due to a copy-paste error. Every CAPSET audit\nrecord therefore reports cap_pi (process inheritable) with the value\nof cap_effective instead of cap_inheritable.\n\nThis silently corrupts audit data used for compliance and forensic\nanalysis: an attacker who modifies inheritable capabili","2026-06-26T20:17:21.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53287",{"cveId":311,"releaseId":17,"cycle":18,"description":312,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":313,"url":314},{"cveId":311,"releaseId":25,"cycle":26,"description":312,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":313,"url":314},{"cveId":318,"releaseId":31,"cycle":32,"description":319,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":320,"url":321},"CVE-2026-53284","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: only release the dirty pages io tree after successful writes\n\n[WARNING]\nWith extra warning on dirty extent buffers at umount (aka, the next\npatch in the series), test case generic\u002F388 can trigger the following\nwarning about dirty extent buffers at unmount time:\n\n  BTRFS critical (device dm-2 state E): emergency shutdown\n  BTRFS error (device dm-2 state E): error while writing out transaction: -30\n  BTRFS warning (device ","2026-06-26T20:17:20.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53284",{"cveId":318,"releaseId":17,"cycle":18,"description":319,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":320,"url":321},{"cveId":318,"releaseId":25,"cycle":26,"description":319,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":320,"url":321},{"cveId":325,"releaseId":31,"cycle":32,"description":326,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":327,"url":328},"CVE-2026-53275","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: Fix use-after-free when processing MLD queries\n\nWhen processing an MLD query, a pointer to the multicast group address\nis retrieved when initially parsing the packet. This pointer is later\ndereferenced without being reloaded despite the fact that the skb header\nmight have been reallocated following the pskb_may_pull() calls, leading\nto a use-after-free [1].\n\nFix by copying the multicast group address when the packe","2026-06-25T09:16:45.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53275",{"cveId":325,"releaseId":17,"cycle":18,"description":326,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":327,"url":328},{"cveId":325,"releaseId":25,"cycle":26,"description":326,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":327,"url":328},{"cveId":332,"releaseId":31,"cycle":32,"description":333,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":334,"url":335},"CVE-2026-53270","In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: clear the svc scheduler ptr early on edit\n\nip_vs_edit_service() while unbinding the old scheduler clears\nthe svc->scheduler ptr after the scheduler module initiates\nRCU callbacks. This can cause packets to use the old\nscheduler at the time when svc->sched_data is already freed\nafter RCU grace period.\n\nFix it by clearing the ptr early in ip_vs_unbind_scheduler(),\nbefore the done_service method schedules any RCU callbacks.\n","2026-06-25T09:16:45.123+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53270",{"cveId":332,"releaseId":17,"cycle":18,"description":333,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":334,"url":335},{"cveId":332,"releaseId":25,"cycle":26,"description":333,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":334,"url":335},{"cveId":339,"releaseId":31,"cycle":32,"description":340,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":342,"url":343},"CVE-2026-53268","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack_irc: fix possible out-of-bounds read\n\nWhen parsing fails after we've matched the command string we\nshould bail out instead of trying to match a different command.\n\nThis helper should be deprecated, given prevalence of TLS I doubt it has\nany relevance in 2026.",8.2,"2026-06-25T09:16:44.883+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53268",{"cveId":339,"releaseId":17,"cycle":18,"description":340,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":342,"url":343},{"cveId":339,"releaseId":25,"cycle":26,"description":340,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":342,"url":343},{"cveId":347,"releaseId":31,"cycle":32,"description":348,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":349,"url":350},"CVE-2026-53267","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: bail out on template ct in get eval\n\nI noticed this issue while looking at a historic syzbot report [1].\n\nA rule like the one below is enough to trigger the bug:\n\n    table ip t {\n        chain pre {\n            type filter hook prerouting priority raw;\n            ct zone set 1\n            ct original saddr 1.2.3.4 accept\n        }\n    }\n\nThe first expression attaches a per-cpu template ct via\nnft_ct_set_zon","2026-06-25T09:16:44.77+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53267",{"cveId":347,"releaseId":17,"cycle":18,"description":348,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":349,"url":350},{"cveId":347,"releaseId":25,"cycle":26,"description":348,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":349,"url":350},{"cveId":354,"releaseId":17,"cycle":18,"description":355,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":356,"url":357},"CVE-2026-53264","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: act_api: use RCU with deferred freeing for action lifecycle\n\nWhen NEWTFILTER and DELFILTER are run concurrently it is possible to create a\nrace with an associated action.\n\nLet's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:\n\n 0: mutex_lock() \u003C-- holds the idr lock\n 0: rcu_read_lock()\n 0: p = idr_find(idr, index) \u003C-- action p is valid (RCU protects IDR)\n 0: mutex_unlock() \u003C-- releases the idr loc","2026-06-25T09:16:44.4+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53264",{"cveId":354,"releaseId":25,"cycle":26,"description":355,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":356,"url":357},{"cveId":360,"releaseId":31,"cycle":32,"description":361,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":362,"url":363},"CVE-2026-53263","In the Linux kernel, the following vulnerability has been resolved:\n\n6lowpan: fix off-by-one in multicast context address compression\n\nThe second memcpy in lowpan_iphc_mcast_ctx_addr_compress() uses\n&data[1] as destination and &ipaddr->s6_addr[11] as source, but\nboth should be offset by one: &data[2] and &ipaddr->s6_addr[12]\nrespectively.\n\nThis off-by-one has two consequences:\n1. data[1] is overwritten with s6_addr[11], corrupting the RIID\n   field in the compressed multicast address\n2. data[5] ","2026-06-25T09:16:44.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53263",{"cveId":360,"releaseId":17,"cycle":18,"description":361,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":362,"url":363},{"cveId":360,"releaseId":25,"cycle":26,"description":361,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":362,"url":363},{"cveId":367,"releaseId":31,"cycle":32,"description":368,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":369,"url":370},"CVE-2026-53262","In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()\n\npppol2tp_ioctl() read sock->sk->sk_user_data directly without any\nlocks or reference counting.  If a controllable sleep was induced during\ncopy_from_user() (e.g. via a userfaultfd page fault sleep), a concurrent\nsocket close could trigger pppol2tp_session_close() asynchronously.  This\nfrees the l2tp_session structure via the l2tp_session_del_work workqueue.\nUpon res","2026-06-25T09:16:44.19+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53262",{"cveId":367,"releaseId":17,"cycle":18,"description":368,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":369,"url":370},{"cveId":367,"releaseId":25,"cycle":26,"description":368,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":369,"url":370},{"cveId":374,"releaseId":31,"cycle":32,"description":375,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":377,"url":378},"CVE-2026-53256","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()\n\nrfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list lock,\nbut returns the selected listener after dropping that lock without\ntaking a reference. rfcomm_connect_ind() then locks the listener,\nqueues a child socket on it, and may notify it after unlocking it.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nr",8,"2026-06-25T09:16:43.593+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53256",{"cveId":374,"releaseId":17,"cycle":18,"description":375,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":377,"url":378},{"cveId":374,"releaseId":25,"cycle":26,"description":375,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":377,"url":378},{"cveId":382,"releaseId":31,"cycle":32,"description":383,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":384,"url":385},"CVE-2026-53255","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: validate advertising TLV before type checks\n\ntlv_data_is_valid() reads each advertising data field length from\ndata[i], then inspects data[i + 1] for managed EIR types before\nchecking that the current field still fits inside the supplied buffer.\n\nA malformed field whose length byte is the last byte of the buffer can\ntherefore make the parser read one byte past the advertising data.\n\nKASAN reported the following","2026-06-25T09:16:43.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53255",{"cveId":382,"releaseId":17,"cycle":18,"description":383,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":384,"url":385},{"cveId":382,"releaseId":25,"cycle":26,"description":383,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":384,"url":385},{"cveId":389,"releaseId":31,"cycle":32,"description":390,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":392,"url":393},"CVE-2026-53254","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: validate skb length in MCC handlers\n\nThe RFCOMM MCC handlers cast skb->data to protocol-specific structs\nwithout validating skb->len first. A malicious remote device can send\ntruncated MCC frames and trigger out-of-bounds reads in these handlers.\n\nFix this by using skb_pull_data() to validate and access the required\ndata before dereferencing it.\n\nrfcomm_recv_rpn() requires special handling since ETSI TS 07.10",8.1,"2026-06-25T09:16:43.373+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53254",{"cveId":389,"releaseId":17,"cycle":18,"description":390,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":392,"url":393},{"cveId":389,"releaseId":25,"cycle":26,"description":390,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":392,"url":393},{"cveId":397,"releaseId":31,"cycle":32,"description":398,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":399,"url":400},"CVE-2026-53253","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bnep: reject short frames before parsing\n\nA BNEP peer can send a short BNEP SDU. bnep_rx_frame() reads the\npacket type byte immediately and, for control packets, reads the control\nopcode and setup UUID-size byte before proving that those bytes are\npresent. bnep_rx_control() also dereferences the control opcode without\nrejecting an empty control payload.\n\nUse skb_pull_data() for the fixed fields in bnep_rx_frame() so ","2026-06-25T09:16:43.253+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53253",{"cveId":397,"releaseId":17,"cycle":18,"description":398,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":399,"url":400},{"cveId":397,"releaseId":25,"cycle":26,"description":398,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":399,"url":400},{"cveId":404,"releaseId":31,"cycle":32,"description":405,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":406,"url":407},"CVE-2026-53249","In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: restrict IPOPT_SSRR and IPOPT_LSRR options\n\nThis patch restricts setting Loose Source and Record Route (LSRR)\nand Strict Source and Record Route (SSRR) IP options to users\nwith CAP_NET_RAW capability.\n\nThis prevents unprivileged applications from forcing packets to route\nthrough attacker-controlled nodes to leak TCP ISN and possibly other\nprotocol information.\n\nWhile LSRR and SSRR are commonly filtered in many network env","2026-06-25T09:16:42.847+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53249",{"cveId":404,"releaseId":17,"cycle":18,"description":405,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":406,"url":407},{"cveId":404,"releaseId":25,"cycle":26,"description":405,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":406,"url":407},{"cveId":411,"releaseId":31,"cycle":32,"description":412,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":413,"url":414},"CVE-2026-53246","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate cached peer INIT chunk length in COOKIE_ECHO processing\n\nWhen a listening SCTP server processes a COOKIE_ECHO chunk, the cached\npeer INIT chunk embedded after the cookie is parsed and its parameters\nare later walked by sctp_process_init() using sctp_walk_params().\n\nHowever, the chunk header length of this cached INIT chunk was not\nvalidated against the remaining buffer in the COOKIE_ECHO payload. If\nthe length fi","2026-06-25T09:16:42.567+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53246",{"cveId":411,"releaseId":17,"cycle":18,"description":412,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":413,"url":414},{"cveId":411,"releaseId":25,"cycle":26,"description":412,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":413,"url":414},{"cveId":418,"releaseId":31,"cycle":32,"description":419,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":420,"url":421},"CVE-2026-53245","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002F802\u002Fmrp: fix vector attribute parsing in mrp_pdu_parse_vecattr\n\nIn mrp_pdu_parse_vecattr(), vector attribute events are encoded three\nper byte and valen tracks the number of events left to process.\n\nThe parser decrements valen after processing the first and second events\nfrom each event byte, but not after processing the third one. When valen\nis exactly a multiple of three, the loop continues after the last valid\nevent and ","2026-06-25T09:16:42.443+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53245",{"cveId":418,"releaseId":17,"cycle":18,"description":419,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":420,"url":421},{"cveId":418,"releaseId":25,"cycle":26,"description":419,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":420,"url":421},{"cveId":425,"releaseId":31,"cycle":32,"description":426,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":427,"url":428},"CVE-2026-53238","In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: validate unlabeled address and mask attribute lengths\n\nnetlbl_unlabel_addrinfo_get() used the address attribute length to\ndetermine whether the attribute data could be read as an IPv4 or IPv6\naddress, but did not independently validate the corresponding mask\nattribute length.  A crafted Generic Netlink request could therefore\nprovide a valid IPv4\u002FIPv6 address attribute with a shorter mask\nattribute, which would later ","2026-06-25T09:16:41.713+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53238",{"cveId":425,"releaseId":17,"cycle":18,"description":426,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":427,"url":428},{"cveId":425,"releaseId":25,"cycle":26,"description":426,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":427,"url":428},{"cveId":432,"releaseId":17,"cycle":18,"description":433,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":434,"url":435},"CVE-2026-53237","In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mvebu: fix NULL pointer dereference in suspend\u002Fresume\n\nmvebu_pwm_suspend() and mvebu_pwm_resume() are called for all GPIO\nbanks during suspend\u002Fresume, but not all banks have PWM functionality.\nGPIO banks without PWM have mvchip->mvpwm set to NULL.\n\nCalling mvebu_pwm_suspend() with mvpwm == NULL causes a NULL pointer\ndereference when it tries to access mvpwm->blink_select.\n\n  Unable to handle kernel NULL pointer dereferenc","2026-06-25T09:16:41.597+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53237",{"cveId":432,"releaseId":25,"cycle":26,"description":433,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":434,"url":435},{"cveId":438,"releaseId":17,"cycle":18,"description":439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":440,"url":441},"CVE-2026-53236","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: restrict SO_ATTACH_FILTER to priv users\n\nThis patch restricts the use of SO_ATTACH_FILTER (cBPF) on TCP sockets\nto users with CAP_NET_ADMIN capability.\n\nThis blocks potential side-channel attack where an unprivileged application\nattaches a filter to leak TCP sequence\u002Facknowledgment numbers.","2026-06-25T09:16:41.493+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53236",{"cveId":438,"releaseId":31,"cycle":32,"description":439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":440,"url":441},{"cveId":438,"releaseId":25,"cycle":26,"description":439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":440,"url":441},{"cveId":445,"releaseId":31,"cycle":32,"description":446,"severity":40,"cvssScore":447,"epssScore":9,"inKev":42,"publishedAt":448,"url":449},"CVE-2026-53230","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list\n\nmlx5_query_nic_vport_mac_list() sizes its firmware command buffer using\nthe PF's log_max_current_uc\u002Fmc_list capabilities. When querying a VF\nvport with a larger configured max (via devlink), the firmware response\ncan overflow this buffer:\n\n BUG: KASAN: slab-out-of-bounds in mlx5_query_nic_vport_mac_list+0x453\u002F0x4c0 [mlx5_core]\n Read of size 4 at addr ff1100013ff",8.7,"2026-06-25T09:16:40.907+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53230",{"cveId":445,"releaseId":17,"cycle":18,"description":446,"severity":40,"cvssScore":447,"epssScore":9,"inKev":42,"publishedAt":448,"url":449},{"cveId":445,"releaseId":25,"cycle":26,"description":446,"severity":40,"cvssScore":447,"epssScore":9,"inKev":42,"publishedAt":448,"url":449},{"cveId":453,"releaseId":31,"cycle":32,"description":454,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":455,"url":456},"CVE-2026-53228","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sit: reload inner IPv6 header after GSO offloads\n\nipip6_tunnel_xmit() caches the inner IPv6 header pointer at function\nentry and continues using it after iptunnel_handle_offloads().\n\nFor GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone().\nWhen the skb header is cloned, skb_header_unclone() can call\npskb_expand_head(), which may move the skb head. The pskb_expand_head()\ncontract requires pointers into the skb ","2026-06-25T09:16:40.657+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53228",{"cveId":453,"releaseId":17,"cycle":18,"description":454,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":455,"url":456},{"cveId":453,"releaseId":25,"cycle":26,"description":454,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":455,"url":456},{"cveId":460,"releaseId":31,"cycle":32,"description":461,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":462,"url":463},"CVE-2026-53227","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix possible kfree_skb of ERR_PTR\n\nAfter the patch in the \"Fixes\" tag, the allocation of the \"reply\" skb\ncan happen either before or after locking the ovs_mutex.\n\nHowever, error cleanups still follow the classical reversed order,\nassuming \"reply\" is allocated before locking: it is freed after unlocking.\n\nIf \"reply\" allocation happens after locking the mutex and it fails,\n\"reply\" is left with an ERR_PTR, and ex","2026-06-25T09:16:40.52+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53227",{"cveId":460,"releaseId":17,"cycle":18,"description":461,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":462,"url":463},{"cveId":460,"releaseId":25,"cycle":26,"description":461,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":462,"url":463},{"cveId":467,"releaseId":31,"cycle":32,"description":468,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":470,"url":471},"CVE-2026-53225","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix uninit-value in __sctp_rcv_asconf_lookup()\n\n__sctp_rcv_asconf_lookup() in net\u002Fsctp\u002Finput.c only checks that the ASCONF\nchunk can hold the ADDIP header and a parameter header, then calls\naf->from_addr_param(), which reads the full address (16 bytes for IPv6)\ntrusting the parameter's declared length.\n\nAn unauthenticated peer can send a truncated trailing ASCONF chunk that\ndeclares an IPv6 address parameter but stops aft",9.1,"2026-06-25T09:16:40.297+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53225",{"cveId":467,"releaseId":17,"cycle":18,"description":468,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":470,"url":471},{"cveId":467,"releaseId":25,"cycle":26,"description":468,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":470,"url":471},{"cveId":475,"releaseId":31,"cycle":32,"description":476,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":477,"url":478},"CVE-2026-53224","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate embedded INIT chunk and address list lengths in cookie\n\nsctp_unpack_cookie() only checked that the embedded INIT chunk length\ndid not exceed the remaining cookie payload, but did not ensure that the\nINIT chunk is large enough to contain a complete INIT header.\n\nA malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose\nlength field is smaller than sizeof(struct sctp_init_chunk).  Later,\nsctp_process","2026-06-25T09:16:40.2+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53224",{"cveId":475,"releaseId":17,"cycle":18,"description":476,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":477,"url":478},{"cveId":475,"releaseId":25,"cycle":26,"description":476,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":477,"url":478},{"cveId":482,"releaseId":17,"cycle":18,"description":483,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":484,"url":485},"CVE-2026-53223","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: guard timestamp cmsgs to real error queue skbs\n\nskb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb\nfrom sk_error_queue. That assumption is not true for AF_PACKET sockets:\noutgoing packet taps are also delivered to packet sockets with\nskb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET\ninstead of struct sock_exterr_skb.\n\nIf such an skb is received with timestamping enabled, the gen","2026-06-25T09:16:40.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53223",{"cveId":482,"releaseId":25,"cycle":26,"description":483,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":484,"url":485},{"cveId":488,"releaseId":31,"cycle":32,"description":489,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":490,"url":491},"CVE-2026-53221","In the Linux kernel, the following vulnerability has been resolved:\n\nip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()\n\nIn vti6_tnl_lookup(), when an exact match for a tunnel fails,\nthe code falls back to searching for wildcard tunnels:\n\n- Tunnels matching the packet's local address, with any remote address\n  wildcard remote).\n\n- Tunnels matching the packet's remote address, with any local address\n  (wildcard local).\n\nHowever, vti6 stores all these different types of tunnels in the sam","2026-06-25T09:16:39.863+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53221",{"cveId":488,"releaseId":17,"cycle":18,"description":489,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":490,"url":491},{"cveId":488,"releaseId":25,"cycle":26,"description":489,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":490,"url":491},{"cveId":495,"releaseId":31,"cycle":32,"description":496,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":497,"url":498},"CVE-2026-53220","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: revalidate bridge ports\n\nebt_redirect_tg() dereferences br_port_get_rcu() return without a\nNULL check, causing a kernel panic when the bridge port has been\nremoved between the original hook invocation and an NFQUEUE\nreinject.\n\nA mere NULL check isn't sufficient, however.  As sashiko review\npoints out userspace can not only remove the port from the bridge,\nit could also place the device in a different virtual device, ","2026-06-25T09:16:39.743+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53220",{"cveId":495,"releaseId":17,"cycle":18,"description":496,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":497,"url":498},{"cveId":495,"releaseId":25,"cycle":26,"description":496,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":497,"url":498},{"cveId":502,"releaseId":31,"cycle":32,"description":503,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":504,"url":505},"CVE-2026-53219","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: avoid leaking percpu counter pointers\n\nThe native and compat get-entries paths copy the fixed rule entry header\nfrom the kernelized rule blob to userspace before overwriting the entry's\ncounter fields with a sanitized counter snapshot.\n\nOn SMP kernels, entry->counters.pcnt contains the percpu allocation\naddress used by x_tables rule counters. A caller can provide a userspace\nbuffer that faults during the in","2026-06-25T09:16:39.613+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53219",{"cveId":502,"releaseId":17,"cycle":18,"description":503,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":504,"url":505},{"cveId":502,"releaseId":25,"cycle":26,"description":503,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":504,"url":505},{"cveId":509,"releaseId":17,"cycle":18,"description":510,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":511,"url":512},"CVE-2026-53218","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_exthdr: fix register tracking for F_PRESENT flag\n\nnft_exthdr_init() passes user-controlled priv->len to\nnft_parse_register_store(), which marks that many bytes in the\nregister bitmap as initialized.  However, when NFT_EXTHDR_F_PRESENT\nis set, the eval paths write only 1 byte (nft_reg_store8) or\n4 bytes (*dest = 0 on TCP\u002FDCCP error path).  When len > 4,\nregisters beyond the first are never written, retaining\nunini","2026-06-25T09:16:39.5+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53218",{"cveId":509,"releaseId":25,"cycle":26,"description":510,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":511,"url":512},{"cveId":515,"releaseId":31,"cycle":32,"description":516,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":517,"url":518},"CVE-2026-53213","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvc4: fix krealloc() memory leak\n\nDon't just overwrite the original pointer passed to krealloc()\nwith its return value without checking latter:\n\n    MEM = krealloc(MEM, SZ, GFP);\n\nIf krealloc() returns NULL, that erases the pointer\nto the still allocated memory, hence leaks this memory.\nInstead, use a temporary variable, check it's not NULL\nand only then assign it to the original pointer:\n\n    TMP = krealloc(MEM, SZ, GFP);\n ","2026-06-25T09:16:38.93+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53213",{"cveId":515,"releaseId":17,"cycle":18,"description":516,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":517,"url":518},{"cveId":515,"releaseId":25,"cycle":26,"description":516,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":517,"url":518},{"cveId":522,"releaseId":17,"cycle":18,"description":523,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":524,"url":525},"CVE-2026-53212","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_tunnel: fix use-after-free on object destroy\n\nnft_tunnel_obj_destroy() calls metadata_dst_free() which directly\nkfree()s the metadata_dst, ignoring the dst_entry refcount. Packets\nthat took a reference via dst_hold() in nft_tunnel_obj_eval() and\nare still queued (e.g. in a netem qdisc) are left with a dangling\npointer. When these packets are eventually dequeued, dst_release()\noperates on freed memory.\n\nReplace me","2026-06-25T09:16:38.793+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53212",{"cveId":527,"releaseId":31,"cycle":32,"description":528,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":529,"url":530},"CVE-2026-53208","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: reject BR\u002FEDR signaling packets over MTUsig\n\nnet\u002Fbluetooth\u002Fl2cap_core.c:l2cap_sig_channel() accepts BR\u002FEDR\nsignaling packets up to the channel MTU and dispatches each command\nwithout enforcing the signaling MTU (MTUsig). A Bluetooth BR\u002FEDR peer\nwithin radio range can send a fixed-channel CID 0x0001 packet that is\nlarger than MTUsig and contains many L2CAP_ECHO_REQ commands before\npairing. In a real-radio stock","2026-06-25T09:16:38.35+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53208",{"cveId":527,"releaseId":17,"cycle":18,"description":528,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":529,"url":530},{"cveId":527,"releaseId":25,"cycle":26,"description":528,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":529,"url":530},{"cveId":534,"releaseId":31,"cycle":32,"description":535,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":536,"url":537},"CVE-2026-53199","In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf\n\nnetvsc_copy_to_send_buf() copies page buffer entries into the VMBus\nsend buffer using phys_to_virt() on the entry PFN. Entries for the\nRNDIS header and the skb linear data come from kmalloc'd memory and\nare always in the kernel direct map, but entries for skb fragments\nreference page cache or user pages, which on 32-bit x86 with\nCONFIG_HIGHMEM=y can live above the LOWME","2026-06-25T09:16:37.44+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53199",{"cveId":534,"releaseId":17,"cycle":18,"description":535,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":536,"url":537},{"cveId":534,"releaseId":25,"cycle":26,"description":535,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":536,"url":537},{"cveId":541,"releaseId":31,"cycle":32,"description":542,"severity":58,"cvssScore":543,"epssScore":9,"inKev":42,"publishedAt":544,"url":545},"CVE-2026-53196","In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_ti: fix heap overflow in get_manuf_info()\n\nget_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the\ndevice I2C EEPROM into a buffer allocated with kmalloc_obj(), which\nis sizeof(struct edge_ti_manuf_descriptor) = 10 bytes.\n\nThe Size field comes from the device and is only validated (in\ncheck_i2c_image()) to make sure the descriptor fits within\nTI_MAX_I2C_SIZE (16384 bytes), not against the destination b",6.8,"2026-06-25T09:16:37.107+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53196",{"cveId":541,"releaseId":17,"cycle":18,"description":542,"severity":58,"cvssScore":543,"epssScore":9,"inKev":42,"publishedAt":544,"url":545},{"cveId":541,"releaseId":25,"cycle":26,"description":542,"severity":58,"cvssScore":543,"epssScore":9,"inKev":42,"publishedAt":544,"url":545},{"cveId":549,"releaseId":31,"cycle":32,"description":550,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":551,"url":552},"CVE-2026-53195","In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()\n\nbuild_i2c_fw_hdr() allocates a fixed-size buffer of\n(16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then\ncopies le16_to_cpu(img_header->Length) bytes into it without\nvalidating that Length fits within the available space after the\nfirmware record header.\n\nimg_header->Length is a __le16 from the firmware file and can be\nup to 65535. check_fw_sanity() valida","2026-06-25T09:16:36.983+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53195",{"cveId":549,"releaseId":17,"cycle":18,"description":550,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":551,"url":552},{"cveId":549,"releaseId":25,"cycle":26,"description":550,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":551,"url":552},{"cveId":556,"releaseId":31,"cycle":32,"description":557,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":558,"url":559},"CVE-2026-53194","In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: kl5kusb105: fix bulk-out buffer overflow\n\nklsi_105_prepare_write_buffer() is called by the generic write path\nwith the bulk-out buffer and its size (bulk_out_size, 64 bytes). It\nstores a two-byte length header at the start of the buffer and copies\nthe payload from the write fifo starting at buf + KLSI_HDR_LEN, but\npasses the full buffer size as the number of bytes to copy:\n\n  count = kfifo_out_locked(&port->write_f","2026-06-25T09:16:36.85+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53194",{"cveId":556,"releaseId":17,"cycle":18,"description":557,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":558,"url":559},{"cveId":556,"releaseId":25,"cycle":26,"description":557,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":558,"url":559},{"cveId":563,"releaseId":17,"cycle":18,"description":564,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":565,"url":566},"CVE-2026-53189","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fhuge_memory: update file PMD counter before folio_put()\n\n__split_huge_pmd_locked() updates the file\u002Fshmem RSS counter after\ndropping the PMD mapping's folio reference.  If folio_put() drops the last\nreference, mm_counter_file() can later read freed folio state via\nfolio_test_swapbacked().\n\nMove the counter update before folio_put().","2026-06-25T09:16:36.327+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53189",{"cveId":568,"releaseId":31,"cycle":32,"description":569,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":570,"url":571},"CVE-2026-53186","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fsrp: bound SRP_RSP sense copy by the received length\n\nsrp_process_rsp() copies sense data from rsp->data + resp_data_len,\nwhere resp_data_len is the full 32-bit value supplied by the SRP target\nand is never checked against the number of bytes actually received\n(wc->byte_len). The copy length is bounded to SCSI_SENSE_BUFFERSIZE, so\nat most 96 bytes are copied, but the source offset is not bounded.\n\nA malicious or compromise","2026-06-25T09:16:36.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53186",{"cveId":568,"releaseId":17,"cycle":18,"description":569,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":570,"url":571},{"cveId":568,"releaseId":25,"cycle":26,"description":569,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":570,"url":571},{"cveId":575,"releaseId":17,"cycle":18,"description":576,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":577,"url":578},"CVE-2026-53185","In the Linux kernel, the following vulnerability has been resolved:\n\nzram: fix use-after-free in zram_bvec_write_partial()\n\nzram_read_page() picks the sync or async backing device read path based on\nwhether the parent bio is NULL.  zram_bvec_write_partial() passes its\nparent bio down, so for ZRAM_WB slots the read is dispatched\nasynchronously and zram_read_page() returns 0 while the bio is still in\nflight.  The caller then runs memcpy_from_bvec(), zram_write_page() and\n__free_page() on the buffe","2026-06-25T09:16:35.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53185",{"cveId":575,"releaseId":25,"cycle":26,"description":576,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":577,"url":578},{"cveId":581,"releaseId":31,"cycle":32,"description":582,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":583,"url":584},"CVE-2026-53181","In the Linux kernel, the following vulnerability has been resolved:\n\nvsock\u002Fvmci: fix sk_ack_backlog leak on failed handshake\n\nWhen vmci_transport_recv_connecting_server() returns an error,\nvmci_transport_recv_listen() calls vsock_remove_pending() but never\ncalls sk_acceptq_removed(). This leaves sk_ack_backlog incremented\npermanently.\n\nRepeated handshake failures (malformed packets, queue pair alloc\nfailure, event subscribe failure) cause sk_ack_backlog to climb\ntoward sk_max_ack_backlog. Once i","2026-06-25T09:16:35.47+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53181",{"cveId":581,"releaseId":17,"cycle":18,"description":582,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":583,"url":584},{"cveId":581,"releaseId":25,"cycle":26,"description":582,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":583,"url":584},{"cveId":588,"releaseId":17,"cycle":18,"description":589,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":590,"url":591},"CVE-2026-53177","In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix NULL pointer dereference\n\nPCIe errors detected by a Root Port or Downstream Port cause error\nrecovery services to run on all subordinate devices regardless of\nadministrative state.\n\nThe .error_detected() callback, bnxt_io_error_detected(), disables\nand synchronizes IRQs via bnxt_disable_int_sync(), which calls\nbnxt_cp_num_to_irq_num() to map completion rings to IRQs using\nbp->bnapi.\n\nSince bp->bnapi is allocated on","2026-06-25T09:16:35.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53177",{"cveId":593,"releaseId":31,"cycle":32,"description":594,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":595,"url":596},"CVE-2026-53176","In the Linux kernel, the following vulnerability has been resolved:\n\nIB\u002Fisert: Reject login PDUs shorter than ISER_HEADERS_LEN\n\nIn drivers\u002Finfiniband\u002Fulp\u002Fisert\u002Fib_isert.c, isert_login_recv_done()\ncomputes the login request payload length as wc->byte_len minus\nISER_HEADERS_LEN with no lower bound, and login_req_len is a signed int.\nA remote iSER initiator can post a login Send work request carrying\nfewer than ISER_HEADERS_LEN (76) bytes, so the subtraction underflows\nand login_req_len becomes neg","2026-06-25T09:16:34.953+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53176",{"cveId":593,"releaseId":17,"cycle":18,"description":594,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":595,"url":596},{"cveId":593,"releaseId":25,"cycle":26,"description":594,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":595,"url":596},{"cveId":600,"releaseId":31,"cycle":32,"description":601,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":602,"url":603},"CVE-2026-53167","In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios\n\nFUSE_NOTIFY_RETRIEVE must be limited to uptodate folios; !uptodate folios\ncan contain uninitialized data.\nSince FUSE_NOTIFY_RETRIEVE is intended to only return data that is already\nin the page cache and not wait for data from the FUSE daemon, treat\n!uptodate folios as if they weren't present.\n\nThis only has security impact on systems that don't enable automatic\nzero-initializ","2026-06-25T09:16:34.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53167",{"cveId":600,"releaseId":17,"cycle":18,"description":601,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":602,"url":603},{"cveId":600,"releaseId":25,"cycle":26,"description":601,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":602,"url":603},{"cveId":607,"releaseId":31,"cycle":32,"description":608,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":609,"url":610},"CVE-2026-53157","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phonet: free phonet_device after RCU grace period\n\nphonet_device_destroy() removes a phonet_device from the per-net device\nlist with list_del_rcu(), but frees it immediately. RCU readers walking\nthe same list can still hold a pointer to the object after it has been\nremoved, leading to a slab-use-after-free.\n\nUse kfree_rcu(), matching the lifetime rule already used by\nphonet_address_del() for the same object type.","2026-06-25T09:16:33.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53157",{"cveId":607,"releaseId":17,"cycle":18,"description":608,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":609,"url":610},{"cveId":607,"releaseId":25,"cycle":26,"description":608,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":609,"url":610},{"cveId":614,"releaseId":17,"cycle":18,"description":615,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":616,"url":617},"CVE-2026-53150","In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Reject zero-length property entries in validator\n\ntb_property_entry_valid() accepts entries with length == 0 for\nDIRECTORY, DATA, and TEXT types.  A zero-length TEXT entry passes\nvalidation but causes an underflow in the null-termination logic:\n\n  property->value.text[property->length * 4 - 1] = '\\0';\n\nWhen property->length is 0 this writes to offset -1 relative to\nthe allocation.\n\nReject zero-length entries early ","2026-06-25T09:16:32.367+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53150",{"cveId":619,"releaseId":17,"cycle":18,"description":620,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":621,"url":622},"CVE-2026-53149","In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Bound root directory content to block size\n\n__tb_property_parse_dir() does not check that content_offset +\ncontent_len fits within block_len for the root directory case.\nWhen rootdir->length equals or exceeds block_len - 2, the entry\nloop reads past the allocated property block.\n\nAdd a bounds check after computing content_offset and content_len\nto reject directories whose content extends past the block.","2026-06-25T09:16:32.257+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53149",{"cveId":624,"releaseId":17,"cycle":18,"description":625,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":626,"url":627},"CVE-2026-53148","In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Clamp XDomain response data copy to allocation size\n\ntb_xdp_properties_request() derives the per-packet copy length from\nthe response header without checking that it fits in the previously\nallocated data buffer.  A malicious peer can set its length field\nlarger than the declared data_length, causing memcpy to write past\nthe kcalloc allocation.\n\nClamp the per-packet copy length so that the cumulative offset\nnever ex","2026-06-25T09:16:32.14+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53148",{"cveId":629,"releaseId":17,"cycle":18,"description":630,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":631,"url":632},"CVE-2026-53147","In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Validate XDomain request packet size before type cast\n\ntb_xdp_handle_request() casts the received packet buffer to\nprotocol-specific structs without verifying that the allocation\nis large enough for the target type.  A peer can send a minimal\nXDomain packet that passes the generic header length check but is\nshorter than the struct accessed after the cast, causing out-of-\nbounds reads from the kmemdup allocation.\n\nP","2026-06-25T09:16:32.037+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53147",{"cveId":634,"releaseId":17,"cycle":18,"description":635,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":636,"url":637},"CVE-2026-53146","In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Limit XDomain response copy to actual frame size\n\ntb_xdomain_copy() copies req->response_size bytes from the received\npacket buffer regardless of the actual frame size.  When a short\nresponse arrives, this reads past the valid frame data in the DMA\npool buffer into stale contents from previous transactions.\n\nUse the minimum of frame size and expected response size for the\ncopy length.","2026-06-25T09:16:31.923+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53146",{"cveId":639,"releaseId":17,"cycle":18,"description":640,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":641,"url":642},"CVE-2026-53138","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Bound VBIOS record-chain walk loops\n\n[Why & How]\nAll record-chain walk loops in bios_parser.c and bios_parser2.c use\nfor(;;) and only terminate on a 0xFF record_type sentinel or zero\nrecord_size. A malformed VBIOS image missing the terminator record\ncauses unbounded iteration at probe time, potentially hundreds of\nthousands of iterations with record_size=1. In the final iterations\nnear the BIOS image boundary, ","2026-06-25T09:16:31.15+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53138",{"cveId":644,"releaseId":17,"cycle":18,"description":645,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":646,"url":647},"CVE-2026-53136","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Clamp VBIOS HDMI retimer register count to array size\n\n[Why & How]\nThe VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and\nHdmi6GRegNum fields that are used as loop bounds when copying retimer I2C\nregister settings into fixed-size arrays (dp*_ext_hdmi_reg_settings[9]\nand dp*_ext_hdmi_6g_reg_settings[3]). These u8 fields are not validated\nbefore use, so a malformed VBIOS can specify values up to","2026-06-25T09:16:30.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53136",{"cveId":649,"releaseId":17,"cycle":18,"description":650,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":651,"url":652},"CVE-2026-53134","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_fib: fix stale stack leak via the OIFNAME register\n\nFor NFT_FIB_RESULT_OIFNAME the destination register is declared with\nlen = IFNAMSIZ (four 32-bit registers), but on the lookup-fail,\nRTN_LOCAL and oif-mismatch paths nft_fib{4,6}_eval() only writes one\nregister via \"*dest = 0\". The remaining three registers are left as\nwhatever was on the stack in nft_do_chain()'s struct nft_regs, and a\ndownstream expression tha","2026-06-25T09:16:30.657+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53134",{"cveId":649,"releaseId":25,"cycle":26,"description":650,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":651,"url":652},{"cveId":655,"releaseId":31,"cycle":32,"description":656,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":658,"url":659},"CVE-2026-53131","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: require Ethernet MAC header before using eth_hdr()\n\n`ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and\n`hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)`\nafter either assuming that the skb is associated with an Ethernet\ndevice or checking only that the `ETH_HLEN` bytes at\n`skb_mac_header(skb)` lie between `skb->head` and `skb->data`.\n\nMake these paths first verify that the skb is associate",9.4,"2026-06-25T09:16:30.307+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53131",{"cveId":655,"releaseId":17,"cycle":18,"description":656,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":658,"url":659},{"cveId":655,"releaseId":25,"cycle":26,"description":656,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":658,"url":659},{"cveId":663,"releaseId":31,"cycle":32,"description":664,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":665,"url":666},"CVE-2026-53130","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Fomfs: reject s_sys_blocksize smaller than OMFS_DIR_START\n\nomfs_fill_super() rejects oversized s_sys_blocksize values (> PAGE_SIZE),\nbut it does not reject values smaller than OMFS_DIR_START (0x1b8 = 440).\n\nLater, omfs_make_empty() uses\n\n    sbi->s_sys_blocksize - OMFS_DIR_START\n\nas the length argument to memset().  Since s_sys_blocksize is u32,\na crafted filesystem image with s_sys_blocksize \u003C OMFS_DIR_START causes\nan unsign","2026-06-24T17:17:28.903+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53130",{"cveId":663,"releaseId":17,"cycle":18,"description":664,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":665,"url":666},{"cveId":663,"releaseId":25,"cycle":26,"description":664,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":665,"url":666},{"cveId":670,"releaseId":31,"cycle":32,"description":671,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":672,"url":673},"CVE-2026-53129","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Fmbcache: cancel shrink work before destroying the cache\n\nmb_cache_destroy() calls shrinker_free() and then frees all cache\nentries and the cache itself, but it does not cancel the pending\nc_shrink_work work item first.\n\nIf mb_cache_entry_create() schedules c_shrink_work via schedule_work()\nand the work item is still pending or running when mb_cache_destroy()\nruns, mb_cache_shrink_worker() will access the cache after its memo","2026-06-24T17:17:28.793+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53129",{"cveId":670,"releaseId":17,"cycle":18,"description":671,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":672,"url":673},{"cveId":670,"releaseId":25,"cycle":26,"description":671,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":672,"url":673},{"cveId":677,"releaseId":31,"cycle":32,"description":678,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":679,"url":680},"CVE-2026-53128","In the Linux kernel, the following vulnerability has been resolved:\n\ndrbd: Balance RCU calls in drbd_adm_dump_devices()\n\nMake drbd_adm_dump_devices() call rcu_read_lock() before\nrcu_read_unlock() is called. This has been detected by the Clang\nthread-safety analyzer.","2026-06-24T17:17:28.647+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53128",{"cveId":677,"releaseId":17,"cycle":18,"description":678,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":679,"url":680},{"cveId":677,"releaseId":25,"cycle":26,"description":678,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":679,"url":680},{"cveId":684,"releaseId":31,"cycle":32,"description":685,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":686,"url":687},"CVE-2026-53120","In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nhel","2026-06-24T17:17:26.38+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53120",{"cveId":684,"releaseId":17,"cycle":18,"description":685,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":686,"url":687},{"cveId":684,"releaseId":25,"cycle":26,"description":685,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":686,"url":687},{"cveId":691,"releaseId":31,"cycle":32,"description":692,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":693,"url":694},"CVE-2026-53112","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet\n\nThe irq_prepare_bcn_tasklet is initialized in rtl_pci_init() and\nscheduled when RTL_IMR_BCNINT interrupt is triggered by hardware.\nBut it is never killed in rtl_pci_deinit(). When the rtlwifi card\nprobe fails or is being detached, the ieee80211_hw is deallocated.\nHowever, irq_prepare_bcn_tasklet may still be running or pending,\nleading","2026-06-24T17:17:25.583+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53112",{"cveId":691,"releaseId":17,"cycle":18,"description":692,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":693,"url":694},{"cveId":691,"releaseId":25,"cycle":26,"description":692,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":693,"url":694},{"cveId":698,"releaseId":31,"cycle":32,"description":699,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":700,"url":701},"CVE-2026-53093","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: Fix error pointer dereference\n\nThe function brcmf_chip_add_core() can return an error pointer and is\nnot checked. Add checks for error pointer.\n\nDetected by Smatch:\ndrivers\u002Fnet\u002Fwireless\u002Fbroadcom\u002Fbrcm80211\u002Fbrcmfmac\u002Fchip.c:1010 brcmf_chip_recognition() error:\n'core' dereferencing possible ERR_PTR()\n\ndrivers\u002Fnet\u002Fwireless\u002Fbroadcom\u002Fbrcm80211\u002Fbrcmfmac\u002Fchip.c:1013 brcmf_chip_recognition() error:\n'core' dereferencing po","2026-06-24T17:17:23.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53093",{"cveId":698,"releaseId":17,"cycle":18,"description":699,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":700,"url":701},{"cveId":698,"releaseId":25,"cycle":26,"description":699,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":700,"url":701},{"cveId":705,"releaseId":31,"cycle":32,"description":706,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":707,"url":708},"CVE-2026-53091","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: pull headers in qdisc_pkt_len_segs_init()\n\nMost ndo_start_xmit() methods expects headers of gso packets\nto be already in skb->head.\n\nnet\u002Fcore\u002Ftso.c users are particularly at risk, because tso_build_hdr()\ndoes a memcpy(hdr, skb->data, hdr_len);\n\nqdisc_pkt_len_segs_init() already does a dissection of gso packets.\n\nUse pskb_may_pull() instead of skb_header_pointer() to make\nsure drivers do not have to reimplement this.\n\nSome ","2026-06-24T17:17:23.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53091",{"cveId":705,"releaseId":17,"cycle":18,"description":706,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":707,"url":708},{"cveId":705,"releaseId":25,"cycle":26,"description":706,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":707,"url":708},{"cveId":712,"releaseId":17,"cycle":18,"description":713,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":714,"url":715},"CVE-2026-53089","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix use-after-free in offloaded map\u002Fprog info fill\n\nWhen querying info for an offloaded BPF map or program,\nbpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns()\nobtain the network namespace with get_net(dev_net(offmap->netdev)).\nHowever, the associated netdev's netns may be racing with teardown\nduring netns destruction. If the netns refcount has already reached 0,\nget_net() performs a refcount_t increment on ","2026-06-24T17:17:23.097+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53089",{"cveId":717,"releaseId":17,"cycle":18,"description":718,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":719,"url":720},"CVE-2026-53088","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmgenet: fix off-by-one in bcmgenet_put_txcb\n\nThe write_ptr points to the next open tx_cb. We want to return the\ntx_cb that gets rewinded, so we must rewind the pointer first then\nreturn the tx_cb that it points to. That way the txcb can be correctly\ncleaned up.","2026-06-24T17:17:22.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53088",{"cveId":717,"releaseId":25,"cycle":26,"description":718,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":719,"url":720},{"cveId":723,"releaseId":31,"cycle":32,"description":724,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":725,"url":726},"CVE-2026-53086","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmgenet: fix racing timeout handler\n\nThe bcmgenet_timeout handler tries to take down all tx queues when\na single queue times out. This is over zealous and causes many race\nconditions with queues that are still chugging along. Instead lets\nonly restart the timed out queue.","2026-06-24T17:17:22.777+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53086",{"cveId":723,"releaseId":17,"cycle":18,"description":724,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":725,"url":726},{"cveId":723,"releaseId":25,"cycle":26,"description":724,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":725,"url":726},{"cveId":730,"releaseId":31,"cycle":32,"description":731,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":732,"url":733},"CVE-2026-53082","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hamradio: 6pack: fix uninit-value in sixpack_receive_buf\n\nsixpack_receive_buf() does not properly skip bytes with TTY error flags.\nThe while loop iterates through the flags buffer but never advances the\ndata pointer (cp), and passes the original count (including error bytes)\nto sixpack_decode(). This causes sixpack_decode() to process bytes that\nshould have been skipped due to TTY errors.  The TTY layer does not\nguarantee ","2026-06-24T17:17:22.343+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53082",{"cveId":730,"releaseId":17,"cycle":18,"description":731,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":732,"url":733},{"cveId":730,"releaseId":25,"cycle":26,"description":731,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":732,"url":733},{"cveId":737,"releaseId":31,"cycle":32,"description":738,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":739,"url":740},"CVE-2026-53077","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Frds: Restrict use of RDS\u002FIB to the initial network namespace\n\nPrevent using RDS\u002FIB in network namespaces other than the initial one.\nThe existing RDS\u002FIB code will not work properly in non-initial network\nnamespaces.","2026-06-24T17:17:21.73+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53077",{"cveId":737,"releaseId":17,"cycle":18,"description":738,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":739,"url":740},{"cveId":737,"releaseId":25,"cycle":26,"description":738,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":739,"url":740},{"cveId":744,"releaseId":31,"cycle":32,"description":745,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":746,"url":747},"CVE-2026-53075","In the Linux kernel, the following vulnerability has been resolved:\n\nppp: require CAP_NET_ADMIN in target netns for unattached ioctls\n\n\u002Fdev\u002Fppp open is currently authorized against file->f_cred->user_ns,\nwhile unattached administrative ioctls operate on current->nsproxy->net_ns.\n\nAs a result, a local unprivileged user can create a new user namespace\nwith CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace,\nand still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against\nan inh","2026-06-24T17:17:21.45+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53075",{"cveId":744,"releaseId":17,"cycle":18,"description":745,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":746,"url":747},{"cveId":744,"releaseId":25,"cycle":26,"description":745,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":746,"url":747},{"cveId":751,"releaseId":31,"cycle":32,"description":752,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":753,"url":754},"CVE-2026-53072","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER\n\nWhen protocol sets HCI_PROTO_DEFER, hci_conn_request_evt() calls\nhci_connect_cfm(conn) without hdev->lock. Generally hci_connect_cfm()\nassumes it is held, and if conn is deleted concurrently -> UAF.\n\nOnly SCO and ISO set HCI_PROTO_DEFER and only for defer setup listen,\nand HCI_EV_CONN_REQUEST is not generated for ISO.  In the non-deferred\nlistening socket co","2026-06-24T17:17:21.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53072",{"cveId":751,"releaseId":17,"cycle":18,"description":752,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":753,"url":754},{"cveId":751,"releaseId":25,"cycle":26,"description":752,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":753,"url":754},{"cveId":758,"releaseId":17,"cycle":18,"description":759,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":760,"url":761},"CVE-2026-53066","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fsun4i: backend: fix error pointer dereference\n\nThe function drm_atomic_get_plane_state() can return an error pointer\nand is not checked for it. Add error pointer check.\n\nDetected by Smatch:\ndrivers\u002Fgpu\u002Fdrm\u002Fsun4i\u002Fsun4i_backend.c:496 sun4i_backend_atomic_check() error:\n'plane_state' dereferencing possible ERR_PTR()","2026-06-24T17:17:19.647+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53066",{"cveId":763,"releaseId":31,"cycle":32,"description":764,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":765,"url":766},"CVE-2026-53065","In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: sti: use managed regmap_field allocations\n\nThe regmap_field objects allocated at player init are never freed and\nmay leak resources if the driver is removed.\n\nSwitch to devm_regmap_field_alloc() to automatically limit the lifetime\nof the allocations the lifetime of the device.","2026-06-24T17:17:19.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53065",{"cveId":763,"releaseId":17,"cycle":18,"description":764,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":765,"url":766},{"cveId":763,"releaseId":25,"cycle":26,"description":764,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":765,"url":766},{"cveId":770,"releaseId":17,"cycle":18,"description":771,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":772,"url":773},"CVE-2026-53064","In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache: fix null-deref with concurrent writes in passthrough mode\n\nIn passthrough mode, when dm-cache starts to invalidate a cache\nentry and bio prison cell lock fails due to concurrent write to\nthe same cached block, mg->cell remains NULL. The error path in\ninvalidate_complete() attempts to unlock and free the cell\nunconditionally, causing a NULL pointer dereference:\n\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000","2026-06-24T17:17:19.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53064",{"cveId":770,"releaseId":25,"cycle":26,"description":771,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":772,"url":773},{"cveId":776,"releaseId":17,"cycle":18,"description":777,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":778,"url":779},"CVE-2026-53063","In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache: fix write hang in passthrough mode\n\nThe invalidate_remove() function has incomplete logic for handling write\nhit bios after cache invalidation. It sets up the remapping for the\noverwrite_bio but then drops it immediately without submission, causing\nwrite operations to hang.\n\nFix by adding a new invalidate_committed() continuation that submits\nthe remapped writes to the cache origin after metadata commit completes,\nwhi","2026-06-24T17:17:19.173+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53063",{"cveId":776,"releaseId":25,"cycle":26,"description":777,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":778,"url":779},{"cveId":782,"releaseId":17,"cycle":18,"description":783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":784,"url":785},"CVE-2026-53062","In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache policy smq: fix missing locks in invalidating cache blocks\n\nIn passthrough mode, the policy invalidate_mapping operation is called\nsimultaneously from multiple workers, thus it should be protected by a\nlock. Otherwise, we might end up with data races on the allocated blocks\ncounter, or even use-after-free issues with internal data structures\nwhen doing concurrent writes.\n\nNote that the existing FIXME in smq_invalidate_","2026-06-24T17:17:19.03+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53062",{"cveId":782,"releaseId":25,"cycle":26,"description":783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":784,"url":785},{"cveId":788,"releaseId":31,"cycle":32,"description":789,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":790,"url":791},"CVE-2026-53061","In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache: fix dirty mapping checking in passthrough mode switching\n\nAs mentioned in commit 9b1cc9f251af (\"dm cache: share cache-metadata\nobject across inactive and active DM tables\"), dm-cache assumed table\nreload occurs after suspension, while LVM's table preload breaks this\nassumption. The dirty mapping check for passthrough mode was designed\naround this assumption and is performed during table creation, causing\nthe check to ","2026-06-24T17:17:18.88+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53061",{"cveId":788,"releaseId":17,"cycle":18,"description":789,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":790,"url":791},{"cveId":788,"releaseId":25,"cycle":26,"description":789,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":790,"url":791},{"cveId":795,"releaseId":31,"cycle":32,"description":796,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":797,"url":798},"CVE-2026-53060","In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache metadata: fix memory leak on metadata abort retry\n\nWhen failing to acquire the root_lock in dm_cache_metadata_abort because\nthe block_manager is read-only, the temporary block_manager created\noutside the root_lock is not properly released, causing a memory leak.\n\nReproduce steps:\n\nThis can be reproduced by reloading a new table while the metadata\nis read-only. While the second call to dm_cache_metadata_abort is\ncaused ","2026-06-24T17:17:18.717+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53060",{"cveId":795,"releaseId":25,"cycle":26,"description":796,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":797,"url":798},{"cveId":795,"releaseId":17,"cycle":18,"description":796,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":797,"url":798},{"cveId":802,"releaseId":31,"cycle":32,"description":803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":804,"url":805},"CVE-2026-53059","In the Linux kernel, the following vulnerability has been resolved:\n\ndm log: fix out-of-bounds write due to region_count overflow\n\nThe local variable region_count in create_log_context() is declared as\nunsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit).\nWhen a device-mapper target has a sufficiently large ti->len with a small\nregion_size, the division result can exceed UINT_MAX. The truncated\nvalue is then used to calculate bitset_size, causing clean_bits,\nsync_bits, and rec","2026-06-24T17:17:18.463+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53059",{"cveId":802,"releaseId":17,"cycle":18,"description":803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":804,"url":805},{"cveId":802,"releaseId":25,"cycle":26,"description":803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":804,"url":805},{"cveId":809,"releaseId":17,"cycle":18,"description":810,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":811,"url":812},"CVE-2026-53050","In the Linux kernel, the following vulnerability has been resolved:\n\nquota: Fix race of dquot_scan_active() with quota deactivation\n\ndquot_scan_active() can race with quota deactivation in\nquota_release_workfn() like:\n\n  CPU0 (quota_release_workfn)         CPU1 (dquot_scan_active)\n  ==============================      ==============================\n  spin_lock(&dq_list_lock);\n  list_replace_init(\n    &releasing_dquots, &rls_head);\n    \u002F* dquot X on rls_head,\n       dq_count == 0,\n       DQ_ACTIV","2026-06-24T17:17:16.887+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53050",{"cveId":814,"releaseId":25,"cycle":26,"description":815,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":816,"url":817},"CVE-2026-53047","In the Linux kernel, the following vulnerability has been resolved:\n\nefi\u002Fcapsule-loader: fix incorrect sizeof in phys array reallocation\n\nThe krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses\nsizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be\ncausing an undersized allocation.\n\nThe allocation is also inconsistent with the initial array allocation in\nefi_capsule_open() that allocates one entry with sizeof(phys_addr_t),\nand the efi_capsule_write() function that","2026-06-24T17:17:16.533+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53047",{"cveId":814,"releaseId":17,"cycle":18,"description":815,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":816,"url":817},{"cveId":820,"releaseId":31,"cycle":32,"description":821,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":822,"url":823},"CVE-2026-53045","In the Linux kernel, the following vulnerability has been resolved:\n\nmemory: tegra124-emc: Fix dll_change check\n\nThe code checking whether the specified memory timing enables DLL\nin the EMRS register was reversed. DLL is enabled if bit A0 is low.\nFix the check.","2026-06-24T17:17:16.29+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53045",{"cveId":820,"releaseId":17,"cycle":18,"description":821,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":822,"url":823},{"cveId":820,"releaseId":25,"cycle":26,"description":821,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":822,"url":823},{"cveId":827,"releaseId":31,"cycle":32,"description":828,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":829,"url":830},"CVE-2026-53043","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2\u002Fdlm: validate qr_numregions in dlm_match_regions()\n\nPatch series \"ocfs2\u002Fdlm: fix two bugs in dlm_match_regions()\".\n\nIn dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGION\nnetwork message is used to drive loops over the qr_regions buffer without\nsufficient validation.  This series fixes two issues:\n\n- Patch 1 adds a bounds check to reject messages where qr_numregions\n  exceeds O2NM_MAX_REGIONS. The o2net l","2026-06-24T17:17:16.063+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53043",{"cveId":827,"releaseId":17,"cycle":18,"description":828,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":829,"url":830},{"cveId":827,"releaseId":25,"cycle":26,"description":828,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":829,"url":830},{"cveId":834,"releaseId":31,"cycle":32,"description":835,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":836,"url":837},"CVE-2026-53041","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix listxattr handling when the buffer is full\n\n[BUG]\nIf an OCFS2 inode has both inline and block-based xattrs, listxattr()\ncan return a size larger than the caller's buffer when the inline names\nconsume that buffer exactly.\n\nkernel BUG at mm\u002Fusercopy.c:102!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nRIP: 0010:usercopy_abort+0xb7\u002F0xd0 mm\u002Fusercopy.c:102\nCall Trace:\n __check_heap_object+0xe3\u002F0x120 mm\u002Fslub.c:8243\n chec","2026-06-24T17:17:15.83+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53041",{"cveId":834,"releaseId":17,"cycle":18,"description":835,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":836,"url":837},{"cveId":834,"releaseId":25,"cycle":26,"description":835,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":836,"url":837},{"cveId":841,"releaseId":31,"cycle":32,"description":842,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":843,"url":844},"CVE-2026-53040","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate bg_bits during freefrag scan\n\n[BUG]\nA crafted filesystem can trigger an out-of-bounds bitmap walk when\nOCFS2_IOC_INFO is issued with OCFS2_INFO_FL_NON_COHERENT.\n\nBUG: KASAN: use-after-free in instrument_atomic_read include\u002Flinux\u002Finstrumented.h:68 [inline]\nBUG: KASAN: use-after-free in _test_bit include\u002Fasm-generic\u002Fbitops\u002Finstrumented-non-atomic.h:141 [inline]\nBUG: KASAN: use-after-free in test_bit_le include\u002Fasm","2026-06-24T17:17:15.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53040",{"cveId":841,"releaseId":17,"cycle":18,"description":842,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":843,"url":844},{"cveId":841,"releaseId":25,"cycle":26,"description":842,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":843,"url":844},{"cveId":848,"releaseId":31,"cycle":32,"description":849,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":850,"url":851},"CVE-2026-53039","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate group add input before caching\n\n[BUG]\nOCFS2_IOC_GROUP_ADD can trigger a BUG_ON in\nocfs2_set_new_buffer_uptodate():\n\nkernel BUG at fs\u002Focfs2\u002Fuptodate.c:509!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nRIP: 0010:ocfs2_set_new_buffer_uptodate+0x194\u002F0x1e0 fs\u002Focfs2\u002Fuptodate.c:509\nCode: ffffe88f 42b9fe4c 89e64889 dfe8b4df\nCall Trace:\n ocfs2_group_add+0x3f1\u002F0x1510 fs\u002Focfs2\u002Fresize.c:507\n ocfs2_ioctl+0x309\u002F0x6e0 fs\u002Foc","2026-06-24T17:17:15.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53039",{"cveId":848,"releaseId":17,"cycle":18,"description":849,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":850,"url":851},{"cveId":848,"releaseId":25,"cycle":26,"description":849,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":850,"url":851},{"cveId":855,"releaseId":31,"cycle":32,"description":856,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":857,"url":858},"CVE-2026-53037","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: usbhid: fix deadlock in hid_post_reset()\n\nYou can build a USB device that includes a HID component\nand a storage or UAS component. The components can be reset\nonly together. That means that hid_pre_reset() and hid_post_reset()\nare in the block IO error handling. Hence no memory allocation\nused in them may do block IO because the IO can deadlock\non the mutex held while resetting a device and calling the\ninterface drivers.\nU","2026-06-24T17:17:15.263+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53037",{"cveId":855,"releaseId":17,"cycle":18,"description":856,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":857,"url":858},{"cveId":855,"releaseId":25,"cycle":26,"description":856,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":857,"url":858},{"cveId":862,"releaseId":31,"cycle":32,"description":863,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":864,"url":865},"CVE-2026-53036","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Fix off-by-one in check_imm signed range check\n\ncheck_imm(bits, imm) is used in the arm64 BPF JIT to verify that\na branch displacement (in arm64 instruction units) fits into the\nsigned N-bit immediate field of a B, B.cond or CBZ\u002FCBNZ encoding\nbefore it is handed to the encoder. The macro currently tests for\n(imm > 0 && imm >> bits) || (imm \u003C 0 && ~imm >> bits) which admits\nvalues in [-2^N, 2^N) — effectively a signe","2026-06-24T17:17:15.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53036",{"cveId":862,"releaseId":17,"cycle":18,"description":863,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":864,"url":865},{"cveId":862,"releaseId":25,"cycle":26,"description":863,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":864,"url":865},{"cveId":869,"releaseId":31,"cycle":32,"description":870,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":871,"url":872},"CVE-2026-53025","In the Linux kernel, the following vulnerability has been resolved:\n\ngreybus: raw: fix use-after-free on cdev close\n\nThis addresses a use-after-free bug when a raw bundle is disconnected\nbut its chardev is still opened by an application. When the application\nreleases the cdev, it causes the following panic when init on free is\nenabled (CONFIG_INIT_ON_FREE_DEFAULT_ON=y):\n\n        refcount_t: underflow; use-after-free.\n        WARNING: CPU: 0 PID: 139 at lib\u002Frefcount.c:28 refcount_warn_saturate+0x","2026-06-24T17:17:13.857+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53025",{"cveId":869,"releaseId":17,"cycle":18,"description":870,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":871,"url":872},{"cveId":869,"releaseId":25,"cycle":26,"description":870,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":871,"url":872},{"cveId":876,"releaseId":31,"cycle":32,"description":877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":878,"url":879},"CVE-2026-53024","In the Linux kernel, the following vulnerability has been resolved:\n\ngreybus: raw: fix use-after-free if write is called after disconnect\n\nIf a user writes to the chardev after disconnect has been called, the\nkernel panics with the following trace (with\nCONFIG_INIT_ON_FREE_DEFAULT_ON=y):\n\n        BUG: kernel NULL pointer dereference, address: 0000000000000218\n         ...\n        Call Trace:\n         \u003CTASK>\n         gb_operation_create_common+0x61\u002F0x180\n         gb_operation_create_flags+0x28\u002F0x","2026-06-24T17:17:13.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53024",{"cveId":876,"releaseId":17,"cycle":18,"description":877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":878,"url":879},{"cveId":876,"releaseId":25,"cycle":26,"description":877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":878,"url":879},{"cveId":883,"releaseId":31,"cycle":32,"description":884,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":885,"url":886},"CVE-2026-53021","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Fix integer overflow in UNMAP bounds check\n\nsbc_execute_unmap() checks LBA + range does not exceed the device capacity,\nbut does not guard against LBA + range wrapping around on 64-bit overflow.\n\nAdd an overflow check matching the pattern already used for WRITE_SAME in\nthe same file.","2026-06-24T17:17:13.41+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53021",{"cveId":883,"releaseId":17,"cycle":18,"description":884,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":885,"url":886},{"cveId":883,"releaseId":25,"cycle":26,"description":884,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":885,"url":886},{"cveId":890,"releaseId":17,"cycle":18,"description":891,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":892,"url":893},"CVE-2026-53018","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: avoid reading already updated pages during GC\n\nWe found the following issue during fuzz testing:\n\npage: refcount:3 mapcount:0 mapping:00000000b6e89c65 index:0x18b2dc pfn:0x161ba9\nmemcg:f8ffff800e269c00\naops:f2fs_meta_aops ino:2\nflags: 0x52880000000080a9(locked|waiters|uptodate|lru|private|zone=1|kasantag=0x4a)\nraw: 52880000000080a9 fffffffec6e17588 fffffffec0ccc088 a7ffff8067063618\nraw: 000000000018b2dc 0000000000000009 0","2026-06-24T17:17:13.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53018",{"cveId":895,"releaseId":31,"cycle":32,"description":896,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":897,"url":898},"CVE-2026-53017","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix data loss caused by incorrect use of nat_entry flag\n\nData loss can occur when fsync is performed on a newly created file\n(before any checkpoint has been written) concurrently with a checkpoint\noperation. The scenario is as follows:\n\ncreate & write & fsync 'file A'                 write checkpoint\n- f2fs_do_sync_file \u002F\u002F inline inode\n - f2fs_write_inode \u002F\u002F inode folio is dirty\n                                           ","2026-06-24T17:17:13.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53017",{"cveId":895,"releaseId":17,"cycle":18,"description":896,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":897,"url":898},{"cveId":895,"releaseId":25,"cycle":26,"description":896,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":897,"url":898},{"cveId":902,"releaseId":31,"cycle":32,"description":903,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":904,"url":905},"CVE-2026-53016","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - copy IV using skcipher ivsize\n\nAF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver.\n\nccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV\nbuffer while RFC3686 skciphers expose an 8-byte IV, so the restore\noverruns the provided buffer.\n\nUse crypto_skcipher_ivsize() to copy only the algorithm's IV length.","2026-06-24T17:17:12.893+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53016",{"cveId":902,"releaseId":17,"cycle":18,"description":903,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":904,"url":905},{"cveId":902,"releaseId":25,"cycle":26,"description":903,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":904,"url":905},{"cveId":909,"releaseId":17,"cycle":18,"description":910,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":911,"url":912},"CVE-2026-53009","In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix double-free of tx_buf skb\n\nIf ice_tso() or ice_tx_csum() fail, the error path in\nice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points\nto it and is marked as valid (ICE_TX_BUF_SKB).\n'next_to_use' remains unchanged, so the potential problem will\nlikely fix itself when the next packet is transmitted and the tx_buf\ngets overwritten. But if there is no next packet and the interface is\nbrought down instea","2026-06-24T17:17:12.117+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53009",{"cveId":914,"releaseId":31,"cycle":32,"description":915,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":916,"url":917},"CVE-2026-53006","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible UAF in icmpv6_rcv()\n\nCaching saddr and daddr before pskb_pull() is problematic\nsince skb->head can change.\n\nRemove these temporary variables:\n\n- We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr\n  when net_dbg_ratelimited() is called in the slow path.\n\n- Avoid potential future misuse after pskb_pull() call.","2026-06-24T17:17:11.75+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53006",{"cveId":914,"releaseId":17,"cycle":18,"description":915,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":916,"url":917},{"cveId":914,"releaseId":25,"cycle":26,"description":915,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":916,"url":917},{"cveId":921,"releaseId":31,"cycle":32,"description":922,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":923,"url":924},"CVE-2026-53004","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks\n\nsctp_getsockopt_peer_auth_chunks() checks that the caller's optval\nbuffer is large enough for the peer AUTH chunk list with\n\n    if (len \u003C num_chunks)\n            return -EINVAL;\n\nbut then writes num_chunks bytes to p->gauth_chunks, which lives\nat offset offsetof(struct sctp_authchunks, gauth_chunks) == 8\ninside optval.  The check is missing the sizeof(struct","2026-06-24T17:17:11.51+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53004",{"cveId":921,"releaseId":17,"cycle":18,"description":922,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":923,"url":924},{"cveId":921,"releaseId":25,"cycle":26,"description":922,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":923,"url":924},{"cveId":928,"releaseId":31,"cycle":32,"description":929,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":930,"url":931},"CVE-2026-53002","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: remove sprintf usage\n\nReplace it with scnprintf, the buffer sizes are expected to be large enough\nto hold the result, no need for snprintf+overflow check.\n\nIncrease buffer size in mangle_content_len() while at it.\n\nBUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5\u002F0x1270\nWrite of size 1 at addr [..]\n vsnprintf+0xea5\u002F0x1270\n sprintf+0xb1\u002F0xe0\n mangle_content_len+0x1ac\u002F0x280\n nf_nat_sdp_session+0x1cc\u002F0x240\n","2026-06-24T17:17:11.263+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53002",{"cveId":928,"releaseId":17,"cycle":18,"description":929,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":930,"url":931},{"cveId":928,"releaseId":25,"cycle":26,"description":929,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":930,"url":931},{"cveId":935,"releaseId":31,"cycle":32,"description":936,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":937,"url":938},"CVE-2026-53001","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xtables: restrict several matches to inet family\n\nThis is a partial revert of:\n\n  commit ab4f21e6fb1c (\"netfilter: xtables: use NFPROTO_UNSPEC in more extensions\")\n\nto allow ipv4 and ipv6 only.\n\n- xt_mac\n- xt_owner\n- xt_physdev\n\nThese extensions are not used by ebtables in userspace.\n\nMoreover, xt_realm is only for ipv4, since dst->tclassid is ipv4\nspecific.","2026-06-24T17:17:11.143+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-53001",{"cveId":935,"releaseId":17,"cycle":18,"description":936,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":937,"url":938},{"cveId":935,"releaseId":25,"cycle":26,"description":936,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":937,"url":938},{"cveId":942,"releaseId":17,"cycle":18,"description":943,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":944,"url":945},"CVE-2026-52999","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix out-of-bounds read on option matching\n\nIn nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once\nand passed by reference to nf_osf_match_one() for each fingerprint\nchecked. During TCP option parsing, nf_osf_match_one() advances the\nshared ctx->optp pointer.\n\nIf a fingerprint perfectly matches, the function returns early without\nrestoring ctx->optp to its initial state. If the user has con","2026-06-24T17:17:10.913+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52999",{"cveId":947,"releaseId":31,"cycle":32,"description":948,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":949,"url":950},"CVE-2026-52998","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix potential NULL dereference in ttl check\n\nThe nf_osf_ttl() function accessed skb->dev to perform a local interface\naddress lookup without verifying that the device pointer was valid.\n\nAdditionally, the implementation utilized an in_dev_for_each_ifa_rcu\nloop to match the packet source address against local interface\naddresses. It assumed that packets from the same subnet should not see a\ndecrement on","2026-06-24T17:17:10.777+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52998",{"cveId":947,"releaseId":17,"cycle":18,"description":948,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":949,"url":950},{"cveId":947,"releaseId":25,"cycle":26,"description":948,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":949,"url":950},{"cveId":954,"releaseId":17,"cycle":18,"description":955,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":956,"url":957},"CVE-2026-52995","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Frds: zero per-item info buffer before handing it to visitors\n\nrds_for_each_conn_info() and rds_walk_conn_path_info() both hand a\ncaller-allocated on-stack u64 buffer to a per-connection visitor and\nthen copy the full item_len bytes back to user space via\nrds_info_copy() regardless of how much of the buffer the visitor\nactually wrote.\n\nrds_ib_conn_info_visitor() and rds6_ib_conn_info_visitor() only\nwrite a subset of their ou","2026-06-24T17:17:10.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52995",{"cveId":954,"releaseId":31,"cycle":32,"description":955,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":956,"url":957},{"cveId":954,"releaseId":25,"cycle":26,"description":955,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":956,"url":957},{"cveId":961,"releaseId":17,"cycle":18,"description":962,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":963,"url":964},"CVE-2026-52993","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix double-free in tipc_buf_append()\n\ntipc_msg_validate() can potentially reallocate the skb it is validating,\nfreeing the old one.  In tipc_buf_append(), it was being called with a\npointer to a local variable which was a copy of the caller's skb\npointer.\n\nIf the skb was reallocated and validation subsequently failed, the error\nhandling path would free the original skb pointer, which had already\nbeen freed, leading to dou","2026-06-24T17:17:10.203+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52993",{"cveId":966,"releaseId":31,"cycle":32,"description":967,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":968,"url":969},"CVE-2026-52986","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: don't use simple_strtoul\n\nReplace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(),\nand ct_sip_parse_request() with a new sip_parse_port() helper that\nvalidates each digit against the buffer limit, eliminating the use of\nsimple_strtoul() which assumes NUL-terminated strings.\n\nThe previous code dereferenced pointers without bounds checks after\nsip_parse_addr() and relied on simple_strto","2026-06-24T17:17:09.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52986",{"cveId":966,"releaseId":17,"cycle":18,"description":967,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":968,"url":969},{"cveId":966,"releaseId":25,"cycle":26,"description":967,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":968,"url":969},{"cveId":973,"releaseId":31,"cycle":32,"description":974,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":975,"url":976},"CVE-2026-52982","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()\n\nsyzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit()\nwhen accessing skb->len for tx statistics after usb_submit_urb() has\nbeen called:\n\n  BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f\u002F0x760\n    drivers\u002Fnet\u002Fusb\u002Frtl8150.c:712\n  Read of size 4 at addr ffff88810eb7a930 by task kworker\u002F0:4\u002F5226\n\nThe URB completion handler write_bulk_call","2026-06-24T17:17:08.887+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52982",{"cveId":973,"releaseId":17,"cycle":18,"description":974,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":975,"url":976},{"cveId":973,"releaseId":25,"cycle":26,"description":974,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":975,"url":976},{"cveId":980,"releaseId":31,"cycle":32,"description":981,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":982,"url":983},"CVE-2026-52981","In the Linux kernel, the following vulnerability has been resolved:\n\nneigh: let neigh_xmit take skb ownership\n\nneigh_xmit always releases the skb, except when no neighbour table is\nfound. But even the first added user of neigh_xmit (mpls) relied on\nneigh_xmit to release the skb (or queue it for tx).\n\nsashiko reported:\n If neigh_xmit() is called with an uninitialized neighbor table (for\n example, NEIGH_ND_TABLE when IPv6 is disabled), it returns -EAFNOSUPPORT\n and bypasses its internal out_kfree_","2026-06-24T17:17:08.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52981",{"cveId":980,"releaseId":17,"cycle":18,"description":981,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":982,"url":983},{"cveId":980,"releaseId":25,"cycle":26,"description":981,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":982,"url":983},{"cveId":987,"releaseId":31,"cycle":32,"description":988,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":989,"url":990},"CVE-2026-52975","In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: 3ad: implement proper RCU rules for port->aggregator\n\nsyzbot found a data-race in bond_3ad_get_active_agg_info \u002F\nbond_3ad_state_machine_handler [1] which hints at lack of proper\nRCU implementation.\n\nAdd __rcu qualifier to port->aggregator, and add proper RCU API.\n\n[1]\n\nBUG: KCSAN: data-race in bond_3ad_get_active_agg_info \u002F bond_3ad_state_machine_handler\n\nwrite to 0xffff88813cf5c4b0 of 8 bytes by task 36 on cpu 0:\n  ad","2026-06-24T17:17:08.05+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52975",{"cveId":987,"releaseId":17,"cycle":18,"description":988,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":989,"url":990},{"cveId":987,"releaseId":25,"cycle":26,"description":988,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":989,"url":990},{"cveId":994,"releaseId":31,"cycle":32,"description":995,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":996,"url":997},"CVE-2026-52972","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Cap AEAD AD length to 0x80000000\n\nIn order to prevent arithmetic overflows when checking the TX\nbuffer size, cap the associated data length to 0x80000000.","2026-06-24T17:17:07.727+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52972",{"cveId":994,"releaseId":17,"cycle":18,"description":995,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":996,"url":997},{"cveId":994,"releaseId":25,"cycle":26,"description":995,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":996,"url":997},{"cveId":1001,"releaseId":31,"cycle":32,"description":1002,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1003,"url":1004},"CVE-2026-52963","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Bound MIDI endpoint descriptor scans\n\nsnd_usbmidi_get_ms_info() validates the internal MIDIStreaming endpoint\ndescriptor size before using baAssocJackID[], but the descriptor walker can\nstill return a class-specific endpoint descriptor whose bLength exceeds the\nremaining bytes in the endpoint-extra scan.\n\nThat leaves later flexible-array reads bounded by bLength, but not by the\nremaining bytes in the endpoint-e","2026-06-24T17:17:06.65+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52963",{"cveId":1001,"releaseId":25,"cycle":26,"description":1002,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1003,"url":1004},{"cveId":1001,"releaseId":17,"cycle":18,"description":1002,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1003,"url":1004},{"cveId":1008,"releaseId":31,"cycle":32,"description":1009,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1010,"url":1011},"CVE-2026-52962","In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix a buffer leak in __ceph_setxattr()\n\nThe old_blob in __ceph_setxattr() can store\nci->i_xattrs.prealloc_blob value during the retry.\nHowever, it is never called the ceph_buffer_put()\nfor the old_blob object. This patch fixes the issue of\nthe buffer leak.","2026-06-24T17:17:06.52+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52962",{"cveId":1008,"releaseId":25,"cycle":26,"description":1009,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1010,"url":1011},{"cveId":1008,"releaseId":17,"cycle":18,"description":1009,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1010,"url":1011},{"cveId":1015,"releaseId":17,"cycle":18,"description":1016,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1017,"url":1018},"CVE-2026-52957","In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix potential null-ptr-deref in decode_choose_args()\n\nA message of type CEPH_MSG_OSD_MAP contains an OSD map that itself\ncontains a CRUSH map. When decoding this CRUSH map in crush_decode(), an\narray of max_buckets CRUSH buckets is decoded, where some indices may\nnot refer to actual buckets and are therefore set to NULL. The received\nCRUSH map may optionally contain choose_args that get decoded in\ndecode_choose_args().","2026-06-24T17:17:05.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52957",{"cveId":1015,"releaseId":25,"cycle":26,"description":1016,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1017,"url":1018},{"cveId":1021,"releaseId":31,"cycle":32,"description":1022,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1023,"url":1024},"CVE-2026-52956","In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix potential out-of-bounds access in __ceph_x_decrypt()\n\nIn __ceph_x_decrypt(), a part of the buffer p is interpreted as a\nceph_x_encrypt_header, and the magic field of this struct is accessed.\nThis happens without any guarantee that the buffer is large enough to\nhold this struct. The function parameter ciphertext_len represents the\nlength of the ciphertext to decrypt and is guaranteed to be at most the\nremaining size","2026-06-24T17:17:05.807+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52956",{"cveId":1021,"releaseId":17,"cycle":18,"description":1022,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1023,"url":1024},{"cveId":1021,"releaseId":25,"cycle":26,"description":1022,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1023,"url":1024},{"cveId":1028,"releaseId":31,"cycle":32,"description":1029,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1030,"url":1031},"CVE-2026-52955","In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix potential out-of-bounds access in crush_decode()\n\nA message of type CEPH_MSG_OSD_MAP containing a crush map with at least\none bucket has two fields holding the bucket algorithm. If the values\nin these two fields differ, an out-of-bounds access can occur. This is\nthe case because the first algorithm field (alg) is used to allocate\nthe correct amount of memory for a bucket of this type, while the second\nalgorithm fie","2026-06-24T17:17:05.67+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52955",{"cveId":1028,"releaseId":17,"cycle":18,"description":1029,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1030,"url":1031},{"cveId":1028,"releaseId":25,"cycle":26,"description":1029,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1030,"url":1031},{"cveId":1035,"releaseId":17,"cycle":18,"description":1036,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1037,"url":1038},"CVE-2026-52954","In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: handle rbtree insertion error in decode_choose_args()\n\nA message of type CEPH_MSG_OSD_MAP contains an OSD map that itself\ncontains a CRUSH map. The received CRUSH map may optionally contain\nchoose_args that get decoded in decode_choose_args(). In this function,\nnum_choose_arg_maps is read from the message, and a corresponding number\nof crush_choose_arg_maps gets decoded afterwards. Each\ncrush_choose_arg_map has a choos","2026-06-24T17:17:05.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52954",{"cveId":1035,"releaseId":25,"cycle":26,"description":1036,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1037,"url":1038},{"cveId":1041,"releaseId":31,"cycle":32,"description":1042,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1043,"url":1044},"CVE-2026-52948","In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl\n\nWhile fuzzing with Syzkaller, a persistent `schedule_timeout: wrong\ntimeout value` warning was observed, accompanied by SMBus controller\nstate machine corruption.\n\nThe I2C_TIMEOUT ioctl accepts a user-provided timeout in multiples of\n10 ms. The user argument is checked against INT_MAX, but it is\nsubsequently multiplied by 10 before being passed to msecs_to_jiffies().\n\nA m","2026-06-24T17:17:04.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52948",{"cveId":1041,"releaseId":17,"cycle":18,"description":1042,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1043,"url":1044},{"cveId":1041,"releaseId":25,"cycle":26,"description":1042,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1043,"url":1044},{"cveId":1048,"releaseId":31,"cycle":32,"description":1049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1050,"url":1051},"CVE-2026-52947","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove\n\nIn qrtr_port_remove(), the socket reference count is decremented via\n__sock_put() before the port is removed from the qrtr_ports XArray and\nbefore the RCU grace period elapses.\n\nThis breaks the fundamental RCU update paradigm. It exposes a race\nwindow where a concurrent RCU reader (such as qrtr_reset_ports() or\nqrtr_port_lookup()) can obtain a pointer to ","2026-06-24T17:17:04.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52947",{"cveId":1048,"releaseId":17,"cycle":18,"description":1049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1050,"url":1051},{"cveId":1048,"releaseId":25,"cycle":26,"description":1049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1050,"url":1051},{"cveId":1055,"releaseId":31,"cycle":32,"description":1056,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1057,"url":1058},"CVE-2026-52946","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Ffcntl: fix SOFTIRQ-unsafe lock order in fasync signaling\n\nA SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in\nsend_sigio() and send_sigurg() when a process group receives a signal.\n\nWhen FASYNC is configured for a process group (PIDTYPE_PGID), both\nfunctions use read_lock(&tasklist_lock) to traverse the task list.\nHowever, they are frequently called from softirq context:\n- send_sigio() via input_inject_event ->","2026-06-24T17:17:04.61+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52946",{"cveId":1055,"releaseId":17,"cycle":18,"description":1056,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1057,"url":1058},{"cveId":1055,"releaseId":25,"cycle":26,"description":1056,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1057,"url":1058},{"cveId":1062,"releaseId":31,"cycle":32,"description":1063,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1064,"url":1065},"CVE-2026-52943","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: fix missing zerocopy reference in pskb_carve helpers\n\npskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy\nthe old skb_shared_info header into a new buffer via memcpy(), which\nincludes the destructor_arg pointer (uarg) for MSG_ZEROCOPY skbs.\nNeither function calls net_zcopy_get() for the new shinfo, creating an\nunaccounted holder: every skb_shared_info with destructor_arg set will\ncall skb_zcopy_c","2026-06-24T10:17:19.293+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52943",{"cveId":1062,"releaseId":17,"cycle":18,"description":1063,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1064,"url":1065},{"cveId":1062,"releaseId":25,"cycle":26,"description":1063,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1064,"url":1065},{"cveId":1069,"releaseId":31,"cycle":32,"description":1070,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1071,"url":1072},"CVE-2026-52942","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_log: validate MAC header was set before dumping it\n\nThe fallback path of dump_mac_header() guards the MAC header access\nonly with \"skb->mac_header != skb->network_header\", without checking\nskb_mac_header_was_set(). When the MAC header is unset, mac_header is\n0xffff, so the test passes and skb_mac_header(skb) returns\nskb->head + 0xffff, ~64 KiB past the buffer; the loop then reads\ndev->hard_header_len bytes out of ","2026-06-24T08:16:24.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52942",{"cveId":1069,"releaseId":17,"cycle":18,"description":1070,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1071,"url":1072},{"cveId":1069,"releaseId":25,"cycle":26,"description":1070,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1071,"url":1072},{"cveId":1076,"releaseId":31,"cycle":32,"description":1077,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1078,"url":1079},"CVE-2026-52939","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Frds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion\n\nrds_ib_xmit_atomic() always programs a masked atomic opcode\n(IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD)\nfor every RDS atomic cmsg.  But the completion-side switch in\nrds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked\natomic completion falls through to default and returns rm == NULL while\nsend->s_op i","2026-06-24T08:16:24.16+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52939",{"cveId":1076,"releaseId":17,"cycle":18,"description":1077,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1078,"url":1079},{"cveId":1076,"releaseId":25,"cycle":26,"description":1077,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1078,"url":1079},{"cveId":1083,"releaseId":31,"cycle":32,"description":1084,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1085,"url":1086},"CVE-2026-52936","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: jitterentropy - replace long-held spinlock with mutex\n\njent_kcapi_random() serializes the shared jitterentropy state, but it\ncurrently holds a spinlock across the jent_read_entropy() call. That\npath performs expensive jitter collection and SHA3 conditioning, so\nparallel readers can trigger stalls as contending waiters spin for\nthe same lock.\n\nTo prevent non-preemptible lock hold, replace rng->jent_lock with a\nmutex so c","2026-06-24T08:16:23.883+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52936",{"cveId":1083,"releaseId":17,"cycle":18,"description":1084,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1085,"url":1086},{"cveId":1083,"releaseId":25,"cycle":26,"description":1084,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1085,"url":1086},{"cveId":1090,"releaseId":31,"cycle":32,"description":1091,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1092,"url":1093},"CVE-2026-52934","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tvlv: reject oversized TVLV packets\n\nbatadv_tvlv_container_ogm_append() builds a TVLV packet section from\nthe tvlv.container_list. The total size of this section is computed by\nbatadv_tvlv_container_list_size(), which sums the sizes of all registered\ncontainers.\n\nThe return type and accumulator in batadv_tvlv_container_list_size() were\nu16. If the accumulated size exceeds U16_MAX, the value wraps around,\ncausing the","2026-06-24T08:16:23.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52934",{"cveId":1090,"releaseId":17,"cycle":18,"description":1091,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1092,"url":1093},{"cveId":1090,"releaseId":25,"cycle":26,"description":1091,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1092,"url":1093},{"cveId":1097,"releaseId":31,"cycle":32,"description":1098,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1099,"url":1100},"CVE-2026-52931","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: avoid use of uninit sender vars\n\nbatadv_tp_recv_ack() and batadv_tp_stop() are only valid for tp_vars in the\nBATADV_TP_SENDER role. When called with a BATADV_TP_RECEIVER role, it\nproceeds to read sender-only members that were never initialized, leading\nto undefined behavior.\n\nThis can be triggered when a node that is currently acting as a receiver in\nan ongoing tp_meter session receives a malicious ACK pac","2026-06-24T08:16:23.273+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52931",{"cveId":1097,"releaseId":17,"cycle":18,"description":1098,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1099,"url":1100},{"cveId":1097,"releaseId":25,"cycle":26,"description":1098,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1099,"url":1100},{"cveId":1104,"releaseId":31,"cycle":32,"description":1105,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1106,"url":1107},"CVE-2026-52930","In the Linux kernel, the following vulnerability has been resolved:\n\nipc\u002Fshm: serialize orphan cleanup with shm_nattch updates\n\nshm_destroy_orphaned() walks the shm idr under shm_ids(ns).rwsem, but that\ndoes not serialize all fields tested by shm_may_destroy().  In particular,\nshm_nattch is updated while holding shm_perm.lock, and attach paths can do\nthat without holding the rwsem.\n\nDo not decide that an orphaned segment is unused before taking the object\nlock.  Move the shm_may_destroy() check ","2026-06-24T08:16:23.157+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52930",{"cveId":1104,"releaseId":17,"cycle":18,"description":1105,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1106,"url":1107},{"cveId":1104,"releaseId":25,"cycle":26,"description":1105,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1106,"url":1107},{"cveId":1111,"releaseId":17,"cycle":18,"description":1112,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1113,"url":1114},"CVE-2026-52929","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: stream: fully roll back denied add-stream state\n\nWhen ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and\nthen lowers outcnt. That leaves removed stream metadata behind, so a\nlater re-add can reuse a stale ext and hit a null-pointer dereference in\nthe scheduler get path.\n\nFix the rollback by tearing down the removed stream state the same way\nother stream resizes do. Unschedule the current scheduler state, d","2026-06-24T08:16:23.04+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52929",{"cveId":1116,"releaseId":31,"cycle":32,"description":1117,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1118,"url":1119},"CVE-2026-52927","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: fix OOB read in compat_mtw_from_user\n\nLuxiao Xu says:\n\n The function compat_mtw_from_user() converts ebtables extensions from\n 32-bit user structures to kernel native structures. However, it lacks\n proper validation of the user-supplied match_size\u002Ftarget_size.\n\n When certain extensions are processed, the kernel-side translation\n logic may perform memory accesses based on the extension's expected\n size. If t","2026-06-24T08:16:22.81+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52927",{"cveId":1116,"releaseId":17,"cycle":18,"description":1117,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1118,"url":1119},{"cveId":1116,"releaseId":25,"cycle":26,"description":1117,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1118,"url":1119},{"cveId":1123,"releaseId":31,"cycle":32,"description":1124,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1125,"url":1126},"CVE-2026-52926","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: clear current gateway during teardown\n\nbatadv_gw_node_free() removes the gateway list entries during mesh teardown,\nbut it does not clear the currently selected gateway. This leaves stale\ngateway state behind across cleanup and can break a later mesh recreation.\n\nClear bat_priv->gw.curr_gw before walking the gateway list so the selected\ngateway reference is dropped as part of teardown.","2026-06-24T08:16:22.697+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52926",{"cveId":1123,"releaseId":17,"cycle":18,"description":1124,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1125,"url":1126},{"cveId":1123,"releaseId":25,"cycle":26,"description":1124,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1125,"url":1126},{"cveId":1130,"releaseId":17,"cycle":18,"description":1131,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1132,"url":1133},"CVE-2026-52925","In the Linux kernel, the following vulnerability has been resolved:\n\nvrf: Fix a potential NPD when removing a port from a VRF\n\nRCU readers that identified a net device as a VRF port using\nnetif_is_l3_slave() assume that a subsequent call to\nnetdev_master_upper_dev_get_rcu() will return a VRF device. They then\ncontinue to dereference its l3mdev operations.\n\nThis assumption is not always correct and can result in a NPD [1]. There\nis no RCU synchronization when removing a port from a VRF, so it is\n","2026-06-24T08:16:22.563+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52925",{"cveId":1130,"releaseId":25,"cycle":26,"description":1131,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1132,"url":1133},{"cveId":1136,"releaseId":17,"cycle":18,"description":1137,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1138,"url":1139},"CVE-2026-52924","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: purge outqueue on stale COOKIE-ECHO handling\n\nsctp_stream_update() is only invoked when the association is moved into\nCOOKIE_WAIT during association setup\u002Freconfiguration. In this path, the\noutbound stream scheduler state (stream->out_curr) is expected to be\nclean, since no user data should have been transmitted yet unless the\nstate machine has already partially progressed.\n\nHowever, a corner case exists in sctp_sf_do_5_2","2026-06-24T08:16:22.43+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52924",{"cveId":1141,"releaseId":31,"cycle":32,"description":1142,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1143,"url":1144},"CVE-2026-52923","In the Linux kernel, the following vulnerability has been resolved:\n\nipc: limit next_id allocation to the valid ID range\n\nThe checkpoint\u002Frestore sysctl path can request the next SysV IPC id\nthrough ids->next_id.  ipc_idr_alloc() currently forwards that request to\nidr_alloc() with an open-ended upper bound.\n\nIf the valid tail of the SysV IPC id space is full, the allocation can\nspill beyond ipc_mni.  The returned SysV IPC id still uses the normal\nindex encoding, so later lookup and removal can ta","2026-06-24T08:16:22.3+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52923",{"cveId":1141,"releaseId":17,"cycle":18,"description":1142,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1143,"url":1144},{"cveId":1141,"releaseId":25,"cycle":26,"description":1142,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1143,"url":1144},{"cveId":1148,"releaseId":31,"cycle":32,"description":1149,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1150,"url":1151},"CVE-2026-52922","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: dat: handle forward allocation error\n\nbatadv_dat_forward_data() calls pskb_copy_for_clone() to duplicate an skb\nfor each DHT candidate, but does not check the return value before passing\nit to batadv_send_skb_prepare_unicast_4addr(). That function dereferences\nthe skb unconditionally, so a failed allocation triggers a NULL pointer\ndereference.\n\nSkip forwarding to the current DHT candidate on allocation failure.","2026-06-24T08:16:22.187+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52922",{"cveId":1148,"releaseId":17,"cycle":18,"description":1149,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1150,"url":1151},{"cveId":1148,"releaseId":25,"cycle":26,"description":1149,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1150,"url":1151},{"cveId":1155,"releaseId":17,"cycle":18,"description":1156,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1157,"url":1158},"CVE-2026-52921","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: stop hash:* range iteration at end\n\nThe following hash set variants:\n\nhash:ip,mark\nhash:ip,port\nhash:ip,port,ip\nhash:ip,port,net\n\niterate IPv4 ranges with a 32-bit iterator.\n\nThe iterator must stop once the last address in the requested range has\nbeen processed. Advancing it once more can move the traversal state past\nthe end of the request, so a later retry may continue from an unintended\nposition.\n\nHandle th","2026-06-24T08:16:22.067+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52921",{"cveId":1155,"releaseId":25,"cycle":26,"description":1156,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1157,"url":1158},{"cveId":1161,"releaseId":31,"cycle":32,"description":1162,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":1164,"url":1165},"CVE-2026-52920","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_policy: fix strict mode inbound policy matching\n\nmatch_policy_in() walks sec_path entries from the last transform to the\nfirst one, but strict policy matching needs to consume info->pol[] in\nthe same forward order as the rule layout.\n\nDerive the strict-match policy position from the number of transforms\nalready consumed so that multi-element inbound rules are matched\nconsistently.",8.3,"2026-06-24T08:16:21.95+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52920",{"cveId":1161,"releaseId":17,"cycle":18,"description":1162,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":1164,"url":1165},{"cveId":1161,"releaseId":25,"cycle":26,"description":1162,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":1164,"url":1165},{"cveId":1169,"releaseId":31,"cycle":32,"description":1170,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1171,"url":1172},"CVE-2026-52919","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: fix tp_meter counter underflow during shutdown\n\nbatadv_tp_sender_shutdown() unconditionally decrements the \"sending\"\natomic counter. If multiple paths (e.g. timeout, user cancel, and\nnormal finish) call this function, the counter can underflow to -1.\n\nSince the sender logic treats any non-zero value as \"still sending\",\na negative value causes the sender kthread to loop indefinitely.\nThis leads to a use-after-free wh","2026-06-24T08:16:21.833+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52919",{"cveId":1169,"releaseId":17,"cycle":18,"description":1170,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1171,"url":1172},{"cveId":1169,"releaseId":25,"cycle":26,"description":1170,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1171,"url":1172},{"cveId":1176,"releaseId":31,"cycle":32,"description":1177,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1178,"url":1179},"CVE-2026-52918","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: serialize accept_q access\n\nbt_sock_poll() walks the accept queue without synchronization, while\nchild teardown can unlink the same socket and drop its last reference.\nThe unsynchronized accept queue walk has existed since the initial\nBluetooth import.\n\nProtect accept_q with a dedicated lock for queue updates and polling.\nAlso rework bt_accept_dequeue() to take temporary child references under\nthe queue lock before dr","2026-06-24T08:16:21.713+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52918",{"cveId":1176,"releaseId":17,"cycle":18,"description":1177,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1178,"url":1179},{"cveId":1176,"releaseId":25,"cycle":26,"description":1177,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1178,"url":1179},{"cveId":1183,"releaseId":31,"cycle":32,"description":1184,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1185,"url":1186},"CVE-2026-52917","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: diag: reject stale associations in dump_one path\n\nThe SCTP exact sock_diag lookup can hold a transport reference, block on\nlock_sock(sk), and then resume after sctp_association_free() has marked\nthe association dead and freed its bind address list.\n\nWhen that happens, inet_assoc_attr_size() and\ninet_diag_msg_sctpasoc_fill() can still dereference association state\nthat is no longer valid for reporting. In particular,\ninet_","2026-06-24T08:16:21.587+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52917",{"cveId":1183,"releaseId":17,"cycle":18,"description":1184,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1185,"url":1186},{"cveId":1183,"releaseId":25,"cycle":26,"description":1184,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1185,"url":1186},{"cveId":1190,"releaseId":31,"cycle":32,"description":1191,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1192,"url":1193},"CVE-2026-52916","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: frag: disallow unicast fragment in fragment\n\nbatadv_frag_skb_buffer() is called by batadv_batman_skb_recv() when a\nBATADV_UNICAST_FRAG packet is received. Once all fragments are collected\nand the packet is reassembled, batadv_recv_frag_packet() calls\nbatadv_batman_skb_recv() again to process the defragmented payload.\n\nA malicious sender can craft a BATADV_UNICAST_FRAG packet whose reassembled\npayload is itself a BAT","2026-06-24T08:16:21.463+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52916",{"cveId":1190,"releaseId":17,"cycle":18,"description":1191,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1192,"url":1193},{"cveId":1190,"releaseId":25,"cycle":26,"description":1191,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1192,"url":1193},{"cveId":1197,"releaseId":31,"cycle":32,"description":1198,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1199,"url":1200},"CVE-2026-52915","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ip6t_hbh: reject oversized option lists\n\nstruct ip6t_opts stores at most IP6T_OPTS_OPTSNR option descriptors,\nbut hbh_mt6_check() does not reject larger optsnr values supplied from\nuserspace.\n\nValidate optsnr in the rule setup path so only match data that fits the\nfixed-size opts array can be installed. This follows the existing xtables\npattern of rejecting invalid user-provided counts in checkentry() and\nkeeps the p","2026-06-24T08:16:21.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52915",{"cveId":1197,"releaseId":17,"cycle":18,"description":1198,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1199,"url":1200},{"cveId":1197,"releaseId":25,"cycle":26,"description":1198,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1199,"url":1200},{"cveId":1204,"releaseId":31,"cycle":32,"description":1205,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1206,"url":1207},"CVE-2026-52914","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: fix fragment reassembly length accounting\n\nbatman-adv keeps a running payload length for queued fragments and uses it\nto validate a fragment chain before reassembly.\n\nThat accounting currently allows the accumulated fragment length to be\ntruncated during updates. As a result, malformed fragment chains can\nbypass the intended validation and drive reassembly with inconsistent\nlength state, leading to a local denial of","2026-06-24T08:16:21.213+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52914",{"cveId":1204,"releaseId":17,"cycle":18,"description":1205,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1206,"url":1207},{"cveId":1204,"releaseId":25,"cycle":26,"description":1205,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1206,"url":1207},{"cveId":1211,"releaseId":31,"cycle":32,"description":1212,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1213,"url":1214},"CVE-2026-52913","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: v: stop OGMv2 on disabled interface\n\nWhen a batadv_hard_iface is disabled, its mesh_iface pointer is set to\nNULL. However, batadv_v_ogm_send_meshif() may still dispatch OGMs via\nbatadv_v_ogm_queue_on_if() for interfaces that have since lost their\nmesh_iface association. This results in a NULL pointer dereference when\nbatadv_v_ogm_queue_on_if() unconditionally calls netdev_priv() on the\nnow NULL hard_iface->mesh_ifac","2026-06-24T08:16:21.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52913",{"cveId":1211,"releaseId":17,"cycle":18,"description":1212,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1213,"url":1214},{"cveId":1211,"releaseId":25,"cycle":26,"description":1212,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1213,"url":1214},{"cveId":1218,"releaseId":31,"cycle":32,"description":1219,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1220,"url":1221},"CVE-2026-52912","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_queue: hold bridge skb->dev while queued\n\nbr_pass_frame_up() rewrites skb->dev from the ingress port to the bridge\nmaster before queueing bridge LOCAL_IN packets. NFQUEUE only holds\nreferences on state.in\u002Fout and bridge physdevs, so a queued bridge\npacket can retain a freed bridge master in skb->dev until reinjection.\n\nWhen the verdict is reinjected later, br_netif_receive_skb() re-enters\nthe receive path with skb","2026-06-24T08:16:20.64+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52912",{"cveId":1218,"releaseId":17,"cycle":18,"description":1219,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1220,"url":1221},{"cveId":1218,"releaseId":25,"cycle":26,"description":1219,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1220,"url":1221},{"cveId":1225,"releaseId":25,"cycle":26,"description":1226,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1227,"url":1228},"CVE-2026-52910","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Free reuseport cBPF prog after RCU grace period.\n\nEulgyu Kim reported the splat below with a repro. [0]\n\nThe repro sets up a UDP reuseport group with a cBPF prog and\nreplaces it with a new one while another thread is sending\na UDP packet to the group.\n\nThe reuseport prog is freed by sk_reuseport_prog_free().\nbpf_prog_put() is called for \"e\"BPF prog to destruct through\nmultiple stages while cBPF prog is freed immediately by","2026-06-19T15:16:35.487+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52910",{"cveId":1225,"releaseId":31,"cycle":32,"description":1226,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1227,"url":1228},{"cveId":1225,"releaseId":17,"cycle":18,"description":1226,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1227,"url":1228},{"cveId":1232,"releaseId":31,"cycle":32,"description":1233,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1234,"url":1235},"CVE-2026-52909","In the Linux kernel, the following vulnerability has been resolved:\n\nip6_vti: set netns_immutable on the fallback device.\n\njohn1988 and Noam Rathaus reported that vti6_init_net() does not set the\nnetns_immutable flag on the per-netns fallback tunnel device (ip6_vti0).\n\nOther similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel)\ncorrectly set this flag during their fallback device initialization to\nprevent them from being moved to another network namespace.","2026-06-19T15:16:35.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-52909",{"cveId":1232,"releaseId":17,"cycle":18,"description":1233,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1234,"url":1235},{"cveId":1232,"releaseId":25,"cycle":26,"description":1233,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1234,"url":1235},{"cveId":1239,"releaseId":17,"cycle":18,"description":1240,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1241,"url":1242},"CVE-2026-46331","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow ","2026-06-16T08:16:23.993+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46331",{"cveId":1244,"releaseId":17,"cycle":18,"description":1245,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":1247,"url":1248},"CVE-2026-46328","In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix rlimit for posix cpu timers\n\nPosix cpu timers requires an additional step beyond setting the rlimit.\nRefactor the code so its clear when what code is setting the\nlimit and conditionally update the posix cpu timers when appropriate.",7.3,"2026-06-09T14:16:42.5+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46328",{"cveId":1244,"releaseId":25,"cycle":26,"description":1245,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":1247,"url":1248},{"cveId":1251,"releaseId":17,"cycle":18,"description":1252,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1253,"url":1254},"CVE-2026-46324","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: use list_del_rcu for netlink hooks\n\nnft_netdev_unregister_hooks and __nft_unregister_flowtable_net_hooks need\nto use list_del_rcu(), this list can be walked by concurrent dumpers.\n\nAdd a new helper and use it consistently.","2026-06-09T13:16:37.893+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46324",{"cveId":1256,"releaseId":31,"cycle":32,"description":1257,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1258,"url":1259},"CVE-2026-46312","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: videobuf2: Set vma_flags in vb2_dma_sg_mmap\n\nvb2_dma_contig sets VMA flags VM_DONTEXPAND and VM_DONTDUMP and I do not\nsee a reason why vb2_dma_sg should behave differently. This avoids\nhitting `WARN_ON(!(vma->vm_flags & VM_DONTEXPAND));` in\ndrm_gem_mmap_obj() during mmap() of an imported dma-buf from the out of\ntree Apple ISP camera capture driver which uses vb2_dma_sg_memops.\n\ngst-launch-1.0 v4l2src ! gtk4paintablesink\n","2026-06-08T17:16:50.16+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46312",{"cveId":1256,"releaseId":17,"cycle":18,"description":1257,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1258,"url":1259},{"cveId":1256,"releaseId":25,"cycle":26,"description":1257,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1258,"url":1259},{"cveId":1263,"releaseId":31,"cycle":32,"description":1264,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":1265,"url":1266},"CVE-2026-46307","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath5k: do not access array OOB\n\nVincent reports:\n> The ath5k driver seems to do an array-index-out-of-bounds access as\n> shown by the UBSAN kernel message:\n> UBSAN: array-index-out-of-bounds in drivers\u002Fnet\u002Fwireless\u002Fath\u002Fath5k\u002Fbase.c:1741:20\n> index 4 is out of range for type 'ieee80211_tx_rate [4]'\n> ...\n> Call Trace:\n>  \u003CTASK>\n>  dump_stack_lvl+0x5d\u002F0x80\n>  ubsan_epilogue+0x5\u002F0x2b\n>  __ubsan_handle_out_of_bounds.cold+0x46","2026-06-08T17:16:49.547+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46307",{"cveId":1263,"releaseId":17,"cycle":18,"description":1264,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":1265,"url":1266},{"cveId":1263,"releaseId":25,"cycle":26,"description":1264,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":1265,"url":1266},{"cveId":1270,"releaseId":31,"cycle":32,"description":1271,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1272,"url":1273},"CVE-2026-46304","In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free\n\nnvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the\nfinal controller reference through nvmet_cq_put(). If that triggers\nnvmet_ctrl_free(), the teardown path flushes ctrl->async_event_work on\nthe same nvmet-wq.\n\nCall chain:\n\n nvmet_tcp_schedule_release_queue()\n   kref_put(&queue->kref, nvmet_tcp_release_queue)\n     nvmet_tcp_release_queue()\n       queue_work(","2026-06-08T17:16:49.053+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46304",{"cveId":1270,"releaseId":17,"cycle":18,"description":1271,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1272,"url":1273},{"cveId":1270,"releaseId":25,"cycle":26,"description":1271,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1272,"url":1273},{"cveId":1277,"releaseId":31,"cycle":32,"description":1278,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1279,"url":1280},"CVE-2026-46303","In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: validate Rock Ridge CE continuation extent against volume size\n\nrock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE\nrecord and passes it to sb_bread() without checking that the block\nnumber is within the mounted ISO 9660 volume.  commit e595447e177b\n(\"[PATCH] rock.c: handle corrupted directories\") added cont_offset\nand cont_size rejection for the CE continuation but did not validate\nthe extent block num","2026-06-08T17:16:48.853+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46303",{"cveId":1277,"releaseId":17,"cycle":18,"description":1278,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1279,"url":1280},{"cveId":1277,"releaseId":25,"cycle":26,"description":1278,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1279,"url":1280},{"cveId":1284,"releaseId":31,"cycle":32,"description":1285,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1286,"url":1287},"CVE-2026-46302","In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: allow multiple opens of \u002Fsys\u002Ffs\u002Fselinux\u002Fpolicy\n\nCurrently there can only be a single open of \u002Fsys\u002Ffs\u002Fselinux\u002Fpolicy at\nany time. This allows any process to block any other process from\nreading the kernel policy. The original motivation seems to have been\na mix of preventing an inconsistent view of the policy size and\npreventing userspace from allocating kernel memory without bound, but\nthis is arguably equally bad. Eli","2026-06-08T17:16:48.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46302",{"cveId":1284,"releaseId":17,"cycle":18,"description":1285,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1286,"url":1287},{"cveId":1284,"releaseId":25,"cycle":26,"description":1285,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1286,"url":1287},{"cveId":1291,"releaseId":31,"cycle":32,"description":1292,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1293,"url":1294},"CVE-2026-46301","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: topcliff-pch: fix use-after-free on unbind\n\nGive the driver a chance to flush its queue before releasing the DMA\nbuffers on driver unbind","2026-06-08T17:16:48.56+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46301",{"cveId":1291,"releaseId":17,"cycle":18,"description":1292,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1293,"url":1294},{"cveId":1291,"releaseId":25,"cycle":26,"description":1292,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1293,"url":1294},{"cveId":1298,"releaseId":31,"cycle":32,"description":1299,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":1300,"url":1301},"CVE-2026-46299","In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: fix held lock freed on hfsplus_fill_super()\n\nhfsplus_fill_super() calls hfs_find_init() to initialize a search\nstructure, which acquires tree->tree_lock. If the subsequent call to\nhfsplus_cat_build_key() fails, the function jumps to the out_put_root\nerror label without releasing the lock. The later cleanup path then\nfrees the tree data structure with the lock still held, triggering a\nheld lock freed warning.\n\nFix this ","2026-06-08T17:16:48.393+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46299",{"cveId":1298,"releaseId":17,"cycle":18,"description":1299,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":1300,"url":1301},{"cveId":1298,"releaseId":25,"cycle":26,"description":1299,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":1300,"url":1301},{"cveId":1305,"releaseId":17,"cycle":18,"description":1306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1307,"url":1308},"CVE-2026-46294","In the Linux kernel, the following vulnerability has been resolved:\n\ndm: fix a buffer overflow in ioctl processing\n\nTony Asleson (using Claude) found a buffer overflow in dm-ioctl in the\nfunction retrieve_status:\n\n1. The code in retrieve_status checks that the output string fits into\n   the output buffer and writes the output string there\n2. Then, the code aligns the \"outptr\" variable to the next 8-byte\n   boundary:\n\toutptr = align_ptr(outptr);\n3. The alignment doesn't check overflow, so outptr ","2026-06-08T17:16:47.757+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46294",{"cveId":1305,"releaseId":25,"cycle":26,"description":1306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1307,"url":1308},{"cveId":1305,"releaseId":31,"cycle":32,"description":1306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1307,"url":1308},{"cveId":1312,"releaseId":17,"cycle":18,"description":1313,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1314,"url":1315},"CVE-2026-46292","In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: core: Fix detach procedure for virtual devices in genpd\n\nIf a device is attached to a PM domain through genpd_dev_pm_attach_by_id(),\ngenpd calls pm_runtime_enable() for the corresponding virtual device that\nit registers. While this avoids boilerplate code in drivers, there is no\ncorresponding call to pm_runtime_disable() in genpd_dev_pm_detach().\n\nThis means these virtual devices are typically detached from its genpd,","2026-06-08T17:16:47.497+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46292",{"cveId":1317,"releaseId":31,"cycle":32,"description":1318,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1319,"url":1320},"CVE-2026-46291","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - guard HMAC key hex dumps in hash_digest_key\n\nUse print_hex_dump_devel() for dumping sensitive HMAC key bytes in\nhash_digest_key() to avoid leaking secrets at runtime when\nCONFIG_DYNAMIC_DEBUG is enabled.","2026-06-08T17:16:47.357+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46291",{"cveId":1317,"releaseId":17,"cycle":18,"description":1318,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1319,"url":1320},{"cveId":1317,"releaseId":25,"cycle":26,"description":1318,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1319,"url":1320},{"cveId":1324,"releaseId":25,"cycle":26,"description":1325,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1326,"url":1327},"CVE-2026-46275","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_uart: fix UAFs and race conditions in close and init paths\n\nVulnerabilities leading to Use-After-Free (UAF) and Null Pointer\nDereference (NPD) conditions were observed in the lifecycle management\nof hci_uart.\n\nThe primary issue arises because the workqueues (init_ready and\nwrite_work) are only flushed\u002Fcancelled if the HCI_UART_PROTO_READY\nflag is set during TTY close. If a hangup occurs before setup completes,\nhc","2026-06-08T16:16:40.863+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46275",{"cveId":1324,"releaseId":17,"cycle":18,"description":1325,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1326,"url":1327},{"cveId":1330,"releaseId":17,"cycle":18,"description":1331,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1332,"url":1333},"CVE-2025-71315","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvkms: Convert to DRM's vblank timer\n\nReplace vkms' vblank timer with the DRM implementation. The DRM\ncode is identical in concept, but differs in implementation.\n\nVblank timers are covered in vblank helpers and initializer macros,\nso remove the corresponding hrtimer in struct vkms_output. The\nvblank timer calls vkms' custom timeout code via handle_vblank_timeout\nin struct drm_crtc_helper_funcs.","2026-06-08T16:16:33.5+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71315",{"cveId":1335,"releaseId":25,"cycle":26,"description":1336,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":1338,"url":1339},"CVE-2026-46273","In the Linux kernel, the following vulnerability has been resolved:\n\nibmveth: Disable GSO for packets with small MSS\n\nSome physical adapters on Power systems do not support segmentation\noffload when the MSS is less than 224 bytes. Attempting to send such\npackets causes the adapter to freeze, stopping all traffic until\nmanually reset.\n\nImplement ndo_features_check to disable GSO for packets with small MSS\nvalues. The network stack will perform software segmentation instead.\n\nThe 224-byte minimum ",8.6,"2026-06-03T18:16:29.16+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46273",{"cveId":1335,"releaseId":17,"cycle":18,"description":1336,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":1338,"url":1339},{"cveId":1335,"releaseId":31,"cycle":32,"description":1336,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":1338,"url":1339},{"cveId":1343,"releaseId":25,"cycle":26,"description":1344,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":1345,"url":1346},"CVE-2026-46270","In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: rt9455: Fix use-after-free in power_supply_changed()\n\nUsing the `devm_` variant for requesting IRQ _before_ the `devm_`\nvariant for allocating\u002Fregistering the `power_supply` handle, means that\nthe `power_supply` handle will be deallocated\u002Funregistered _before_ the\ninterrupt handler (since `devm_` naturally deallocates in reverse\nallocation order). This means that during removal, there is a race\ncondition where an","2026-06-03T18:16:28.733+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46270",{"cveId":1343,"releaseId":17,"cycle":18,"description":1344,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":1345,"url":1346},{"cveId":1343,"releaseId":31,"cycle":32,"description":1344,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":1345,"url":1346},{"cveId":1350,"releaseId":25,"cycle":26,"description":1351,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1352,"url":1353},"CVE-2026-46267","In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: hci: shdlc: Stop timers and work before freeing context\n\nllc_shdlc_deinit() purges SHDLC skb queues and frees the llc_shdlc\nstructure while its timers and state machine work may still be active.\n\nTimer callbacks can schedule sm_work, and sm_work accesses SHDLC state\nand the skb queues. If teardown happens in parallel with a queued\u002Frunning\nwork item, it can lead to UAF and other shutdown races.\n\nStop all SHDLC timers and ca","2026-06-03T18:16:28.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46267",{"cveId":1350,"releaseId":17,"cycle":18,"description":1351,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1352,"url":1353},{"cveId":1350,"releaseId":31,"cycle":32,"description":1351,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1352,"url":1353},{"cveId":1357,"releaseId":25,"cycle":26,"description":1358,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":1359,"url":1360},"CVE-2026-46266","In the Linux kernel, the following vulnerability has been resolved:\n\ninet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP\n\nYizhou Zhao reported that simply having one RAW socket on protocol\nIPPROTO_RAW (255) was dangerous.\n\n  socket(AF_INET, SOCK_RAW, 255);\n\nA malicious incoming ICMP packet can set the protocol field to 255\nand match this socket, leading to FNHE cache changes.\n\ninner = IP(src=\"192.168.2.1\", dst=\"8.8.8.8\", proto=255)\u002FRaw(\"TEST\")\npkt = IP(src=\"192.168.1.1\", dst=\"192.168.2.1","2026-06-03T18:16:28.147+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46266",{"cveId":1357,"releaseId":17,"cycle":18,"description":1358,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":1359,"url":1360},{"cveId":1357,"releaseId":31,"cycle":32,"description":1358,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":1359,"url":1360},{"cveId":1364,"releaseId":25,"cycle":26,"description":1365,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1366,"url":1367},"CVE-2026-46259","In the Linux kernel, the following vulnerability has been resolved:\n\nprocfs: fix missing RCU protection when reading real_parent in do_task_stat()\n\nWhen reading \u002Fproc\u002F[pid]\u002Fstat, do_task_stat() accesses task->real_parent\nwithout proper RCU protection, which leads to:\n\n  cpu 0                               cpu 1\n  -----                               -----\n  do_task_stat\n    var = task->real_parent\n                                      release_task\n                                        call_rcu(","2026-06-03T18:16:26.987+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46259",{"cveId":1364,"releaseId":17,"cycle":18,"description":1365,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1366,"url":1367},{"cveId":1364,"releaseId":31,"cycle":32,"description":1365,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1366,"url":1367},{"cveId":1371,"releaseId":25,"cycle":26,"description":1372,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1373,"url":1374},"CVE-2026-46254","In the Linux kernel, the following vulnerability has been resolved:\n\nAppArmor: Allow apparmor to handle unaligned dfa tables\n\nThe dfa tables can originate from kernel or userspace and 8-byte alignment\nisn't always guaranteed and as such may trigger unaligned memory accesses\non various architectures. Resulting in the following\n\n[   73.901376] WARNING: CPU: 0 PID: 341 at security\u002Fapparmor\u002Fmatch.c:316 aa_dfa_unpack+0x6cc\u002F0x720\n[   74.015867] Modules linked in: binfmt_misc evdev flash sg drm drm_pan","2026-06-03T18:16:26.323+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46254",{"cveId":1371,"releaseId":17,"cycle":18,"description":1372,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1373,"url":1374},{"cveId":1377,"releaseId":25,"cycle":26,"description":1378,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1379,"url":1380},"CVE-2026-46253","In the Linux kernel, the following vulnerability has been resolved:\n\npstore\u002Fram: fix buffer overflow in persistent_ram_save_old()\n\npersistent_ram_save_old() can be called multiple times for the same\npersistent_ram_zone (e.g., via ramoops_pstore_read -> ramoops_get_next_prz\nfor PSTORE_TYPE_DMESG records).\n\nCurrently, the function only allocates prz->old_log when it is NULL,\nbut it unconditionally updates prz->old_log_size to the current buffer\nsize and then performs memcpy_fromio() using this new","2026-06-03T18:16:26.17+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46253",{"cveId":1377,"releaseId":17,"cycle":18,"description":1378,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1379,"url":1380},{"cveId":1377,"releaseId":31,"cycle":32,"description":1378,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1379,"url":1380},{"cveId":1384,"releaseId":25,"cycle":26,"description":1385,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1386,"url":1387},"CVE-2026-46252","In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: core: fix locking in regulator_resolve_supply() error path\n\nIf late enabling of a supply regulator fails in\nregulator_resolve_supply(), the code currently triggers a lockdep\nwarning:\n\n    WARNING: drivers\u002Fregulator\u002Fcore.c:2649 at _regulator_put+0x80\u002F0xa0, CPU#6: kworker\u002Fu32:4\u002F596\n    ...\n    Call trace:\n     _regulator_put+0x80\u002F0xa0 (P)\n     regulator_resolve_supply+0x7cc\u002F0xbe0\n     regulator_register_resolve_supply+","2026-06-03T18:16:25.797+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46252",{"cveId":1384,"releaseId":17,"cycle":18,"description":1385,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1386,"url":1387},{"cveId":1384,"releaseId":31,"cycle":32,"description":1385,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1386,"url":1387},{"cveId":1391,"releaseId":25,"cycle":26,"description":1392,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":1393,"url":1394},"CVE-2026-46250","In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: Work around LLVM bug when gp is used as global register variable\n\nOn MIPS, __current_thread_info is defined as global register variable\nlocating in $gp, and is simply assigned with new address during kernel\nrelocation.\n\nThis however is broken with LLVM, which always restores $gp if it finds\n$gp is clobbered in any form, including when intentionally through a\nglobal register variable. This is against GCC's documentation[1]","2026-06-03T18:16:25.4+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46250",{"cveId":1391,"releaseId":17,"cycle":18,"description":1392,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":1393,"url":1394},{"cveId":1391,"releaseId":31,"cycle":32,"description":1392,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":1393,"url":1394},{"cveId":1398,"releaseId":25,"cycle":26,"description":1399,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1400,"url":1401},"CVE-2026-46247","In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: gfx3d: add parent to parent request map\n\nAfter commit d228ece36345 (\"clk: divider: remove round_rate() in favor\nof determine_rate()\") determining GFX3D clock rate crashes, because the\npassed parent map doesn't provide the expected best_parent_hw clock\n(with the roundd_rate path before the offending commit the\nbest_parent_hw was ignored).\n\nSet the field in parent_req in addition to setting it in the req,\nfixing the cr","2026-06-03T18:16:24.93+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46247",{"cveId":1398,"releaseId":17,"cycle":18,"description":1399,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1400,"url":1401},{"cveId":1398,"releaseId":31,"cycle":32,"description":1399,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1400,"url":1401},{"cveId":1405,"releaseId":17,"cycle":18,"description":1406,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1407,"url":1408},"CVE-2026-46245","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix dc_link NULL handling in HPD init\n\namdgpu_dm_hpd_init() may see connectors without a valid dc_link.\n\nThe code already checks dc_link for the polling decision, but later\nunconditionally dereferences it when setting up HPD interrupts.\n\nAssign dc_link early and skip connectors where it is NULL.\n\nFixes the below:\ndrivers\u002Fgpu\u002Fdrm\u002Famd\u002Famdgpu\u002F..\u002Fdisplay\u002Famdgpu_dm\u002Famdgpu_dm_irq.c:940 amdgpu_dm_hpd_init()\nerror: we ","2026-06-03T18:16:24.637+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46245",{"cveId":1410,"releaseId":25,"cycle":26,"description":1411,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1412,"url":1413},"CVE-2026-46243","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject userspace cifs.spnego descriptions\n\ncifs.spnego key descriptions contain authority-bearing fields such as\npid, uid, creduid, and upcall_target that cifs.upcall treats as\nkernel-originating inputs. However, userspace can also create keys of\nthis type through request_key(2) or add_key(2), allowing those fields to\nbe supplied without CIFS origin.\n\nOnly accept cifs.spnego descriptions while CIFS is using its pri","2026-06-01T17:17:34.173+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46243",{"cveId":1410,"releaseId":17,"cycle":18,"description":1411,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1412,"url":1413},{"cveId":1410,"releaseId":31,"cycle":32,"description":1411,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1412,"url":1413},{"cveId":1417,"releaseId":25,"cycle":26,"description":1418,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1419,"url":1420},"CVE-2026-46241","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mpc52xx: fix use-after-free on registration failure\n\nMake sure to disable and free the interrupts in case controller\nregistration fails to avoid a potential use-after-free and resource\nleak.\n\nThis issue was flagged by Sashiko when reviewing a controller\nderegistration fix.","2026-05-28T10:16:39.71+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46241",{"cveId":1417,"releaseId":17,"cycle":18,"description":1418,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1419,"url":1420},{"cveId":1417,"releaseId":31,"cycle":32,"description":1418,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1419,"url":1420},{"cveId":1424,"releaseId":25,"cycle":26,"description":1425,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1426,"url":1427},"CVE-2026-46238","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: stop caching unowned originator pointers in BAT IV\n\nBAT IV keeps the last-hop neighbor address in each neigh_node, but some\npaths also cache an originator pointer derived from a temporary lookup.\nThat pointer is not owned by the neigh_node and may no longer refer to a\nlive originator entry after purge handling runs.\n\nStop storing the auxiliary originator pointer in the BAT IV neighbor\nstate. When BAT IV needs the ne","2026-05-28T10:16:39.427+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46238",{"cveId":1424,"releaseId":17,"cycle":18,"description":1425,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1426,"url":1427},{"cveId":1424,"releaseId":31,"cycle":32,"description":1425,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1426,"url":1427},{"cveId":1431,"releaseId":25,"cycle":26,"description":1432,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1433,"url":1434},"CVE-2026-46235","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: saa7164: add ioremap return checks and cleanups\n\nAdd checks for ioremap return values in saa7164_dev_setup(). If\nioremap for BAR0 or BAR2 fails, release the already allocated PCI\nmemory regions, remove the device from the global list, decrement\nthe device count, and return -ENODEV.\n\nThis prevents potential null pointer dereferences and ensures proper\ncleanup on memory mapping failures.","2026-05-28T10:16:39.143+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46235",{"cveId":1431,"releaseId":17,"cycle":18,"description":1432,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1433,"url":1434},{"cveId":1431,"releaseId":31,"cycle":32,"description":1432,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1433,"url":1434},{"cveId":1438,"releaseId":25,"cycle":26,"description":1439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1440,"url":1441},"CVE-2026-46233","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: only purge non-released claims\n\nWhen batadv_bla_purge_claims() goes through the list of claims, it is only\ntraversing the hash list with an rcu_read_lock(). Due to a potential\nparallel batadv_claim_put(), it can happen that it encounters a claim which\nwas actually in the process of being released+freed by\nbatadv_claim_release(). In this case, backbone_gw is set to NULL before the\ndelayed RCU kfree is started. C","2026-05-28T10:16:38.943+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46233",{"cveId":1438,"releaseId":17,"cycle":18,"description":1439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1440,"url":1441},{"cveId":1438,"releaseId":31,"cycle":32,"description":1439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1440,"url":1441},{"cveId":1445,"releaseId":25,"cycle":26,"description":1446,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1447,"url":1448},"CVE-2026-46231","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: put backbone reference on failed claim hash insert\n\nWhen batadv_bla_add_claim() fails to insert a new claim into the hash, it\nleaked a reference to the backbone_gw for which the claim was intended.\nCall batadv_backbone_gw_put() on the error path to release the reference\nand avoid leaking the backbone_gw object.","2026-05-28T10:16:38.743+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46231",{"cveId":1445,"releaseId":17,"cycle":18,"description":1446,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1447,"url":1448},{"cveId":1445,"releaseId":31,"cycle":32,"description":1446,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1447,"url":1448},{"cveId":1452,"releaseId":17,"cycle":18,"description":1453,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1454,"url":1455},"CVE-2026-46227","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL\n\nThe SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with\nlist_for_each_entry_safe(), which caches the next entry in @tmp before\nthe loop body runs.  The body calls sctp_sendmsg_to_asoc(), which may\ndrop the socket lock inside sctp_wait_for_sndbuf().\n\nWhile the lock is dropped, another thread can SCTP_SOCKOPT_PEELOFF the\nassociation cached in @tmp,","2026-05-28T10:16:38.317+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46227",{"cveId":1457,"releaseId":17,"cycle":18,"description":1458,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1459,"url":1460},"CVE-2026-46226","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: fsl: fix controller deregistration\n\nMake sure to deregister the controller before releasing underlying\nresources like DMA during driver unbind.","2026-05-28T10:16:38.227+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46226",{"cveId":1457,"releaseId":25,"cycle":26,"description":1458,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1459,"url":1460},{"cveId":1457,"releaseId":31,"cycle":32,"description":1458,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1459,"url":1460},{"cveId":1464,"releaseId":25,"cycle":26,"description":1465,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1466,"url":1467},"CVE-2026-46225","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: rspi: fix controller deregistration\n\nMake sure to deregister the controller before releasing underlying\nresources like DMA during driver unbind.","2026-05-28T10:16:38.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46225",{"cveId":1464,"releaseId":17,"cycle":18,"description":1465,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1466,"url":1467},{"cveId":1464,"releaseId":31,"cycle":32,"description":1465,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1466,"url":1467},{"cveId":1471,"releaseId":25,"cycle":26,"description":1472,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1473,"url":1474},"CVE-2026-46220","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu\u002Fsdma4: replace BUG_ON with WARN_ON in fence emission\n\nsdma_v4_0_ring_emit_fence() contains two BUG_ON(addr & 0x3) assertions\nthat verify fence writeback addresses are dword-aligned.  These\nassertions can be reached from unprivileged userspace via crafted\nDRM_IOCTL_AMDGPU_CS submissions, causing a fatal kernel panic in a\nscheduler worker thread.\n\nReplace both BUG_ON() calls with WARN_ON() to log the condition without\n","2026-05-28T10:16:37.64+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46220",{"cveId":1471,"releaseId":17,"cycle":18,"description":1472,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1473,"url":1474},{"cveId":1477,"releaseId":25,"cycle":26,"description":1478,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1479,"url":1480},"CVE-2026-46218","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: Add bounds checking to ib_{get,set}_value\n\nThe uvd\u002Fvce\u002Fvcn code accesses the IB at predefined offsets without\nchecking that the IB is large enough. Check the bounds here. The caller\nis responsible for making sure it can handle arbitrary return values.\n\nAlso make the idx a uint32_t to prevent overflows causing the condition\nto fail.","2026-05-28T10:16:37.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46218",{"cveId":1477,"releaseId":17,"cycle":18,"description":1478,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1479,"url":1480},{"cveId":1477,"releaseId":31,"cycle":32,"description":1478,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1479,"url":1480},{"cveId":1484,"releaseId":25,"cycle":26,"description":1485,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1486,"url":1487},"CVE-2026-46212","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: prevent use-after-free when deleting claims\n\nWhen batadv_bla_del_backbone_claims() removes all claims for a backbone, it\ndoes this by dropping the link entry in the hash list. This list entry\nitself was one of the references which need to be dropped at the same time\nvia batadv_claim_put().\n\nBut the batadv_claim_put() must not be done before the last access to the\nclaim object in this function. Otherwise the cla","2026-05-28T10:16:36.853+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46212",{"cveId":1484,"releaseId":17,"cycle":18,"description":1485,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1486,"url":1487},{"cveId":1484,"releaseId":31,"cycle":32,"description":1485,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1486,"url":1487},{"cveId":1491,"releaseId":25,"cycle":26,"description":1492,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1493,"url":1494},"CVE-2026-46209","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fgem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()\n\ndrm_gem_fb_init_with_funcs() computes sub-sampled plane dimensions\nusing plain integer division:\n\n  unsigned int width  = mode_cmd->width  \u002F (i ? info->hsub : 1);\n  unsigned int height = mode_cmd->height \u002F (i ? info->vsub : 1);\n\nHowever, the ioctl-level framebuffer_check() in drm_framebuffer.c uses\ndrm_format_info_plane_width\u002Fheight() which r","2026-05-28T10:16:36.567+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46209",{"cveId":1491,"releaseId":17,"cycle":18,"description":1492,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1493,"url":1494},{"cveId":1497,"releaseId":25,"cycle":26,"description":1498,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1499,"url":1500},"CVE-2026-46208","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: stop tp_meter sessions during mesh teardown\n\nTP meter sessions remain linked on bat_priv->tp_list after the netlink\nrequest has already finished. When the mesh interface is removed,\nbatadv_mesh_free() currently tears down the mesh without first draining\nthese sessions.\n\nA running sender thread or a late incoming tp_meter packet can then keep\nprocessing against a mesh instance which is already shutting down.\nSynchron","2026-05-28T10:16:36.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46208",{"cveId":1497,"releaseId":17,"cycle":18,"description":1498,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1499,"url":1500},{"cveId":1497,"releaseId":31,"cycle":32,"description":1498,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1499,"url":1500},{"cveId":1504,"releaseId":25,"cycle":26,"description":1505,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1506,"url":1507},"CVE-2026-46206","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: reject new tp_meter sessions during teardown\n\nPrevent tp_meter from starting new sender or receiver sessions after\nmesh_state has left BATADV_MESH_ACTIVE.","2026-05-28T10:16:36.243+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46206",{"cveId":1504,"releaseId":17,"cycle":18,"description":1505,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1506,"url":1507},{"cveId":1504,"releaseId":31,"cycle":32,"description":1505,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1506,"url":1507},{"cveId":1511,"releaseId":25,"cycle":26,"description":1512,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1513,"url":1514},"CVE-2026-46205","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: media: atomisp: Disallow all private IOCTLs\n\nDisallow all private IOCTLs. These aren't quite as safe as one could\nassume of IOCTL handlers; disable them for now. Instead of removing the\ncode, return in the beginning of the function if cmd is non-zero in order\nto keep static checkers happy.","2026-05-28T10:16:36.153+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46205",{"cveId":1511,"releaseId":17,"cycle":18,"description":1512,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1513,"url":1514},{"cveId":1517,"releaseId":25,"cycle":26,"description":1518,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1519,"url":1520},"CVE-2026-46200","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mpc52xx: fix controller deregistration\n\nMake sure to deregister the controller before disabling and releasing\nunderlying resources like interrupts and gpios during driver unbind.","2026-05-28T10:16:35.677+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46200",{"cveId":1517,"releaseId":17,"cycle":18,"description":1518,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1519,"url":1520},{"cveId":1517,"releaseId":31,"cycle":32,"description":1518,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1519,"url":1520},{"cveId":1524,"releaseId":25,"cycle":26,"description":1525,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1526,"url":1527},"CVE-2026-46198","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: fix integer overflow on buff_pos\n\nFixing an integer overflow present in batadv_iv_ogm_send_to_if. The size\ncheck is done using the int type in batadv_iv_ogm_aggr_packet whereas the\nbuff_pos variable uses the s16 type. This could lead to an out-of-bound\nread.","2026-05-28T10:16:35.46+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46198",{"cveId":1524,"releaseId":17,"cycle":18,"description":1525,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1526,"url":1527},{"cveId":1524,"releaseId":31,"cycle":32,"description":1525,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1526,"url":1527},{"cveId":1531,"releaseId":25,"cycle":26,"description":1532,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1533,"url":1534},"CVE-2026-46196","In the Linux kernel, the following vulnerability has been resolved:\n\ntracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()\n\nWhen a tracepoint goes through the 0 -> 1 transition, tracepoint_add_func()\ninvokes the subsystem's ext->regfunc() before attempting to install the\nnew probe via func_add(). If func_add() then fails (for example, when\nallocate_probes() cannot allocate a new probe array under memory pressure\nand returns -ENOMEM), the function returns the error without ","2026-05-28T10:16:35.253+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46196",{"cveId":1531,"releaseId":17,"cycle":18,"description":1532,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1533,"url":1534},{"cveId":1537,"releaseId":25,"cycle":26,"description":1538,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1539,"url":1540},"CVE-2026-46193","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: ah: account for ESN high bits in async callbacks\n\nAH allocates its temporary auth\u002FICV layout differently when ESN is enabled:\nthe async ahash setup appends a 4-byte seqhi slot before the ICV or\nauth_data area, but the async completion callbacks still reconstruct the\ntemporary layout as if seqhi were absent.\n\nWith an async AH implementation selected, that makes AH copy or compare\nthe wrong bytes on both the IPv4 and IPv6 p","2026-05-28T10:16:34.923+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46193",{"cveId":1537,"releaseId":17,"cycle":18,"description":1538,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1539,"url":1540},{"cveId":1537,"releaseId":31,"cycle":32,"description":1538,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1539,"url":1540},{"cveId":1544,"releaseId":25,"cycle":26,"description":1545,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1546,"url":1547},"CVE-2026-46191","In the Linux kernel, the following vulnerability has been resolved:\n\nfbcon: Avoid OOB font access if console rotation fails\n\nClear the font buffer if the reallocation during console rotation fails\nin fbcon_rotate_font(). The putcs implementations for the rotated buffer\nwill return early in this case. See [1] for an example.\n\nCurrently, fbcon_rotate_font() keeps the old buffer, which is too small\nfor the rotated font. Printing to the rotated console with a high-enough\ncharacter code will overflow","2026-05-28T10:16:34.74+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46191",{"cveId":1544,"releaseId":17,"cycle":18,"description":1545,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1546,"url":1547},{"cveId":1544,"releaseId":31,"cycle":32,"description":1545,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1546,"url":1547},{"cveId":1551,"releaseId":25,"cycle":26,"description":1552,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1553,"url":1554},"CVE-2026-46189","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fvmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path\n\nSashiko points out that pvrdma_uar_free() is already called within\npvrdma_dealloc_ucontext(), so calling it before triggers a double free.","2026-05-28T10:16:34.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46189",{"cveId":1551,"releaseId":17,"cycle":18,"description":1552,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1553,"url":1554},{"cveId":1557,"releaseId":31,"cycle":32,"description":1558,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1559,"url":1560},"CVE-2026-46187","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rsi: fix kthread lifetime race between self-exit and external-stop\n\nRSI driver use both self-exit(kthread_complete_and_exit) and external-stop\n(kthread_stop) when killing a kthread. Generally, kthread_stop() is called\nfirst, and in this case, no particular issues occur.\n\nHowever, in rare instances where kthread_complete_and_exit() is called\nfirst and then kthread_stop() is called, a UAF occurs because the kthread\nobject, ","2026-05-28T10:16:34.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46187",{"cveId":1557,"releaseId":25,"cycle":26,"description":1558,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1559,"url":1560},{"cveId":1557,"releaseId":17,"cycle":18,"description":1558,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1559,"url":1560},{"cveId":1564,"releaseId":17,"cycle":18,"description":1565,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1566,"url":1567},"CVE-2026-46184","In the Linux kernel, the following vulnerability has been resolved:\n\nsound: ua101: fix division by zero at probe\n\nAdd a missing sanity check for bNrChannels in detect_usb_format()\nto prevent a division by zero in playback_urb_complete() and\ncapture_urb_complete().\n\nUSB core does not validate class-specific descriptor fields such\nas bNrChannels, so drivers must verify them before use. If a\ndevice provides bNrChannels = 0, frame_bytes becomes zero and is\nlater used as a divisor in the URB completi","2026-05-28T10:16:34.023+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46184",{"cveId":1564,"releaseId":31,"cycle":32,"description":1565,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1566,"url":1567},{"cveId":1564,"releaseId":25,"cycle":26,"description":1565,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1566,"url":1567},{"cveId":1571,"releaseId":25,"cycle":26,"description":1572,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1573,"url":1574},"CVE-2026-46181","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fmlx4: Fix mis-use of RCU in mlx4_srq_event()\n\nSashiko points out the radix_tree itself is RCU safe, but nothing ever\nfrees the mlx4_srq struct with RCU, and it isn't even accessed within the\nRCU critical section. It also will crash if an event is delivered before\nthe srq object is finished initializing.\n\nUse the spinlock since it isn't easy to make RCU work, use\nrefcount_inc_not_zero() to protect against partially initiali","2026-05-28T10:16:33.743+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46181",{"cveId":1571,"releaseId":17,"cycle":18,"description":1572,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1573,"url":1574},{"cveId":1571,"releaseId":31,"cycle":32,"description":1572,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1573,"url":1574},{"cveId":1578,"releaseId":25,"cycle":26,"description":1579,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1580,"url":1581},"CVE-2026-46180","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task\n\nWatchdog task might end between send_sig() and kthread_stop() calls, what\nresults in the use-after-free issue. Fix this by increasing watchdog task\nreference count before calling send_sig() and dropping it by switching to\nkthread_stop_put().","2026-05-28T10:16:33.643+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46180",{"cveId":1578,"releaseId":17,"cycle":18,"description":1579,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1580,"url":1581},{"cveId":1578,"releaseId":31,"cycle":32,"description":1579,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1580,"url":1581},{"cveId":1585,"releaseId":25,"cycle":26,"description":1586,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1587,"url":1588},"CVE-2026-46178","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fmlx4: Fix resource leak on error in mlx4_ib_create_srq()\n\nSashiko points out that mlx4_srq_alloc() was not undone during error\nunwind, add the missing call to mlx4_srq_free().","2026-05-28T10:16:33.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46178",{"cveId":1585,"releaseId":17,"cycle":18,"description":1586,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1587,"url":1588},{"cveId":1585,"releaseId":31,"cycle":32,"description":1586,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1587,"url":1588},{"cveId":1592,"releaseId":25,"cycle":26,"description":1593,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1594,"url":1595},"CVE-2026-46177","In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: Add limits to event and receive message requests\n\nThe driver would just fetch events and receive messages until the\nBMC said it was done.  To avoid issues with BMCs that never say they are\ndone, add a limit of 10 fetches at a time.\n\nIn addition, an si interface has an attn state it can return from the\nhardware which is supposed to cause a flag fetch to see if the driver\nneeds to fetch events or message or a few other thin","2026-05-28T10:16:33.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46177",{"cveId":1592,"releaseId":17,"cycle":18,"description":1593,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1594,"url":1595},{"cveId":1592,"releaseId":31,"cycle":32,"description":1593,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1594,"url":1595},{"cveId":1599,"releaseId":17,"cycle":18,"description":1600,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1601,"url":1602},"CVE-2026-46175","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix fsck inconsistency caused by FGGC of node block\n\nDuring FGGC node block migration, fsck may incorrectly treat the\nmigrated node block as fsync-written data.\n\nThe reproduction scenario:\nroot@vm:\u002Fmnt\u002Ff2fs# seq 1 2048 | xargs -n 1 .\u002Ftest_sync \u002F\u002F write inline inode and sync\nroot@vm:\u002Fmnt\u002Ff2fs# rm -f 1\nroot@vm:\u002Fmnt\u002Ff2fs# sync\nroot@vm:\u002Fmnt\u002Ff2fs# f2fs_io gc_range \u002F\u002F move data block in sync mode and not write CP\n  SPO, \"fsck -","2026-05-28T10:16:33.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46175",{"cveId":1599,"releaseId":31,"cycle":32,"description":1600,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1601,"url":1602},{"cveId":1599,"releaseId":25,"cycle":26,"description":1600,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1601,"url":1602},{"cveId":1606,"releaseId":31,"cycle":32,"description":1607,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1608,"url":1609},"CVE-2026-46174","In the Linux kernel, the following vulnerability has been resolved:\n\nx86\u002FCPU\u002FAMD: Prevent improper isolation of shared resources in Zen2's op cache\n\nMake sure resources are not improperly shared in the op cache and\ncause instruction corruption this way.","2026-05-28T10:16:33.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46174",{"cveId":1606,"releaseId":25,"cycle":26,"description":1607,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1608,"url":1609},{"cveId":1606,"releaseId":17,"cycle":18,"description":1607,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1608,"url":1609},{"cveId":1613,"releaseId":25,"cycle":26,"description":1614,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1615,"url":1616},"CVE-2026-46169","In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: fix uninit-value by validating catalog record size\n\nSyzbot reported a KMSAN uninit-value issue in hfsplus_strcasecmp(). The\nroot cause is that hfs_brec_read() doesn't validate that the on-disk\nrecord size matches the expected size for the record type being read.\n\nWhen mounting a corrupted filesystem, hfs_brec_read() may read less data\nthan expected. For example, when reading a catalog thread record, the\ndebug output sh","2026-05-28T10:16:32.537+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46169",{"cveId":1613,"releaseId":17,"cycle":18,"description":1614,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1615,"url":1616},{"cveId":1613,"releaseId":31,"cycle":32,"description":1614,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1615,"url":1616},{"cveId":1620,"releaseId":25,"cycle":26,"description":1621,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1622,"url":1623},"CVE-2026-46167","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl\n\nJust like in a previous problem in this driver, usblp_ctrl_msg() will\ncollapse the usb_control_msg() return value to 0\u002F-errno, discarding the\nactual number of bytes transferred.\n\nIdeally that short command should be detected and error out, but many\nprinters are known to send \"incorrect\" responses back so we can't just\ndo that.\n\nstatusbuf is kmalloc(8) at probe time ","2026-05-28T10:16:32.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46167",{"cveId":1620,"releaseId":17,"cycle":18,"description":1621,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1622,"url":1623},{"cveId":1620,"releaseId":31,"cycle":32,"description":1621,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1622,"url":1623},{"cveId":1627,"releaseId":25,"cycle":26,"description":1628,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1629,"url":1630},"CVE-2026-46163","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: b43legacy: enforce bounds check on firmware key index in RX path\n\nSame fix as b43: the firmware-controlled key index in b43legacy_rx()\ncan exceed dev->max_nr_keys. The existing B43legacy_WARN_ON is\nnon-enforcing in production builds, allowing an out-of-bounds read of\ndev->key[].\n\nMake the check enforcing by dropping the frame for invalid indices.","2026-05-28T10:16:31.95+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46163",{"cveId":1627,"releaseId":17,"cycle":18,"description":1628,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1629,"url":1630},{"cveId":1627,"releaseId":31,"cycle":32,"description":1628,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1629,"url":1630},{"cveId":1634,"releaseId":25,"cycle":26,"description":1635,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1636,"url":1637},"CVE-2026-46161","In the Linux kernel, the following vulnerability has been resolved:\n\nmd\u002Fraid10: fix divide-by-zero in setup_geo() with zero far_copies\n\nsetup_geo() extracts near_copies (nc) and far_copies (fc) from the\nuser-provided layout parameter without checking for zero. When fc=0\nwith the \"improved\" far set layout selected, 'geo->far_set_size =\ndisks \u002F fc' triggers a divide-by-zero.\n\nValidate nc and fc immediately after extraction, returning -1 if\neither is zero.","2026-05-28T10:16:31.77+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46161",{"cveId":1634,"releaseId":17,"cycle":18,"description":1635,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1636,"url":1637},{"cveId":1634,"releaseId":31,"cycle":32,"description":1635,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1636,"url":1637},{"cveId":1641,"releaseId":25,"cycle":26,"description":1642,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1643,"url":1644},"CVE-2026-46160","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix missing last_unlink_trans update when removing a directory\n\nWhen removing a directory we are not updating its last_unlink_trans field,\nwhich can result in incorrect fsync behaviour in case some one fsyncs the\ndirectory after it was removed because it's holding a file descriptor on\nit.\n\nExample scenario:\n\n   mkdir \u002Fmnt\u002Fdir1\n   mkdir \u002Fmnt\u002Fdir1\u002Fdir2\n   mkdir \u002Fmnt\u002Fdir3\n\n   sync -f \u002Fmnt\n\n   # Do some change to the directo","2026-05-28T10:16:31.647+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46160",{"cveId":1641,"releaseId":17,"cycle":18,"description":1642,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1643,"url":1644},{"cveId":1641,"releaseId":31,"cycle":32,"description":1642,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1643,"url":1644},{"cveId":1648,"releaseId":25,"cycle":26,"description":1649,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1650,"url":1651},"CVE-2026-46159","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak\n\nbtrfs_ioctl_space_info() has a TOCTOU race between two passes over the\nblock group RAID type lists. The first pass counts entries to determine\nthe allocation size, then the second pass fills the buffer. The\ngroups_sem rwlock is released between passes, allowing concurrent block\ngroup removal to reduce the entry count.\n\nWhen the second pass fills ","2026-05-28T10:16:31.553+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46159",{"cveId":1648,"releaseId":17,"cycle":18,"description":1649,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1650,"url":1651},{"cveId":1648,"releaseId":31,"cycle":32,"description":1649,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1650,"url":1651},{"cveId":1655,"releaseId":25,"cycle":26,"description":1656,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1657,"url":1658},"CVE-2026-46157","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger\n\nCurrently the runtime.oss.trigger field may be accessed concurrently\nwithout protection, which may lead to the data race.  And, in this\ncase, it may lead to more severe problem because it's a bit field; as\nwriting the data, it may overwrite other bit fields as well, which\nconfuses the operation completely, as spotted by fuzzing.\n\nFix it by covering runtime.oss.trig","2026-05-28T10:16:31.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46157",{"cveId":1655,"releaseId":17,"cycle":18,"description":1656,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1657,"url":1658},{"cveId":1655,"releaseId":31,"cycle":32,"description":1656,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1657,"url":1658},{"cveId":1662,"releaseId":25,"cycle":26,"description":1663,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1664,"url":1665},"CVE-2026-46153","In the Linux kernel, the following vulnerability has been resolved:\n\n8021q: delete cleared egress QoS mappings\n\nvlan_dev_set_egress_priority() currently keeps cleared egress\npriority mappings in the hash as tombstones. Repeated set\u002Fclear cycles\nwith distinct skb priorities therefore accumulate mapping nodes until\ndevice teardown and leak memory.\n\nDelete mappings when vlan_prio is cleared instead of keeping tombstones.\nNow that the egress mapping lists are RCU protected, the node can be\nunlinked ","2026-05-28T10:16:30.947+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46153",{"cveId":1662,"releaseId":17,"cycle":18,"description":1663,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1664,"url":1665},{"cveId":1662,"releaseId":31,"cycle":32,"description":1663,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1664,"url":1665},{"cveId":1669,"releaseId":25,"cycle":26,"description":1670,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1671,"url":1672},"CVE-2026-46151","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usblp: fix heap leak in IEEE 1284 device ID via short response\n\nusblp_ctrl_msg() collapses the usb_control_msg() return value to\n0\u002F-errno, discarding the actual number of bytes transferred.  A broken\nprinter can complete the GET_DEVICE_ID control transfer short and the\ndriver has no way to know.\n\nusblp_cache_device_id_string() reads the 2-byte big-endian length prefix\nfrom the response and trusts it (clamped only to the bu","2026-05-28T10:16:30.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46151",{"cveId":1669,"releaseId":17,"cycle":18,"description":1670,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1671,"url":1672},{"cveId":1669,"releaseId":31,"cycle":32,"description":1670,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1671,"url":1672},{"cveId":1676,"releaseId":25,"cycle":26,"description":1677,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1678,"url":1679},"CVE-2026-46150","In the Linux kernel, the following vulnerability has been resolved:\n\nfanotify: fix false positive on permission events\n\nfsnotify_get_mark_safe() may return false for a mark on an unrelated group,\nwhich results in bypassing the permission check.\n\nFix by skipping over detached marks that are not in the current group.","2026-05-28T10:16:30.63+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46150",{"cveId":1676,"releaseId":17,"cycle":18,"description":1677,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1678,"url":1679},{"cveId":1682,"releaseId":25,"cycle":26,"description":1683,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1684,"url":1685},"CVE-2026-46149","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()\n\ntarget_tg_pt_gp_members_show() formats LUN paths with snprintf() into a\n256-byte stack buffer, then will memcpy() cur_len bytes from that\nbuffer.  snprintf() returns the length the output would have had, which\ncan exceed the buffer size when the fabric WWN is long because iSCSI IQN\nnames can be up to 223 bytes.  The check at the memcpy() site only\nguard","2026-05-28T10:16:30.513+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46149",{"cveId":1682,"releaseId":17,"cycle":18,"description":1683,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1684,"url":1685},{"cveId":1682,"releaseId":31,"cycle":32,"description":1683,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1684,"url":1685},{"cveId":1689,"releaseId":25,"cycle":26,"description":1690,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1691,"url":1692},"CVE-2026-46147","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()\n\nTwo bugs exist in the vCPU initialisation path:\n\n1. If a check fails after hyp_pin_shared_mem() succeeds, the cleanup\n   path jumps to 'unlock' without calling unpin_host_vcpu() or\n   unpin_host_sve_state(), permanently leaking pin references on the\n   host vCPU and SVE state pages.\n\n   Extract a register_hyp_vcpu() helper that performs the checks and\n   t","2026-05-28T10:16:30.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46147",{"cveId":1689,"releaseId":17,"cycle":18,"description":1690,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1691,"url":1692},{"cveId":1689,"releaseId":31,"cycle":32,"description":1690,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1691,"url":1692},{"cveId":1696,"releaseId":31,"cycle":32,"description":1697,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1698,"url":1699},"CVE-2026-46116","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: defensively unhash xfrm_state lists in __xfrm_state_delete\n\nKASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s\nhlist_del_rcu calls under syzkaller load on linux-6.12.y stable\n(reproduced on 6.12.47, also reachable via the same code path on\ntorvalds\u002Fmaster and on the ipsec tree). Nine unique signatures cluster\nin the xfrm_state lifecycle, the load-bearing one being:\n\n  BUG: KASAN: slab-use-after-free in __hl","2026-05-28T10:16:27.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46116",{"cveId":1696,"releaseId":17,"cycle":18,"description":1697,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1698,"url":1699},{"cveId":1696,"releaseId":25,"cycle":26,"description":1697,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1698,"url":1699},{"cveId":1703,"releaseId":17,"cycle":18,"description":1704,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":1705,"url":1706},"CVE-2026-46099","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels\n\nseg6_input_core() and rpl_input() call ip6_route_input() which sets a\nNOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking\ndst_hold() unconditionally.\nOn PREEMPT_RT, ksoftirqd is preemptible and a higher-priority task can\nrelease the underlying pcpu_rt between the lookup and the caching\nthrough a concurrent FIB lookup on a shared nexthop.\nSimplified race sequ","2026-05-27T14:17:31.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46099",{"cveId":1703,"releaseId":25,"cycle":26,"description":1704,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":1705,"url":1706},{"cveId":1709,"releaseId":31,"cycle":32,"description":1710,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1711,"url":1712},"CVE-2026-46090","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Fix peer runtime UAF during format-change stop\n\nloopback_check_format() may stop the capture side when playback starts\nwith parameters that no longer match a running capture stream. Commit\n826af7fa62e3 (\"ALSA: aloop: Fix racy access at PCM trigger\") moved\nthe peer lookup under cable->lock, but the actual snd_pcm_stop() still\nruns after dropping that lock.\n\nA concurrent close can clear the capture entry from cable->","2026-05-27T14:17:30.547+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46090",{"cveId":1709,"releaseId":17,"cycle":18,"description":1710,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1711,"url":1712},{"cveId":1709,"releaseId":25,"cycle":26,"description":1710,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1711,"url":1712},{"cveId":1716,"releaseId":17,"cycle":18,"description":1717,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1718,"url":1719},"CVE-2026-46054","In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: fix overlayfs mmap() and mprotect() access checks\n\nThe existing SELinux security model for overlayfs is to allow access if\nthe current task is able to access the top level file (the \"user\" file)\nand the mounter's credentials are sufficient to access the lower\nlevel file (the \"backing\" file).  Unfortunately, the current code does\nnot properly enforce these access controls for both mmap() and mprotect()\noperations on ove","2026-05-27T14:17:25.043+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46054",{"cveId":1721,"releaseId":17,"cycle":18,"description":1722,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1723,"url":1724},"CVE-2026-46033","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: authencesn - reject short ahash digests during instance creation\n\nauthencesn requires either a zero authsize or an authsize of at least\n4 bytes because the ESN encrypt\u002Fdecrypt paths always move 4 bytes of\nhigh-order sequence number data at the end of the authenticated data.\n\nWhile crypto_authenc_esn_setauthsize() already rejects explicit\nnon-zero authsizes in the range 1..3, crypto_authenc_esn_create()\nstill copied auth","2026-05-27T14:17:22.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46033",{"cveId":1721,"releaseId":25,"cycle":26,"description":1722,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1723,"url":1724},{"cveId":1727,"releaseId":31,"cycle":32,"description":1728,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1729,"url":1730},"CVE-2026-45944","In the Linux kernel, the following vulnerability has been resolved:\n\niommu\u002Fvt-d: Clear Present bit before tearing down context entry\n\nWhen tearing down a context entry, the current implementation zeros the\nentire 128-bit entry using multiple 64-bit writes. This creates a window\nwhere the hardware can fetch a \"torn\" entry — where some fields are\nalready zeroed while the 'Present' bit is still set — leading to\nunpredictable behavior or spurious faults.\n\nWhile x86 provides strong write ordering, th","2026-05-27T14:17:10.677+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45944",{"cveId":1727,"releaseId":17,"cycle":18,"description":1728,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1729,"url":1730},{"cveId":1727,"releaseId":25,"cycle":26,"description":1728,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":1729,"url":1730},{"cveId":1734,"releaseId":17,"cycle":18,"description":1735,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1736,"url":1737},"CVE-2026-45852","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Frxe: Fix double free in rxe_srq_from_init\n\nIn rxe_srq_from_init(), the queue pointer 'q' is assigned to\n'srq->rq.queue' before copying the SRQ number to user space.\nIf copy_to_user() fails, the function calls rxe_queue_cleanup()\nto free the queue, but leaves the now-invalid pointer in\n'srq->rq.queue'.\n\nThe caller of rxe_srq_from_init() (rxe_create_srq) eventually\ncalls rxe_srq_cleanup() upon receiving the error, which trig","2026-05-27T14:16:57.193+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45852",{"cveId":1739,"releaseId":31,"cycle":32,"description":1740,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1741,"url":1742},"CVE-2026-45844","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: arp_tables: fix IEEE1394 ARP payload parsing\n\nWeiming Shi says:\n\n\"arp_packet_match() unconditionally parses the ARP payload assuming two\nhardware addresses are present (source and target). However,\nIPv4-over-IEEE1394 ARP (RFC 2734) omits the target hardware address\nfield, and arp_hdr_len() already accounts for this by returning a\nshorter length for ARPHRD_IEEE1394 devices.\n\nAs a result, on IEEE1394 interfaces arp_pac","2026-05-27T11:16:23.847+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45844",{"cveId":1739,"releaseId":17,"cycle":18,"description":1740,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1741,"url":1742},{"cveId":1739,"releaseId":25,"cycle":26,"description":1740,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1741,"url":1742},{"cveId":1746,"releaseId":31,"cycle":32,"description":1747,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1748,"url":1749},"CVE-2026-45843","In the Linux kernel, the following vulnerability has been resolved:\n\nslip: bound decode() reads against the compressed packet length\n\nslhc_uncompress() parses a VJ-compressed TCP header by advancing a\npointer through the packet via decode() and pull16(). Neither helper\nbounds-checks against isize, and decode() masks its return with\n& 0xffff so it can never return the -1 that callers test for -- those\nerror paths are dead code.\n\nA short compressed frame whose change byte requests optional fields\n","2026-05-27T11:16:23.743+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45843",{"cveId":1746,"releaseId":17,"cycle":18,"description":1747,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1748,"url":1749},{"cveId":1746,"releaseId":25,"cycle":26,"description":1747,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1748,"url":1749},{"cveId":1753,"releaseId":31,"cycle":32,"description":1754,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1755,"url":1756},"CVE-2026-45842","In the Linux kernel, the following vulnerability has been resolved:\n\nslip: reject VJ receive packets on instances with no rstate array\n\nslhc_init() accepts rslots == 0 as a valid configuration, with the\ndocumented meaning of 'no receive compression'. In that case the\nallocation loop in slhc_init() is skipped, so comp->rstate stays\nNULL and comp->rslot_limit stays 0 (from the kzalloc of struct\nslcompress).\n\nThe receive helpers do not defend against that configuration.\nslhc_uncompress() dereferenc","2026-05-27T11:16:23.6+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45842",{"cveId":1753,"releaseId":17,"cycle":18,"description":1754,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1755,"url":1756},{"cveId":1753,"releaseId":25,"cycle":26,"description":1754,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1755,"url":1756},{"cveId":1760,"releaseId":31,"cycle":32,"description":1761,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1762,"url":1763},"CVE-2026-45841","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO\n\nnf_osf_match_one() computes ctx->window % f->wss.val in the\nOSF_WSS_MODULO branch with no guard for f->wss.val == 0. A\nCAP_NET_ADMIN user can add such a fingerprint via nfnetlink; a\nsubsequent matching TCP SYN divides by zero and panics the kernel.\n\nReject the bogus fingerprint in nfnl_osf_add_callback() above the\nper-option for-loop. f->wss is per-fingerprint, not","2026-05-27T11:16:23.493+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45841",{"cveId":1760,"releaseId":17,"cycle":18,"description":1761,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1762,"url":1763},{"cveId":1760,"releaseId":25,"cycle":26,"description":1761,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1762,"url":1763},{"cveId":1767,"releaseId":31,"cycle":32,"description":1768,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1769,"url":1770},"CVE-2026-45840","In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: cap upcall PID array size and pre-size vport replies\n\nThe vport netlink reply helpers allocate a fixed-size skb with\nnlmsg_new(NLMSG_DEFAULT_SIZE, ...) but serialize the full upcall PID\narray via ovs_vport_get_upcall_portids().  Since\novs_vport_set_upcall_portids() accepts any non-zero multiple of\nsizeof(u32) with no upper bound, a CAP_NET_ADMIN user can install a PID\narray large enough to overflow the reply buffer","2026-05-27T11:16:23.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45840",{"cveId":1767,"releaseId":17,"cycle":18,"description":1768,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1769,"url":1770},{"cveId":1767,"releaseId":25,"cycle":26,"description":1768,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1769,"url":1770},{"cveId":1774,"releaseId":17,"cycle":18,"description":1775,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1776,"url":1777},"CVE-2026-45838","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: fix end-of-list detection in cgroup_storage_get_next_key()\n\nlist_next_entry() never returns NULL -- when the current element is the\nlast entry it wraps to the list head via container_of(). The subsequent\nNULL check is therefore dead code and get_next_key() never returns\n-ENOENT for the last element, instead reading storage->key from a bogus\npointer that aliases internal map fields and copying the result to\nuserspace.\n\nRepl","2026-05-27T11:16:23.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45838",{"cveId":1779,"releaseId":31,"cycle":32,"description":1780,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1781,"url":1782},"CVE-2026-45836","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()\n\nAdd the same NULL guard already present in\nl2cap_sock_resume_cb() and l2cap_sock_ready_cb().","2026-05-26T17:16:50.813+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45836",{"cveId":1779,"releaseId":17,"cycle":18,"description":1780,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1781,"url":1782},{"cveId":1779,"releaseId":25,"cycle":26,"description":1780,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1781,"url":1782},{"cveId":1786,"releaseId":31,"cycle":32,"description":1787,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1788,"url":1789},"CVE-2026-45835","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()\n\nAdd the same NULL guard already present in\nl2cap_sock_resume_cb() and l2cap_sock_ready_cb().","2026-05-26T17:16:48.227+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45835",{"cveId":1786,"releaseId":17,"cycle":18,"description":1787,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1788,"url":1789},{"cveId":1786,"releaseId":25,"cycle":26,"description":1787,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1788,"url":1789},{"cveId":1793,"releaseId":31,"cycle":32,"description":1794,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1795,"url":1796},"CVE-2026-45834","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()\n\nAdd the same NULL guard already present in\nl2cap_sock_resume_cb() and l2cap_sock_ready_cb().","2026-05-26T17:16:48.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45834",{"cveId":1793,"releaseId":17,"cycle":18,"description":1794,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1795,"url":1796},{"cveId":1793,"releaseId":25,"cycle":26,"description":1794,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1795,"url":1796},{"cveId":1800,"releaseId":25,"cycle":26,"description":1801,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1802,"url":1803},"CVE-2026-46300","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: preserve shared-frag marker during coalescing\n\nskb_try_coalesce() can attach paged frags from @from to @to.  If @from\nhas SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same\nexternally-owned or page-cache-backed frags, but the shared-frag marker\nis currently lost.\n\nThat breaks the invariant relied on by later in-place writers.  In\nparticular, ESP input checks skb_has_shared_frag() before deciding\nwhet","2026-05-23T12:17:02.66+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46300",{"cveId":1800,"releaseId":17,"cycle":18,"description":1801,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1802,"url":1803},{"cveId":1800,"releaseId":31,"cycle":32,"description":1801,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1802,"url":1803},{"cveId":1807,"releaseId":31,"cycle":32,"description":1808,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1809,"url":1810},"CVE-2026-43503","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: propagate shared-frag marker through frag-transfer helpers\n\nTwo frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail\nto propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when\nmoving frags from source to destination.  __pskb_copy_fclone() defers\nthe rest of the shinfo metadata to skb_copy_header() after copying\nfrag descriptors, but that helper only carries over gso_{size,segs,\ntype} and never ","2026-05-23T12:17:02.547+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43503",{"cveId":1807,"releaseId":17,"cycle":18,"description":1808,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1809,"url":1810},{"cveId":1807,"releaseId":25,"cycle":26,"description":1808,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":1809,"url":1810},{"cveId":1814,"releaseId":17,"cycle":18,"description":1815,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1816,"url":1817},"CVE-2026-43502","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Frds: handle zerocopy send cleanup before the message is queued\n\nA zerocopy send can fail after user pages have been pinned but before\nthe message is attached to the sending socket.\n\nThe purge path currently infers zerocopy state from rm->m_rs, so an\nunqueued message can be cleaned up as if it owned normal payload pages.\nHowever, zerocopy ownership is really determined by the presence of\nop_mmp_znotifier, regardless of wheth","2026-05-21T13:16:19.52+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43502",{"cveId":1819,"releaseId":31,"cycle":32,"description":1820,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1821,"url":1822},"CVE-2026-43499","In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_l","2026-05-21T13:16:19.3+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43499",{"cveId":1819,"releaseId":17,"cycle":18,"description":1820,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1821,"url":1822},{"cveId":1819,"releaseId":25,"cycle":26,"description":1820,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1821,"url":1822},{"cveId":1826,"releaseId":17,"cycle":18,"description":1827,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":1828,"url":1829},"CVE-2026-43497","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free\n\ndlfb_ops_mmap() uses remap_pfn_range() to map vmalloc framebuffer pages\nto userspace but sets no vm_ops on the VMA. This means the kernel cannot\ntrack active mmaps. When dlfb_realloc_framebuffer() replaces the backing\nbuffer via FBIOPUT_VSCREENINFO, existing mmap PTEs are not invalidated.\nOn USB disconnect, dlfb_ops_destroy() calls vfree() on the old pages\nwhi","2026-05-21T13:16:19.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43497",{"cveId":1831,"releaseId":31,"cycle":32,"description":1832,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1833,"url":1834},"CVE-2026-43496","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nWhen red qdisc has children (eg qfq qdisc) whose peek() callback is\nqdisc_peek_dequeued(), we could get a kernel panic. When the parent of such\nqdiscs (eg illustrated in patch #3 as tbf) wants to retrieve an skb from\nits child (red in this case), it will do the following:\n 1a. do a peek() - and when sensing there's an skb the child can offer, th","2026-05-21T13:16:18.96+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43496",{"cveId":1831,"releaseId":17,"cycle":18,"description":1832,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1833,"url":1834},{"cveId":1831,"releaseId":25,"cycle":26,"description":1832,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1833,"url":1834},{"cveId":1838,"releaseId":17,"cycle":18,"description":1839,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1840,"url":1841},"CVE-2026-43494","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Frds: reset op_nents when zerocopy page pin fails\n\nWhen iov_iter_get_pages2() fails in rds_message_zcopy_from_user(),\nthe pinned pages are released with put_page(), and\nrm->data.op_mmp_znotifier is cleared.  But we fail to properly\nclear rm->data.op_nents.\n\nLater when rds_message_purge() is called from rds_sendmsg() the\ncleanup loop iterates over the incorrectly non zero number of\nop_nents and frees them again.\n\nFix this by ","2026-05-21T12:16:19.957+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43494",{"cveId":1843,"releaseId":31,"cycle":32,"description":1844,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1845,"url":1846},"CVE-2026-43493","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: pcrypt - Fix handling of MAY_BACKLOG requests\n\nMAY_BACKLOG requests can return EBUSY.  Handle them by checking\nfor that value and filtering out EINPROGRESS notifications.","2026-05-19T12:16:19.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43493",{"cveId":1843,"releaseId":17,"cycle":18,"description":1844,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1845,"url":1846},{"cveId":1843,"releaseId":25,"cycle":26,"description":1844,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":1845,"url":1846},{"cveId":1850,"releaseId":31,"cycle":32,"description":1851,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1852,"url":1853},"CVE-2026-43492","In the Linux kernel, the following vulnerability has been resolved:\n\nlib\u002Fcrypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()\n\nYiming reports an integer underflow in mpi_read_raw_from_sgl() when\nsubtracting \"lzeros\" from the unsigned \"nbytes\".\n\nFor this to happen, the scatterlist \"sgl\" needs to occupy more bytes\nthan the \"nbytes\" parameter and the first \"nbytes + 1\" bytes of the\nscatterlist must be zero.  Under these conditions, the while loop\niterating over the scatterlist will count m","2026-05-19T12:16:18.88+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43492",{"cveId":1850,"releaseId":17,"cycle":18,"description":1851,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1852,"url":1853},{"cveId":1850,"releaseId":25,"cycle":26,"description":1851,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1852,"url":1853},{"cveId":1857,"releaseId":31,"cycle":32,"description":1858,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1859,"url":1860},"CVE-2026-46333","In the Linux kernel, the following vulnerability has been resolved:\n\nptrace: slightly saner 'get_dumpable()' logic\n\nThe 'dumpability' of a task is fundamentally about the memory image of\nthe task - the concept comes from whether it can core dump or not - and\nmakes no sense when you don't have an associated mm.\n\nAnd almost all users do in fact use it only for the case where the task\nhas a mm pointer.\n\nBut we have one odd special case: ptrace_may_access() uses 'dumpable' to\ncheck various other thi","2026-05-15T14:16:35.793+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-46333",{"cveId":1857,"releaseId":17,"cycle":18,"description":1858,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1859,"url":1860},{"cveId":1857,"releaseId":25,"cycle":26,"description":1858,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1859,"url":1860},{"cveId":1864,"releaseId":17,"cycle":18,"description":1865,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1866,"url":1867},"CVE-2026-43484","In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: core: Avoid bitfield RMW for claim\u002Fretune flags\n\nMove claimed and retune control flags out of the bitfield word to\navoid unrelated RMW side effects in asynchronous contexts.\n\nThe host->claimed bit shared a word with retune flags. Writes to claimed\nin __mmc_claim_host() or retune_now in mmc_mq_queue_rq() can overwrite\nother bits when concurrent updates happen in other contexts, triggering\nspurious WARN_ON(!host->claimed). C","2026-05-13T16:16:51.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43484",{"cveId":1869,"releaseId":31,"cycle":32,"description":1870,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1871,"url":1872},"CVE-2026-43483","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Set\u002Fclear CR8 write interception when AVIC is (de)activated\n\nExplicitly set\u002Fclear CR8 write interception when AVIC is (de)activated to\nfix a bug where KVM leaves the interception enabled after AVIC is\nactivated.  E.g. if KVM emulates INIT=>WFS while AVIC is deactivated, CR8\nwill remain intercepted in perpetuity.\n\nOn its own, the dangling CR8 intercept is \"just\" a performance issue, but\ncombined with the TPR sync bug f","2026-05-13T16:16:51.497+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43483",{"cveId":1869,"releaseId":17,"cycle":18,"description":1870,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1871,"url":1872},{"cveId":1869,"releaseId":25,"cycle":26,"description":1870,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1871,"url":1872},{"cveId":1876,"releaseId":25,"cycle":26,"description":1877,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1878,"url":1879},"CVE-2026-43475","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: storvsc: Fix scheduling while atomic on PREEMPT_RT\n\nThis resolves the follow splat and lock-up when running with PREEMPT_RT\nenabled on Hyper-V:\n\n[  415.140818] BUG: scheduling while atomic: stress-ng-iomix\u002F1048\u002F0x00000002\n[  415.140822] INFO: lockdep is turned off.\n[  415.140823] Modules linked in: intel_rapl_msr intel_rapl_common intel_uncore_frequency_common intel_pmc_core pmt_telemetry pmt_discovery pmt_class intel_pmc","2026-05-08T15:17:00.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43475",{"cveId":1876,"releaseId":17,"cycle":18,"description":1877,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1878,"url":1879},{"cveId":1882,"releaseId":25,"cycle":26,"description":1883,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1884,"url":1885},"CVE-2026-43472","In the Linux kernel, the following vulnerability has been resolved:\n\nunshare: fix unshare_fs() handling\n\nThere's an unpleasant corner case in unshare(2), when we have a\nCLONE_NEWNS in flags and current->fs hadn't been shared at all; in that\ncase copy_mnt_ns() gets passed current->fs instead of a private copy,\nwhich causes interesting warts in proof of correctness]\n\n> I guess if private means fs->users == 1, the condition could still be true.\n\nUnfortunately, it's worse than just a convoluted proo","2026-05-08T15:17:00.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43472",{"cveId":1882,"releaseId":17,"cycle":18,"description":1883,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1884,"url":1885},{"cveId":1882,"releaseId":31,"cycle":32,"description":1883,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1884,"url":1885},{"cveId":1889,"releaseId":17,"cycle":18,"description":1890,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1891,"url":1892},"CVE-2026-43466","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5e: Fix DMA FIFO desync on error CQE SQ recovery\n\nIn case of a TX error CQE, a recovery flow is triggered,\nmlx5e_reset_txqsq_cc_pc() resets dma_fifo_cc to 0 but not dma_fifo_pc,\ndesyncing the DMA FIFO producer and consumer.\n\nAfter recovery, the producer pushes new DMA entries at the old\ndma_fifo_pc, while the consumer reads from position 0.\nThis causes us to unmap stale DMA addresses from before the recovery.\n\nThe DMA FI","2026-05-08T15:16:59.543+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43466",{"cveId":1894,"releaseId":25,"cycle":26,"description":1895,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1896,"url":1897},"CVE-2026-43458","In the Linux kernel, the following vulnerability has been resolved:\n\nserial: caif: hold tty->link reference in ldisc_open and ser_release\n\nA reproducer triggers a KASAN slab-use-after-free in pty_write_room()\nwhen caif_serial's TX path calls tty_write_room(). The faulting access\nis on tty->link->port.\n\nHold an extra kref on tty->link for the lifetime of the caif_serial line\ndiscipline: get it in ldisc_open() and drop it in ser_release(), and\nalso drop it on the ldisc_open() error path.\n\nWith thi","2026-05-08T15:16:58.63+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43458",{"cveId":1894,"releaseId":17,"cycle":18,"description":1895,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1896,"url":1897},{"cveId":1894,"releaseId":31,"cycle":32,"description":1895,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1896,"url":1897},{"cveId":1901,"releaseId":25,"cycle":26,"description":1902,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1903,"url":1904},"CVE-2026-43456","In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix type confusion in bond_setup_by_slave()\n\nkernel BUG at net\u002Fcore\u002Fskbuff.c:2306!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nRIP: 0010:pskb_expand_head+0xa08\u002F0xfe0 net\u002Fcore\u002Fskbuff.c:2306\nRSP: 0018:ffffc90004aff760 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffff88807e3c8780 RCX: ffffffff89593e0e\nRDX: ffff88807b7c4900 RSI: ffffffff89594747 RDI: ffff88807b7c4900\nRBP: 0000000000000820 R08: 0000000000000005 R09: 0000","2026-05-08T15:16:58.387+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43456",{"cveId":1901,"releaseId":17,"cycle":18,"description":1902,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1903,"url":1904},{"cveId":1901,"releaseId":31,"cycle":32,"description":1902,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1903,"url":1904},{"cveId":1908,"releaseId":25,"cycle":26,"description":1909,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1910,"url":1911},"CVE-2026-43452","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: guard option walkers against 1-byte tail reads\n\nWhen the last byte of options is a non-single-byte option kind, walkers\nthat advance with i += op[i + 1] ? : 1 can read op[i + 1] past the end\nof the option area.\n\nAdd an explicit i == optlen - 1 check before dereferencing op[i + 1]\nin xt_tcpudp and xt_dccp option walkers.","2026-05-08T15:16:57.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43452",{"cveId":1908,"releaseId":17,"cycle":18,"description":1909,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1910,"url":1911},{"cveId":1908,"releaseId":31,"cycle":32,"description":1909,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":1910,"url":1911},{"cveId":1915,"releaseId":25,"cycle":26,"description":1916,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1917,"url":1918},"CVE-2026-43451","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_queue: fix entry leak in bridge verdict error path\n\nnfqnl_recv_verdict() calls find_dequeue_entry() to remove the queue\nentry from the queue data structures, taking ownership of the entry.\nFor PF_BRIDGE packets, it then calls nfqa_parse_bridge() to parse VLAN\nattributes.  If nfqa_parse_bridge() returns an error (e.g. NFQA_VLAN\npresent but NFQA_VLAN_TCI missing), the function returns immediately\nwithout free","2026-05-08T15:16:57.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43451",{"cveId":1915,"releaseId":17,"cycle":18,"description":1916,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1917,"url":1918},{"cveId":1915,"releaseId":31,"cycle":32,"description":1916,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1917,"url":1918},{"cveId":1922,"releaseId":25,"cycle":26,"description":1923,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1924,"url":1925},"CVE-2026-43450","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()\n\nnfnl_cthelper_dump_table() has a 'goto restart' that jumps to a label\ninside the for loop body.  When the \"last\" helper saved in cb->args[1]\nis deleted between dump rounds, every entry fails the (cur != last)\ncheck, so cb->args[1] is never cleared.  The for loop finishes with\ncb->args[0] == nf_ct_helper_hsize, and the 'goto restart' jumps back\ninto the l","2026-05-08T15:16:57.643+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43450",{"cveId":1922,"releaseId":17,"cycle":18,"description":1923,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1924,"url":1925},{"cveId":1922,"releaseId":31,"cycle":32,"description":1923,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1924,"url":1925},{"cveId":1929,"releaseId":25,"cycle":26,"description":1930,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1931,"url":1932},"CVE-2026-43449","In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set\n\ndev->online_queues is a count incremented in nvme_init_queue. Thus,\nvalid indices are 0 through dev->online_queues − 1.\n\nThis patch fixes the loop condition to ensure the index stays within the\nvalid range. Index 0 is excluded because it is the admin queue.\n\nKASAN splat:\n\n==================================================================\nBUG: KASAN: slab-out-of-bounds in nvme_","2026-05-08T15:16:57.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43449",{"cveId":1929,"releaseId":17,"cycle":18,"description":1930,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1931,"url":1932},{"cveId":1935,"releaseId":25,"cycle":26,"description":1936,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1937,"url":1938},"CVE-2026-43445","In the Linux kernel, the following vulnerability has been resolved:\n\ne1000\u002Fe1000e: Fix leak in DMA error cleanup\n\nIf an error is encountered while mapping TX buffers, the driver should\nunmap any buffers already mapped for that skb.\n\nBecause count is incremented after a successful mapping, it will always\nmatch the correct number of unmappings needed when dma_error is reached.\nDecrementing count before the while loop in dma_error causes an\noff-by-one error. If any mapping was successful before an ","2026-05-08T15:16:56.983+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43445",{"cveId":1935,"releaseId":17,"cycle":18,"description":1936,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1937,"url":1938},{"cveId":1935,"releaseId":31,"cycle":32,"description":1936,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1937,"url":1938},{"cveId":1942,"releaseId":25,"cycle":26,"description":1943,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1944,"url":1945},"CVE-2026-43439","In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: fix race between task migration and iteration\n\nWhen a task is migrated out of a css_set, cgroup_migrate_add_task()\nfirst moves it from cset->tasks to cset->mg_tasks via:\n\n    list_move_tail(&task->cg_list, &cset->mg_tasks);\n\nIf a css_task_iter currently has it->task_pos pointing to this task,\ncss_set_move_task() calls css_task_iter_skip() to keep the iterator\nvalid. However, since the task has already been moved to ->mg","2026-05-08T15:16:56.263+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43439",{"cveId":1942,"releaseId":17,"cycle":18,"description":1943,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1944,"url":1945},{"cveId":1948,"releaseId":25,"cycle":26,"description":1949,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1950,"url":1951},"CVE-2026-43437","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()\n\nIn the drain loop, the local variable 'runtime' is reassigned to a\nlinked stream's runtime (runtime = s->runtime at line 2157).  After\nreleasing the stream lock at line 2169, the code accesses\nruntime->no_period_wakeup, runtime->rate, and runtime->buffer_size\n(lines 2170-2178) — all referencing the linked stream's runtime without\nany lock or refcount pro","2026-05-08T15:16:56.037+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43437",{"cveId":1948,"releaseId":17,"cycle":18,"description":1949,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1950,"url":1951},{"cveId":1948,"releaseId":31,"cycle":32,"description":1949,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1950,"url":1951},{"cveId":1955,"releaseId":17,"cycle":18,"description":1956,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1957,"url":1958},"CVE-2026-43432","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix memory leak in xhci_disable_slot()\n\nxhci_alloc_command() allocates a command structure and, when the\nsecond argument is true, also allocates a completion structure.\nCurrently, the error handling path in xhci_disable_slot() only frees\nthe command structure using kfree(), causing the completion structure\nto leak.\n\nUse xhci_free_command() instead of kfree(). xhci_free_command() correctly\nfrees both the command struc","2026-05-08T15:16:55.47+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43432",{"cveId":1960,"releaseId":25,"cycle":26,"description":1961,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1962,"url":1963},"CVE-2026-43430","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: yurex: fix race in probe\n\nThe bbu member of the descriptor must be set to the value\nstanding for uninitialized values before the URB whose\ncompletion handler sets bbu is submitted. Otherwise there is\na window during which probing can overwrite already retrieved\ndata.","2026-05-08T15:16:55.243+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43430",{"cveId":1960,"releaseId":17,"cycle":18,"description":1961,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1962,"url":1963},{"cveId":1960,"releaseId":31,"cycle":32,"description":1961,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":1962,"url":1963},{"cveId":1967,"releaseId":17,"cycle":18,"description":1968,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1969,"url":1970},"CVE-2026-43429","In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts\n\nThe usbtmc driver accepts timeout values specified by the user in an\nioctl command, and uses these timeouts for some usb_bulk_msg() calls.\nSince the user can specify arbitrarily long timeouts and\nusb_bulk_msg() uses unkillable waits, call usb_bulk_msg_killable()\ninstead to avoid the possibility of the user hanging a kernel thread\nindefinitely.","2026-05-08T15:16:55.117+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43429",{"cveId":1972,"releaseId":25,"cycle":26,"description":1973,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1974,"url":1975},"CVE-2026-43428","In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: core: Limit the length of unkillable synchronous timeouts\n\nThe usb_control_msg(), usb_bulk_msg(), and usb_interrupt_msg() APIs in\nusbcore allow unlimited timeout durations.  And since they use\nuninterruptible waits, this leaves open the possibility of hanging a\ntask for an indefinitely long time, with no way to kill it short of\nunplugging the target device.\n\nTo prevent this sort of problem, enforce a maximum limit on the l","2026-05-08T15:16:54.99+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43428",{"cveId":1972,"releaseId":17,"cycle":18,"description":1973,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1974,"url":1975},{"cveId":1972,"releaseId":31,"cycle":32,"description":1973,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1974,"url":1975},{"cveId":1979,"releaseId":25,"cycle":26,"description":1980,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1981,"url":1982},"CVE-2026-43427","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: class: cdc-wdm: fix reordering issue in read code path\n\nQuoting the bug report:\n\nDue to compiler optimization or CPU out-of-order execution, the\ndesc->length update can be reordered before the memmove. If this\nhappens, wdm_read() can see the new length and call copy_to_user() on\nuninitialized memory. This also violates LKMM data race rules [1].\n\nFix it by using WRITE_ONCE and memory barriers.","2026-05-08T15:16:54.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43427",{"cveId":1979,"releaseId":17,"cycle":18,"description":1980,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1981,"url":1982},{"cveId":1979,"releaseId":31,"cycle":32,"description":1980,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":1981,"url":1982},{"cveId":1986,"releaseId":25,"cycle":26,"description":1987,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1988,"url":1989},"CVE-2026-43426","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: renesas_usbhs: fix use-after-free in ISR during device removal\n\nIn usbhs_remove(), the driver frees resources (including the pipe array)\nwhile the interrupt handler (usbhs_interrupt) is still registered. If an\ninterrupt fires after usbhs_pipe_remove() but before the driver is fully\nunbound, the ISR may access freed memory, causing a use-after-free.\n\nFix this by calling devm_free_irq() before freeing resources. This ensures","2026-05-08T15:16:54.74+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43426",{"cveId":1986,"releaseId":17,"cycle":18,"description":1987,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1988,"url":1989},{"cveId":1986,"releaseId":31,"cycle":32,"description":1987,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":1988,"url":1989},{"cveId":1993,"releaseId":25,"cycle":26,"description":1994,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1995,"url":1996},"CVE-2026-43425","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: image: mdc800: kill download URB on timeout\n\nmdc800_device_read() submits download_urb and waits for completion.\nIf the timeout fires and the device has not responded, the function\nreturns without killing the URB, leaving it active.\n\nA subsequent read() resubmits the same URB while it is still\nin-flight, triggering the WARN in usb_submit_urb():\n\n  \"URB submitted while active\"\n\nCheck the return value of wait_event_timeout()","2026-05-08T15:16:54.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43425",{"cveId":1993,"releaseId":17,"cycle":18,"description":1994,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1995,"url":1996},{"cveId":1993,"releaseId":31,"cycle":32,"description":1994,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":1995,"url":1996},{"cveId":2000,"releaseId":25,"cycle":26,"description":2001,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2002,"url":2003},"CVE-2026-43424","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling\n\nThe `tpg->tpg_nexus` pointer in the USB Target driver is dynamically\nmanaged and tied to userspace configuration via ConfigFS. It can be\nNULL if the USB host sends requests before the nexus is fully\nestablished or immediately after it is dropped.\n\nCurrently, functions like `bot_submit_command()` and the data\ntransfer paths retrieve `tv_nexus = tpg->tpg_nexus` ","2026-05-08T15:16:54.497+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43424",{"cveId":2000,"releaseId":17,"cycle":18,"description":2001,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2002,"url":2003},{"cveId":2000,"releaseId":31,"cycle":32,"description":2001,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2002,"url":2003},{"cveId":2007,"releaseId":25,"cycle":26,"description":2008,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2009,"url":2010},"CVE-2026-43421","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: Fix net_device lifecycle with device_move\n\nThe network device outlived its parent gadget device during\ndisconnection, resulting in dangling sysfs links and null pointer\ndereference problems.\n\nA prior attempt to solve this by removing SET_NETDEV_DEV entirely [1]\nwas reverted due to power management ordering concerns and a NO-CARRIER\nregression.\n\nA subsequent attempt to defer net_device allocation to bind [2] ","2026-05-08T15:16:54.173+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43421",{"cveId":2007,"releaseId":17,"cycle":18,"description":2008,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2009,"url":2010},{"cveId":2007,"releaseId":31,"cycle":32,"description":2008,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2009,"url":2010},{"cveId":2014,"releaseId":25,"cycle":26,"description":2015,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2016,"url":2017},"CVE-2026-43416","In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc, perf: Check that current->mm is alive before getting user callchain\n\nIt may happen that mm is already released, which leads to kernel panic.\nThis adds the NULL check for current->mm, similarly to\ncommit 20afc60f892d (\"x86, perf: Check that current->mm is alive before getting user callchain\").\n\nI was getting this panic when running a profiling BPF program\n(profile.py from bcc-tools):\n\n    [26215.051935] Kernel attempted","2026-05-08T15:16:53.597+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43416",{"cveId":2014,"releaseId":17,"cycle":18,"description":2015,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2016,"url":2017},{"cveId":2014,"releaseId":31,"cycle":32,"description":2015,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2016,"url":2017},{"cveId":2021,"releaseId":25,"cycle":26,"description":2022,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2023,"url":2024},"CVE-2026-43413","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Fix NULL pointer exception during user_scan()\n\nuser_scan() invokes updated sas_user_scan() for channel 0, and if\nsuccessful, iteratively scans remaining channels (1 to shost->max_channel)\nvia scsi_scan_host_selected() in commit 37c4e72b0651 (\"scsi: Fix\nsas_user_scan() to handle wildcard and multi-channel scans\"). However,\nhisi_sas supports only one channel, and the current value of max_channel is\n1. sas_user_sca","2026-05-08T15:16:53.193+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43413",{"cveId":2021,"releaseId":17,"cycle":18,"description":2022,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2023,"url":2024},{"cveId":2027,"releaseId":25,"cycle":26,"description":2028,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2029,"url":2030},"CVE-2026-43409","In the Linux kernel, the following vulnerability has been resolved:\n\nkprobes: avoid crash when rmmod\u002Finsmod after ftrace killed\n\nAfter we hit ftrace is killed by some errors, the kernel crash if\nwe remove modules in which kprobe probes.\n\nBUG: unable to handle page fault for address: fffffbfff805000d\nPGD 817fcc067 P4D 817fcc067 PUD 817fc8067 PMD 101555067 PTE 0\nOops: Oops: 0000 [#1] SMP KASAN PTI\nCPU: 4 UID: 0 PID: 2012 Comm: rmmod Tainted: G        W  OE\nTainted: [W]=WARN, [O]=OOT_MODULE, [E]=UN","2026-05-08T15:16:52.513+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43409",{"cveId":2027,"releaseId":17,"cycle":18,"description":2028,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2029,"url":2030},{"cveId":2027,"releaseId":31,"cycle":32,"description":2028,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2029,"url":2030},{"cveId":2034,"releaseId":25,"cycle":26,"description":2035,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2036,"url":2037},"CVE-2026-43407","In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()\n\nThis patch fixes an out-of-bounds access in ceph_handle_auth_reply()\nthat can be triggered by a message of type CEPH_MSG_AUTH_REPLY. In\nceph_handle_auth_reply(), the value of the payload_len field of such a\nmessage is stored in a variable of type int. A value greater than\nINT_MAX leads to an integer overflow and is interpreted as a negative\nvalue. This lea","2026-05-08T15:16:52.25+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43407",{"cveId":2034,"releaseId":17,"cycle":18,"description":2035,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2036,"url":2037},{"cveId":2034,"releaseId":31,"cycle":32,"description":2035,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2036,"url":2037},{"cveId":2041,"releaseId":25,"cycle":26,"description":2042,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2043,"url":2044},"CVE-2026-43387","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: properly validate the data in rtw_get_ie_ex()\n\nJust like in commit 154828bf9559 (\"staging: rtl8723bs: fix out-of-bounds\nread in rtw_get_ie() parser\"), we don't trust the data in the frame so\nwe should check the length better before acting on it","2026-05-08T15:16:50.06+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43387",{"cveId":2041,"releaseId":17,"cycle":18,"description":2042,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2043,"url":2044},{"cveId":2047,"releaseId":25,"cycle":26,"description":2048,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2049,"url":2050},"CVE-2026-43386","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie\n\nThe current code checks 'i + 5 \u003C in_len' at the end of the if statement.\nHowever, it accesses 'in_ie[i + 5]' before that check, which can lead\nto an out-of-bounds read. Move the length check to the beginning of the\nconditional to ensure the index is within bounds before accessing the\narray.","2026-05-08T15:16:49.933+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43386",{"cveId":2047,"releaseId":17,"cycle":18,"description":2048,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2049,"url":2050},{"cveId":2053,"releaseId":25,"cycle":26,"description":2054,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":2055,"url":2056},"CVE-2026-43383","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Ftcp-md5: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant\ntime.  Use the appropriate helper function for this.","2026-05-08T15:16:49.593+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43383",{"cveId":2053,"releaseId":17,"cycle":18,"description":2054,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":2055,"url":2056},{"cveId":2053,"releaseId":31,"cycle":32,"description":2054,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":2055,"url":2056},{"cveId":2060,"releaseId":25,"cycle":26,"description":2061,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2062,"url":2063},"CVE-2026-43381","In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau\u002Fdpcd: return EBUSY for aux xfer if the device is asleep\n\nIf we have runtime suspended, and userspace wants to use \u002Fdev\u002Fdrm_dp_*\nthen just tell it the device is busy instead of crashing in the GSP\ncode.\n\nWARNING: CPU: 2 PID: 565741 at drivers\u002Fgpu\u002Fdrm\u002Fnouveau\u002Fnvkm\u002Fsubdev\u002Fgsp\u002Frm\u002Fr535\u002Frpc.c:164 r535_gsp_msgq_wait+0x9a\u002F0xb0 [nouveau]\nCPU: 2 UID: 0 PID: 565741 Comm: fwupd Not tainted 6.18.10-200.fc43.x86_64 #1 PREEMPT(lazy)\nH","2026-05-08T15:16:49.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43381",{"cveId":2060,"releaseId":17,"cycle":18,"description":2061,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2062,"url":2063},{"cveId":2060,"releaseId":31,"cycle":32,"description":2061,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2062,"url":2063},{"cveId":2067,"releaseId":25,"cycle":26,"description":2068,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2069,"url":2070},"CVE-2026-43373","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ncsi: fix skb leak in error paths\n\nEarly return paths in NCSI RX and AEN handlers fail to release\nthe received skb, resulting in a memory leak.\n\nSpecifically, ncsi_aen_handler() returns on invalid AEN packets\nwithout consuming the skb. Similarly, ncsi_rcv_rsp() exits early\nwhen failing to resolve the NCSI device, response handler, or\nrequest, leaving the skb unfreed.","2026-05-08T15:16:48.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43373",{"cveId":2067,"releaseId":17,"cycle":18,"description":2068,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2069,"url":2070},{"cveId":2067,"releaseId":31,"cycle":32,"description":2068,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2069,"url":2070},{"cveId":2074,"releaseId":17,"cycle":18,"description":2075,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2076,"url":2077},"CVE-2026-43370","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: Fix use-after-free race in VM acquire\n\nReplace non-atomic vm->process_info assignment with cmpxchg()\nto prevent race when parent\u002Fchild processes sharing a drm_file\nboth try to acquire the same VM after fork().\n\n(cherry picked from commit c7c573275ec20db05be769288a3e3bb2250ec618)","2026-05-08T15:16:48.067+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43370",{"cveId":2079,"releaseId":25,"cycle":26,"description":2080,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2081,"url":2082},"CVE-2026-43363","In the Linux kernel, the following vulnerability has been resolved:\n\nx86\u002Fapic: Disable x2apic on resume if the kernel expects so\n\nWhen resuming from s2ram, firmware may re-enable x2apic mode, which may have\nbeen disabled by the kernel during boot either because it doesn't support IRQ\nremapping or for other reasons. This causes the kernel to continue using the\nxapic interface, while the hardware is in x2apic mode, which causes hangs.\nThis happens on defconfig + bare metal + s2ram.\n\nFix this in la","2026-05-08T15:16:47.247+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43363",{"cveId":2079,"releaseId":17,"cycle":18,"description":2080,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2081,"url":2082},{"cveId":2079,"releaseId":31,"cycle":32,"description":2080,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2081,"url":2082},{"cveId":2086,"releaseId":25,"cycle":26,"description":2087,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":2088,"url":2089},"CVE-2026-43362","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix in-place encryption corruption in SMB2_write()\n\nSMB2_write() places write payload in iov[1..n] as part of rq_iov.\nsmb3_init_transform_rq() pointer-shares rq_iov, so crypt_message()\nencrypts iov[1] in-place, replacing the original plaintext with\nciphertext. On a replayable error, the retry sends the same iov[1]\nwhich now contains ciphertext instead of the original data,\nresulting in corruption.\n\nThe corruption i","2026-05-08T15:16:47.133+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43362",{"cveId":2086,"releaseId":17,"cycle":18,"description":2087,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":2088,"url":2089},{"cveId":2092,"releaseId":25,"cycle":26,"description":2093,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2094,"url":2095},"CVE-2026-43361","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix transaction abort when snapshotting received subvolumes\n\nCurrently a user can trigger a transaction abort by snapshotting a\npreviously received snapshot a bunch of times until we reach a\nBTRFS_UUID_KEY_RECEIVED_SUBVOL item overflow (the maximum item size we\ncan store in a leaf). This is very likely not common in practice, but\nif it happens, it turns the filesystem into RO mode. The snapshot, send\nand set_received_sub","2026-05-08T15:16:46.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43361",{"cveId":2092,"releaseId":17,"cycle":18,"description":2093,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2094,"url":2095},{"cveId":2092,"releaseId":31,"cycle":32,"description":2093,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2094,"url":2095},{"cveId":2099,"releaseId":17,"cycle":18,"description":2100,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2101,"url":2102},"CVE-2026-43359","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix transaction abort on set received ioctl due to item overflow\n\nIf the set received ioctl fails due to an item overflow when attempting to\nadd the BTRFS_UUID_KEY_RECEIVED_SUBVOL we have to abort the transaction\nsince we did some metadata updates before.\n\nThis means that if a user calls this ioctl with the same received UUID\nfield for a lot of subvolumes, we will hit the overflow, trigger the\ntransaction abort and turn ","2026-05-08T15:16:46.717+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43359",{"cveId":2099,"releaseId":31,"cycle":32,"description":2100,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2101,"url":2102},{"cveId":2099,"releaseId":25,"cycle":26,"description":2100,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2101,"url":2102},{"cveId":2106,"releaseId":25,"cycle":26,"description":2107,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2108,"url":2109},"CVE-2026-43357","In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: mpu3050-core: fix pm_runtime error handling\n\nThe return value of pm_runtime_get_sync() is not checked, allowing\nthe driver to access hardware that may fail to resume. The device\nusage count is also unconditionally incremented. Use\npm_runtime_resume_and_get() which propagates errors and avoids\nincrementing the usage count on failure.\n\nIn preenable, add pm_runtime_put_autosuspend() on set_8khz_samplerate()\nfailure sinc","2026-05-08T15:16:46.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43357",{"cveId":2106,"releaseId":17,"cycle":18,"description":2107,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2108,"url":2109},{"cveId":2112,"releaseId":25,"cycle":26,"description":2113,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2114,"url":2115},"CVE-2026-43355","In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: bh1780: fix PM runtime leak on error path\n\nMove pm_runtime_put_autosuspend() before the error check to ensure\nthe PM runtime reference count is always decremented after\npm_runtime_get_sync(), regardless of whether the read operation\nsucceeds or fails.","2026-05-08T15:16:46.25+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43355",{"cveId":2112,"releaseId":17,"cycle":18,"description":2113,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2114,"url":2115},{"cveId":2112,"releaseId":31,"cycle":32,"description":2113,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2114,"url":2115},{"cveId":2119,"releaseId":25,"cycle":26,"description":2120,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2121,"url":2122},"CVE-2026-43343","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_subset: Fix unbalanced refcnt in geth_free\n\ngeth_alloc() increments the reference count, but geth_free() fails to\ndecrement it. This prevents the configuration of attributes via configfs\nafter unlinking the function.\n\nDecrement the reference count in geth_free() to ensure proper cleanup.","2026-05-08T14:16:44.3+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43343",{"cveId":2119,"releaseId":17,"cycle":18,"description":2120,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2121,"url":2122},{"cveId":2119,"releaseId":31,"cycle":32,"description":2120,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2121,"url":2122},{"cveId":2126,"releaseId":25,"cycle":26,"description":2127,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":2128,"url":2129},"CVE-2026-43342","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_rndis: Protect RNDIS options with mutex\n\nThe class\u002Fsubclass\u002Fprotocol options are suspectible to race conditions\nas they can be accessed concurrently through configfs.\n\nUse existing mutex to protect these options. This issue was identified\nduring code inspection.","2026-05-08T14:16:44.17+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43342",{"cveId":2126,"releaseId":17,"cycle":18,"description":2127,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":2128,"url":2129},{"cveId":2132,"releaseId":25,"cycle":26,"description":2133,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2134,"url":2135},"CVE-2026-43340","In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: Reinit dev->spinlock between attachments to low-level drivers\n\n`struct comedi_device` is the main controlling structure for a COMEDI\ndevice created by the COMEDI subsystem.  It contains a member `spinlock`\ncontaining a spin-lock that is initialized by the COMEDI subsystem, but\nis reserved for use by a low-level driver attached to the COMEDI device\n(at least since commit 25436dc9d84f (\"Staging: comedi: remove RT\ncode\")).","2026-05-08T14:16:43.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43340",{"cveId":2132,"releaseId":17,"cycle":18,"description":2133,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2134,"url":2135},{"cveId":2132,"releaseId":31,"cycle":32,"description":2133,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2134,"url":2135},{"cveId":2139,"releaseId":25,"cycle":26,"description":2140,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2141,"url":2142},"CVE-2026-43339","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent possible UaF in addrconf_permanent_addr()\n\nThe mentioned helper try to warn the user about an exceptional\ncondition, but the message is delivered too late, accessing the ipv6\nafter its possible deletion.\n\nReorder the statement to avoid the possible UaF; while at it, place the\nwarning outside the idev->lock as it needs no protection.","2026-05-08T14:16:43.777+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43339",{"cveId":2139,"releaseId":17,"cycle":18,"description":2140,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2141,"url":2142},{"cveId":2139,"releaseId":31,"cycle":32,"description":2140,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2141,"url":2142},{"cveId":2146,"releaseId":25,"cycle":26,"description":2147,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2148,"url":2149},"CVE-2026-43338","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reserve enough transaction items for qgroup ioctls\n\nCurrently our qgroup ioctls don't reserve any space, they just do a\ntransaction join, which does not reserve any space, neither for the quota\ntree updates nor for the delayed refs generated when updating the quota\ntree. The quota root uses the global block reserve, which is fine most of\nthe time since we don't expect a lot of updates to the quota root, or to\nbe too clos","2026-05-08T14:16:43.63+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43338",{"cveId":2146,"releaseId":17,"cycle":18,"description":2147,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2148,"url":2149},{"cveId":2146,"releaseId":31,"cycle":32,"description":2147,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2148,"url":2149},{"cveId":2153,"releaseId":25,"cycle":26,"description":2154,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2155,"url":2156},"CVE-2026-43336","In the Linux kernel, the following vulnerability has been resolved:\n\nlib\u002Fcrypto: chacha: Zeroize permuted_state before it leaves scope\n\nSince the ChaCha permutation is invertible, the local variable\n'permuted_state' is sufficient to compute the original 'state', and thus\nthe key, even after the permutation has been done.\n\nWhile the kernel is quite inconsistent about zeroizing secrets on the\nstack (and some prominent userspace crypto libraries don't bother at all\nsince it's not guaranteed to work","2026-05-08T14:16:43.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43336",{"cveId":2153,"releaseId":17,"cycle":18,"description":2154,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2155,"url":2156},{"cveId":2153,"releaseId":31,"cycle":32,"description":2154,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2155,"url":2156},{"cveId":2160,"releaseId":25,"cycle":26,"description":2161,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2162,"url":2163},"CVE-2026-43334","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SMP: force responder MITM requirements before building the pairing response\n\nsmp_cmd_pairing_req() currently builds the pairing response from the\ninitiator auth_req before enforcing the local BT_SECURITY_HIGH\nrequirement. If the initiator omits SMP_AUTH_MITM, the response can\nalso omit it even though the local side still requires MITM.\n\ntk_request() then sees an auth value without SMP_AUTH_MITM and may\nselect JUST_CF","2026-05-08T14:16:43.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43334",{"cveId":2160,"releaseId":17,"cycle":18,"description":2161,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2162,"url":2163},{"cveId":2160,"releaseId":31,"cycle":32,"description":2161,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2162,"url":2163},{"cveId":2167,"releaseId":31,"cycle":32,"description":2168,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2169,"url":2170},"CVE-2026-43327","In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: dummy-hcd: Fix locking\u002Fsynchronization error\n\nSyzbot testing was able to provoke an addressing exception and crash\nin the usb_gadget_udc_reset() routine in\ndrivers\u002Fusb\u002Fgadgets\u002Fudc\u002Fcore.c, resulting from the fact that the\nroutine was called with a second (\"driver\") argument of NULL.  The bad\ncaller was set_link_state() in dummy_hcd.c, and the problem arose\nbecause of a race between a USB reset and driver unbind.\n\nThese sort","2026-05-08T14:16:42.243+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43327",{"cveId":2167,"releaseId":25,"cycle":26,"description":2168,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2169,"url":2170},{"cveId":2167,"releaseId":17,"cycle":18,"description":2168,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2169,"url":2170},{"cveId":2174,"releaseId":25,"cycle":26,"description":2175,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2176,"url":2177},"CVE-2026-43316","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: solo6x10: Check for out of bounds chip_id\n\nClang with CONFIG_UBSAN_SHIFT=y noticed a condition where a signed type\n(literal \"1\" is an \"int\") could end up being shifted beyond 32 bits,\nso instrumentation was added (and due to the double is_tw286x() call\nseen via inlining), Clang decides the second one must now be undefined\nbehavior and elides the rest of the function[1]. This is a known problem\nwith Clang (that is still b","2026-05-08T14:16:40.117+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43316",{"cveId":2174,"releaseId":17,"cycle":18,"description":2175,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2176,"url":2177},{"cveId":2174,"releaseId":31,"cycle":32,"description":2175,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2176,"url":2177},{"cveId":2181,"releaseId":25,"cycle":26,"description":2182,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2183,"url":2184},"CVE-2026-43314","In the Linux kernel, the following vulnerability has been resolved:\n\ndm: remove fake timeout to avoid leak request\n\nSince commit 15f73f5b3e59 (\"blk-mq: move failure injection out of\nblk_mq_complete_request\"), drivers are responsible for calling\nblk_should_fake_timeout() at appropriate code paths and opportunities.\n\nHowever, the dm driver does not implement its own timeout handler and\nrelies on the timeout handling of its slave devices.\n\nIf an io-timeout-fail error is injected to a dm device, the","2026-05-08T14:16:39.83+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43314",{"cveId":2181,"releaseId":17,"cycle":18,"description":2182,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2183,"url":2184},{"cveId":2181,"releaseId":31,"cycle":32,"description":2182,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2183,"url":2184},{"cveId":2188,"releaseId":25,"cycle":26,"description":2189,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2190,"url":2191},"CVE-2026-43313","In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()\n\nIn acpi_processor_errata_piix4(), the pointer dev is first assigned an IDE\ndevice and then reassigned an ISA device:\n\n  dev = pci_get_subsys(..., PCI_DEVICE_ID_INTEL_82371AB, ...);\n  dev = pci_get_subsys(..., PCI_DEVICE_ID_INTEL_82371AB_0, ...);\n\nIf the first lookup succeeds but the second fails, dev becomes NULL. This\nleads to a potential null-poin","2026-05-08T14:16:39.71+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43313",{"cveId":2188,"releaseId":17,"cycle":18,"description":2189,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2190,"url":2191},{"cveId":2188,"releaseId":31,"cycle":32,"description":2189,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2190,"url":2191},{"cveId":2195,"releaseId":25,"cycle":26,"description":2196,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2197,"url":2198},"CVE-2026-43309","In the Linux kernel, the following vulnerability has been resolved:\n\nmd raid: fix hang when stopping arrays with metadata through dm-raid\n\nWhen using device-mapper's dm-raid target, stopping a RAID array can cause\nthe system to hang under specific conditions.\n\nThis occurs when:\n\n- A dm-raid managed device tree is suspended from top to bottom\n   (the top-level RAID device is suspended first, followed by its\n    underlying metadata and data devices)\n\n- The top-level RAID device is then removed\n\nRe","2026-05-08T14:16:38.25+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43309",{"cveId":2195,"releaseId":17,"cycle":18,"description":2196,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2197,"url":2198},{"cveId":2201,"releaseId":25,"cycle":26,"description":2202,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2203,"url":2204},"CVE-2026-43308","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()\n\nThere is no need to BUG(), we can just return an error and log an error\nmessage.","2026-05-08T14:16:38.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43308",{"cveId":2201,"releaseId":17,"cycle":18,"description":2202,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2203,"url":2204},{"cveId":2201,"releaseId":31,"cycle":32,"description":2202,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2203,"url":2204},{"cveId":2208,"releaseId":17,"cycle":18,"description":2209,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2210,"url":2211},"CVE-2026-43302","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fv3d: Set DMA segment size to avoid debug warnings\n\nWhen using V3D rendering with CONFIG_DMA_API_DEBUG enabled, the\nkernel occasionally reports a segment size mismatch. This is because\n'max_seg_size' is not set. The kernel defaults to 64K. setting\n'max_seg_size' to the maximum will prevent 'debug_dma_map_sg()'\nfrom complaining about the over-mapping of the V3D segment length.\n\nDMA-API: v3d 1002000000.v3d: mapping sg segment ","2026-05-08T14:16:37.447+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43302",{"cveId":2213,"releaseId":25,"cycle":26,"description":2214,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2215,"url":2216},"CVE-2026-43299","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()\n\n[BUG]\nThere is a bug report that when btrfs hits ENOSPC error in a critical\npath, btrfs flips RO (this part is expected, although the ENOSPC bug\nstill needs to be addressed).\n\nThe problem is after the RO flip, if there is a read repair pending, we\ncan hit the ASSERT() inside btrfs_repair_io_failure() like the following:\n\n  BTRFS info (device vdc): rel","2026-05-08T14:16:37.1+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43299",{"cveId":2213,"releaseId":17,"cycle":18,"description":2214,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2215,"url":2216},{"cveId":2213,"releaseId":31,"cycle":32,"description":2214,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2215,"url":2216},{"cveId":2220,"releaseId":25,"cycle":26,"description":2221,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2222,"url":2223},"CVE-2026-43295","In the Linux kernel, the following vulnerability has been resolved:\n\nrapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net()\n\nWhen idtab allocation fails, net is not registered with rio_add_net() yet,\nso kfree(net) is sufficient to release the memory.  Set mport->net to NULL\nto avoid dangling pointer.","2026-05-08T14:16:36.593+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43295",{"cveId":2220,"releaseId":17,"cycle":18,"description":2221,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2222,"url":2223},{"cveId":2220,"releaseId":31,"cycle":32,"description":2221,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2222,"url":2223},{"cveId":2227,"releaseId":17,"cycle":18,"description":2228,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2229,"url":2230},"CVE-2026-43289","In the Linux kernel, the following vulnerability has been resolved:\n\nkexec: derive purgatory entry from symbol\n\nkexec_load_purgatory() derives image->start by locating e_entry inside an\nSHF_EXECINSTR section.  If the purgatory object contains multiple\nexecutable sections with overlapping sh_addr, the entrypoint check can\nmatch more than once and trigger a WARN.\n\nDerive the entry section from the purgatory_start symbol when present and\ncompute image->start from its final placement.  Keep the exis","2026-05-08T14:16:35.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43289",{"cveId":2232,"releaseId":25,"cycle":26,"description":2233,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2234,"url":2235},"CVE-2026-43288","In the Linux kernel, the following vulnerability has been resolved:\n\next4: move ext4_percpu_param_init() before ext4_mb_init()\n\nWhen running `kvm-xfstests -c ext4\u002F1k -C 1 generic\u002F383` with the\n`DOUBLE_CHECK` macro defined, the following panic is triggered:\n\n==================================================================\nEXT4-fs error (device vdc): ext4_validate_block_bitmap:423:\n                        comm mount: bg 0: bad block bitmap checksum\nBUG: unable to handle page fault for address: f","2026-05-08T14:16:35.737+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43288",{"cveId":2232,"releaseId":17,"cycle":18,"description":2233,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2234,"url":2235},{"cveId":2232,"releaseId":31,"cycle":32,"description":2233,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2234,"url":2235},{"cveId":2239,"releaseId":25,"cycle":26,"description":2240,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2241,"url":2242},"CVE-2026-43287","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: Account property blob allocations to memcg\n\nDRM_IOCTL_MODE_CREATEPROPBLOB allows userspace to allocate arbitrary-sized\nproperty blobs backed by kernel memory.\n\nCurrently, the blob data allocation is not accounted to the allocating\nprocess's memory cgroup, allowing unprivileged users to trigger unbounded\nkernel memory consumption and potentially cause system-wide OOM.\n\nMark the property blob data allocation with GFP_KERNEL_","2026-05-08T14:16:35.6+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43287",{"cveId":2239,"releaseId":17,"cycle":18,"description":2240,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2241,"url":2242},{"cveId":2239,"releaseId":31,"cycle":32,"description":2240,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2241,"url":2242},{"cveId":2246,"releaseId":25,"cycle":26,"description":2247,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2248,"url":2249},"CVE-2026-43284","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: esp: avoid in-place decrypt on shared skb frags\n\nMSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP\nmarks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),\nso later paths that may modify packet data can first make a private\ncopy. The IPv4\u002FIPv6 datagram append paths did not set this flag when\nsplicing pages into UDP skbs.\n\nThat leaves an ESP-in-UDP packet made from shared pipe pages looking\n","2026-05-08T08:16:43.827+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43284",{"cveId":2246,"releaseId":17,"cycle":18,"description":2247,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2248,"url":2249},{"cveId":2252,"releaseId":25,"cycle":26,"description":2253,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2254,"url":2255},"CVE-2026-43281","In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: Prevent out-of-bounds access in fw_mbox_index_xlate()\n\nAlthough it is guided that `#mbox-cells` must be at least 1, there are\nmany instances of `#mbox-cells = \u003C0>;` in the device tree. If that is\nthe case and the corresponding mailbox controller does not provide\n`fw_xlate` and of_xlate` function pointers, `fw_mbox_index_xlate()` will\nbe used by default and out-of-bounds accesses could occur due to lack of\nbounds check ","2026-05-06T12:16:49.587+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43281",{"cveId":2252,"releaseId":17,"cycle":18,"description":2253,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2254,"url":2255},{"cveId":2252,"releaseId":31,"cycle":32,"description":2253,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2254,"url":2255},{"cveId":2259,"releaseId":31,"cycle":32,"description":2260,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2261,"url":2262},"CVE-2026-43216","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Drop the lock in skb_may_tx_timestamp()\n\nskb_may_tx_timestamp() may acquire sock::sk_callback_lock. The lock must\nnot be taken in IRQ context, only softirq is okay. A few drivers receive\nthe timestamp via a dedicated interrupt and complete the TX timestamp\nfrom that handler. This will lead to a deadlock if the lock is already\nwrite-locked on the same CPU.\n\nTaking the lock can be avoided. The socket (pointed by the skb) wil","2026-05-06T12:16:41.19+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43216",{"cveId":2259,"releaseId":17,"cycle":18,"description":2260,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2261,"url":2262},{"cveId":2259,"releaseId":25,"cycle":26,"description":2260,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2261,"url":2262},{"cveId":2266,"releaseId":31,"cycle":32,"description":2267,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2268,"url":2269},"CVE-2026-43198","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix potential race in tcp_v6_syn_recv_sock()\n\nCode in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock()\nis done too late.\n\nAfter tcp_v4_syn_recv_sock(), the child socket is already visible\nfrom TCP ehash table and other cpus might use it.\n\nSince newinet->pinet6 is still pointing to the listener ipv6_pinfo\nbad things can happen as syzbot found.\n\nMove the problematic code in tcp_v6_mapped_child_init()\nand call ","2026-05-06T12:16:38.857+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43198",{"cveId":2266,"releaseId":17,"cycle":18,"description":2267,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2268,"url":2269},{"cveId":2266,"releaseId":25,"cycle":26,"description":2267,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2268,"url":2269},{"cveId":2273,"releaseId":31,"cycle":32,"description":2274,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2275,"url":2276},"CVE-2026-43125","In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: validate length in dlm_search_rsb_tree\n\nThe len parameter in dlm_dump_rsb_name() is not validated and comes\nfrom network messages. When it exceeds DLM_RESNAME_MAXLEN, it can\ncause out-of-bounds write in dlm_search_rsb_tree().\n\nAdd length validation to prevent potential buffer overflow.","2026-05-06T12:16:29.45+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43125",{"cveId":2273,"releaseId":17,"cycle":18,"description":2274,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2275,"url":2276},{"cveId":2273,"releaseId":25,"cycle":26,"description":2274,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2275,"url":2276},{"cveId":2280,"releaseId":31,"cycle":32,"description":2281,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2282,"url":2283},"CVE-2025-71292","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: nlink overflow in jfs_rename\n\nIf nlink is maximal for a directory (-1) and inside that directory you\nperform a rename for some child directory (not moving from the parent),\nthen the nlink of the first directory is first incremented and later\ndecremented. Normally this is fine, but when nlink = -1 this causes a\nwrap around to 0, and then drop_nlink issues a warning.\n\nAfter applying the patch syzbot no longer issues any warn","2026-05-06T12:16:28.453+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71292",{"cveId":2280,"releaseId":17,"cycle":18,"description":2281,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2282,"url":2283},{"cveId":2280,"releaseId":25,"cycle":26,"description":2281,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2282,"url":2283},{"cveId":2287,"releaseId":17,"cycle":18,"description":2288,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2289,"url":2290},"CVE-2025-71274","In the Linux kernel, the following vulnerability has been resolved:\n\nrpmsg: core: fix race in driver_override_show() and use core helper\n\nThe driver_override_show function reads the driver_override string\nwithout holding the device_lock. However, the store function modifies\nand frees the string while holding the device_lock. This creates a race\ncondition where the string can be freed by the store function while\nbeing read by the show function, leading to a use-after-free.\n\nTo fix this, replace t","2026-05-06T12:16:27.447+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71274",{"cveId":2292,"releaseId":25,"cycle":26,"description":2293,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2294,"url":2295},"CVE-2026-43117","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()\n\nIf overlay is used on top of btrfs, dentry->d_sb translates to overlay's\nsuper block and fsid assignment will lead to a crash.\n\nUse file_inode(file)->i_sb to always get btrfs_sb.","2026-05-06T10:16:25.513+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43117",{"cveId":2292,"releaseId":17,"cycle":18,"description":2293,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2294,"url":2295},{"cveId":2292,"releaseId":31,"cycle":32,"description":2293,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2294,"url":2295},{"cveId":2299,"releaseId":25,"cycle":26,"description":2300,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2301,"url":2302},"CVE-2026-43113","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wl1251: validate packet IDs before indexing tx_frames\n\nwl1251_tx_packet_cb() uses the firmware completion ID directly to index\nthe fixed 16-entry wl->tx_frames[] array. The ID is a raw u8 from the\ncompletion block, and the callback does not currently verify that it\nfits the array before dereferencing it.\n\nReject completion IDs that fall outside wl->tx_frames[] and keep the\nexisting NULL check in the same guard. This keeps","2026-05-06T10:16:25.05+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43113",{"cveId":2299,"releaseId":17,"cycle":18,"description":2300,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2301,"url":2302},{"cveId":2299,"releaseId":31,"cycle":32,"description":2300,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2301,"url":2302},{"cveId":2306,"releaseId":25,"cycle":26,"description":2307,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2308,"url":2309},"CVE-2026-43111","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: roccat: fix use-after-free in roccat_report_event\n\nroccat_report_event() iterates over the device->readers list without\nholding the readers_lock. This allows a concurrent roccat_release() to\nremove and free a reader while it's still being accessed, leading to a\nuse-after-free.\n\nProtect the readers list traversal with the readers_lock mutex.","2026-05-06T10:16:24.807+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43111",{"cveId":2306,"releaseId":17,"cycle":18,"description":2307,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2308,"url":2309},{"cveId":2306,"releaseId":31,"cycle":32,"description":2307,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2308,"url":2309},{"cveId":2313,"releaseId":25,"cycle":26,"description":2314,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2315,"url":2316},"CVE-2026-43110","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: validate bsscfg indices in IF events\n\nbrcmf_fweh_handle_if_event() validates the firmware-provided interface\nindex before it touches drvr->iflist[], but it still uses the raw\nbsscfgidx field as an array index without a matching range check.\n\nReject IF events whose bsscfg index does not fit in drvr->iflist[]\nbefore indexing the interface array.\n\n[add missing wifi prefix]","2026-05-06T10:16:24.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43110",{"cveId":2313,"releaseId":17,"cycle":18,"description":2314,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2315,"url":2316},{"cveId":2313,"releaseId":31,"cycle":32,"description":2314,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2315,"url":2316},{"cveId":2320,"releaseId":25,"cycle":26,"description":2321,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2322,"url":2323},"CVE-2026-43105","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvc4: Fix memory leak of BO array in hang state\n\nThe hang state's BO array is allocated separately with kzalloc() in\nvc4_save_hang_state() but never freed in vc4_free_hang_state(). Add the\nmissing kfree() for the BO array before freeing the hang state struct.","2026-05-06T10:16:24.097+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43105",{"cveId":2320,"releaseId":17,"cycle":18,"description":2321,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2322,"url":2323},{"cveId":2320,"releaseId":31,"cycle":32,"description":2321,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2322,"url":2323},{"cveId":2327,"releaseId":25,"cycle":26,"description":2328,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2329,"url":2330},"CVE-2026-43104","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvc4: Fix a memory leak in hang state error path\n\nWhen vc4_save_hang_state() encounters an early return condition, it\nreturns without freeing the previously allocated `kernel_state`,\nleaking memory.\n\nAdd the missing kfree() calls by consolidating the early return paths\ninto a single place.","2026-05-06T10:16:23.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43104",{"cveId":2327,"releaseId":17,"cycle":18,"description":2328,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2329,"url":2330},{"cveId":2327,"releaseId":31,"cycle":32,"description":2328,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2329,"url":2330},{"cveId":2334,"releaseId":25,"cycle":26,"description":2335,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2336,"url":2337},"CVE-2026-43103","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lapbether: handle NETDEV_PRE_TYPE_CHANGE\n\nlapbeth_data_transmit() expects the underlying device type\nto be ARPHRD_ETHER.\n\nReturning NOTIFY_BAD from lapbeth_device_event() makes sure\nbonding driver can not break this expectation.","2026-05-06T10:16:23.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43103",{"cveId":2334,"releaseId":17,"cycle":18,"description":2335,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2336,"url":2337},{"cveId":2334,"releaseId":31,"cycle":32,"description":2335,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2336,"url":2337},{"cveId":2341,"releaseId":17,"cycle":18,"description":2342,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2343,"url":2344},"CVE-2026-43093","In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: tighten UMEM headroom validation to account for tailroom and min frame\n\nThe current headroom validation in xdp_umem_reg() could leave us with\ninsufficient space dedicated to even receive minimum-sized ethernet\nframe. Furthermore if multi-buffer would come to play then\nskb_shared_info stored at the end of XSK frame would be corrupted.\n\nHW typically works with 128-aligned sizes so let us provide this value\nas bare minimum.\n\n","2026-05-06T10:16:22.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43093",{"cveId":2346,"releaseId":25,"cycle":26,"description":2347,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2348,"url":2349},"CVE-2026-43091","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Wait for RCU readers during policy netns exit\n\nxfrm_policy_fini() frees the policy_bydst hash tables after flushing the\npolicy work items and deleting all policies, but it does not wait for\nconcurrent RCU readers to leave their read-side critical sections first.\n\nThe policy_bydst tables are published via rcu_assign_pointer() and are\nlooked up through rcu_dereference_check(), so netns teardown must also\nwait for an RCU gra","2026-05-06T10:16:22.433+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43091",{"cveId":2346,"releaseId":17,"cycle":18,"description":2347,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2348,"url":2349},{"cveId":2346,"releaseId":31,"cycle":32,"description":2347,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2348,"url":2349},{"cveId":2353,"releaseId":25,"cycle":26,"description":2354,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2355,"url":2356},"CVE-2026-43089","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm_user: fix info leak in build_mapping()\n\nstruct xfrm_usersa_id has a one-byte padding hole after the proto\nfield, which ends up never getting set to zero before copying out to\nuserspace.  Fix that up by zeroing out the whole structure before\nsetting individual variables.","2026-05-06T10:16:22.2+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43089",{"cveId":2353,"releaseId":17,"cycle":18,"description":2354,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2355,"url":2356},{"cveId":2353,"releaseId":31,"cycle":32,"description":2354,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2355,"url":2356},{"cveId":2360,"releaseId":25,"cycle":26,"description":2361,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2362,"url":2363},"CVE-2026-43088","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: zero aligned sockaddr tail in PF_KEY exports\n\nPF_KEY export paths use `pfkey_sockaddr_size()` when reserving sockaddr\npayload space, so IPv6 addresses occupy 32 bytes on the wire. However,\n`pfkey_sockaddr_fill()` initializes only the first 28 bytes of\n`struct sockaddr_in6`, leaving the final 4 aligned bytes uninitialized.\n\nNot every PF_KEY message is affected. The state and policy dump builders\nalready zero the who","2026-05-06T10:16:22.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43088",{"cveId":2360,"releaseId":17,"cycle":18,"description":2361,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2362,"url":2363},{"cveId":2360,"releaseId":31,"cycle":32,"description":2361,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2362,"url":2363},{"cveId":2367,"releaseId":25,"cycle":26,"description":2368,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2369,"url":2370},"CVE-2026-43085","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator\n\nWhen batching multiple NFLOG messages (inst->qlen > 1), __nfulnl_send()\nappends an NLMSG_DONE terminator with sizeof(struct nfgenmsg) payload via\nnlmsg_put(), but never initializes the nfgenmsg bytes. The nlmsg_put()\nhelper only zeroes alignment padding after the payload, not the payload\nitself, so four bytes of stale kernel heap data are leaked to userspac","2026-05-06T10:16:21.72+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43085",{"cveId":2367,"releaseId":17,"cycle":18,"description":2368,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2369,"url":2370},{"cveId":2367,"releaseId":31,"cycle":32,"description":2368,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2369,"url":2370},{"cveId":2374,"releaseId":25,"cycle":26,"description":2375,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2376,"url":2377},"CVE-2026-43080","In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: Drop large packets with UDP encap\n\nsyzbot reported a WARN on my patch series [1]. The actual issue is an\noverflow of 16-bit UDP length field, and it exists in the upstream code.\nMy series added a debug WARN with an overflow check that exposed the\nissue, that's why syzbot tripped on my patches, rather than on upstream\ncode.\n\nsyzbot's repro:\n\nr0 = socket$pppl2tp(0x18, 0x1, 0x1)\nr1 = socket$inet6_udp(0xa, 0x2, 0x0)\nconnect$i","2026-05-06T10:16:21.11+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43080",{"cveId":2374,"releaseId":17,"cycle":18,"description":2375,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2376,"url":2377},{"cveId":2374,"releaseId":31,"cycle":32,"description":2375,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2376,"url":2377},{"cveId":2381,"releaseId":25,"cycle":26,"description":2382,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2383,"url":2384},"CVE-2026-43078","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl\n\nWhen page reassignment was added to af_alg_pull_tsgl the original\nloop wasn't updated so it may try to reassign one more page than\nnecessary.\n\nAdd the check to the reassignment so that this does not happen.\n\nAlso update the comment which still refers to the obsolete offset\nargument.","2026-05-06T10:16:20.853+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43078",{"cveId":2381,"releaseId":17,"cycle":18,"description":2382,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2383,"url":2384},{"cveId":2387,"releaseId":25,"cycle":26,"description":2388,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2389,"url":2390},"CVE-2026-43077","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Fix minimum RX size check for decryption\n\nThe check for the minimum receive buffer size did not take the\ntag size into account during decryption.  Fix this by adding the\nrequired extra length.","2026-05-06T10:16:20.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43077",{"cveId":2387,"releaseId":17,"cycle":18,"description":2388,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2389,"url":2390},{"cveId":2393,"releaseId":25,"cycle":26,"description":2394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2395,"url":2396},"CVE-2026-43076","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate inline data i_size during inode read\n\nWhen reading an inode from disk, ocfs2_validate_inode_block() performs\nvarious sanity checks but does not validate the size of inline data.  If\nthe filesystem is corrupted, an inode's i_size can exceed the actual\ninline data capacity (id_count).\n\nThis causes ocfs2_dir_foreach_blk_id() to iterate beyond the inline data\nbuffer, triggering a use-after-free when accessing direct","2026-05-06T10:16:20.59+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43076",{"cveId":2393,"releaseId":17,"cycle":18,"description":2394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2395,"url":2396},{"cveId":2393,"releaseId":31,"cycle":32,"description":2394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2395,"url":2396},{"cveId":2400,"releaseId":25,"cycle":26,"description":2401,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2402,"url":2403},"CVE-2026-43075","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix out-of-bounds write in ocfs2_write_end_inline\n\nKASAN reports a use-after-free write of 4086 bytes in\nocfs2_write_end_inline, called from ocfs2_write_end_nolock during a\ncopy_file_range splice fallback on a corrupted ocfs2 filesystem mounted on\na loop device.  The actual bug is an out-of-bounds write past the inode\nblock buffer, not a true use-after-free.  The write overflows into an\nadjacent freed page, which KASAN r","2026-05-06T10:16:20.463+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43075",{"cveId":2400,"releaseId":17,"cycle":18,"description":2401,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2402,"url":2403},{"cveId":2400,"releaseId":31,"cycle":32,"description":2401,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2402,"url":2403},{"cveId":2407,"releaseId":25,"cycle":26,"description":2408,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2409,"url":2410},"CVE-2026-43073","In the Linux kernel, the following vulnerability has been resolved:\n\nx86-64: rename misleadingly named '__copy_user_nocache()' function\n\nThis function was a masterclass in bad naming, for various historical\nreasons.\n\nIt claimed to be a non-cached user copy.  It is literally _neither_ of\nthose things.  It's a specialty memory copy routine that uses\nnon-temporal stores for the destination (but not the source), and that\ndoes exception handling for both source and destination accesses.\n\nAlso note th","2026-05-05T16:16:16.65+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43073",{"cveId":2407,"releaseId":17,"cycle":18,"description":2408,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2409,"url":2410},{"cveId":2407,"releaseId":31,"cycle":32,"description":2408,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2409,"url":2410},{"cveId":2414,"releaseId":25,"cycle":26,"description":2415,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2416,"url":2417},"CVE-2026-43071","In the Linux kernel, the following vulnerability has been resolved:\n\ndcache: Limit the minimal number of bucket to two\n\nThere is an OOB read problem on dentry_hashtable when user sets\n'dhash_entries=1':\n  BUG: unable to handle page fault for address: ffff888b30b774b0\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  Oops: Oops: 0000 [#1] SMP PTI\n  RIP: 0010:__d_lookup+0x56\u002F0x120\n   Call Trace:\n    d_lookup.cold+0x16\u002F0x5d\n    lookup_dcache+0x27\u002F0xf0\n    l","2026-05-05T16:16:16.42+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43071",{"cveId":2414,"releaseId":17,"cycle":18,"description":2415,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2416,"url":2417},{"cveId":2414,"releaseId":31,"cycle":32,"description":2415,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2416,"url":2417},{"cveId":2421,"releaseId":25,"cycle":26,"description":2422,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2423,"url":2424},"CVE-2026-43069","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_ll: Fix firmware leak on error path\n\nSmatch reports:\n\ndrivers\u002Fbluetooth\u002Fhci_ll.c:587 download_firmware() warn:\n'fw' from request_firmware() not released on lines: 544.\n\nIn download_firmware(), if request_firmware() succeeds but the returned\nfirmware content is invalid (no data or zero size), the function returns\nwithout releasing the firmware, resulting in a resource leak.\n\nFix this by calling release_firmware() ","2026-05-05T16:16:16.197+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43069",{"cveId":2421,"releaseId":17,"cycle":18,"description":2422,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2423,"url":2424},{"cveId":2427,"releaseId":25,"cycle":26,"description":2428,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2429,"url":2430},"CVE-2026-43068","In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid allocate block from corrupted group in ext4_mb_find_by_goal()\n\nThere's issue as follows:\n...\nEXT4-fs (mmcblk0p1): Delayed block allocation failed for inode 206 at logical offset 0 with max blocks 1 with error 117\nEXT4-fs (mmcblk0p1): This should not happen!! Data will be lost\n\nEXT4-fs (mmcblk0p1): Delayed block allocation failed for inode 206 at logical offset 0 with max blocks 1 with error 117\nEXT4-fs (mmcblk0p1): ","2026-05-05T16:16:16.053+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43068",{"cveId":2427,"releaseId":17,"cycle":18,"description":2428,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2429,"url":2430},{"cveId":2427,"releaseId":31,"cycle":32,"description":2428,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2429,"url":2430},{"cveId":2434,"releaseId":17,"cycle":18,"description":2435,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2436,"url":2437},"CVE-2026-43060","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: drop pending enqueued packets on removal\n\nPackets sitting in nfqueue might hold a reference to:\n\n- templates that specify the conntrack zone, because a percpu area is\n  used and module removal is possible.\n- conntrack timeout policies and helper, where object removal leave\n  a stale reference.\n\nSince these objects can just go away, drop enqueued packets to avoid\nstale reference to them.\n\nIf there is a need fo","2026-05-05T16:16:15.05+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43060",{"cveId":2439,"releaseId":25,"cycle":26,"description":2440,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2441,"url":2442},"CVE-2026-43052","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: check tdls flag in ieee80211_tdls_oper\n\nWhen NL80211_TDLS_ENABLE_LINK is called, the code only checks if the\nstation exists but not whether it is actually a TDLS station. This\nallows the operation to proceed for non-TDLS stations, causing\nunintended side effects like modifying channel context and HT\nprotection before failing.\n\nAdd a check for sta->sta.tdls early in the ENABLE_LINK case, before\nany side effects o","2026-05-01T15:16:51.67+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43052",{"cveId":2439,"releaseId":17,"cycle":18,"description":2440,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2441,"url":2442},{"cveId":2439,"releaseId":31,"cycle":32,"description":2440,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2441,"url":2442},{"cveId":2446,"releaseId":31,"cycle":32,"description":2447,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2448,"url":2449},"CVE-2026-43040","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak\n\nWhen processing Router Advertisements with user options the kernel\nbuilds an RTM_NEWNDUSEROPT netlink message. The nduseroptmsg struct\nhas three padding fields that are never zeroed and can leak kernel data\n\nThe fix is simple, just zeroes the padding fields.","2026-05-01T15:16:50.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43040",{"cveId":2446,"releaseId":17,"cycle":18,"description":2447,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2448,"url":2449},{"cveId":2446,"releaseId":25,"cycle":26,"description":2447,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2448,"url":2449},{"cveId":2453,"releaseId":31,"cycle":32,"description":2454,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2455,"url":2456},"CVE-2026-43038","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()\n\nSashiko AI-review observed:\n\n  In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet\n  where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2\n  and passed to icmp6_send(), it uses IP6CB(skb2).\n\n  IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso\n  offset in inet_skb_parm.opt directly overlaps with dsthao ","2026-05-01T15:16:48.533+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43038",{"cveId":2453,"releaseId":17,"cycle":18,"description":2454,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2455,"url":2456},{"cveId":2453,"releaseId":25,"cycle":26,"description":2454,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2455,"url":2456},{"cveId":2460,"releaseId":31,"cycle":32,"description":2461,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2462,"url":2463},"CVE-2026-43037","In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: clear skb2->cb[] in ip4ip6_err()\n\nOskar Kjos reported the following problem.\n\nip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written\nby the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes\nIPCB(skb2) to __ip_options_echo(), which interprets that cb[] region\nas struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff\nat offset 14 overlaps inet_skb_parm.opt.rr, producing a non","2026-05-01T15:16:48.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43037",{"cveId":2460,"releaseId":17,"cycle":18,"description":2461,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2462,"url":2463},{"cveId":2460,"releaseId":25,"cycle":26,"description":2461,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2462,"url":2463},{"cveId":2467,"releaseId":17,"cycle":18,"description":2468,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2469,"url":2470},"CVE-2026-43035","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak\n\nWhen building netlink messages, tc_chain_fill_node() never initializes\nthe tcm_info field of struct tcmsg. Since the allocation is not zeroed,\nkernel heap memory is leaked to userspace through this 4-byte field.\n\nThe fix simply zeroes tcm_info alongside the other fields that are\nalready initialized.","2026-05-01T15:16:48.147+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43035",{"cveId":2472,"releaseId":31,"cycle":32,"description":2473,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2474,"url":2475},"CVE-2026-43033","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption\n\nWhen decrypting data that is not in-place (src != dst), there is\nno need to save the high-order sequence bits in dst as it could\nsimply be re-copied from the source.\n\nHowever, the data to be hashed need to be rearranged accordingly.\n\n\nThanks,","2026-05-01T15:16:47.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43033",{"cveId":2472,"releaseId":17,"cycle":18,"description":2473,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2474,"url":2475},{"cveId":2472,"releaseId":25,"cycle":26,"description":2473,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2474,"url":2475},{"cveId":2479,"releaseId":25,"cycle":26,"description":2480,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2481,"url":2482},"CVE-2026-43028","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: ensure names are nul-terminated\n\nReject names that lack a \\0 character before feeding them\nto functions that expect c-strings.\n\nFixes tag is the most recent commit that needs this change.","2026-05-01T15:16:47.297+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43028",{"cveId":2479,"releaseId":31,"cycle":32,"description":2480,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2481,"url":2482},{"cveId":2479,"releaseId":17,"cycle":18,"description":2480,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2481,"url":2482},{"cveId":2486,"releaseId":17,"cycle":18,"description":2487,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2488,"url":2489},"CVE-2026-43027","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_helper: pass helper to expect cleanup\n\nnf_conntrack_helper_unregister() calls nf_ct_expect_iterate_destroy()\nto remove expectations belonging to the helper being unregistered.\nHowever, it passes NULL instead of the helper pointer as the data\nargument, so expect_iter_me() never matches any expectation and all\nof them survive the cleanup.\n\nAfter unregister returns, nfnl_cthelper_del() frees the helper\nobje","2026-05-01T15:16:47.167+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43027",{"cveId":2486,"releaseId":25,"cycle":26,"description":2487,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2488,"url":2489},{"cveId":2492,"releaseId":17,"cycle":18,"description":2493,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2494,"url":2495},"CVE-2026-43026","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent\n\nctnetlink_alloc_expect() allocates expectations from a non-zeroing\nslab cache via nf_ct_expect_alloc().  When CTA_EXPECT_NAT is not\npresent in the netlink message, saved_addr and saved_proto are\nnever initialized.  Stale data from a previous slab occupant can\nthen be dumped to userspace by ctnetlink_exp_dump_expect(), which\nchecks these fields to decide wh","2026-05-01T15:16:47.033+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43026",{"cveId":2492,"releaseId":25,"cycle":26,"description":2493,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2494,"url":2495},{"cveId":2492,"releaseId":31,"cycle":32,"description":2493,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2494,"url":2495},{"cveId":2499,"releaseId":31,"cycle":32,"description":2500,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":2501,"url":2502},"CVE-2026-43025","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: ignore explicit helper on new expectations\n\nUse the existing master conntrack helper, anything else is not really\nsupported and it just makes validation more complicated, so just ignore\nwhat helper userspace suggests for this expectation.\n\nThis was uncovered when validating CTA_EXPECT_CLASS via different helper\nprovided by userspace than the existing master conntrack helper:\n\n  BUG: KASAN: slab-out-of-boun","2026-05-01T15:16:46.903+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43025",{"cveId":2499,"releaseId":17,"cycle":18,"description":2500,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":2501,"url":2502},{"cveId":2499,"releaseId":25,"cycle":26,"description":2500,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":2501,"url":2502},{"cveId":2506,"releaseId":17,"cycle":18,"description":2507,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2508,"url":2509},"CVE-2026-43024","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: reject immediate NF_QUEUE verdict\n\nnft_queue is always used from userspace nftables to deliver the NF_QUEUE\nverdict. Immediately emitting an NF_QUEUE verdict is never used by the\nuserspace nft tools, so reject immediate NF_QUEUE verdicts.\n\nThe arp family does not provide queue support, but such an immediate\nverdict is still reachable. Globally reject NF_QUEUE immediate verdicts\nto address this issue.","2026-05-01T15:16:46.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43024",{"cveId":2511,"releaseId":31,"cycle":32,"description":2512,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2513,"url":2514},"CVE-2026-43011","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fx25: Fix potential double free of skb\n\nWhen alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at\nline 48 and returns 1 (error).\nThis error propagates back through the call chain:\n\nx25_queue_rx_frame returns 1\n    |\n    v\nx25_state3_machine receives the return value 1 and takes the else\nbranch at line 278, setting queued=0 and returning 0\n    |\n    v\nx25_process_rx_frame returns queued=0\n    |\n    v\nx25_backlog_r","2026-05-01T15:16:44.993+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-43011",{"cveId":2511,"releaseId":17,"cycle":18,"description":2512,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2513,"url":2514},{"cveId":2511,"releaseId":25,"cycle":26,"description":2512,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2513,"url":2514},{"cveId":2518,"releaseId":31,"cycle":32,"description":2519,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2520,"url":2521},"CVE-2026-31768","In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-adc161s626: use DMA-safe memory for spi_read()\n\nAdd a DMA-safe buffer and use it for spi_read() instead of a stack\nmemory. All SPI buffers must be DMA-safe.\n\nSince we only need up to 3 bytes, we just use a u8[] instead of __be16\nand __be32 and change the conversion functions appropriately.","2026-05-01T15:16:39.977+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31768",{"cveId":2518,"releaseId":17,"cycle":18,"description":2519,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2520,"url":2521},{"cveId":2518,"releaseId":25,"cycle":26,"description":2519,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2520,"url":2521},{"cveId":2525,"releaseId":17,"cycle":18,"description":2526,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2527,"url":2528},"CVE-2026-31761","In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: mpu3050: Move iio_device_register() to correct location\n\niio_device_register() should be at the end of the probe function to\nprevent race conditions.\n\nPlace iio_device_register() at the end of the probe function and place\niio_device_unregister() accordingly.","2026-05-01T15:16:39.153+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31761",{"cveId":2525,"releaseId":25,"cycle":26,"description":2526,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2527,"url":2528},{"cveId":2531,"releaseId":17,"cycle":18,"description":2532,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2533,"url":2534},"CVE-2026-31752","In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: br_nd_send: validate ND option lengths\n\nbr_nd_send() walks ND options according to option-provided lengths.\nA malformed option can make the parser advance beyond the computed\noption span or use a too-short source LLADDR option payload.\n\nValidate option lengths against the remaining NS option area before\nadvancing, and only read source LLADDR when the option is large enough\nfor an Ethernet address.","2026-05-01T15:16:38.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31752",{"cveId":2536,"releaseId":17,"cycle":18,"description":2537,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2538,"url":2539},"CVE-2026-31737","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ftgmac100: fix ring allocation unwind on open failure\n\nftgmac100_alloc_rings() allocates rx_skbs, tx_skbs, rxdes, txdes, and\nrx_scratch in stages. On intermediate failures it returned -ENOMEM\ndirectly, leaking resources allocated earlier in the function.\n\nRework the failure path to use staged local unwind labels and free\nallocated resources in reverse order before returning -ENOMEM. This\nmatches common netdev allocation cl","2026-05-01T15:16:36.347+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31737",{"cveId":2536,"releaseId":25,"cycle":26,"description":2537,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2538,"url":2539},{"cveId":2542,"releaseId":17,"cycle":18,"description":2543,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2544,"url":2545},"CVE-2026-31715","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io()\n\nThe xfstests case \"generic\u002F107\" and syzbot have both reported a NULL\npointer dereference.\n\nThe concurrent scenario that triggers the panic is as follows:\n\nF2FS_WB_CP_DATA write callback          umount\n                                        - f2fs_write_checkpoint\n                                         - f2fs_wait_on_all_pages(sbi, F2FS_WB_CP_DATA)\n","2026-05-01T14:16:21.637+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31715",{"cveId":2547,"releaseId":17,"cycle":18,"description":2548,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2549,"url":2550},"CVE-2026-31699","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed\n\nWhen retrieving the PEK CSR, don't attempt to copy the blob to userspace\nif the firmware command failed.  If the failure was due to an invalid\nlength, i.e. the userspace buffer+length was too small, copying the number\nof bytes _firmware_ requires will overflow the kernel-allocated buffer and\nleak data to userspace.\n\n  BUG: KASAN: slab-out-of-bounds in in","2026-05-01T14:16:19.777+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31699",{"cveId":2552,"releaseId":17,"cycle":18,"description":2553,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2554,"url":2555},"CVE-2026-31698","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed\n\nWhen retrieving the PDH cert, don't attempt to copy the blobs to userspace\nif the firmware command failed.  If the failure was due to an invalid\nlength, i.e. the userspace buffer+length was too small, copying the number\nof bytes _firmware_ requires will overflow the kernel-allocated buffer and\nleak data to userspace.\n\n  BUG: KASAN: slab-out-of-bound","2026-05-01T14:16:19.65+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31698",{"cveId":2557,"releaseId":25,"cycle":26,"description":2558,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2559,"url":2560},"CVE-2026-31696","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix missing validation of ticket length in non-XDR key preparsing\n\nIn rxrpc_preparse(), there are two paths for parsing key payloads: the\nXDR path (for large payloads) and the non-XDR path (for payloads \u003C= 28\nbytes). While the XDR path (rxrpc_preparse_xdr_rxkad()) correctly\nvalidates the ticket length against AFSTOKEN_RK_TIX_MAX, the non-XDR\npath fails to do so.\n\nThis allows an unprivileged user to provide a very large t","2026-05-01T14:16:19.403+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31696",{"cveId":2557,"releaseId":17,"cycle":18,"description":2558,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2559,"url":2560},{"cveId":2557,"releaseId":31,"cycle":32,"description":2558,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2559,"url":2560},{"cveId":2564,"releaseId":17,"cycle":18,"description":2565,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2566,"url":2567},"CVE-2026-31686","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fkasan: fix double free for kasan pXds\n\nkasan_free_pxd() assumes the page table is always struct page aligned. \nBut that's not always the case for all architectures.  E.g.  In case of\npowerpc with 64K pagesize, PUD table (of size 4096) comes from slab cache\nnamed pgtable-2^9.  Hence instead of page_to_virt(pxd_page()) let's just\ndirectly pass the start of the pxd table which is passed as the 1st\nargument.\n\nThis fixes the belo","2026-04-27T18:16:53.987+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31686",{"cveId":2569,"releaseId":25,"cycle":26,"description":2570,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":2571,"url":2572},"CVE-2026-31685","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ip6t_eui64: reject invalid MAC header for all packets\n\n`eui64_mt6()` derives a modified EUI-64 from the Ethernet source address\nand compares it with the low 64 bits of the IPv6 source address.\n\nThe existing guard only rejects an invalid MAC header when\n`par->fragoff != 0`. For packets with `par->fragoff == 0`, `eui64_mt6()`\ncan still reach `eth_hdr(skb)` even when the MAC header is not valid.\n\nFix this by removing th","2026-04-25T09:16:02.273+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31685",{"cveId":2569,"releaseId":17,"cycle":18,"description":2570,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":2571,"url":2572},{"cveId":2569,"releaseId":31,"cycle":32,"description":2570,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":2571,"url":2572},{"cveId":2576,"releaseId":17,"cycle":18,"description":2577,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2578,"url":2579},"CVE-2026-31684","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: act_csum: validate nested VLAN headers\n\ntcf_csum_act() walks nested VLAN headers directly from skb->data when an\nskb still carries in-payload VLAN tags. The current code reads\nvlan->h_vlan_encapsulated_proto and then pulls VLAN_HLEN bytes without\nfirst ensuring that the full VLAN header is present in the linear area.\n\nIf only part of an inner VLAN header is linearized, accessing\nh_vlan_encapsulated_proto reads past ","2026-04-25T09:16:02.163+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31684",{"cveId":2581,"releaseId":17,"cycle":18,"description":2582,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":2583,"url":2584},"CVE-2026-31682","In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: br_nd_send: linearize skb before parsing ND options\n\nbr_nd_send() parses neighbour discovery options from ns->opt[] and\nassumes that these options are in the linear part of request.\n\nIts callers only guarantee that the ICMPv6 header and target address\nare available, so the option area can still be non-linear. Parsing\nns->opt[] in that case can access data past the linear buffer.\n\nLinearize request before option parsing ","2026-04-25T09:16:01.913+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31682",{"cveId":2586,"releaseId":25,"cycle":26,"description":2587,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2588,"url":2589},"CVE-2026-31681","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_multiport: validate range encoding in checkentry\n\nports_match_v1() treats any non-zero pflags entry as the start of a\nport range and unconditionally consumes the next ports[] element as\nthe range end.\n\nThe checkentry path currently validates protocol, flags and count, but\nit does not validate the range encoding itself. As a result, malformed\nrules can mark the last slot as a range start or place two range starts\nb","2026-04-25T09:16:01.8+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31681",{"cveId":2586,"releaseId":17,"cycle":18,"description":2587,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2588,"url":2589},{"cveId":2586,"releaseId":31,"cycle":32,"description":2587,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2588,"url":2589},{"cveId":2593,"releaseId":31,"cycle":32,"description":2594,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2595,"url":2596},"CVE-2026-31680","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: flowlabel: defer exclusive option free until RCU teardown\n\n`ip6fl_seq_show()` walks the global flowlabel hash under the seq-file\nRCU read-side lock and prints `fl->opt->opt_nflen` when an option block\nis present.\n\nExclusive flowlabels currently free `fl->opt` as soon as `fl->users`\ndrops to zero in `fl_release()`. However, the surrounding\n`struct ip6_flowlabel` remains visible in the global hash table until\nlater gar","2026-04-25T09:16:01.673+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31680",{"cveId":2593,"releaseId":17,"cycle":18,"description":2594,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2595,"url":2596},{"cveId":2593,"releaseId":25,"cycle":26,"description":2594,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2595,"url":2596},{"cveId":2600,"releaseId":25,"cycle":26,"description":2601,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2602,"url":2603},"CVE-2026-31676","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: only handle RESPONSE during service challenge\n\nOnly process RESPONSE packets while the service connection is still in\nRXRPC_CONN_SERVICE_CHALLENGING. Check that state under state_lock before\nrunning response verification and security initialization, then use a local\nsecured flag to decide whether to queue the secured-connection work after\nthe state transition. This keeps duplicate or late RESPONSE packets from\nre-running","2026-04-25T09:16:01.21+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31676",{"cveId":2600,"releaseId":17,"cycle":18,"description":2601,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2602,"url":2603},{"cveId":2600,"releaseId":31,"cycle":32,"description":2601,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2602,"url":2603},{"cveId":2607,"releaseId":31,"cycle":32,"description":2608,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2609,"url":2610},"CVE-2026-31674","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()\n\nReject rt match rules whose addrnr exceeds IP6T_RT_HOPS.\n\nrt_mt6() expects addrnr to stay within the bounds of rtinfo->addrs[].\nValidate addrnr during rule installation so malformed rules are rejected\nbefore the match logic can use an out-of-range value.","2026-04-25T09:16:00.963+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31674",{"cveId":2607,"releaseId":17,"cycle":18,"description":2608,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2609,"url":2610},{"cveId":2607,"releaseId":25,"cycle":26,"description":2608,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2609,"url":2610},{"cveId":2614,"releaseId":25,"cycle":26,"description":2615,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2616,"url":2617},"CVE-2026-31673","In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: read UNIX_DIAG_VFS data under unix_state_lock\n\nExact UNIX diag lookups hold a reference to the socket, but not to\nu->path. Meanwhile, unix_release_sock() clears u->path under\nunix_state_lock() and drops the path reference after unlocking.\n\nRead the inode and device numbers for UNIX_DIAG_VFS while holding\nunix_state_lock(), then emit the netlink attribute after dropping the\nlock.\n\nThis keeps the VFS data stable while th","2026-04-25T09:16:00.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31673",{"cveId":2614,"releaseId":17,"cycle":18,"description":2615,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2616,"url":2617},{"cveId":2614,"releaseId":31,"cycle":32,"description":2615,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2616,"url":2617},{"cveId":2621,"releaseId":31,"cycle":32,"description":2622,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2623,"url":2624},"CVE-2026-31671","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm_user: fix info leak in build_report()\n\nstruct xfrm_user_report is a __u8 proto field followed by a struct\nxfrm_selector which means there is three \"empty\" bytes of padding, but\nthe padding is never zeroed before copying to userspace.  Fix that up by\nzeroing the structure before setting individual member variables.","2026-04-24T15:16:46.903+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31671",{"cveId":2621,"releaseId":17,"cycle":18,"description":2622,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2623,"url":2624},{"cveId":2621,"releaseId":25,"cycle":26,"description":2622,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2623,"url":2624},{"cveId":2628,"releaseId":31,"cycle":32,"description":2629,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2630,"url":2631},"CVE-2026-31670","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rfkill: prevent unlimited numbers of rfkill events from being created\n\nUserspace can create an unlimited number of rfkill events if the system\nis so configured, while not consuming them from the rfkill file\ndescriptor, causing a potential out of memory situation.  Prevent this\nfrom bounding the number of pending rfkill events at a \"large\" number\n(i.e. 1000) to prevent abuses like this.","2026-04-24T15:16:46.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31670",{"cveId":2628,"releaseId":17,"cycle":18,"description":2629,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2630,"url":2631},{"cveId":2628,"releaseId":25,"cycle":26,"description":2629,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2630,"url":2631},{"cveId":2635,"releaseId":17,"cycle":18,"description":2636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2637,"url":2638},"CVE-2026-31665","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: fix use-after-free in timeout object destroy\n\nnft_ct_timeout_obj_destroy() frees the timeout object with kfree()\nimmediately after nf_ct_untimeout(), without waiting for an RCU grace\nperiod. Concurrent packet processing on other CPUs may still hold\nRCU-protected references to the timeout object obtained via\nrcu_dereference() in nf_ct_timeout_data().\n\nAdd an rcu_head to struct nf_ct_timeout and use kfree_rcu()","2026-04-24T15:16:46.157+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31665",{"cveId":2640,"releaseId":25,"cycle":26,"description":2641,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2642,"url":2643},"CVE-2026-31664","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: clear trailing padding in build_polexpire()\n\nbuild_expire() clears the trailing padding bytes of struct\nxfrm_user_expire after setting the hard field via memset_after(),\nbut the analogous function build_polexpire() does not do this for\nstruct xfrm_user_polexpire.\n\nThe padding bytes after the __u8 hard field are left\nuninitialized from the heap allocation, and are then sent to\nuserspace via netlink multicast to XFRMNLGRP_E","2026-04-24T15:16:46.043+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31664",{"cveId":2640,"releaseId":17,"cycle":18,"description":2641,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2642,"url":2643},{"cveId":2640,"releaseId":31,"cycle":32,"description":2641,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2642,"url":2643},{"cveId":2647,"releaseId":25,"cycle":26,"description":2648,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2649,"url":2650},"CVE-2026-31663","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: hold dev ref until after transport_finish NF_HOOK\n\nAfter async crypto completes, xfrm_input_resume() calls dev_put()\nimmediately on re-entry before the skb reaches transport_finish.\nThe skb->dev pointer is then used inside NF_HOOK and its okfn,\nwhich can race with device teardown.\n\nRemove the dev_put from the async resumption entry and instead\ndrop the reference after the NF_HOOK call in transport_finish,\nusing a saved de","2026-04-24T15:16:45.947+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31663",{"cveId":2647,"releaseId":17,"cycle":18,"description":2648,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2649,"url":2650},{"cveId":2653,"releaseId":31,"cycle":32,"description":2654,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2655,"url":2656},"CVE-2026-31658","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()\n\nWhen dma_map_single() fails in tse_start_xmit(), the function returns\nNETDEV_TX_OK without freeing the skb. Since NETDEV_TX_OK tells the\nstack the packet was consumed, the skb is never freed, leaking memory\non every DMA mapping failure.\n\nAdd dev_kfree_skb_any() before returning to properly free the skb.","2026-04-24T15:16:45.337+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31658",{"cveId":2653,"releaseId":17,"cycle":18,"description":2654,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2655,"url":2656},{"cveId":2653,"releaseId":25,"cycle":26,"description":2654,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2655,"url":2656},{"cveId":2660,"releaseId":25,"cycle":26,"description":2661,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2662,"url":2663},"CVE-2026-31657","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: hold claim backbone gateways by reference\n\nbatadv_bla_add_claim() can replace claim->backbone_gw and drop the old\ngateway's last reference while readers still follow the pointer.\n\nThe netlink claim dump path dereferences claim->backbone_gw->orig and\ntakes claim->backbone_gw->crc_lock without pinning the underlying\nbackbone gateway. batadv_bla_check_claim() still has the same naked\npointer access pattern.\n\nReuse bata","2026-04-24T15:16:45.227+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31657",{"cveId":2660,"releaseId":17,"cycle":18,"description":2661,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2662,"url":2663},{"cveId":2660,"releaseId":31,"cycle":32,"description":2661,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2662,"url":2663},{"cveId":2667,"releaseId":31,"cycle":32,"description":2668,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2669,"url":2670},"CVE-2026-31651","In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: vub300: fix NULL-deref on disconnect\n\nMake sure to deregister the controller before dropping the reference to\nthe driver data on disconnect to avoid NULL-pointer dereferences or\nuse-after-free.","2026-04-24T15:16:44.573+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31651",{"cveId":2667,"releaseId":17,"cycle":18,"description":2668,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2669,"url":2670},{"cveId":2667,"releaseId":25,"cycle":26,"description":2668,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2669,"url":2670},{"cveId":2674,"releaseId":31,"cycle":32,"description":2675,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2676,"url":2677},"CVE-2026-31649","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: fix integer underflow in chain mode\n\nThe jumbo_frm() chain-mode implementation unconditionally computes\n\n    len = nopaged_len - bmax;\n\nwhere nopaged_len = skb_headlen(skb) (linear bytes only) and bmax is\nBUF_SIZE_8KiB or BUF_SIZE_2KiB.  However, the caller stmmac_xmit()\ndecides to invoke jumbo_frm() based on skb->len (total length including\npage fragments):\n\n    is_jumbo = stmmac_is_jumbo_frm(priv, skb->len, enh_d","2026-04-24T15:16:44.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31649",{"cveId":2674,"releaseId":17,"cycle":18,"description":2675,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2676,"url":2677},{"cveId":2674,"releaseId":25,"cycle":26,"description":2675,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2676,"url":2677},{"cveId":2681,"releaseId":25,"cycle":26,"description":2682,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2683,"url":2684},"CVE-2026-31642","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix call removal to use RCU safe deletion\n\nFix rxrpc call removal from the rxnet->calls list to use list_del_rcu()\nrather than list_del_init() to prevent stuffing up reading\n\u002Fproc\u002Fnet\u002Frxrpc\u002Fcalls from potentially getting into an infinite loop.\n\nThis, however, means that list_empty() no longer works on an entry that's\nbeen deleted from the list, making it harder to detect prior deletion.  Fix\nthis by:\n\nFirstly, make rxrpc","2026-04-24T15:16:43.567+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31642",{"cveId":2681,"releaseId":17,"cycle":18,"description":2682,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2683,"url":2684},{"cveId":2687,"releaseId":25,"cycle":26,"description":2688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2689,"url":2690},"CVE-2026-31637","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: reject undecryptable rxkad response tickets\n\nrxkad_decrypt_ticket() decrypts the RXKAD response ticket and then\nparses the buffer as plaintext without checking whether\ncrypto_skcipher_decrypt() succeeded.\n\nA malformed RESPONSE can therefore use a non-block-aligned ticket\nlength, make the decrypt operation fail, and still drive the ticket\nparser with attacker-controlled bytes.\n\nCheck the decrypt result and abort the conne","2026-04-24T15:16:43.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31637",{"cveId":2687,"releaseId":17,"cycle":18,"description":2688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2689,"url":2690},{"cveId":2687,"releaseId":31,"cycle":32,"description":2688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2689,"url":2690},{"cveId":2694,"releaseId":17,"cycle":18,"description":2695,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2696,"url":2697},"CVE-2026-31634","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: fix reference count leak in rxrpc_server_keyring()\n\nThis patch fixes a reference count leak in rxrpc_server_keyring()\nby checking if rx->securities is already set.","2026-04-24T15:16:42.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31634",{"cveId":2694,"releaseId":31,"cycle":32,"description":2695,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2696,"url":2697},{"cveId":2694,"releaseId":25,"cycle":26,"description":2695,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2696,"url":2697},{"cveId":2701,"releaseId":25,"cycle":26,"description":2702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2703,"url":2704},"CVE-2026-31630","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: proc: size address buffers for %pISpc output\n\nThe AF_RXRPC procfs helpers format local and remote socket addresses into\nfixed 50-byte stack buffers with \"%pISpc\".\n\nThat is too small for the longest current-tree IPv6-with-port form the\nformatter can produce. In lib\u002Fvsprintf.c, the compressed IPv6 path uses a\ndotted-quad tail not only for v4mapped addresses, but also for ISATAP\naddresses via ipv6_addr_is_isatap().\n\nAs a re","2026-04-24T15:16:42.323+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31630",{"cveId":2701,"releaseId":17,"cycle":18,"description":2702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2703,"url":2704},{"cveId":2701,"releaseId":31,"cycle":32,"description":2702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2703,"url":2704},{"cveId":2708,"releaseId":25,"cycle":26,"description":2709,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2710,"url":2711},"CVE-2026-31629","In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: add missing return after LLCP_CLOSED checks\n\nIn nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket\nstate is LLCP_CLOSED, the code correctly calls release_sock() and\nnfc_llcp_sock_put() but fails to return. Execution falls through to\nthe remainder of the function, which calls release_sock() and\nnfc_llcp_sock_put() again. This results in a double release_sock()\nand a refcount underflow via double nfc_llcp_s","2026-04-24T15:16:42.217+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31629",{"cveId":2708,"releaseId":17,"cycle":18,"description":2709,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2710,"url":2711},{"cveId":2708,"releaseId":31,"cycle":32,"description":2709,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2710,"url":2711},{"cveId":2715,"releaseId":31,"cycle":32,"description":2716,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2717,"url":2718},"CVE-2026-31628","In the Linux kernel, the following vulnerability has been resolved:\n\nx86\u002FCPU: Fix FPDSS on Zen1\n\nZen1's hardware divider can leave, under certain circumstances, partial\nresults from previous operations.  Those results can be leaked by\nanother, attacker thread.\n\nFix that with a chicken bit.","2026-04-24T15:16:42.103+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31628",{"cveId":2715,"releaseId":17,"cycle":18,"description":2716,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2717,"url":2718},{"cveId":2715,"releaseId":25,"cycle":26,"description":2716,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2717,"url":2718},{"cveId":2722,"releaseId":25,"cycle":26,"description":2723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2724,"url":2725},"CVE-2026-31627","In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: s3c24xx: check the size of the SMBUS message before using it\n\nThe first byte of an i2c SMBUS message is the size, and it should be\nverified to ensure that it is in the range of 0..I2C_SMBUS_BLOCK_MAX\nbefore processing it.\n\nThis is the same logic that was added in commit a6e04f05ce0b (\"i2c:\ntegra: check msg length in SMBUS block read\") to the i2c tegra driver.","2026-04-24T15:16:42.003+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31627",{"cveId":2722,"releaseId":17,"cycle":18,"description":2723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2724,"url":2725},{"cveId":2722,"releaseId":31,"cycle":32,"description":2723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2724,"url":2725},{"cveId":2729,"releaseId":25,"cycle":26,"description":2730,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2731,"url":2732},"CVE-2026-31626","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()\n\nInitialize le_tmp64 to zero in rtw_BIP_verify() to prevent using\nuninitialized data.\n\nSmatch warns that only 6 bytes are copied to this 8-byte (u64)\nvariable, leaving the last two bytes uninitialized:\n\ndrivers\u002Fstaging\u002Frtl8723bs\u002Fcore\u002Frtw_security.c:1308 rtw_BIP_verify()\nwarn: not copying enough bytes for '&le_tmp64' (8 vs 6 bytes)\n\nInitializing the variable at the star","2026-04-24T15:16:41.907+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31626",{"cveId":2729,"releaseId":17,"cycle":18,"description":2730,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2731,"url":2732},{"cveId":2735,"releaseId":17,"cycle":18,"description":2736,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2737,"url":2738},"CVE-2026-31625","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: alps: fix NULL pointer dereference in alps_raw_event()\n\nCommit ecfa6f34492c (\"HID: Add HID_CLAIMED_INPUT guards in raw_event\ncallbacks missing them\") attempted to fix up the HID drivers that had\nmissed the previous fix that was done in 2ff5baa9b527 (\"HID: appleir:\nFix potential NULL dereference at raw event handle\"), but the alps\ndriver was missed.\n\nFix this up by properly checking in the hid-alps driver that it had been\nc","2026-04-24T15:16:41.807+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31625",{"cveId":2740,"releaseId":25,"cycle":26,"description":2741,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2742,"url":2743},"CVE-2026-31624","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: clamp report_size in s32ton() to avoid undefined shift\n\ns32ton() shifts by n-1 where n is the field's report_size, a value that\ncomes directly from a HID device.  The HID parser bounds report_size\nonly to \u003C= 256, so a broken HID device can supply a report descriptor\nwith a wide field that triggers shift exponents up to 256 on a 32-bit\ntype when an output report is built via hid_output_field() or\nhid_set_field().\n\nCom","2026-04-24T15:16:41.697+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31624",{"cveId":2740,"releaseId":17,"cycle":18,"description":2741,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2742,"url":2743},{"cveId":2740,"releaseId":31,"cycle":32,"description":2741,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2742,"url":2743},{"cveId":2747,"releaseId":25,"cycle":26,"description":2748,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2749,"url":2750},"CVE-2026-31623","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()\n\nA malicious USB device claiming to be a CDC Phonet modem can overflow\nthe skb_shared_info->frags[] array by sending an unbounded sequence of\nfull-page bulk transfers.\n\nDrop the skb and increment the length error when the frag limit is\nreached.  This matches the same fix that commit f0813bcd2d9d (\"net:\nwwan: t7xx: fix potential skb->frags overflow in RX path\") did ","2026-04-24T15:16:41.587+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31623",{"cveId":2747,"releaseId":17,"cycle":18,"description":2748,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2749,"url":2750},{"cveId":2747,"releaseId":31,"cycle":32,"description":2748,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2749,"url":2750},{"cveId":2754,"releaseId":17,"cycle":18,"description":2755,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2756,"url":2757},"CVE-2026-31622","In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: digital: Bounds check NFC-A cascade depth in SDD response handler\n\nThe NFC-A anti-collision cascade in digital_in_recv_sdd_res() appends 3\nor 4 bytes to target->nfcid1 on each round, but the number of cascade\nrounds is controlled entirely by the peer device.  The peer sets the\ncascade tag in the SDD_RES (deciding 3 vs 4 bytes) and the\ncascade-incomplete bit in the SEL_RES (deciding whether another round\nfollows).\n\nISO 1444","2026-04-24T15:16:41.487+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31622",{"cveId":2754,"releaseId":31,"cycle":32,"description":2755,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2756,"url":2757},{"cveId":2754,"releaseId":25,"cycle":26,"description":2755,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2756,"url":2757},{"cveId":2761,"releaseId":25,"cycle":26,"description":2762,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2763,"url":2764},"CVE-2026-31619","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: fireworks: bound device-supplied status before string array lookup\n\nThe status field in an EFW response is a 32-bit value supplied by the\nfirewire device.  efr_status_names[] has 17 entries so a status value\noutside that range goes off into the weeds when looking at the %s value.\n\nEven worse, the status could return EFR_STATUS_INCOMPLETE which is\n0x80000000, and is obviously not in that array of potential strings.\n\nFix th","2026-04-24T15:16:41.18+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31619",{"cveId":2761,"releaseId":17,"cycle":18,"description":2762,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2763,"url":2764},{"cveId":2761,"releaseId":31,"cycle":32,"description":2762,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2763,"url":2764},{"cveId":2768,"releaseId":25,"cycle":26,"description":2769,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2770,"url":2771},"CVE-2026-31618","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO\n\nMuch like commit 19f953e74356 (\"fbdev: fb_pm2fb: Avoid potential divide\nby zero error\"), we also need to prevent that same crash from happening\nin the udlfb driver as it uses pixclock directly when dividing, which\nwill crash.","2026-04-24T15:16:41.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31618",{"cveId":2768,"releaseId":17,"cycle":18,"description":2769,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2770,"url":2771},{"cveId":2768,"releaseId":31,"cycle":32,"description":2769,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2770,"url":2771},{"cveId":2775,"releaseId":25,"cycle":26,"description":2776,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2777,"url":2778},"CVE-2026-31616","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()\n\nA broken\u002Fbored\u002Fmean USB host can overflow the skb_shared_info->frags[]\narray on a Linux gadget exposing a Phonet function by sending an\nunbounded sequence of full-page OUT transfers.\n\npn_rx_complete() finalizes the skb only when req->actual \u003C req->length,\nwhere req->length is set to PAGE_SIZE by the gadget.  If the host always\nsends exactly PAGE_SIZE bytes per","2026-04-24T15:16:40.87+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31616",{"cveId":2775,"releaseId":17,"cycle":18,"description":2776,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2777,"url":2778},{"cveId":2775,"releaseId":31,"cycle":32,"description":2776,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2777,"url":2778},{"cveId":2782,"releaseId":25,"cycle":26,"description":2783,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2784,"url":2785},"CVE-2026-31615","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: renesas_usb3: validate endpoint index in standard request handlers\n\nThe GET_STATUS and SET\u002FCLEAR_FEATURE handlers extract the endpoint\nnumber from the host-supplied wIndex without any sort of validation.\nFix this up by validating the number of endpoints actually match up with\nthe number the device has before attempting to dereference a pointer\nbased on this math.\n\nThis is just like what was done in commit ee0d382fe","2026-04-24T15:16:40.767+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31615",{"cveId":2782,"releaseId":17,"cycle":18,"description":2783,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2784,"url":2785},{"cveId":2782,"releaseId":31,"cycle":32,"description":2783,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2784,"url":2785},{"cveId":2789,"releaseId":25,"cycle":26,"description":2790,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2791,"url":2792},"CVE-2026-31607","In the Linux kernel, the following vulnerability has been resolved:\n\nusbip: validate number_of_packets in usbip_pack_ret_submit()\n\nWhen a USB\u002FIP client receives a RET_SUBMIT response,\nusbip_pack_ret_submit() unconditionally overwrites\nurb->number_of_packets from the network PDU. This value is\nsubsequently used as the loop bound in usbip_recv_iso() and\nusbip_pad_iso() to iterate over urb->iso_frame_desc[], a flexible\narray whose size was fixed at URB allocation time based on the\n*original* number","2026-04-24T15:16:39.94+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31607",{"cveId":2789,"releaseId":17,"cycle":18,"description":2790,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2791,"url":2792},{"cveId":2789,"releaseId":31,"cycle":32,"description":2790,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":2791,"url":2792},{"cveId":2796,"releaseId":25,"cycle":26,"description":2797,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2798,"url":2799},"CVE-2026-31605","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO\n\nMuch like commit 19f953e74356 (\"fbdev: fb_pm2fb: Avoid potential divide\nby zero error\"), we also need to prevent that same crash from happening\nin the udlfb driver as it uses pixclock directly when dividing, which\nwill crash.","2026-04-24T15:16:39.73+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31605",{"cveId":2796,"releaseId":17,"cycle":18,"description":2797,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2798,"url":2799},{"cveId":2796,"releaseId":31,"cycle":32,"description":2797,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2798,"url":2799},{"cveId":2803,"releaseId":25,"cycle":26,"description":2804,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2805,"url":2806},"CVE-2026-31603","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: sm750fb: fix division by zero in ps_to_hz()\n\nps_to_hz() is called from hw_sm750_crtc_set_mode() without validating\nthat pixclock is non-zero. A zero pixclock passed via FBIOPUT_VSCREENINFO\ncauses a division by zero.\n\nFix by rejecting zero pixclock in lynxfb_ops_check_var(), consistent\nwith other framebuffer drivers.","2026-04-24T15:16:39.453+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31603",{"cveId":2803,"releaseId":17,"cycle":18,"description":2804,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2805,"url":2806},{"cveId":2803,"releaseId":31,"cycle":32,"description":2804,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2805,"url":2806},{"cveId":2810,"releaseId":25,"cycle":26,"description":2811,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2812,"url":2813},"CVE-2026-31602","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ctxfi: Limit PTP to a single page\n\nCommit 391e69143d0a increased CT_PTP_NUM from 1 to 4 to support 256\nplayback streams, but the additional pages are not used by the card\ncorrectly. The CT20K2 hardware already has multiple VMEM_PTPAL\nregisters, but using them separately would require refactoring the\nentire virtual memory allocation logic.\n\nct_vm_map() always uses PTEs in vm->ptp[0].area regardless of\nCT_PTP_NUM. On AMD64 ","2026-04-24T15:16:39.263+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31602",{"cveId":2810,"releaseId":17,"cycle":18,"description":2811,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2812,"url":2813},{"cveId":2810,"releaseId":31,"cycle":32,"description":2811,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2812,"url":2813},{"cveId":2817,"releaseId":25,"cycle":26,"description":2818,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2819,"url":2820},"CVE-2026-31598","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix possible deadlock between unlink and dio_end_io_write\n\nocfs2_unlink takes orphan dir inode_lock first and then ip_alloc_sem,\nwhile in ocfs2_dio_end_io_write, it acquires these locks in reverse order.\nThis creates an ABBA lock ordering violation on lock classes\nocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE] and\nocfs2_file_ip_alloc_sem_key.\n\nLock Chain #0 (orphan dir inode_lock -> ip_alloc_sem):\nocfs2_unlink\n  ocfs2_p","2026-04-24T15:16:37.56+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31598",{"cveId":2817,"releaseId":17,"cycle":18,"description":2818,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2819,"url":2820},{"cveId":2817,"releaseId":31,"cycle":32,"description":2818,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":2819,"url":2820},{"cveId":2824,"releaseId":25,"cycle":26,"description":2825,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2826,"url":2827},"CVE-2026-31597","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY\n\nfilemap_fault() may drop the mmap_lock before returning VM_FAULT_RETRY,\nas documented in mm\u002Ffilemap.c:\n\n  \"If our return value has VM_FAULT_RETRY set, it's because the mmap_lock\n  may be dropped before doing I\u002FO or by lock_folio_maybe_drop_mmap().\"\n\nWhen this happens, a concurrent munmap() can call remove_vma() and free\nthe vm_area_struct via RCU. The saved 'vma' p","2026-04-24T15:16:37.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31597",{"cveId":2824,"releaseId":17,"cycle":18,"description":2825,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2826,"url":2827},{"cveId":2824,"releaseId":31,"cycle":32,"description":2825,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2826,"url":2827},{"cveId":2831,"releaseId":25,"cycle":26,"description":2832,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2833,"url":2834},"CVE-2026-31596","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: handle invalid dinode in ocfs2_group_extend\n\n[BUG]\nkernel BUG at fs\u002Focfs2\u002Fresize.c:308!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nRIP: 0010:ocfs2_group_extend+0x10aa\u002F0x1ae0 fs\u002Focfs2\u002Fresize.c:308\nCode: 8b8520ff ffff83f8 860f8580 030000e8 5cc3c1fe\nCall Trace:\n ...\n ocfs2_ioctl+0x175\u002F0x6e0 fs\u002Focfs2\u002Fioctl.c:869\n vfs_ioctl fs\u002Fioctl.c:51 [inline]\n __do_sys_ioctl fs\u002Fioctl.c:597 [inline]\n __se_sys_ioctl fs\u002Fioctl.c:583 [inl","2026-04-24T15:16:37.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31596",{"cveId":2831,"releaseId":17,"cycle":18,"description":2832,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2833,"url":2834},{"cveId":2831,"releaseId":31,"cycle":32,"description":2832,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2833,"url":2834},{"cveId":2838,"releaseId":25,"cycle":26,"description":2839,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2840,"url":2841},"CVE-2026-31588","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Use scratch field in MMIO fragment to hold small write values\n\nWhen exiting to userspace to service an emulated MMIO write, copy the\nto-be-written value to a scratch field in the MMIO fragment if the size\nof the data payload is 8 bytes or less, i.e. can fit in a single chunk,\ninstead of pointing the fragment directly at the source value.\n\nThis fixes a class of use-after-free bugs that occur when the emulator\ninitiates","2026-04-24T15:16:33.733+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31588",{"cveId":2838,"releaseId":17,"cycle":18,"description":2839,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2840,"url":2841},{"cveId":2838,"releaseId":31,"cycle":32,"description":2839,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":2840,"url":2841},{"cveId":2845,"releaseId":17,"cycle":18,"description":2846,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2847,"url":2848},"CVE-2026-31586","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: blk-cgroup: fix use-after-free in cgwb_release_workfn()\n\ncgwb_release_workfn() calls css_put(wb->blkcg_css) and then later accesses\nwb->blkcg_css again via blkcg_unpin_online().  If css_put() drops the last\nreference, the blkcg can be freed asynchronously (css_free_rwork_fn ->\nblkcg_css_free -> kfree) before blkcg_unpin_online() dereferences the\npointer to access blkcg->online_pin, resulting in a use-after-free:\n\n  BUG: KAS","2026-04-24T15:16:33.393+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31586",{"cveId":2850,"releaseId":25,"cycle":26,"description":2851,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2852,"url":2853},"CVE-2026-31583","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: em28xx: fix use-after-free in em28xx_v4l2_open()\n\nem28xx_v4l2_open() reads dev->v4l2 without holding dev->lock,\ncreating a race with em28xx_v4l2_init()'s error path and\nem28xx_v4l2_fini(), both of which free the em28xx_v4l2 struct\nand set dev->v4l2 to NULL under dev->lock.\n\nThis race leads to two issues:\n - use-after-free in v4l2_fh_init() when accessing vdev->ctrl_handler,\n   since the video_device is embedded in the fr","2026-04-24T15:16:33.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31583",{"cveId":2850,"releaseId":17,"cycle":18,"description":2851,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2852,"url":2853},{"cveId":2850,"releaseId":31,"cycle":32,"description":2851,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2852,"url":2853},{"cveId":2857,"releaseId":25,"cycle":26,"description":2858,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2859,"url":2860},"CVE-2026-31581","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: 6fire: fix use-after-free on disconnect\n\nIn usb6fire_chip_abort(), the chip struct is allocated as the card's\nprivate data (via snd_card_new with sizeof(struct sfire_chip)).  When\nsnd_card_free_when_closed() is called and no file handles are open, the\ncard and embedded chip are freed synchronously.  The subsequent\nchip->card = NULL write then hits freed slab memory.\n\nCall trace:\n  usb6fire_chip_abort sound\u002Fusb\u002F6fire\u002Fchip.","2026-04-24T15:16:32.797+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31581",{"cveId":2857,"releaseId":17,"cycle":18,"description":2858,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2859,"url":2860},{"cveId":2857,"releaseId":31,"cycle":32,"description":2858,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2859,"url":2860},{"cveId":2864,"releaseId":17,"cycle":18,"description":2865,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2866,"url":2867},"CVE-2026-31580","In the Linux kernel, the following vulnerability has been resolved:\n\nbcache: fix cached_dev.sb_bio use-after-free and crash\n\nIn our production environment, we have received multiple crash reports\nregarding libceph, which have caught our attention:\n\n```\n[6888366.280350] Call Trace:\n[6888366.280452]  blk_update_request+0x14e\u002F0x370\n[6888366.280561]  blk_mq_end_request+0x1a\u002F0x130\n[6888366.280671]  rbd_img_handle_request+0x1a0\u002F0x1b0 [rbd]\n[6888366.280792]  rbd_obj_handle_request+0x32\u002F0x40 [rbd]\n[6888","2026-04-24T15:16:32.683+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31580",{"cveId":2864,"releaseId":31,"cycle":32,"description":2865,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2866,"url":2867},{"cveId":2864,"releaseId":25,"cycle":26,"description":2865,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2866,"url":2867},{"cveId":2871,"releaseId":25,"cycle":26,"description":2872,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2873,"url":2874},"CVE-2026-31578","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: as102: fix to not free memory after the device is registered in as102_usb_probe()\n\nIn as102_usb driver, the following race condition occurs:\n```\n\t\tCPU0\t\t\t\t\t\tCPU1\nas102_usb_probe()\n  kzalloc(); \u002F\u002F alloc as102_dev_t\n  ....\n  usb_register_dev();\n\t\t\t\t\t\tfd = sys_open(\"\u002Fpath\u002Fto\u002Fdev\"); \u002F\u002F open as102 fd\n\t\t\t\t\t\t....\n  usb_deregister_dev();\n  ....\n  kfree(); \u002F\u002F free as102_dev_t\n  ....\n\t\t\t\t\t\tsys_close(fd);\n\t\t\t\t\t\t  as102_release() \u002F\u002F","2026-04-24T15:16:32.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31578",{"cveId":2871,"releaseId":17,"cycle":18,"description":2872,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2873,"url":2874},{"cveId":2871,"releaseId":31,"cycle":32,"description":2872,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2873,"url":2874},{"cveId":2878,"releaseId":25,"cycle":26,"description":2879,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2880,"url":2881},"CVE-2026-31577","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map\n\nThe DAT inode's btree node cache (i_assoc_inode) is initialized lazily\nduring btree operations. However, nilfs_mdt_save_to_shadow_map()\nassumes i_assoc_inode is already initialized when copying dirty pages\nto the shadow map during GC.\n\nIf NILFS_IOCTL_CLEAN_SEGMENTS is called immediately after mount before\nany btree operation has occurred on the DAT inod","2026-04-24T15:16:32.347+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31577",{"cveId":2878,"releaseId":17,"cycle":18,"description":2879,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2880,"url":2881},{"cveId":2878,"releaseId":31,"cycle":32,"description":2879,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2880,"url":2881},{"cveId":2885,"releaseId":17,"cycle":18,"description":2886,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2887,"url":2888},"CVE-2026-31576","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: hackrf: fix to not free memory after the device is registered in hackrf_probe()\n\nIn hackrf driver, the following race condition occurs:\n```\n\t\tCPU0\t\t\t\t\t\tCPU1\nhackrf_probe()\n  kzalloc(); \u002F\u002F alloc hackrf_dev\n  ....\n  v4l2_device_register();\n  ....\n\t\t\t\t\t\tfd = sys_open(\"\u002Fpath\u002Fto\u002Fdev\"); \u002F\u002F open hackrf fd\n\t\t\t\t\t\t....\n  v4l2_device_unregister();\n  ....\n  kfree(); \u002F\u002F free hackrf_dev\n  ....\n\t\t\t\t\t\tsys_ioctl(fd, ...);\n\t\t\t\t\t\t  v4l2_io","2026-04-24T15:16:32.23+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31576",{"cveId":2885,"releaseId":31,"cycle":32,"description":2886,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2887,"url":2888},{"cveId":2885,"releaseId":25,"cycle":26,"description":2886,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2887,"url":2888},{"cveId":2892,"releaseId":31,"cycle":32,"description":2893,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2894,"url":2895},"CVE-2026-31555","In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Clear stale exiting pointer in futex_lock_pi() retry path\n\nFuzzying\u002Fstressing futexes triggered:\n\n    WARNING: kernel\u002Ffutex\u002Fcore.c:825 at wait_for_owner_exiting+0x7a\u002F0x80, CPU#11: futex_lock_pi_s\u002F524\n\nWhen futex_lock_pi_atomic() sees the owner is exiting, it returns -EBUSY\nand stores a refcounted task pointer in 'exiting'.\n\nAfter wait_for_owner_exiting() consumes that reference, the local pointer\nis never reset to nil. U","2026-04-24T15:16:29.837+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31555",{"cveId":2892,"releaseId":25,"cycle":26,"description":2893,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2894,"url":2895},{"cveId":2892,"releaseId":17,"cycle":18,"description":2893,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2894,"url":2895},{"cveId":2899,"releaseId":31,"cycle":32,"description":2900,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2901,"url":2902},"CVE-2026-31546","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bonding: fix NULL deref in bond_debug_rlb_hash_show\n\nrlb_clear_slave intentionally keeps RLB hash-table entries on\nthe rx_hashtbl_used_head list with slave set to NULL when no\nreplacement slave is available. However, bond_debug_rlb_hash_show\nvisites client_info->slave without checking if it's NULL.\n\nOther used-list iterators in bond_alb.c already handle this NULL-slave\nstate safely:\n\n- rlb_update_client returns early on !c","2026-04-24T15:16:28.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31546",{"cveId":2899,"releaseId":17,"cycle":18,"description":2900,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2901,"url":2902},{"cveId":2899,"releaseId":25,"cycle":26,"description":2900,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2901,"url":2902},{"cveId":2906,"releaseId":25,"cycle":26,"description":2907,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2908,"url":2909},"CVE-2026-31532","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: raw: fix ro->uniq use-after-free in raw_rcv()\n\nraw_release() unregisters raw CAN receive filters via can_rx_unregister(),\nbut receiver deletion is deferred with call_rcu(). This leaves a window\nwhere raw_rcv() may still be running in an RCU read-side critical section\nafter raw_release() frees ro->uniq, leading to a use-after-free of the\npercpu uniq storage.\n\nMove free_percpu(ro->uniq) out of raw_release() and into a raw-sp","2026-04-23T12:17:01.927+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31532",{"cveId":2906,"releaseId":17,"cycle":18,"description":2907,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2908,"url":2909},{"cveId":2906,"releaseId":31,"cycle":32,"description":2907,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2908,"url":2909},{"cveId":2913,"releaseId":25,"cycle":26,"description":2914,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2915,"url":2916},"CVE-2026-31527","In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: platform: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without t","2026-04-22T14:16:52.903+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31527",{"cveId":2913,"releaseId":17,"cycle":18,"description":2914,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2915,"url":2916},{"cveId":2913,"releaseId":31,"cycle":32,"description":2914,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2915,"url":2916},{"cveId":2920,"releaseId":31,"cycle":32,"description":2921,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2922,"url":2923},"CVE-2026-31521","In the Linux kernel, the following vulnerability has been resolved:\n\nmodule: Fix kernel panic when a symbol st_shndx is out of bounds\n\nThe module loader doesn't check for bounds of the ELF section index in\nsimplify_symbols():\n\n       for (i = 1; i \u003C symsec->sh_size \u002F sizeof(Elf_Sym); i++) {\n\t\tconst char *name = info->strtab + sym[i].st_name;\n\n\t\tswitch (sym[i].st_shndx) {\n\t\tcase SHN_COMMON:\n\n\t\t[...]\n\n\t\tdefault:\n\t\t\t\u002F* Divert to percpu allocation if a percpu var. *\u002F\n\t\t\tif (sym[i].st_shndx == info->","2026-04-22T14:16:51.93+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31521",{"cveId":2920,"releaseId":17,"cycle":18,"description":2921,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2922,"url":2923},{"cveId":2920,"releaseId":25,"cycle":26,"description":2921,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2922,"url":2923},{"cveId":2927,"releaseId":31,"cycle":32,"description":2928,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2929,"url":2930},"CVE-2026-31515","In the Linux kernel, the following vulnerability has been resolved:\n\naf_key: validate families in pfkey_send_migrate()\n\nsyzbot was able to trigger a crash in skb_put() [1]\n\nIssue is that pfkey_send_migrate() does not check old\u002Fnew families,\nand that set_ipsecrequest() @family argument was truncated,\nthus possibly overfilling the skb.\n\nValidate families early, do not wait set_ipsecrequest().\n\n[1]\n\nskbuff: skb_over_panic: text:ffffffff8a752120 len:392 put:16 head:ffff88802a4ad040 data:ffff88802a4a","2026-04-22T14:16:50.94+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31515",{"cveId":2927,"releaseId":17,"cycle":18,"description":2928,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2929,"url":2930},{"cveId":2927,"releaseId":25,"cycle":26,"description":2928,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2929,"url":2930},{"cveId":2934,"releaseId":17,"cycle":18,"description":2935,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2936,"url":2937},"CVE-2026-31507","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer\n\nsmc_rx_splice() allocates one smc_spd_priv per pipe_buffer and stores\nthe pointer in pipe_buffer.private.  The pipe_buf_operations for these\nbuffers used .get = generic_pipe_buf_get, which only increments the page\nreference count when tee(2) duplicates a pipe buffer.  The smc_spd_priv\npointer itself was not handled, so after tee() both the origin","2026-04-22T14:16:49.523+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31507",{"cveId":2939,"releaseId":31,"cycle":32,"description":2940,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2941,"url":2942},"CVE-2026-31504","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix fanout UAF in packet_release() via NETDEV_UP race\n\n`packet_release()` has a race window where `NETDEV_UP` can re-register a\nsocket into a fanout group's `arr[]` array. The re-registration is not\ncleaned up by `fanout_release()`, leaving a dangling pointer in the fanout\narray.\n`packet_release()` does NOT zero `po->num` in its `bind_lock` section.\nAfter releasing `bind_lock`, `po->num` is still non-zero and `po->ifindex`","2026-04-22T14:16:49.04+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31504",{"cveId":2939,"releaseId":17,"cycle":18,"description":2940,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2941,"url":2942},{"cveId":2939,"releaseId":25,"cycle":26,"description":2940,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2941,"url":2942},{"cveId":2946,"releaseId":31,"cycle":32,"description":2947,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2948,"url":2949},"CVE-2026-31503","In the Linux kernel, the following vulnerability has been resolved:\n\nudp: Fix wildcard bind conflict check when using hash2\n\nWhen binding a udp_sock to a local address and port, UDP uses\ntwo hashes (udptable->hash and udptable->hash2) for collision\ndetection. The current code switches to \"hash2\" when\nhslot->count > 10.\n\n\"hash2\" is keyed by local address and local port.\n\"hash\" is keyed by local port only.\n\nThe issue can be shown in the following bind sequence (pseudo code):\n\nbind(fd1,  \"[fd00::1]","2026-04-22T14:16:48.863+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31503",{"cveId":2946,"releaseId":17,"cycle":18,"description":2947,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2948,"url":2949},{"cveId":2946,"releaseId":25,"cycle":26,"description":2947,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2948,"url":2949},{"cveId":2953,"releaseId":31,"cycle":32,"description":2954,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2955,"url":2956},"CVE-2026-31502","In the Linux kernel, the following vulnerability has been resolved:\n\nteam: fix header_ops type confusion with non-Ethernet ports\n\nSimilar to commit 950803f72547 (\"bonding: fix type confusion in\nbond_setup_by_slave()\") team has the same class of header_ops type\nconfusion.\n\nFor non-Ethernet ports, team_setup_by_port() copies port_dev->header_ops\ndirectly. When the team device later calls dev_hard_header() or\ndev_parse_header(), these callbacks can run with the team net_device\ninstead of the real l","2026-04-22T14:16:48.713+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31502",{"cveId":2953,"releaseId":17,"cycle":18,"description":2954,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2955,"url":2956},{"cveId":2953,"releaseId":25,"cycle":26,"description":2954,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2955,"url":2956},{"cveId":2960,"releaseId":25,"cycle":26,"description":2961,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2962,"url":2963},"CVE-2026-31500","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock\n\nbtintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET\nand Intel exception-info retrieval) without holding\nhci_req_sync_lock().  This lets it race against\nhci_dev_do_close() -> btintel_shutdown_combined(), which also runs\n__hci_cmd_sync() under the same lock.  When both paths manipulate\nhdev->req_status\u002Freq_rsp concurrently, the close path may ","2026-04-22T14:16:48.427+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31500",{"cveId":2960,"releaseId":17,"cycle":18,"description":2961,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2962,"url":2963},{"cveId":2960,"releaseId":31,"cycle":32,"description":2961,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2962,"url":2963},{"cveId":2967,"releaseId":31,"cycle":32,"description":2968,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2969,"url":2970},"CVE-2026-31496","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_expect: skip expectations in other netns via proc\n\nSkip expectations that do not reside in this netns.\n\nSimilar to e77e6ff502ea (\"netfilter: conntrack: do not dump other netns's\nconntrack entries via proc\").","2026-04-22T14:16:47.693+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31496",{"cveId":2967,"releaseId":17,"cycle":18,"description":2968,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2969,"url":2970},{"cveId":2967,"releaseId":25,"cycle":26,"description":2968,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2969,"url":2970},{"cveId":2974,"releaseId":25,"cycle":26,"description":2975,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2976,"url":2977},"CVE-2026-31495","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: use netlink policy range checks\n\nReplace manual range and mask validations with netlink policy\nannotations in ctnetlink code paths, so that the netlink core rejects\ninvalid values early and can generate extack errors.\n\n- CTA_PROTOINFO_TCP_STATE: reject values > TCP_CONNTRACK_SYN_SENT2 at\n  policy level, removing the manual >= TCP_CONNTRACK_MAX check.\n- CTA_PROTOINFO_TCP_WSCALE_ORIGINAL\u002FREPLY: reject values","2026-04-22T14:16:47.5+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31495",{"cveId":2974,"releaseId":31,"cycle":32,"description":2975,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2976,"url":2977},{"cveId":2974,"releaseId":17,"cycle":18,"description":2975,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":2976,"url":2977},{"cveId":2981,"releaseId":17,"cycle":18,"description":2982,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2983,"url":2984},"CVE-2026-31494","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: use the current queue number for stats\n\nThere's a potential mismatch between the memory reserved for statistics\nand the amount of memory written.\n\ngem_get_sset_count() correctly computes the number of stats based on the\nactive queues, whereas gem_get_ethtool_stats() indiscriminately copies\ndata using the maximum number of queues, and in the case the number of\nactive queues is less than MACB_MAX_QUEUES, this results i","2026-04-22T14:16:47.293+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31494",{"cveId":2986,"releaseId":25,"cycle":26,"description":2987,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2988,"url":2989},"CVE-2026-31489","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: meson-spicc: Fix double-put in remove path\n\nmeson_spicc_probe() registers the controller with\ndevm_spi_register_controller(), so teardown already drops the\ncontroller reference via devm cleanup.\n\nCalling spi_controller_put() again in meson_spicc_remove()\ncauses a double-put.","2026-04-22T14:16:46.603+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31489",{"cveId":2986,"releaseId":17,"cycle":18,"description":2987,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":2988,"url":2989},{"cveId":2992,"releaseId":25,"cycle":26,"description":2993,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2994,"url":2995},"CVE-2026-31486","In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus\u002Fcore) Protect regulator operations with mutex\n\nThe regulator operations pmbus_regulator_get_voltage(),\npmbus_regulator_set_voltage(), and pmbus_regulator_list_voltage()\naccess PMBus registers and shared data but were not protected by\nthe update_lock mutex. This could lead to race conditions.\n\nHowever, adding mutex protection directly to these functions causes\na deadlock because pmbus_regulator_notify() (which call","2026-04-22T14:16:46.16+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31486",{"cveId":2992,"releaseId":17,"cycle":18,"description":2993,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2994,"url":2995},{"cveId":2992,"releaseId":31,"cycle":32,"description":2993,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":2994,"url":2995},{"cveId":2999,"releaseId":17,"cycle":18,"description":3000,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3001,"url":3002},"CVE-2026-31485","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-fsl-lpspi: fix teardown order issue (UAF)\n\nThere is a teardown order issue in the driver. The SPI controller is\nregistered using devm_spi_register_controller(), which delays\nunregistration of the SPI controller until after the fsl_lpspi_remove()\nfunction returns.\n\nAs the fsl_lpspi_remove() function synchronously tears down the DMA\nchannels, a running SPI transfer triggers the following NULL pointer\ndereference due to u","2026-04-22T14:16:45.923+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31485",{"cveId":2999,"releaseId":25,"cycle":26,"description":3000,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3001,"url":3002},{"cveId":3005,"releaseId":31,"cycle":32,"description":3006,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3007,"url":3008},"CVE-2026-31469","In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false\n\nA UAF issue occurs when the virtio_net driver is configured with napi_tx=N\nand the device's IFF_XMIT_DST_RELEASE flag is cleared\n(e.g., during the configuration of tc route filter rules).\n\nWhen IFF_XMIT_DST_RELEASE is removed from the net_device, the network stack\nexpects the driver to hold the reference to skb->dst until the packet\nis ful","2026-04-22T14:16:43.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31469",{"cveId":3005,"releaseId":17,"cycle":18,"description":3006,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3007,"url":3008},{"cveId":3005,"releaseId":25,"cycle":26,"description":3006,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3007,"url":3008},{"cveId":3012,"releaseId":31,"cycle":32,"description":3013,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3014,"url":3015},"CVE-2026-31466","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fhuge_memory: fix folio isn't locked in softleaf_to_folio()\n\nOn arm64 server, we found folio that get from migration entry isn't locked\nin softleaf_to_folio().  This issue triggers when mTHP splitting and\nzap_nonpresent_ptes() races, and the root cause is lack of memory barrier\nin softleaf_to_folio().  The race is as follows:\n\n\tCPU0                                             CPU1\n\ndeferred_split_scan()                       ","2026-04-22T14:16:42.78+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31466",{"cveId":3012,"releaseId":17,"cycle":18,"description":3013,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3014,"url":3015},{"cveId":3012,"releaseId":25,"cycle":26,"description":3013,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3014,"url":3015},{"cveId":3019,"releaseId":31,"cycle":32,"description":3020,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3021,"url":3022},"CVE-2026-31452","In the Linux kernel, the following vulnerability has been resolved:\n\next4: convert inline data to extents when truncate exceeds inline size\n\nAdd a check in ext4_setattr() to convert files from inline data storage\nto extent-based storage when truncate() grows the file size beyond the\ninline capacity. This prevents the filesystem from entering an\ninconsistent state where the inline data flag is set but the file size\nexceeds what can be stored inline.\n\nWithout this fix, the following sequence cause","2026-04-22T14:16:39.46+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31452",{"cveId":3019,"releaseId":17,"cycle":18,"description":3020,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3021,"url":3022},{"cveId":3019,"releaseId":25,"cycle":26,"description":3020,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3021,"url":3022},{"cveId":3026,"releaseId":31,"cycle":32,"description":3027,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3028,"url":3029},"CVE-2026-31451","In the Linux kernel, the following vulnerability has been resolved:\n\next4: replace BUG_ON with proper error handling in ext4_read_inline_folio\n\nReplace BUG_ON() with proper error handling when inline data size\nexceeds PAGE_SIZE. This prevents kernel panic and allows the system to\ncontinue running while properly reporting the filesystem corruption.\n\nThe error is logged via ext4_error_inode(), the buffer head is released\nto prevent memory leak, and -EFSCORRUPTED is returned to indicate\nfilesystem ","2026-04-22T14:16:39.31+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31451",{"cveId":3026,"releaseId":17,"cycle":18,"description":3027,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3028,"url":3029},{"cveId":3026,"releaseId":25,"cycle":26,"description":3027,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3028,"url":3029},{"cveId":3033,"releaseId":31,"cycle":32,"description":3034,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3035,"url":3036},"CVE-2026-31450","In the Linux kernel, the following vulnerability has been resolved:\n\next4: publish jinode after initialization\n\next4_inode_attach_jinode() publishes ei->jinode to concurrent users.\nIt used to set ei->jinode before jbd2_journal_init_jbd_inode(),\nallowing a reader to observe a non-NULL jinode with i_vfs_inode\nstill unset.\n\nThe fast commit flush path can then pass this jinode to\njbd2_wait_inode_data(), which dereferences i_vfs_inode->i_mapping and\nmay crash.\n\nBelow is the crash I observe:\n```\nBUG: ","2026-04-22T14:16:39.083+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31450",{"cveId":3033,"releaseId":17,"cycle":18,"description":3034,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3035,"url":3036},{"cveId":3033,"releaseId":25,"cycle":26,"description":3034,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3035,"url":3036},{"cveId":3040,"releaseId":25,"cycle":26,"description":3041,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3042,"url":3043},"CVE-2026-31449","In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate p_idx bounds in ext4_ext_correct_indexes\n\next4_ext_correct_indexes() walks up the extent tree correcting\nindex entries when the first extent in a leaf is modified. Before\naccessing path[k].p_idx->ei_block, there is no validation that\np_idx falls within the valid range of index entries for that\nlevel.\n\nIf the on-disk extent header contains a corrupted or crafted\neh_entries value, p_idx can point past the end of th","2026-04-22T14:16:38.933+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31449",{"cveId":3040,"releaseId":17,"cycle":18,"description":3041,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3042,"url":3043},{"cveId":3040,"releaseId":31,"cycle":32,"description":3041,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3042,"url":3043},{"cveId":3047,"releaseId":31,"cycle":32,"description":3048,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":3049,"url":3050},"CVE-2026-31448","In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid infinite loops caused by residual data\n\nOn the mkdir\u002Fmknod path, when mapping logical blocks to physical blocks,\nif inserting a new extent into the extent tree fails (in this example,\nbecause the file system disabled the huge file feature when marking the\ninode as dirty), ext4_ext_map_blocks() only calls ext4_free_blocks() to\nreclaim the physical block without deleting the corresponding data in\nthe extent tree. This","2026-04-22T14:16:38.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31448",{"cveId":3047,"releaseId":17,"cycle":18,"description":3048,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":3049,"url":3050},{"cveId":3047,"releaseId":25,"cycle":26,"description":3048,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":3049,"url":3050},{"cveId":3054,"releaseId":25,"cycle":26,"description":3055,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3056,"url":3057},"CVE-2026-31447","In the Linux kernel, the following vulnerability has been resolved:\n\next4: reject mount if bigalloc with s_first_data_block != 0\n\nbigalloc with s_first_data_block != 0 is not supported, reject mounting\nit.","2026-04-22T14:16:38.577+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31447",{"cveId":3054,"releaseId":31,"cycle":32,"description":3055,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3056,"url":3057},{"cveId":3054,"releaseId":17,"cycle":18,"description":3055,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3056,"url":3057},{"cveId":3061,"releaseId":25,"cycle":26,"description":3062,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3063,"url":3064},"CVE-2026-31431","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.","2026-04-22T09:16:21.27+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31431",{"cveId":3061,"releaseId":17,"cycle":18,"description":3062,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3063,"url":3064},{"cveId":3067,"releaseId":25,"cycle":26,"description":3068,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3069,"url":3070},"CVE-2026-31428","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD\n\n__build_packet_message() manually constructs the NFULA_PAYLOAD netlink\nattribute using skb_put() and skb_copy_bits(), bypassing the standard\nnla_reserve()\u002Fnla_put() helpers. While nla_total_size(data_len) bytes\nare allocated (including NLA alignment padding), only data_len bytes\nof actual packet data are copied. The trailing nla_padlen(data_len)\nbytes (1","2026-04-13T14:16:12.957+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31428",{"cveId":3067,"releaseId":17,"cycle":18,"description":3068,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3069,"url":3070},{"cveId":3067,"releaseId":31,"cycle":32,"description":3068,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3069,"url":3070},{"cveId":3074,"releaseId":25,"cycle":26,"description":3075,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3076,"url":3077},"CVE-2026-31427","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp\n\nprocess_sdp() declares union nf_inet_addr rtp_addr on the stack and\npasses it to the nf_nat_sip sdp_session hook after walking the SDP\nmedia descriptions. However rtp_addr is only initialized inside the\nmedia loop when a recognized media type with a non-zero port is found.\n\nIf the SDP body contains no m= lines, only inactive media sections\n(m=audio 0","2026-04-13T14:16:12.783+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31427",{"cveId":3074,"releaseId":17,"cycle":18,"description":3075,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3076,"url":3077},{"cveId":3074,"releaseId":31,"cycle":32,"description":3075,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3076,"url":3077},{"cveId":3081,"releaseId":25,"cycle":26,"description":3082,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3083,"url":3084},"CVE-2026-31425","In the Linux kernel, the following vulnerability has been resolved:\n\nrds: ib: reject FRMR registration before IB connection is established\n\nrds_ib_get_mr() extracts the rds_ib_connection from conn->c_transport_data\nand passes it to rds_ib_reg_frmr() for FRWR memory registration. On a\nfresh outgoing connection, ic is allocated in rds_ib_conn_alloc() with\ni_cm_id = NULL because the connection worker has not yet called\nrds_ib_conn_path_connect() to create the rdma_cm_id. When sendmsg() with\nRDS_CMS","2026-04-13T14:16:12.42+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31425",{"cveId":3081,"releaseId":17,"cycle":18,"description":3082,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3083,"url":3084},{"cveId":3081,"releaseId":31,"cycle":32,"description":3082,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3083,"url":3084},{"cveId":3088,"releaseId":17,"cycle":18,"description":3089,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3090,"url":3091},"CVE-2026-31424","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: restrict xt_check_match\u002Fxt_check_target extensions for NFPROTO_ARP\n\nWeiming Shi says:\n\nxt_match and xt_target structs registered with NFPROTO_UNSPEC can be\nloaded by any protocol family through nft_compat. When such a\nmatch\u002Ftarget sets .hooks to restrict which hooks it may run on, the\nbitmask uses NF_INET_* constants. This is only correct for families\nwhose hook layout matches NF_INET_*: IPv4, IPv6, INET, a","2026-04-13T14:16:12.24+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31424",{"cveId":3088,"releaseId":31,"cycle":32,"description":3089,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3090,"url":3091},{"cveId":3088,"releaseId":25,"cycle":26,"description":3089,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3090,"url":3091},{"cveId":3095,"releaseId":25,"cycle":26,"description":3096,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3097,"url":3098},"CVE-2026-31423","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: sch_hfsc: fix divide-by-zero in rtsc_min()\n\nm2sm() converts a u32 slope to a u64 scaled value.  For large inputs\n(e.g. m1=4000000000), the result can reach 2^32.  rtsc_min() stores\nthe difference of two such u64 values in a u32 variable `dsm` and\nuses it as a divisor.  When the difference is exactly 2^32 the\ntruncation yields zero, causing a divide-by-zero oops in the\nconcave-curve intersection path:\n\n  Oops: divide ","2026-04-13T14:16:12.07+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31423",{"cveId":3095,"releaseId":17,"cycle":18,"description":3096,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3097,"url":3098},{"cveId":3095,"releaseId":31,"cycle":32,"description":3096,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3097,"url":3098},{"cveId":3102,"releaseId":17,"cycle":18,"description":3103,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3104,"url":3105},"CVE-2026-31422","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: cls_flow: fix NULL pointer dereference on shared blocks\n\nflow_change() calls tcf_block_q() and dereferences q->handle to derive\na default baseclass.  Shared blocks leave block->q NULL, causing a NULL\nderef when a flow filter without a fully qualified baseclass is created\non a shared block.\n\nCheck tcf_block_shared() before accessing block->q and return -EINVAL\nfor shared blocks.  This avoids the null-deref shown below","2026-04-13T14:16:11.907+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31422",{"cveId":3107,"releaseId":17,"cycle":18,"description":3108,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3109,"url":3110},"CVE-2026-31421","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: cls_fw: fix NULL pointer dereference on shared blocks\n\nThe old-method path in fw_classify() calls tcf_block_q() and\ndereferences q->handle.  Shared blocks leave block->q NULL, causing a\nNULL deref when an empty cls_fw filter is attached to a shared block\nand a packet with a nonzero major skb mark is classified.\n\nReject the configuration in fw_change() when the old method (no\nTCA_OPTIONS) is used on a shared block, si","2026-04-13T14:16:11.74+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31421",{"cveId":3112,"releaseId":25,"cycle":26,"description":3113,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3114,"url":3115},"CVE-2026-31417","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fx25: Fix overflow when accumulating packets\n\nAdd a check to ensure that `x25_sock.fraglen` does not overflow.\n\nThe `fraglen` also needs to be resetted when purging `fragment_queue` in\n`x25_clear_queues()`.","2026-04-13T14:16:11.097+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31417",{"cveId":3112,"releaseId":17,"cycle":18,"description":3113,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3114,"url":3115},{"cveId":3112,"releaseId":31,"cycle":32,"description":3113,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3114,"url":3115},{"cveId":3119,"releaseId":25,"cycle":26,"description":3120,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3121,"url":3122},"CVE-2026-31416","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: account for netlink header size\n\nThis is a followup to an old bug fix: NLMSG_DONE needs to account\nfor the netlink header size, not just the attribute size.\n\nThis can result in a WARN splat + drop of the netlink message,\nbut other than this there are no ill effects.","2026-04-13T14:16:10.907+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31416",{"cveId":3119,"releaseId":17,"cycle":18,"description":3120,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3121,"url":3122},{"cveId":3119,"releaseId":31,"cycle":32,"description":3120,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3121,"url":3122},{"cveId":3126,"releaseId":25,"cycle":26,"description":3127,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3128,"url":3129},"CVE-2026-31415","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: avoid overflows in ip6_datagram_send_ctl()\n\nYiming Qian reported :\n\u003Cquote>\n I believe I found a locally triggerable kernel bug in the IPv6 sendmsg\n ancillary-data path that can panic the kernel via `skb_under_panic()`\n (local DoS).\n\n The core issue is a mismatch between:\n\n - a 16-bit length accumulator (`struct ipv6_txoptions::opt_flen`, type\n `__u16`) and\n - a pointer to the *last* provided destination-options header (`o","2026-04-13T14:16:10.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31415",{"cveId":3126,"releaseId":17,"cycle":18,"description":3127,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3128,"url":3129},{"cveId":3126,"releaseId":31,"cycle":32,"description":3127,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3128,"url":3129},{"cveId":3133,"releaseId":25,"cycle":26,"description":3134,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3135,"url":3136},"CVE-2026-31414","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_expect: use expect->helper\n\nUse expect->helper in ctnetlink and \u002Fproc to dump the helper name.\nUsing nfct_help() without holding a reference to the master conntrack\nis unsafe.\n\nUse exp->master->helper in ctnetlink path if userspace does not provide\nan explicit helper when creating an expectation to retain the existing\nbehaviour. The ctnetlink expectation path holds the reference on the\nmaster conntrack a","2026-04-13T14:16:10.537+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31414",{"cveId":3133,"releaseId":17,"cycle":18,"description":3134,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3135,"url":3136},{"cveId":3133,"releaseId":31,"cycle":32,"description":3134,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3135,"url":3136},{"cveId":3140,"releaseId":25,"cycle":26,"description":3141,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3142,"url":3143},"CVE-2026-31412","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks()\n\nThe `check_command_size_in_blocks()` function calculates the data size\nin bytes by left shifting `common->data_size_from_cmnd` by the block\nsize (`common->curlun->blkbits`). However, it does not validate whether\nthis shift operation will cause an integer overflow.\n\nInitially, the block size is set up in `fsg_lun_open()` , and the\n`com","2026-04-10T11:16:22.967+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31412",{"cveId":3140,"releaseId":17,"cycle":18,"description":3141,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3142,"url":3143},{"cveId":3140,"releaseId":31,"cycle":32,"description":3141,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3142,"url":3143},{"cveId":3147,"releaseId":25,"cycle":26,"description":3148,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3149,"url":3150},"CVE-2026-31411","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atm: fix crash due to unvalidated vcc pointer in sigd_send()\n\nReproducer available at [1].\n\nThe ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc\npointer from msg->vcc and uses it directly without any validation. This\npointer comes from userspace via sendmsg() and can be arbitrarily forged:\n\n    int fd = socket(AF_ATMSVC, SOCK_DGRAM, 0);\n    ioctl(fd, ATMSIGD_CTRL);  \u002F\u002F become ATM signaling daemon\n    struc","2026-04-08T14:16:27.977+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31411",{"cveId":3147,"releaseId":17,"cycle":18,"description":3148,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3149,"url":3150},{"cveId":3147,"releaseId":31,"cycle":32,"description":3148,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3149,"url":3150},{"cveId":3154,"releaseId":25,"cycle":26,"description":3155,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3156,"url":3157},"CVE-2026-31408","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold\n\nsco_recv_frame() reads conn->sk under sco_conn_lock() but immediately\nreleases the lock without holding a reference to the socket. A concurrent\nclose() can free the socket between the lock release and the subsequent\nsk->sk_state access, resulting in a use-after-free.\n\nOther functions in the same file (sco_sock_timeout(), sco_conn_del())\ncorrectly u","2026-04-06T08:16:38.757+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31408",{"cveId":3154,"releaseId":17,"cycle":18,"description":3155,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3156,"url":3157},{"cveId":3154,"releaseId":31,"cycle":32,"description":3155,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3156,"url":3157},{"cveId":3161,"releaseId":25,"cycle":26,"description":3162,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3163,"url":3164},"CVE-2026-31407","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: add missing netlink policy validations\n\nHyunwoo Kim reports out-of-bounds access in sctp and ctnetlink.\n\nThese attributes are used by the kernel without any validation.\nExtend the netlink policies accordingly.\n\nQuoting the reporter:\n  nlattr_to_sctp() assigns the user-supplied CTA_PROTOINFO_SCTP_STATE\n  value directly to ct->proto.sctp.state without checking that it is\n  within the valid range. [..]\n\n  and","2026-04-06T08:16:38.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31407",{"cveId":3161,"releaseId":17,"cycle":18,"description":3162,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3163,"url":3164},{"cveId":3161,"releaseId":31,"cycle":32,"description":3162,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3163,"url":3164},{"cveId":3168,"releaseId":25,"cycle":26,"description":3169,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3170,"url":3171},"CVE-2026-31405","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-net: fix OOB access in ULE extension header tables\n\nThe ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables\nin handle_one_ule_extension() are declared with 255 elements (valid\nindices 0-254), but the index htype is derived from network-controlled\ndata as (ule_sndu_type & 0x00FF), giving a range of 0-255. When\nhtype equals 255, an out-of-bounds read occurs on the function pointer\ntable, and the OOB val","2026-04-06T08:16:38.253+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31405",{"cveId":3168,"releaseId":17,"cycle":18,"description":3169,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3170,"url":3171},{"cveId":3168,"releaseId":31,"cycle":32,"description":3169,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3170,"url":3171},{"cveId":3175,"releaseId":25,"cycle":26,"description":3176,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3177,"url":3178},"CVE-2026-31403","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Hold net reference for the lifetime of \u002Fproc\u002Ffs\u002Fnfs\u002Fexports fd\n\nThe \u002Fproc\u002Ffs\u002Fnfs\u002Fexports proc entry is created at module init\nand persists for the module's lifetime. exports_proc_open()\ncaptures the caller's current network namespace and stores\nits svc_export_cache in seq->private, but takes no reference\non the namespace. If the namespace is subsequently torn down\n(e.g. container destruction after the opener does setns() ","2026-04-03T16:16:39.467+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31403",{"cveId":3175,"releaseId":17,"cycle":18,"description":3176,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3177,"url":3178},{"cveId":3175,"releaseId":31,"cycle":32,"description":3176,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3177,"url":3178},{"cveId":3182,"releaseId":25,"cycle":26,"description":3183,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3184,"url":3185},"CVE-2026-31402","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix heap overflow in NFSv4.0 LOCK replay cache\n\nThe NFSv4.0 replay cache uses a fixed 112-byte inline buffer\n(rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operation responses.\nThis size was calculated based on OPEN responses and does not account\nfor LOCK denied responses, which include the conflicting lock owner as\na variable-length field up to 1024 bytes (NFS4_OPAQUE_LIMIT).\n\nWhen a LOCK operation is denied due to a con","2026-04-03T16:16:39.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31402",{"cveId":3182,"releaseId":17,"cycle":18,"description":3183,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3184,"url":3185},{"cveId":3182,"releaseId":31,"cycle":32,"description":3183,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":3184,"url":3185},{"cveId":3189,"releaseId":25,"cycle":26,"description":3190,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3191,"url":3192},"CVE-2026-31400","In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: fix cache_request leak in cache_release\n\nWhen a reader's file descriptor is closed while in the middle of reading\na cache_request (rp->offset != 0), cache_release() decrements the\nrequest's readers count but never checks whether it should free the\nrequest.\n\nIn cache_read(), when readers drops to 0 and CACHE_PENDING is clear, the\ncache_request is removed from the queue and freed along with its buffer\nand cache_head refer","2026-04-03T16:16:38.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31400",{"cveId":3189,"releaseId":17,"cycle":18,"description":3190,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3191,"url":3192},{"cveId":3189,"releaseId":31,"cycle":32,"description":3190,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3191,"url":3192},{"cveId":3196,"releaseId":31,"cycle":32,"description":3197,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3198,"url":3199},"CVE-2026-31399","In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm\u002Fbus: Fix potential use after free in asynchronous initialization\n\nDingisoul with KASAN reports a use after free if device_add() fails in\nnd_async_device_register().\n\nCommit b6eae0f61db2 (\"libnvdimm: Hold reference on parent while\nscheduling async init\") correctly added a reference on the parent device\nto be held until asynchronous initialization was complete.  However, if\ndevice_add() results in an allocation failure the","2026-04-03T16:16:38.41+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31399",{"cveId":3196,"releaseId":25,"cycle":26,"description":3197,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3198,"url":3199},{"cveId":3196,"releaseId":17,"cycle":18,"description":3197,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3198,"url":3199},{"cveId":3203,"releaseId":25,"cycle":26,"description":3204,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3205,"url":3206},"CVE-2026-31396","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix use-after-free access to PTP clock\n\nPTP clock is registered on every opening of the interface and destroyed on\nevery closing.  However it may be accessed via get_ts_info ethtool call\nwhich is possible while the interface is just present in the kernel.\n\nBUG: KASAN: use-after-free in ptp_clock_index+0x47\u002F0x50 drivers\u002Fptp\u002Fptp_clock.c:426\nRead of size 4 at addr ffff8880194345cc by task syz.0.6\u002F948\n\nCPU: 1 PID: 948 Co","2026-04-03T16:16:37.887+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31396",{"cveId":3203,"releaseId":17,"cycle":18,"description":3204,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3205,"url":3206},{"cveId":3209,"releaseId":25,"cycle":26,"description":3210,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":3211,"url":3212},"CVE-2026-31393","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access\n\nl2cap_information_rsp() checks that cmd_len covers the fixed\nl2cap_info_rsp header (type + result, 4 bytes) but then reads\nrsp->data without verifying that the payload is present:\n\n - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads\n   4 bytes past the header (needs cmd_len >= 8).\n\n - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past th","2026-04-03T16:16:37.42+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31393",{"cveId":3209,"releaseId":17,"cycle":18,"description":3210,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":3211,"url":3212},{"cveId":3209,"releaseId":31,"cycle":32,"description":3210,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":3211,"url":3212},{"cveId":3216,"releaseId":25,"cycle":26,"description":3217,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":3218,"url":3219},"CVE-2026-31392","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix krb5 mount with username option\n\nCustomer reported that some of their krb5 mounts were failing against\na single server as the client was trying to mount the shares with\nwrong credentials.  It turned out the client was reusing SMB session\nfrom first mount to try mounting the other shares, even though a\ndifferent username= option had been specified to the other mounts.\n\nBy using username mount option along with s","2026-04-03T16:16:37.3+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31392",{"cveId":3216,"releaseId":17,"cycle":18,"description":3217,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":3218,"url":3219},{"cveId":3216,"releaseId":31,"cycle":32,"description":3217,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":3218,"url":3219},{"cveId":3223,"releaseId":25,"cycle":26,"description":3224,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3225,"url":3226},"CVE-2026-23474","In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: Avoid boot crash in RedBoot partition table parser\n\nGiven CONFIG_FORTIFY_SOURCE=y and a recent compiler,\ncommit 439a1bcac648 (\"fortify: Use __builtin_dynamic_object_size() when\navailable\") produces the warning below and an oops.\n\n    Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000\n    ------------[ cut here ]------------\n    WARNING: lib\u002Fstring_helpers.c:1035 at 0xc029e04c, CPU#0: swapper\u002F0\u002F1\n   ","2026-04-03T16:16:35.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23474",{"cveId":3223,"releaseId":17,"cycle":18,"description":3224,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3225,"url":3226},{"cveId":3223,"releaseId":31,"cycle":32,"description":3224,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3225,"url":3226},{"cveId":3230,"releaseId":25,"cycle":26,"description":3231,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3232,"url":3233},"CVE-2026-23472","In the Linux kernel, the following vulnerability has been resolved:\n\nserial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN\n\nuart_write_room() and uart_write() behave inconsistently when\nxmit_buf is NULL (which happens for PORT_UNKNOWN ports that were\nnever properly initialized):\n\n- uart_write_room() returns kfifo_avail() which can be > 0\n- uart_write() checks xmit_buf and returns 0 if NULL\n\nThis inconsistency causes an infinite loop in drivers that rely on\ntty_write_room() to determine","2026-04-03T16:16:34.977+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23472",{"cveId":3230,"releaseId":17,"cycle":18,"description":3231,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3232,"url":3233},{"cveId":3230,"releaseId":31,"cycle":32,"description":3231,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3232,"url":3233},{"cveId":3237,"releaseId":25,"cycle":26,"description":3238,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3239,"url":3240},"CVE-2026-23468","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: Limit BO list entry count to prevent resource exhaustion\n\nUserspace can pass an arbitrary number of BO list entries via the\nbo_number field. Although the previous multiplication overflow check\nprevents out-of-bounds allocation, a large number of entries could still\ncause excessive memory allocation (up to potentially gigabytes) and\nunnecessarily long list processing times.\n\nIntroduce a hard limit of 128k entries per","2026-04-03T16:16:34.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23468",{"cveId":3237,"releaseId":17,"cycle":18,"description":3238,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3239,"url":3240},{"cveId":3237,"releaseId":31,"cycle":32,"description":3238,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3239,"url":3240},{"cveId":3244,"releaseId":25,"cycle":26,"description":3245,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3246,"url":3247},"CVE-2026-23463","In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: fsl: qbman: fix race condition in qman_destroy_fq\n\nWhen QMAN_FQ_FLAG_DYNAMIC_FQID is set, there's a race condition between\nfq_table[fq->idx] state and freeing\u002Fallocating from the pool and\nWARN_ON(fq_table[fq->idx]) in qman_create_fq() gets triggered.\n\nIndeed, we can have:\n         Thread A                             Thread B\n    qman_destroy_fq()                    qman_create_fq()\n      qman_release_fqid()\n        qman_s","2026-04-03T16:16:33.52+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23463",{"cveId":3244,"releaseId":17,"cycle":18,"description":3245,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3246,"url":3247},{"cveId":3244,"releaseId":31,"cycle":32,"description":3245,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3246,"url":3247},{"cveId":3251,"releaseId":25,"cycle":26,"description":3252,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3253,"url":3254},"CVE-2026-23462","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HIDP: Fix possible UAF\n\nThis fixes the following trace caused by not dropping l2cap_conn\nreference when user->remove callback is called:\n\n[   97.809249] l2cap_conn_free: freeing conn ffff88810a171c00\n[   97.809907] CPU: 1 UID: 0 PID: 1419 Comm: repro_standalon Not tainted 7.0.0-rc1-dirty #14 PREEMPT(lazy)\n[   97.809935] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04\u002F01\u002F2014\n[   ","2026-04-03T16:16:33.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23462",{"cveId":3251,"releaseId":17,"cycle":18,"description":3252,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3253,"url":3254},{"cveId":3251,"releaseId":31,"cycle":32,"description":3252,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3253,"url":3254},{"cveId":3258,"releaseId":25,"cycle":26,"description":3259,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3260,"url":3261},"CVE-2026-23460","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Frose: fix NULL pointer dereference in rose_transmit_link on reconnect\n\nsyzkaller reported a bug [1], and the reproducer is available at [2].\n\nROSE sockets use four sk->sk_state values: TCP_CLOSE, TCP_LISTEN,\nTCP_SYN_SENT, and TCP_ESTABLISHED. rose_connect() already rejects\ncalls for TCP_ESTABLISHED (-EISCONN) and TCP_CLOSE with SS_CONNECTING\n(-ECONNREFUSED), but lacks a check for TCP_SYN_SENT.\n\nWhen rose_connect() is called","2026-04-03T16:16:32.963+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23460",{"cveId":3258,"releaseId":17,"cycle":18,"description":3259,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3260,"url":3261},{"cveId":3258,"releaseId":31,"cycle":32,"description":3259,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3260,"url":3261},{"cveId":3265,"releaseId":25,"cycle":26,"description":3266,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3267,"url":3268},"CVE-2026-23458","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()\n\nctnetlink_dump_exp_ct() stores a conntrack pointer in cb->data for the\nnetlink dump callback ctnetlink_exp_ct_dump_table(), but drops the\nconntrack reference immediately after netlink_dump_start().  When the\ndump spans multiple rounds, the second recvmsg() triggers the dump\ncallback which dereferences the now-freed conntrack via nfct_help(ct),\nleading to a use","2026-04-03T16:16:32.647+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23458",{"cveId":3265,"releaseId":17,"cycle":18,"description":3266,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3267,"url":3268},{"cveId":3265,"releaseId":31,"cycle":32,"description":3266,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3267,"url":3268},{"cveId":3272,"releaseId":25,"cycle":26,"description":3273,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":3274,"url":3275},"CVE-2026-23457","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()\n\nsip_help_tcp() parses the SIP Content-Length header with\nsimple_strtoul(), which returns unsigned long, but stores the result in\nunsigned int clen.  On 64-bit systems, values exceeding UINT_MAX are\nsilently truncated before computing the SIP message boundary.\n\nFor example, Content-Length 4294967328 (2^32 + 32) is truncated to 32,\ncausing the parse","2026-04-03T16:16:32.473+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23457",{"cveId":3272,"releaseId":17,"cycle":18,"description":3273,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":3274,"url":3275},{"cveId":3272,"releaseId":31,"cycle":32,"description":3273,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":3274,"url":3275},{"cveId":3279,"releaseId":25,"cycle":26,"description":3280,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":3281,"url":3282},"CVE-2026-23456","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case\n\nIn decode_int(), the CONS case calls get_bits(bs, 2) to read a length\nvalue, then calls get_uint(bs, len) without checking that len bytes\nremain in the buffer. The existing boundary check only validates the\n2 bits for get_bits(), not the subsequent 1-4 bytes that get_uint()\nreads. This allows a malformed H.323\u002FRAS packet to cause a 1-4 byte\nslab-out-of-bounds","2026-04-03T16:16:32.3+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23456",{"cveId":3279,"releaseId":17,"cycle":18,"description":3280,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":3281,"url":3282},{"cveId":3279,"releaseId":31,"cycle":32,"description":3280,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":3281,"url":3282},{"cveId":3286,"releaseId":25,"cycle":26,"description":3287,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3288,"url":3289},"CVE-2026-23455","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_h323: check for zero length in DecodeQ931()\n\nIn DecodeQ931(), the UserUserIE code path reads a 16-bit length from\nthe packet, then decrements it by 1 to skip the protocol discriminator\nbyte before passing it to DecodeH323_UserInformation(). If the encoded\nlength is 0, the decrement wraps to -1, which is then passed as a\nlarge value to the decoder, leading to an out-of-bounds read.\n\nAdd a check to ensure ","2026-04-03T16:16:32.123+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23455",{"cveId":3286,"releaseId":17,"cycle":18,"description":3287,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3288,"url":3289},{"cveId":3286,"releaseId":31,"cycle":32,"description":3287,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3288,"url":3289},{"cveId":3293,"releaseId":25,"cycle":26,"description":3294,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3295,"url":3296},"CVE-2026-23452","In the Linux kernel, the following vulnerability has been resolved:\n\nPM: runtime: Fix a race condition related to device removal\n\nThe following code in pm_runtime_work() may dereference the dev->parent\npointer after the parent device has been freed:\n\n\t\u002F* Maybe the parent is now able to suspend. *\u002F\n\tif (parent && !parent->power.ignore_children) {\n\t\tspin_unlock(&dev->power.lock);\n\n\t\tspin_lock(&parent->power.lock);\n\t\trpm_idle(parent, RPM_ASYNC);\n\t\tspin_unlock(&parent->power.lock);\n\n\t\tspin_lock(&dev","2026-04-03T16:16:31.617+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23452",{"cveId":3293,"releaseId":17,"cycle":18,"description":3294,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3295,"url":3296},{"cveId":3293,"releaseId":31,"cycle":32,"description":3294,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":3295,"url":3296},{"cveId":3300,"releaseId":17,"cycle":18,"description":3301,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3302,"url":3303},"CVE-2026-23449","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: teql: Fix double-free in teql_master_xmit\n\nWhenever a TEQL devices has a lockless Qdisc as root, qdisc_reset should\nbe called using the seq_lock to avoid racing with the datapath. Failure\nto do so may cause crashes like the following:\n\n[  238.028993][  T318] BUG: KASAN: double-free in skb_release_data (net\u002Fcore\u002Fskbuff.c:1139)\n[  238.029328][  T318] Free of addr ffff88810c67ec00 by task poc_teql_uaf_ke\u002F318\n[  238.0297","2026-04-03T16:16:31.037+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23449",{"cveId":3305,"releaseId":25,"cycle":26,"description":3306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3307,"url":3308},"CVE-2026-23448","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check\n\ncdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE\nentries fit within the skb. The first check correctly accounts for\nndpoffset:\n\n  if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in->len)\n\nbut the second check omits it:\n\n  if ((sizeof(struct usb_cdc_ncm_ndp16) +\n       ret * (sizeof(struct usb_cdc_ncm_dpe16))) > skb_in->len)\n\nThis validat","2026-04-03T16:16:30.863+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23448",{"cveId":3305,"releaseId":17,"cycle":18,"description":3306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3307,"url":3308},{"cveId":3305,"releaseId":31,"cycle":32,"description":3306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3307,"url":3308},{"cveId":3312,"releaseId":25,"cycle":26,"description":3313,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3314,"url":3315},"CVE-2026-23447","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check\n\nThe same bounds-check bug fixed for NDP16 in the previous patch also\nexists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated\nagainst the total skb length without accounting for ndpoffset, allowing\nout-of-bounds reads when the NDP32 is placed near the end of the NTB.\n\nAdd ndpoffset to the nframes bounds check and use struct_size_t() to\nexpress the NDP-p","2026-04-03T16:16:30.663+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23447",{"cveId":3312,"releaseId":17,"cycle":18,"description":3313,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3314,"url":3315},{"cveId":3318,"releaseId":25,"cycle":26,"description":3319,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3320,"url":3321},"CVE-2026-23444","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure\n\nieee80211_tx_prepare_skb() has three error paths, but only two of them\nfree the skb. The first error path (ieee80211_tx_prepare() returning\nTX_DROP) does not free it, while invoke_tx_handlers() failure and the\nfragmentation check both do.\n\nAdd kfree_skb() to the first error path so all three are consistent,\nand remove the now-redundant frees in callers (ath9","2026-04-03T16:16:28.81+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23444",{"cveId":3318,"releaseId":17,"cycle":18,"description":3319,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3320,"url":3321},{"cveId":3318,"releaseId":31,"cycle":32,"description":3319,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3320,"url":3321},{"cveId":3325,"releaseId":25,"cycle":26,"description":3326,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3327,"url":3328},"CVE-2026-23442","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: add NULL checks for idev in SRv6 paths\n\n__in6_dev_get() can return NULL when the device has no IPv6 configuration\n(e.g. MTU \u003C IPV6_MIN_MTU or after NETDEV_UNREGISTER).\n\nAdd NULL checks for idev returned by __in6_dev_get() in both\nseg6_hmac_validate_skb() and ipv6_srh_rcv() to prevent potential NULL\npointer dereferences.","2026-04-03T16:16:28.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23442",{"cveId":3325,"releaseId":17,"cycle":18,"description":3326,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3327,"url":3328},{"cveId":3331,"releaseId":31,"cycle":32,"description":3332,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3333,"url":3334},"CVE-2026-23439","In the Linux kernel, the following vulnerability has been resolved:\n\nudp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n\n\nWhen CONFIG_IPV6 is disabled, the udp_sock_create6() function returns 0\n(success) without actually creating a socket. Callers such as\nfou_create() then proceed to dereference the uninitialized socket\npointer, resulting in a NULL pointer dereference.\n\nThe captured NULL deref crash:\n  BUG: kernel NULL pointer dereference, address: 0000000000000018\n  RIP: 00","2026-04-03T16:16:25.737+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23439",{"cveId":3331,"releaseId":17,"cycle":18,"description":3332,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3333,"url":3334},{"cveId":3331,"releaseId":25,"cycle":26,"description":3332,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3333,"url":3334},{"cveId":3338,"releaseId":17,"cycle":18,"description":3339,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3340,"url":3341},"CVE-2026-23420","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wlcore: Fix a locking bug\n\nMake sure that wl->mutex is locked before it is unlocked. This has been\ndetected by the Clang thread-safety analyzer.","2026-04-03T14:16:28.027+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23420",{"cveId":3343,"releaseId":31,"cycle":32,"description":3344,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3345,"url":3346},"CVE-2026-23398","In the Linux kernel, the following vulnerability has been resolved:\n\nicmp: fix NULL pointer dereference in icmp_tag_validation()\n\nicmp_tag_validation() unconditionally dereferences the result of\nrcu_dereference(inet_protos[proto]) without checking for NULL.\nThe inet_protos[] array is sparse -- only about 15 of 256 protocol\nnumbers have registered handlers. When ip_no_pmtu_disc is set to 3\n(hardened PMTU mode) and the kernel receives an ICMP Fragmentation\nNeeded error with a quoted inner IP heade","2026-03-26T11:16:19.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23398",{"cveId":3343,"releaseId":17,"cycle":18,"description":3344,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3345,"url":3346},{"cveId":3343,"releaseId":25,"cycle":26,"description":3344,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3345,"url":3346},{"cveId":3350,"releaseId":31,"cycle":32,"description":3351,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3352,"url":3353},"CVE-2026-23397","In the Linux kernel, the following vulnerability has been resolved:\n\nnfnetlink_osf: validate individual option lengths in fingerprints\n\nnfnl_osf_add_callback() validates opt_num bounds and string\nNUL-termination but does not check individual option length fields.\nA zero-length option causes nf_osf_match_one() to enter the option\nmatching loop even when foptsize sums to zero, which matches packets\nwith no TCP options where ctx->optp is NULL:\n\n Oops: general protection fault\n KASAN: null-ptr-deref","2026-03-26T11:16:19.72+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23397",{"cveId":3350,"releaseId":17,"cycle":18,"description":3351,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3352,"url":3353},{"cveId":3350,"releaseId":25,"cycle":26,"description":3351,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3352,"url":3353},{"cveId":3357,"releaseId":17,"cycle":18,"description":3358,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3359,"url":3360},"CVE-2026-23392","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: release flowtable after rcu grace period on error\n\nCall synchronize_rcu() after unregistering the hooks from error path,\nsince a hook that already refers to this flowtable can be already\nregistered, exposing this flowtable to packet path and nfnetlink_hook\ncontrol plane.\n\nThis error path is rare, it should only happen by reaching the maximum\nnumber hooks or by failing to set up to hardware offload, just ca","2026-03-25T11:16:39.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23392",{"cveId":3362,"releaseId":31,"cycle":32,"description":3363,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3364,"url":3365},"CVE-2026-23391","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_CT: drop pending enqueued packets on template removal\n\nTemplates refer to objects that can go away while packets are sitting in\nnfqueue refer to:\n\n- helper, this can be an issue on module removal.\n- timeout policy, nfnetlink_cttimeout might remove it.\n\nThe use of templates with zone and event cache filter are safe, since\nthis just copies values.\n\nFlush these enqueued packets in case the template rule gets removed.","2026-03-25T11:16:39.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23391",{"cveId":3362,"releaseId":17,"cycle":18,"description":3363,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3364,"url":3365},{"cveId":3362,"releaseId":25,"cycle":26,"description":3363,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3364,"url":3365},{"cveId":3369,"releaseId":17,"cycle":18,"description":3370,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3371,"url":3372},"CVE-2026-23389","In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix memory leak in ice_set_ringparam()\n\nIn ice_set_ringparam, tx_rings and xdp_rings are allocated before\nrx_rings. If the allocation of rx_rings fails, the code jumps to\nthe done label leaking both tx_rings and xdp_rings. Furthermore, if\nthe setup of an individual Rx ring fails during the loop, the code jumps\nto the free_tx label which releases tx_rings but leaks xdp_rings.\n\nFix this by introducing a free_xdp label and up","2026-03-25T11:16:39.44+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23389",{"cveId":3374,"releaseId":17,"cycle":18,"description":3375,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3376,"url":3377},"CVE-2026-23381","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: fix nd_tbl NULL dereference when IPv6 is disabled\n\nWhen booting with the 'ipv6.disable=1' parameter, the nd_tbl is never\ninitialized because inet6_init() exits before ndisc_init() is called\nwhich initializes it. Then, if neigh_suppress is enabled and an ICMPv6\nNeighbor Discovery packet reaches the bridge, br_do_suppress_nd() will\ndereference ipv6_stub->nd_tbl which is NULL, passing it to\nneigh_lookup(). This causes","2026-03-25T11:16:38.16+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23381",{"cveId":3379,"releaseId":17,"cycle":18,"description":3380,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3381,"url":3382},"CVE-2026-23378","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: act_ife: Fix metalist update behavior\n\nWhenever an ife action replace changes the metalist, instead of\nreplacing the old data on the metalist, the current ife code is appending\nthe new metadata. Aside from being innapropriate behavior, this may lead\nto an unbounded addition of metadata to the metalist which might cause an\nout of bounds error when running the encode op:\n\n[  138.423369][    C1] ========================","2026-03-25T11:16:37.643+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23378",{"cveId":3384,"releaseId":17,"cycle":18,"description":3385,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3386,"url":3387},"CVE-2026-23371","In the Linux kernel, the following vulnerability has been resolved:\n\nsched\u002Fdeadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting\n\nRunning stress-ng --schedpolicy 0 on an RT kernel on a big machine\nmight lead to the following WARNINGs (edited).\n\n sched: DL de-boosted task PID 22725: REPLENISH flag missing\n\n WARNING: CPU: 93 PID: 0 at kernel\u002Fsched\u002Fdeadline.c:239 dequeue_task_dl+0x15c\u002F0x1f8\n ... (running_bw underflow)\n Call trace:\n  dequeue_task_dl+0x15c\u002F0x1f8 (P)\n  dequeue_task+0x80\u002F0x168\n","2026-03-25T11:16:36.637+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23371",{"cveId":3389,"releaseId":17,"cycle":18,"description":3390,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3391,"url":3392},"CVE-2026-23368","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: register phy led_triggers during probe to avoid AB-BA deadlock\n\nThere is an AB-BA deadlock when both LEDS_TRIGGER_NETDEV and\nLED_TRIGGER_PHY are enabled:\n\n[ 1362.049207] [\u003C8054e4b8>] led_trigger_register+0x5c\u002F0x1fc             \u003C-- Trying to get lock \"triggers_list_lock\" via down_write(&triggers_list_lock);\n[ 1362.054536] [\u003C80662830>] phy_led_triggers_register+0xd0\u002F0x234\n[ 1362.060329] [\u003C8065e200>] phy_attach_direct+0x","2026-03-25T11:16:36.167+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23368",{"cveId":3394,"releaseId":31,"cycle":32,"description":3395,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3396,"url":3397},"CVE-2026-23365","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: kalmia: validate USB endpoints\n\nThe kalmia driver should validate that the device it is probing has the\nproper number and types of USB endpoints it is expecting before it binds\nto it.  If a malicious device were to not have the same urbs the driver\nwill crash later on when it blindly accesses these endpoints.","2026-03-25T11:16:35.71+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23365",{"cveId":3394,"releaseId":17,"cycle":18,"description":3395,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3396,"url":3397},{"cveId":3394,"releaseId":25,"cycle":26,"description":3395,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3396,"url":3397},{"cveId":3401,"releaseId":17,"cycle":18,"description":3402,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3403,"url":3404},"CVE-2026-23340","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs\n\nWhen shrinking the number of real tx queues,\nnetif_set_real_num_tx_queues() calls qdisc_reset_all_tx_gt() to flush\nqdiscs for queues which will no longer be used.\n\nqdisc_reset_all_tx_gt() currently serializes qdisc_reset() with\nqdisc_lock(). However, for lockless qdiscs, the dequeue path is\nserialized by qdisc_run_begin\u002Fend() using qdisc->seqlock ins","2026-03-25T11:16:31.837+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23340",{"cveId":3406,"releaseId":25,"cycle":26,"description":3407,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3408,"url":3409},"CVE-2026-23312","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: kaweth: validate USB endpoints\n\nThe kaweth driver should validate that the device it is probing has the\nproper number and types of USB endpoints it is expecting before it binds\nto it.  If a malicious device were to not have the same urbs the driver\nwill crash later on when it blindly accesses these endpoints.","2026-03-25T11:16:27.463+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23312",{"cveId":3406,"releaseId":17,"cycle":18,"description":3407,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3408,"url":3409},{"cveId":3406,"releaseId":31,"cycle":32,"description":3407,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3408,"url":3409},{"cveId":3413,"releaseId":25,"cycle":26,"description":3414,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3415,"url":3416},"CVE-2026-23307","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message\n\nWhen looking at the data in a USB urb, the actual_length is the size of\nthe buffer passed to the driver, not the transfer_buffer_length which is\nset by the driver as the max size of the buffer.\n\nWhen parsing the messages in ems_usb_read_bulk_callback() properly check\nthe size both at the beginning of parsing the message to make sure it is\nbig enou","2026-03-25T11:16:26.657+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23307",{"cveId":3413,"releaseId":17,"cycle":18,"description":3414,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3415,"url":3416},{"cveId":3413,"releaseId":31,"cycle":32,"description":3414,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3415,"url":3416},{"cveId":3420,"releaseId":25,"cycle":26,"description":3421,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3422,"url":3423},"CVE-2026-23304","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()\n\nl3mdev_master_dev_rcu() can return NULL when the slave device is being\nun-slaved from a VRF. All other callers deal with this, but we lost\nthe fallback to loopback in ip6_rt_pcpu_alloc() -> ip6_rt_get_dev_rcu()\nwith commit 4832c30d5458 (\"net: ipv6: put host and anycast routes on\ndevice with address\").\n\n  KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f]\n","2026-03-25T11:16:26.18+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23304",{"cveId":3420,"releaseId":17,"cycle":18,"description":3421,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3422,"url":3423},{"cveId":3426,"releaseId":25,"cycle":26,"description":3427,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3428,"url":3429},"CVE-2026-23303","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Don't log plaintext credentials in cifs_set_cifscreds\n\nWhen debug logging is enabled, cifs_set_cifscreds() logs the key\npayload and exposes the plaintext username and password. Remove the\ndebug log to avoid exposing credentials.","2026-03-25T11:16:26.06+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23303",{"cveId":3426,"releaseId":17,"cycle":18,"description":3427,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3428,"url":3429},{"cveId":3426,"releaseId":31,"cycle":32,"description":3427,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3428,"url":3429},{"cveId":3433,"releaseId":17,"cycle":18,"description":3434,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3435,"url":3436},"CVE-2026-23298","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: ucan: Fix infinite loop from zero-length messages\n\nIf a broken ucan device gets a message with the message length field set\nto 0, then the driver will loop for forever in\nucan_read_bulk_callback(), hanging the system.  If the length is 0, just\nskip the message and go on to the next one.\n\nThis has been fixed in the kvaser_usb driver in the past in commit\n0c73772cd2b8 (\"can: kvaser_usb: leaf: Fix potential infinite loop in\nc","2026-03-25T11:16:25.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23298",{"cveId":3438,"releaseId":25,"cycle":26,"description":3439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3440,"url":3441},"CVE-2026-23293","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled\n\nWhen booting with the 'ipv6.disable=1' parameter, the nd_tbl is never\ninitialized because inet6_init() exits before ndisc_init() is called\nwhich initializes it. If an IPv6 packet is injected into the interface,\nroute_shortcircuit() is called and a NULL pointer dereference happens on\nneigh_lookup().\n\n BUG: kernel NULL pointer dereference, address: 0000000000000380\n O","2026-03-25T11:16:24.52+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23293",{"cveId":3438,"releaseId":17,"cycle":18,"description":3439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3440,"url":3441},{"cveId":3438,"releaseId":31,"cycle":32,"description":3439,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3440,"url":3441},{"cveId":3445,"releaseId":31,"cycle":32,"description":3446,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3447,"url":3448},"CVE-2026-23292","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Fix recursive locking in __configfs_open_file()\n\nIn flush_write_buffer, &p->frag_sem is acquired and then the loaded store\nfunction is called, which, here, is target_core_item_dbroot_store().  This\nfunction called filp_open(), following which these functions were called\n(in reverse order), according to the call trace:\n\n  down_read\n  __configfs_open_file\n  do_dentry_open\n  vfs_open\n  do_open\n  path_openat\n  do_filp","2026-03-25T11:16:24.357+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23292",{"cveId":3445,"releaseId":25,"cycle":26,"description":3446,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3447,"url":3448},{"cveId":3445,"releaseId":17,"cycle":18,"description":3446,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3447,"url":3448},{"cveId":3452,"releaseId":25,"cycle":26,"description":3453,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3454,"url":3455},"CVE-2026-23291","In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: properly drop the usb interface reference on disconnect\n\nWhen the device is disconnected from the driver, there is a \"dangling\"\nreference count on the usb interface that was grabbed in the probe\ncallback.  Fix this up by properly dropping the reference after we are\ndone with it.","2026-03-25T11:16:24.197+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23291",{"cveId":3452,"releaseId":17,"cycle":18,"description":3453,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3454,"url":3455},{"cveId":3452,"releaseId":31,"cycle":32,"description":3453,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3454,"url":3455},{"cveId":3459,"releaseId":25,"cycle":26,"description":3460,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3461,"url":3462},"CVE-2026-23290","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: pegasus: validate USB endpoints\n\nThe pegasus driver should validate that the device it is probing has the\nproper number and types of USB endpoints it is expecting before it binds\nto it.  If a malicious device were to not have the same urbs the driver\nwill crash later on when it blindly accesses these endpoints.","2026-03-25T11:16:24.043+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23290",{"cveId":3459,"releaseId":17,"cycle":18,"description":3460,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3461,"url":3462},{"cveId":3459,"releaseId":31,"cycle":32,"description":3460,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3461,"url":3462},{"cveId":3466,"releaseId":25,"cycle":26,"description":3467,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3468,"url":3469},"CVE-2026-23289","In the Linux kernel, the following vulnerability has been resolved:\n\nIB\u002Fmthca: Add missed mthca_unmap_user_db() for mthca_create_srq()\n\nFix a user triggerable leak on the system call failure path.","2026-03-25T11:16:23.887+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23289",{"cveId":3466,"releaseId":17,"cycle":18,"description":3467,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3468,"url":3469},{"cveId":3466,"releaseId":31,"cycle":32,"description":3467,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3468,"url":3469},{"cveId":3473,"releaseId":25,"cycle":26,"description":3474,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3475,"url":3476},"CVE-2026-23286","In the Linux kernel, the following vulnerability has been resolved:\n\natm: lec: fix null-ptr-deref in lec_arp_clear_vccs\n\nsyzkaller reported a null-ptr-deref in lec_arp_clear_vccs().\nThis issue can be easily reproduced using the syzkaller reproducer.\n\nIn the ATM LANE (LAN Emulation) module, the same atm_vcc can be shared by\nmultiple lec_arp_table entries (e.g., via entry->vcc or entry->recv_vcc).\nWhen the underlying VCC is closed, lec_vcc_close() iterates over all\nARP entries and calls lec_arp_cl","2026-03-25T11:16:23.393+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23286",{"cveId":3473,"releaseId":17,"cycle":18,"description":3474,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3475,"url":3476},{"cveId":3473,"releaseId":31,"cycle":32,"description":3474,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3475,"url":3476},{"cveId":3480,"releaseId":25,"cycle":26,"description":3481,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3482,"url":3483},"CVE-2026-23281","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas: fix use-after-free in lbs_free_adapter()\n\nThe lbs_free_adapter() function uses timer_delete() (non-synchronous)\nfor both command_timer and tx_lockup_timer before the structure is\nfreed. This is incorrect because timer_delete() does not wait for\nany running timer callback to complete.\n\nIf a timer callback is executing when lbs_free_adapter() is called,\nthe callback will access freed memory since lbs_cfg_free() fr","2026-03-25T11:16:22.657+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23281",{"cveId":3480,"releaseId":17,"cycle":18,"description":3481,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3482,"url":3483},{"cveId":3480,"releaseId":31,"cycle":32,"description":3481,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3482,"url":3483},{"cveId":3487,"releaseId":25,"cycle":26,"description":3488,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3489,"url":3490},"CVE-2026-23279","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame()\n\nIn mesh_rx_csa_frame(), elems->mesh_chansw_params_ie is dereferenced\nat lines 1638 and 1642 without a prior NULL check:\n\n    ifmsh->chsw_ttl = elems->mesh_chansw_params_ie->mesh_ttl;\n    ...\n    pre_value = le16_to_cpu(elems->mesh_chansw_params_ie->mesh_pre_value);\n\nThe mesh_matches_local() check above only validates the Mesh ID,\nMesh Configuration, and Suppor","2026-03-25T11:16:22.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23279",{"cveId":3487,"releaseId":17,"cycle":18,"description":3488,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3489,"url":3490},{"cveId":3487,"releaseId":31,"cycle":32,"description":3488,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3489,"url":3490},{"cveId":3494,"releaseId":17,"cycle":18,"description":3495,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3496,"url":3497},"CVE-2026-23278","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: always walk all pending catchall elements\n\nDuring transaction processing we might have more than one catchall element:\n1 live catchall element and 1 pending element that is coming as part of the\nnew batch.\n\nIf the map holding the catchall elements is also going away, its\nrequired to toggle all catchall elements and not just the first viable\ncandidate.\n\nOtherwise, we get:\n WARNING: .\u002Finclude\u002Fnet\u002Fnetfilter\u002Fn","2026-03-20T09:16:13.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23278",{"cveId":3499,"releaseId":25,"cycle":26,"description":3500,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3501,"url":3502},"CVE-2026-23277","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit\n\nteql_master_xmit() calls netdev_start_xmit(skb, slave) to transmit\nthrough slave devices, but does not update skb->dev to the slave device\nbeforehand.\n\nWhen a gretap tunnel is a TEQL slave, the transmit path reaches\niptunnel_xmit() which saves dev = skb->dev (still pointing to teql0\nmaster) and later calls iptunnel_xmit_stats(dev, pkt_len). This\n","2026-03-20T09:16:13.533+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23277",{"cveId":3499,"releaseId":17,"cycle":18,"description":3500,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3501,"url":3502},{"cveId":3499,"releaseId":31,"cycle":32,"description":3500,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3501,"url":3502},{"cveId":3506,"releaseId":25,"cycle":26,"description":3507,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3508,"url":3509},"CVE-2026-23276","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add xmit recursion limit to tunnel xmit functions\n\nTunnel xmit functions (iptunnel_xmit, ip6tunnel_xmit) lack their own\nrecursion limit. When a bond device in broadcast mode has GRE tap\ninterfaces as slaves, and those GRE tunnels route back through the\nbond, multicast\u002Fbroadcast traffic triggers infinite recursion between\nbond_xmit_broadcast() and ip_tunnel_xmit()\u002Fip6_tnl_xmit(), causing\nkernel stack overflow.\n\nThe existing","2026-03-20T09:16:13.37+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23276",{"cveId":3506,"releaseId":17,"cycle":18,"description":3507,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3508,"url":3509},{"cveId":3506,"releaseId":31,"cycle":32,"description":3507,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3508,"url":3509},{"cveId":3513,"releaseId":31,"cycle":32,"description":3514,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3515,"url":3516},"CVE-2026-23272","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: unconditionally bump set->nelems before insertion\n\nIn case that the set is full, a new element gets published then removed\nwithout waiting for the RCU grace period, while RCU reader can be\nwalking over it already.\n\nTo address this issue, add the element transaction even if set is full,\nbut toggle the set_full flag to report -ENFILE so the abort path safely\nunwinds the set to its previous state.\n\nAs for ele","2026-03-20T09:16:12.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23272",{"cveId":3513,"releaseId":25,"cycle":26,"description":3514,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3515,"url":3516},{"cveId":3513,"releaseId":17,"cycle":18,"description":3514,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3515,"url":3516},{"cveId":3520,"releaseId":25,"cycle":26,"description":3521,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3522,"url":3523},"CVE-2026-23271","In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix __perf_event_overflow() vs perf_remove_from_context() race\n\nMake sure that __perf_event_overflow() runs with IRQs disabled for all\npossible callchains. Specifically the software events can end up running\nit with only preemption disabled.\n\nThis opens up a race vs perf_event_exit_event() and friends that will go\nand free various things the overflow path expects to be present, like\nthe BPF program.","2026-03-20T09:16:11.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23271",{"cveId":3520,"releaseId":17,"cycle":18,"description":3521,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3522,"url":3523},{"cveId":3520,"releaseId":31,"cycle":32,"description":3521,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3522,"url":3523},{"cveId":3527,"releaseId":25,"cycle":26,"description":3528,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3529,"url":3530},"CVE-2026-23269","In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: validate DFA start states are in bounds in unpack_pdb\n\nStart states are read from untrusted data and used as indexes into the\nDFA state tables. The aa_dfa_next() function call in unpack_pdb() will\naccess dfa->tables[YYTD_ID_BASE][start], and if the start state exceeds\nthe number of states in the DFA, this results in an out-of-bound read.\n\n==================================================================\n BUG: KASAN: ","2026-03-18T18:16:25.907+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23269",{"cveId":3527,"releaseId":17,"cycle":18,"description":3528,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3529,"url":3530},{"cveId":3527,"releaseId":31,"cycle":32,"description":3528,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3529,"url":3530},{"cveId":3534,"releaseId":25,"cycle":26,"description":3535,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3536,"url":3537},"CVE-2026-23268","In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix unprivileged local user can do privileged policy management\n\nAn unprivileged local user can load, replace, and remove profiles by\nopening the apparmorfs interfaces, via a confused deputy attack, by\npassing the opened fd to a privileged process, and getting the\nprivileged process to write to the interface.\n\nThis does require a privileged target that can be manipulated to do\nthe write for the unprivileged process, b","2026-03-18T18:16:25.753+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23268",{"cveId":3534,"releaseId":17,"cycle":18,"description":3535,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3536,"url":3537},{"cveId":3540,"releaseId":25,"cycle":26,"description":3541,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3542,"url":3543},"CVE-2026-23267","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes\n\nDuring SPO tests, when mounting F2FS, an -EINVAL error was returned from\nf2fs_recover_inode_page. The issue occurred under the following scenario\n\nThread A                                     Thread B\nf2fs_ioc_commit_atomic_write\n - f2fs_do_sync_file \u002F\u002F atomic = true\n  - f2fs_fsync_node_pages\n    : last_folio = inode fol","2026-03-18T18:16:25.573+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23267",{"cveId":3540,"releaseId":17,"cycle":18,"description":3541,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3542,"url":3543},{"cveId":3540,"releaseId":31,"cycle":32,"description":3541,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3542,"url":3543},{"cveId":3547,"releaseId":25,"cycle":26,"description":3548,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3549,"url":3550},"CVE-2026-23266","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: rivafb: fix divide error in nv3_arb()\n\nA userspace program can trigger the RIVA NV3 arbitration code by calling\nthe FBIOPUT_VSCREENINFO ioctl on \u002Fdev\u002Ffb*. When doing so, the driver\nrecomputes FIFO arbitration parameters in nv3_arb(), using state->mclk_khz\n(derived from the PRAMDAC MCLK PLL) as a divisor without validating it\nfirst.\n\nIn a normal setup, state->mclk_khz is provided by the real hardware and is\nnon-zero. Howe","2026-03-18T18:16:25.37+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23266",{"cveId":3547,"releaseId":17,"cycle":18,"description":3548,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3549,"url":3550},{"cveId":3547,"releaseId":31,"cycle":32,"description":3548,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3549,"url":3550},{"cveId":3554,"releaseId":25,"cycle":26,"description":3555,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3556,"url":3557},"CVE-2026-23265","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on node footer in {read,write}_end_io\n\n-----------[ cut here ]------------\nkernel BUG at fs\u002Ff2fs\u002Fdata.c:358!\nCall Trace:\n \u003CIRQ>\n blk_update_request+0x5eb\u002F0xe70 block\u002Fblk-mq.c:987\n blk_mq_end_request+0x3e\u002F0x70 block\u002Fblk-mq.c:1149\n blk_complete_reqs block\u002Fblk-mq.c:1224 [inline]\n blk_done_softirq+0x107\u002F0x160 block\u002Fblk-mq.c:1229\n handle_softirqs+0x283\u002F0x870 kernel\u002Fsoftirq.c:579\n __do_softirq kernel\u002Fsoft","2026-03-18T18:16:25.233+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23265",{"cveId":3554,"releaseId":17,"cycle":18,"description":3555,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3556,"url":3557},{"cveId":3554,"releaseId":31,"cycle":32,"description":3555,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3556,"url":3557},{"cveId":3561,"releaseId":17,"cycle":18,"description":3562,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3563,"url":3564},"CVE-2026-23258","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: liquidio: Initialize netdev pointer before queue setup\n\nIn setup_nic_devices(), the netdev is allocated using alloc_etherdev_mq().\nHowever, the pointer to this structure is stored in oct->props[i].netdev\nonly after the calls to netif_set_real_num_rx_queues() and\nnetif_set_real_num_tx_queues().\n\nIf either of these functions fails, setup_nic_devices() returns an error\nwithout freeing the allocated netdev. Since oct->props[i]","2026-03-18T18:16:24.167+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23258",{"cveId":3566,"releaseId":17,"cycle":18,"description":3567,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3568,"url":3569},"CVE-2026-23257","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup\n\nIn setup_nic_devices(), the initialization loop jumps to the label\nsetup_nic_dev_free on failure. The current cleanup loop while(i--)\nskip the failing index i, causing a memory leak.\n\nFix this by changing the loop to iterate from the current index i\ndown to 0.\n\nAlso, decrement i in the devlink_alloc failure path to point to the\nlast successfully allocated in","2026-03-18T18:16:23.997+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23257",{"cveId":3566,"releaseId":31,"cycle":32,"description":3567,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3568,"url":3569},{"cveId":3566,"releaseId":25,"cycle":26,"description":3567,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3568,"url":3569},{"cveId":3573,"releaseId":25,"cycle":26,"description":3574,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3575,"url":3576},"CVE-2026-23256","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup\n\nIn setup_nic_devices(), the initialization loop jumps to the label\nsetup_nic_dev_free on failure. The current cleanup loop while(i--)\nskip the failing index i, causing a memory leak.\n\nFix this by changing the loop to iterate from the current index i\ndown to 0.\n\nCompile tested only. Issue found using code review.","2026-03-18T18:16:23.817+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23256",{"cveId":3573,"releaseId":17,"cycle":18,"description":3574,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3575,"url":3576},{"cveId":3579,"releaseId":25,"cycle":26,"description":3580,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3581,"url":3582},"CVE-2026-23255","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add proper RCU protection to \u002Fproc\u002Fnet\u002Fptype\n\nYin Fengwei reported an RCU stall in ptype_seq_show() and provided\na patch.\n\nReal issue is that ptype_seq_next() and ptype_seq_show() violate\nRCU rules.\n\nptype_seq_show() runs under rcu_read_lock(), and reads pt->dev\nto get device name without any barrier.\n\nAt the same time, concurrent writers can remove a packet_type structure\n(which is correctly freed after an RCU grace perio","2026-03-18T18:16:23.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23255",{"cveId":3579,"releaseId":17,"cycle":18,"description":3580,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3581,"url":3582},{"cveId":3579,"releaseId":31,"cycle":32,"description":3580,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3581,"url":3582},{"cveId":3586,"releaseId":25,"cycle":26,"description":3587,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3588,"url":3589},"CVE-2026-23253","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-core: fix wrong reinitialization of ringbuffer on reopen\n\ndvb_dvr_open() calls dvb_ringbuffer_init() when a new reader opens the\nDVR device.  dvb_ringbuffer_init() calls init_waitqueue_head(), which\nreinitializes the waitqueue list head to empty.\n\nSince dmxdev->dvr_buffer.queue is a shared waitqueue (all opens of the\nsame DVR device share it), this orphans any existing waitqueue entries\nfrom io_uring poll or epoll, l","2026-03-18T18:16:23.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23253",{"cveId":3586,"releaseId":17,"cycle":18,"description":3587,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3588,"url":3589},{"cveId":3586,"releaseId":31,"cycle":32,"description":3587,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3588,"url":3589},{"cveId":3593,"releaseId":25,"cycle":26,"description":3594,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3595,"url":3596},"CVE-2025-71269","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not free data reservation in fallback from inline due to -ENOSPC\n\nIf we fail to create an inline extent due to -ENOSPC, we will attempt to\ngo through the normal COW path, reserve an extent, create an ordered\nextent, etc. However we were always freeing the reserved qgroup data,\nwhich is wrong since we will use data. Fix this by freeing the reserved\nqgroup data in __cow_file_range_inline() only if we are not doing the\nf","2026-03-18T18:16:22.11+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71269",{"cveId":3593,"releaseId":17,"cycle":18,"description":3594,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3595,"url":3596},{"cveId":3593,"releaseId":31,"cycle":32,"description":3594,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3595,"url":3596},{"cveId":3600,"releaseId":25,"cycle":26,"description":3601,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3602,"url":3603},"CVE-2025-71268","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix reservation leak in some error paths when inserting inline extent\n\nIf we fail to allocate a path or join a transaction, we return from\n__cow_file_range_inline() without freeing the reserved qgroup data,\nresulting in a leak. Fix this by ensuring we call btrfs_qgroup_free_data()\nin such cases.","2026-03-18T18:16:21.96+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71268",{"cveId":3600,"releaseId":17,"cycle":18,"description":3601,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3602,"url":3603},{"cveId":3600,"releaseId":31,"cycle":32,"description":3601,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3602,"url":3603},{"cveId":3607,"releaseId":25,"cycle":26,"description":3608,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3609,"url":3610},"CVE-2026-23247","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: secure_seq: add back ports to TS offset\n\nThis reverts 28ee1b746f49 (\"secure_seq: downgrade to per-host timestamp offsets\")\n\ntcp_tw_recycle went away in 2017.\n\nZhouyan Deng reported off-path TCP source port leakage via\nSYN cookie side-channel that can be fixed in multiple ways.\n\nOne of them is to bring back TCP ports in TS offset randomization.\n\nAs a bonus, we perform a single siphash() computation\nto provide both an ISN an","2026-03-18T11:16:16.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23247",{"cveId":3607,"releaseId":17,"cycle":18,"description":3608,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3609,"url":3610},{"cveId":3613,"releaseId":25,"cycle":26,"description":3614,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3615,"url":3616},"CVE-2026-23243","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fumad: Reject negative data_len in ib_umad_write\n\nib_umad_write computes data_len from user-controlled count and the\nMAD header sizes. With a mismatched user MAD header size and RMPP\nheader length, data_len can become negative and reach ib_create_send_mad().\nThis can make the padding calculation exceed the segment size and trigger\nan out-of-bounds memset in alloc_send_rmpp_list().\n\nAdd an explicit check to reject negative d","2026-03-18T11:16:16.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23243",{"cveId":3613,"releaseId":17,"cycle":18,"description":3614,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3615,"url":3616},{"cveId":3613,"releaseId":31,"cycle":32,"description":3614,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3615,"url":3616},{"cveId":3620,"releaseId":25,"cycle":26,"description":3621,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3622,"url":3623},"CVE-2026-23238","In the Linux kernel, the following vulnerability has been resolved:\n\nromfs: check sb_set_blocksize() return value\n\nromfs_fill_super() ignores the return value of sb_set_blocksize(), which\ncan fail if the requested block size is incompatible with the block\ndevice's configuration.\n\nThis can be triggered by setting a loop device's block size larger than\nPAGE_SIZE using ioctl(LOOP_SET_BLOCK_SIZE, 32768), then mounting a romfs\nfilesystem on that device.\n\nWhen sb_set_blocksize(sb, ROMBSIZE) is called ","2026-03-04T15:16:14.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23238",{"cveId":3620,"releaseId":17,"cycle":18,"description":3621,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3622,"url":3623},{"cveId":3620,"releaseId":31,"cycle":32,"description":3621,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3622,"url":3623},{"cveId":3627,"releaseId":25,"cycle":26,"description":3628,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":3629,"url":3630},"CVE-2026-23236","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: properly copy ioctl memory to kernelspace\n\nThe UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from\nuserspace to kernelspace, and instead directly references the memory,\nwhich can cause problems if invalid data is passed from userspace.  Fix\nthis all up by correctly copying the memory before accessing it within\nthe kernel.","2026-03-04T15:16:14.173+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23236",{"cveId":3627,"releaseId":17,"cycle":18,"description":3628,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":3629,"url":3630},{"cveId":3627,"releaseId":31,"cycle":32,"description":3628,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":3629,"url":3630},{"cveId":3634,"releaseId":25,"cycle":26,"description":3635,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3636,"url":3637},"CVE-2026-23231","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix use-after-free in nf_tables_addchain()\n\nnf_tables_addchain() publishes the chain to table->chains via\nlist_add_tail_rcu() (in nft_chain_add()) before registering hooks.\nIf nf_tables_register_hook() then fails, the error path calls\nnft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy()\nwith no RCU grace period in between.\n\nThis creates two use-after-free conditions:\n\n 1) Control-plane: n","2026-03-04T13:15:58.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23231",{"cveId":3634,"releaseId":17,"cycle":18,"description":3635,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3636,"url":3637},{"cveId":3634,"releaseId":31,"cycle":32,"description":3635,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3636,"url":3637},{"cveId":3641,"releaseId":17,"cycle":18,"description":3642,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3643,"url":3644},"CVE-2026-23229","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio - Add spinlock protection with virtqueue notification\n\nWhen VM boots with one virtio-crypto PCI device and builtin backend,\nrun openssl benchmark command with multiple processes, such as\n  openssl speed -evp aes-128-cbc -engine afalg  -seconds 10 -multi 32\n\nopenssl processes will hangup and there is error reported like this:\n virtio_crypto virtio0: dataq.0:id 3 is not a head!\n\nIt seems that the data virtqueue nee","2026-02-18T16:22:32.693+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23229",{"cveId":3646,"releaseId":25,"cycle":26,"description":3647,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3648,"url":3649},"CVE-2026-23222","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly\n\nThe existing allocation of scatterlists in omap_crypto_copy_sg_lists()\nwas allocating an array of scatterlist pointers, not scatterlist objects,\nresulting in a 4x too small allocation.\n\nUse sizeof(*new_sg) to get the correct object size.","2026-02-18T16:22:31.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23222",{"cveId":3646,"releaseId":17,"cycle":18,"description":3647,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3648,"url":3649},{"cveId":3652,"releaseId":17,"cycle":18,"description":3653,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3654,"url":3655},"CVE-2025-71236","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Validate sp before freeing associated memory\n\nSystem crash with the following signature\n[154563.214890] nvme nvme2: NVME-FC{1}: controller connect complete\n[154564.169363] qla2xxx [0000:b0:00.1]-3002:2: nvme: Sched: Set ZIO exchange threshold to 3.\n[154564.169405] qla2xxx [0000:b0:00.1]-ffffff:2: SET ZIO Activity exchange threshold to 5.\n[154565.539974] qla2xxx [0000:b0:00.1]-5013:2: RSCN database changed – 0078 ","2026-02-18T16:22:30.407+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71236",{"cveId":3657,"releaseId":25,"cycle":26,"description":3658,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3659,"url":3660},"CVE-2026-23204","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: cls_u32: use skb_header_pointer_careful()\n\nskb_header_pointer() does not fully validate negative @offset values.\n\nUse skb_header_pointer_careful() instead.\n\nGangMin Kim provided a report and a repro fooling u32_classify():\n\nBUG: KASAN: slab-out-of-bounds in u32_classify+0x1180\u002F0x11b0\nnet\u002Fsched\u002Fcls_u32.c:221","2026-02-14T17:15:58.297+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23204",{"cveId":3657,"releaseId":17,"cycle":18,"description":3658,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3659,"url":3660},{"cveId":3657,"releaseId":31,"cycle":32,"description":3658,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3659,"url":3660},{"cveId":3664,"releaseId":25,"cycle":26,"description":3665,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":3666,"url":3667},"CVE-2025-71221","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()\n\nAdd proper locking in mmp_pdma_residue() to prevent use-after-free when\naccessing descriptor list and descriptor contents.\n\nThe race occurs when multiple threads call tx_status() while the tasklet\non another CPU is freeing completed descriptors:\n\nCPU 0                              CPU 1\n-----                              -----\nmmp_pdma_tx_status()\nmmp_pdma_residue()","2026-02-14T17:15:54.45+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71221",{"cveId":3664,"releaseId":17,"cycle":18,"description":3665,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":3666,"url":3667},{"cveId":3664,"releaseId":31,"cycle":32,"description":3665,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":3666,"url":3667},{"cveId":3671,"releaseId":25,"cycle":26,"description":3672,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3673,"url":3674},"CVE-2026-23157","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not strictly require dirty metadata threshold for metadata writepages\n\n[BUG]\nThere is an internal report that over 1000 processes are\nwaiting at the io_schedule_timeout() of balance_dirty_pages(), causing\na system hang and trigger a kernel coredump.\n\nThe kernel is v6.4 kernel based, but the root problem still applies to\nany upstream kernel before v6.18.\n\n[CAUSE]\nFrom Jan Kara for his wisdom on the dirty page balance b","2026-02-14T16:15:55.863+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23157",{"cveId":3671,"releaseId":17,"cycle":18,"description":3672,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3673,"url":3674},{"cveId":3671,"releaseId":31,"cycle":32,"description":3672,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3673,"url":3674},{"cveId":3678,"releaseId":25,"cycle":26,"description":3679,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3680,"url":3681},"CVE-2026-23141","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: send: check for inline extents in range_is_hole_in_parent()\n\nBefore accessing the disk_bytenr field of a file extent item we need\nto check if we are dealing with an inline extent.\nThis is because for inline extents their data starts at the offset of\nthe disk_bytenr field. So accessing the disk_bytenr\nmeans we are accessing inline data or in case the inline data is less\nthan 8 bytes we can actually cause an invalid\nmemory","2026-02-14T16:15:54.163+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23141",{"cveId":3678,"releaseId":17,"cycle":18,"description":3679,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3680,"url":3681},{"cveId":3684,"releaseId":31,"cycle":32,"description":3685,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3686,"url":3687},"CVE-2025-71202","In the Linux kernel, the following vulnerability has been resolved:\n\niommu\u002Fsva: invalidate stale IOTLB entries for kernel address space\n\nIntroduce a new IOMMU interface to flush IOTLB paging cache entries for\nthe CPU kernel address space.  This interface is invoked from the x86\narchitecture code that manages combined user and kernel page tables,\nspecifically before any kernel page table page is freed and reused.\n\nThis addresses the main issue with vfree() which is a common occurrence\nand can be ","2026-02-14T16:15:52.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71202",{"cveId":3684,"releaseId":17,"cycle":18,"description":3685,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3686,"url":3687},{"cveId":3684,"releaseId":25,"cycle":26,"description":3685,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3686,"url":3687},{"cveId":3691,"releaseId":17,"cycle":18,"description":3692,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3693,"url":3694},"CVE-2026-23111","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()\n\nnft_map_catchall_activate() has an inverted element activity check\ncompared to its non-catchall counterpart nft_mapelem_activate() and\ncompared to what is logically required.\n\nnft_map_catchall_activate() is called from the abort path to re-activate\ncatchall map elements that were deactivated during a failed transaction.\nIt should skip elements that","2026-02-13T14:16:10.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23111",{"cveId":3696,"releaseId":17,"cycle":18,"description":3697,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3698,"url":3699},"CVE-2026-23103","In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: Make the addrs_lock be per port\n\nMake the addrs_lock be per port, not per ipvlan dev.\n\nInitial code seems to be written in the assumption,\nthat any address change must occur under RTNL.\nBut it is not so for the case of IPv6. So\n\n1) Introduce per-port addrs_lock.\n\n2) It was needed to fix places where it was forgotten\nto take lock (ipvlan_open\u002Fipvlan_close)\n\nThis appears to be a very minor problem though.\nSince it's highl","2026-02-04T17:16:21.177+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23103",{"cveId":3701,"releaseId":31,"cycle":32,"description":3702,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3703,"url":3704},"CVE-2026-23095","In the Linux kernel, the following vulnerability has been resolved:\n\ngue: Fix skb memleak with inner IP protocol 0.\n\nsyzbot reported skb memleak below. [0]\n\nThe repro generated a GUE packet with its inner protocol 0.\n\ngue_udp_recv() returns -guehdr->proto_ctype for \"resubmit\"\nin ip_protocol_deliver_rcu(), but this only works with\nnon-zero protocol number.\n\nLet's drop such packets.\n\nNote that 0 is a valid number (IPv6 Hop-by-Hop Option).\n\nI think it is not practical to encap HOPOPT in GUE, so onc","2026-02-04T17:16:20.37+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23095",{"cveId":3701,"releaseId":17,"cycle":18,"description":3702,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3703,"url":3704},{"cveId":3701,"releaseId":25,"cycle":26,"description":3702,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3703,"url":3704},{"cveId":3708,"releaseId":31,"cycle":32,"description":3709,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3710,"url":3711},"CVE-2026-23087","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: xen: scsiback: Fix potential memory leak in scsiback_remove()\n\nMemory allocated for struct vscsiblk_info in scsiback_probe() is not\nfreed in scsiback_remove() leading to potential memory leaks on remove,\nas well as in the scsiback_probe() error paths. Fix that by freeing it\nin scsiback_remove().","2026-02-04T17:16:19.57+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23087",{"cveId":3708,"releaseId":17,"cycle":18,"description":3709,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3710,"url":3711},{"cveId":3708,"releaseId":25,"cycle":26,"description":3709,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3710,"url":3711},{"cveId":3715,"releaseId":31,"cycle":32,"description":3716,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3717,"url":3718},"CVE-2026-23086","In the Linux kernel, the following vulnerability has been resolved:\n\nvsock\u002Fvirtio: cap TX credit to local buffer size\n\nThe virtio transports derives its TX credit directly from peer_buf_alloc,\nwhich is set from the remote endpoint's SO_VM_SOCKETS_BUFFER_SIZE value.\n\nOn the host side this means that the amount of data we are willing to\nqueue for a connection is scaled by a guest-chosen buffer size, rather\nthan the host's own vsock configuration. A malicious guest can advertise\na large buffer and ","2026-02-04T17:16:19.467+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23086",{"cveId":3715,"releaseId":17,"cycle":18,"description":3716,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3717,"url":3718},{"cveId":3715,"releaseId":25,"cycle":26,"description":3716,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3717,"url":3718},{"cveId":3722,"releaseId":31,"cycle":32,"description":3723,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3724,"url":3725},"CVE-2026-23084","In the Linux kernel, the following vulnerability has been resolved:\n\nbe2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list\n\nWhen the parameter pmac_id_valid argument of be_cmd_get_mac_from_list() is\nset to false, the driver may request the PMAC_ID from the firmware of the\nnetwork card, and this function will store that PMAC_ID at the provided\naddress pmac_id. This is the contract of this function.\n\nHowever, there is a location within the driver where both\npmac_id_valid == false and pm","2026-02-04T17:16:19.257+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23084",{"cveId":3722,"releaseId":17,"cycle":18,"description":3723,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3724,"url":3725},{"cveId":3722,"releaseId":25,"cycle":26,"description":3723,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3724,"url":3725},{"cveId":3729,"releaseId":31,"cycle":32,"description":3730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3731,"url":3732},"CVE-2026-23083","In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Don't allow 0 for FOU_ATTR_IPPROTO.\n\nfou_udp_recv() has the same problem mentioned in the previous\npatch.\n\nIf FOU_ATTR_IPPROTO is set to 0, skb is not freed by\nfou_udp_recv() nor \"resubmit\"-ted in ip_protocol_deliver_rcu().\n\nLet's forbid 0 for FOU_ATTR_IPPROTO.","2026-02-04T17:16:19.163+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23083",{"cveId":3729,"releaseId":17,"cycle":18,"description":3730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3731,"url":3732},{"cveId":3729,"releaseId":25,"cycle":26,"description":3730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3731,"url":3732},{"cveId":3736,"releaseId":31,"cycle":32,"description":3737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3738,"url":3739},"CVE-2026-23074","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: Enforce that teql can only be used as root qdisc\n\nDesign intent of teql is that it is only supposed to be used as root qdisc.\nWe need to check for that constraint.\n\nAlthough not important, I will describe the scenario that unearthed this\nissue for the curious.\n\nGangMin Kim \u003Ckm.kim1503@gmail.com> managed to concot a scenario as follows:\n\nROOT qdisc 1:0 (QFQ)\n  ├── class 1:1 (weight=15, lmax=16384) netem with delay 6.4","2026-02-04T17:16:18.127+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23074",{"cveId":3736,"releaseId":17,"cycle":18,"description":3737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3738,"url":3739},{"cveId":3736,"releaseId":25,"cycle":26,"description":3737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3738,"url":3739},{"cveId":3743,"releaseId":25,"cycle":26,"description":3744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3745,"url":3746},"CVE-2026-23066","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix recvmsg() unconditional requeue\n\nIf rxrpc_recvmsg() fails because MSG_DONTWAIT was specified but the call at\nthe front of the recvmsg queue already has its mutex locked, it requeues\nthe call - whether or not the call is already queued.  The call may be on\nthe queue because MSG_PEEK was also passed and so the call was not dequeued\nor because the I\u002FO thread requeued it.\n\nThe unconditional requeue may then corrupt the r","2026-02-04T17:16:17.303+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23066",{"cveId":3743,"releaseId":17,"cycle":18,"description":3744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3745,"url":3746},{"cveId":3749,"releaseId":31,"cycle":32,"description":3750,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3751,"url":3752},"CVE-2026-23060","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: authencesn - reject too-short AAD (assoclen\u003C8) to match ESP\u002FESN spec\n\nauthencesn assumes an ESP\u002FESN-formatted AAD. When assoclen is shorter than\nthe minimum expected length, crypto_authenc_esn_decrypt() can advance past\nthe end of the destination scatterlist and trigger a NULL pointer dereference\nin scatterwalk_map_and_copy(), leading to a kernel panic (DoS).\n\nAdd a minimum AAD length check to fail fast on invalid input","2026-02-04T17:16:16.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23060",{"cveId":3749,"releaseId":17,"cycle":18,"description":3750,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3751,"url":3752},{"cveId":3749,"releaseId":25,"cycle":26,"description":3750,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3751,"url":3752},{"cveId":3756,"releaseId":25,"cycle":26,"description":3757,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3758,"url":3759},"CVE-2025-71191","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: at_hdmac: fix device leak on of_dma_xlate()\n\nMake sure to drop the reference taken when looking up the DMA platform\ndevice during of_dma_xlate() when releasing channel resources.\n\nNote that commit 3832b78b3ec2 (\"dmaengine: at_hdmac: add missing\nput_device() call in at_dma_xlate()\") fixed the leak in a couple of\nerror paths but the reference is still leaking on successful allocation.","2026-01-31T12:16:04.38+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71191",{"cveId":3756,"releaseId":17,"cycle":18,"description":3757,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3758,"url":3759},{"cveId":3756,"releaseId":31,"cycle":32,"description":3757,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3758,"url":3759},{"cveId":3763,"releaseId":25,"cycle":26,"description":3764,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3765,"url":3766},"CVE-2025-71190","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: bcm-sba-raid: fix device leak on probe\n\nMake sure to drop the reference taken when looking up the mailbox device\nduring probe on probe failures and on driver unbind.","2026-01-31T12:16:04.28+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71190",{"cveId":3763,"releaseId":17,"cycle":18,"description":3764,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3765,"url":3766},{"cveId":3769,"releaseId":25,"cycle":26,"description":3770,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3771,"url":3772},"CVE-2025-71188","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: lpc18xx-dmamux: fix device leak on route allocation\n\nMake sure to drop the reference taken when looking up the DMA mux\nplatform device during route allocation.\n\nNote that holding a reference to a device does not prevent its driver\ndata from going away so there is no point in keeping the reference.","2026-01-31T12:16:04.067+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71188",{"cveId":3769,"releaseId":17,"cycle":18,"description":3770,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3771,"url":3772},{"cveId":3769,"releaseId":31,"cycle":32,"description":3770,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3771,"url":3772},{"cveId":3776,"releaseId":17,"cycle":18,"description":3777,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3778,"url":3779},"CVE-2025-71186","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: stm32: dmamux: fix device leak on route allocation\n\nMake sure to drop the reference taken when looking up the DMA mux\nplatform device during route allocation.\n\nNote that holding a reference to a device does not prevent its driver\ndata from going away so there is no point in keeping the reference.","2026-01-31T12:16:03.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71186",{"cveId":3781,"releaseId":25,"cycle":26,"description":3782,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3783,"url":3784},"CVE-2025-71185","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: ti: dma-crossbar: fix device leak on am335x route allocation\n\nMake sure to drop the reference taken when looking up the crossbar\nplatform device during am335x route allocation.","2026-01-31T12:16:03.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71185",{"cveId":3781,"releaseId":17,"cycle":18,"description":3782,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3783,"url":3784},{"cveId":3781,"releaseId":31,"cycle":32,"description":3782,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3783,"url":3784},{"cveId":3788,"releaseId":31,"cycle":32,"description":3789,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3790,"url":3791},"CVE-2025-71183","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: always detect conflicting inodes when logging inode refs\n\nAfter rename exchanging (either with the rename exchange operation or\nregular renames in multiple non-atomic steps) two inodes and at least\none of them is a directory, we can end up with a log tree that contains\nonly of the inodes and after a power failure that can result in an attempt\nto delete the other inode when it should not because it was not deleted\nbefore ","2026-01-31T12:16:03.57+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71183",{"cveId":3788,"releaseId":17,"cycle":18,"description":3789,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3790,"url":3791},{"cveId":3788,"releaseId":25,"cycle":26,"description":3789,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3790,"url":3791},{"cveId":3795,"releaseId":31,"cycle":32,"description":3796,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3797,"url":3798},"CVE-2026-23011","In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: ip_gre: make ipgre_header() robust\n\nAnalog to commit db5b4e39c4e6 (\"ip6_gre: make ip6gre_header() robust\")\n\nOver the years, syzbot found many ways to crash the kernel\nin ipgre_header() [1].\n\nThis involves team or bonding drivers ability to dynamically\nchange their dev->needed_headroom and\u002For dev->hard_header_len\n\nIn this particular crash mld_newpack() allocated an skb\nwith a too small reserve\u002Fheadroom, and by the time mld","2026-01-25T15:15:55.977+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23011",{"cveId":3795,"releaseId":17,"cycle":18,"description":3796,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3797,"url":3798},{"cveId":3795,"releaseId":25,"cycle":26,"description":3796,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3797,"url":3798},{"cveId":3802,"releaseId":31,"cycle":32,"description":3803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3804,"url":3805},"CVE-2025-71162","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: tegra-adma: Fix use-after-free\n\nA use-after-free bug exists in the Tegra ADMA driver when audio streams\nare terminated, particularly during XRUN conditions. The issue occurs\nwhen the DMA buffer is freed by tegra_adma_terminate_all() before the\nvchan completion tasklet finishes accessing it.\n\nThe race condition follows this sequence:\n\n  1. DMA transfer completes, triggering an interrupt that schedules the\n     complet","2026-01-25T15:15:53.947+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71162",{"cveId":3802,"releaseId":17,"cycle":18,"description":3803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3804,"url":3805},{"cveId":3802,"releaseId":25,"cycle":26,"description":3803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3804,"url":3805},{"cveId":3809,"releaseId":31,"cycle":32,"description":3810,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3811,"url":3812},"CVE-2026-22980","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: provide locking for v4_end_grace\n\nWriting to v4_end_grace can race with server shutdown and result in\nmemory being accessed after it was freed - reclaim_str_hashtbl in\nparticularly.\n\nWe cannot hold nfsd_mutex across the nfsd4_end_grace() call as that is\nheld while client_tracking_op->init() is called and that can wait for\nan upcall to nfsdcltrack which can write to v4_end_grace, resulting in a\ndeadlock.\n\nnfsd4_end_grace()","2026-01-23T16:15:54.003+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-22980",{"cveId":3809,"releaseId":17,"cycle":18,"description":3810,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3811,"url":3812},{"cveId":3809,"releaseId":25,"cycle":26,"description":3810,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3811,"url":3812},{"cveId":3816,"releaseId":17,"cycle":18,"description":3817,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3818,"url":3819},"CVE-2025-71161","In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity: disable recursive forward error correction\n\nThere are two problems with the recursive correction:\n\n1. It may cause denial-of-service. In fec_read_bufs, there is a loop that\nhas 253 iterations. For each iteration, we may call verity_hash_for_block\nrecursively. There is a limit of 4 nested recursions - that means that\nthere may be at most 253^4 (4 billion) iterations. Red Hat QE team\nactually created an image that push","2026-01-23T16:15:53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71161",{"cveId":3816,"releaseId":31,"cycle":32,"description":3817,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3818,"url":3819},{"cveId":3816,"releaseId":25,"cycle":26,"description":3817,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3818,"url":3819},{"cveId":3823,"releaseId":17,"cycle":18,"description":3824,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3825,"url":3826},"CVE-2026-22977","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sock: fix hardened usercopy panic in sock_recv_errqueue\n\nskbuff_fclone_cache was created without defining a usercopy region,\n[1] unlike skbuff_head_cache which properly whitelists the cb[] field.\n[2] This causes a usercopy BUG() when CONFIG_HARDENED_USERCOPY is\nenabled and the kernel attempts to copy sk_buff.cb data to userspace\nvia sock_recv_errqueue() -> put_cmsg().\n\nThe crash occurs when: 1. TCP allocates an skb using a","2026-01-21T14:16:06.853+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-22977",{"cveId":3828,"releaseId":25,"cycle":26,"description":3829,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3830,"url":3831},"CVE-2026-22976","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset\n\n`qfq_class->leaf_qdisc->q.qlen > 0` does not imply that the class\nitself is active.\n\nTwo qfq_class objects may point to the same leaf_qdisc. This happens\nwhen:\n\n1. one QFQ qdisc is attached to the dev as the root qdisc, and\n\n2. another QFQ qdisc is temporarily referenced (e.g., via qdisc_get()\n\u002F qdisc_put()) and is pending to be destroyed, as ","2026-01-21T07:16:01.433+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-22976",{"cveId":3828,"releaseId":17,"cycle":18,"description":3829,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3830,"url":3831},{"cveId":3828,"releaseId":31,"cycle":32,"description":3829,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3830,"url":3831},{"cveId":3835,"releaseId":31,"cycle":32,"description":3836,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3837,"url":3838},"CVE-2025-71136","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status()\n\nIt's possible for cp_read() and hdmi_read() to return -EIO. Those\nvalues are further used as indexes for accessing arrays.\n\nFix that by checking return values where it's needed.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.","2026-01-14T15:16:03.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71136",{"cveId":3835,"releaseId":17,"cycle":18,"description":3836,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3837,"url":3838},{"cveId":3835,"releaseId":25,"cycle":26,"description":3836,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3837,"url":3838},{"cveId":3842,"releaseId":31,"cycle":32,"description":3843,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3844,"url":3845},"CVE-2025-71131","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: seqiv - Do not use req->iv after crypto_aead_encrypt\n\nAs soon as crypto_aead_encrypt is called, the underlying request\nmay be freed by an asynchronous completion.  Thus dereferencing\nreq->iv after it returns is invalid.\n\nInstead of checking req->iv against info, create a new variable\nunaligned_info and use it for that purpose instead.","2026-01-14T15:16:02.843+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71131",{"cveId":3842,"releaseId":17,"cycle":18,"description":3843,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3844,"url":3845},{"cveId":3842,"releaseId":25,"cycle":26,"description":3843,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3844,"url":3845},{"cveId":3849,"releaseId":17,"cycle":18,"description":3850,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3851,"url":3852},"CVE-2025-71120","In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf\n\nA zero length gss_token results in pages == 0 and in_token->pages[0]\nis NULL. The code unconditionally evaluates\npage_address(in_token->pages[0]) for the initial memcpy, which can\ndereference NULL even when the copy length is 0. Guard the first\nmemcpy so it only runs when length > 0.","2026-01-14T15:16:01.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71120",{"cveId":3854,"releaseId":31,"cycle":32,"description":3855,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3856,"url":3857},"CVE-2025-71116","In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: make decode_pool() more resilient against corrupted osdmaps\n\nIf the osdmap is (maliciously) corrupted such that the encoded length\nof ceph_pg_pool envelope is less than what is expected for a particular\nencoding version, out-of-bounds reads may ensue because the only bounds\ncheck that is there is based on that length value.\n\nThis patch adds explicit bounds checks for each field that is decoded\nor skipped.","2026-01-14T15:16:01.277+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71116",{"cveId":3854,"releaseId":17,"cycle":18,"description":3855,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3856,"url":3857},{"cveId":3854,"releaseId":25,"cycle":26,"description":3855,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3856,"url":3857},{"cveId":3861,"releaseId":31,"cycle":32,"description":3862,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3863,"url":3864},"CVE-2025-71114","In the Linux kernel, the following vulnerability has been resolved:\n\nvia_wdt: fix critical boot hang due to unnamed resource allocation\n\nThe VIA watchdog driver uses allocate_resource() to reserve a MMIO\nregion for the watchdog control register. However, the allocated\nresource was not given a name, which causes the kernel resource tree\nto contain an entry marked as \"\u003CBAD>\" under \u002Fproc\u002Fiomem on x86\nplatforms.\n\nDuring boot, this unnamed resource can lead to a critical hang because\nsubsequent resou","2026-01-14T15:16:01.063+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71114",{"cveId":3861,"releaseId":17,"cycle":18,"description":3862,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3863,"url":3864},{"cveId":3861,"releaseId":25,"cycle":26,"description":3862,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3863,"url":3864},{"cveId":3868,"releaseId":31,"cycle":32,"description":3869,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3870,"url":3871},"CVE-2025-71113","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - zero initialize memory allocated via sock_kmalloc\n\nSeveral crypto user API contexts and requests allocated with\nsock_kmalloc() were left uninitialized, relying on callers to\nset fields explicitly. This resulted in the use of uninitialized\ndata in certain error paths or when new fields are added in the\nfuture.\n\nThe ACVP patches also contain two user-space interface files:\nalgif_kpp.c and algif_akcipher.c. These ","2026-01-14T15:16:00.433+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71113",{"cveId":3868,"releaseId":17,"cycle":18,"description":3869,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3870,"url":3871},{"cveId":3868,"releaseId":25,"cycle":26,"description":3869,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3870,"url":3871},{"cveId":3875,"releaseId":31,"cycle":32,"description":3876,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3877,"url":3878},"CVE-2025-71109","In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits\n\nSince commit e424054000878 (\"MIPS: Tracing: Reduce the overhead of\ndynamic Function Tracer\"), the macro UASM_i_LA_mostly has been used,\nand this macro can generate more than 2 instructions. At the same\ntime, the code in ftrace assumes that no more than 2 instructions can\nbe generated, which is why it stores them in an int[2] array. However,\nas previously","2026-01-14T15:15:59.973+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71109",{"cveId":3875,"releaseId":17,"cycle":18,"description":3876,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3877,"url":3878},{"cveId":3875,"releaseId":25,"cycle":26,"description":3876,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":3877,"url":3878},{"cveId":3882,"releaseId":25,"cycle":26,"description":3883,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3884,"url":3885},"CVE-2025-71104","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer\n\nWhen advancing the target expiration for the guest's APIC timer in periodic\nmode, set the expiration to \"now\" if the target expiration is in the past\n(similar to what is done in update_target_expiration()).  Blindly adding\nthe period to the previous target expiration can result in KVM generating\na practically unbounded number of hrtimer IRQs due to ","2026-01-14T15:15:59.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71104",{"cveId":3882,"releaseId":17,"cycle":18,"description":3883,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3884,"url":3885},{"cveId":3888,"releaseId":31,"cycle":32,"description":3889,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3890,"url":3891},"CVE-2025-71098","In the Linux kernel, the following vulnerability has been resolved:\n\nip6_gre: make ip6gre_header() robust\n\nOver the years, syzbot found many ways to crash the kernel\nin ip6gre_header() [1].\n\nThis involves team or bonding drivers ability to dynamically\nchange their dev->needed_headroom and\u002For dev->hard_header_len\n\nIn this particular crash mld_newpack() allocated an skb\nwith a too small reserve\u002Fheadroom, and by the time mld_sendpack()\nwas called, syzbot managed to attach an ip6gre device.\n\n[1]\nskb","2026-01-13T16:16:09.703+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71098",{"cveId":3888,"releaseId":17,"cycle":18,"description":3889,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3890,"url":3891},{"cveId":3888,"releaseId":25,"cycle":26,"description":3889,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3890,"url":3891},{"cveId":3895,"releaseId":31,"cycle":32,"description":3896,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3897,"url":3898},"CVE-2025-71093","In the Linux kernel, the following vulnerability has been resolved:\n\ne1000: fix OOB in e1000_tbi_should_accept()\n\nIn e1000_tbi_should_accept() we read the last byte of the frame via\n'data[length - 1]' to evaluate the TBI workaround. If the descriptor-\nreported length is zero or larger than the actual RX buffer size, this\nread goes out of bounds and can hit unrelated slab objects. The issue\nis observed from the NAPI receive path (e1000_clean_rx_irq):\n\n=============================================","2026-01-13T16:16:09.033+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71093",{"cveId":3895,"releaseId":17,"cycle":18,"description":3896,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3897,"url":3898},{"cveId":3895,"releaseId":25,"cycle":26,"description":3896,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":3897,"url":3898},{"cveId":3902,"releaseId":17,"cycle":18,"description":3903,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3904,"url":3905},"CVE-2025-71086","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rose: fix invalid array index in rose_kill_by_device()\n\nrose_kill_by_device() collects sockets into a local array[] and then\niterates over them to disconnect sockets bound to a device being brought\ndown.\n\nThe loop mistakenly indexes array[cnt] instead of array[i]. For cnt \u003C\nARRAY_SIZE(array), this reads an uninitialized entry; for cnt ==\nARRAY_SIZE(array), it is an out-of-bounds read. Either case can lead to\nan invalid soc","2026-01-13T16:16:08.23+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71086",{"cveId":3907,"releaseId":31,"cycle":32,"description":3908,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3909,"url":3910},"CVE-2025-71085","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()\n\nThere exists a kernel oops caused by a BUG_ON(nhead \u003C 0) at\nnet\u002Fcore\u002Fskbuff.c:2232 in pskb_expand_head().\nThis bug is triggered as part of the calipso_skbuff_setattr()\nroutine when skb_cow() is passed headroom > INT_MAX\n(i.e. (int)(skb_headroom(skb) + len_delta) \u003C 0).\n\nThe root cause of the bug is due to an implicit integer cast in\n__skb_cow(). The check (he","2026-01-13T16:16:08.117+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71085",{"cveId":3907,"releaseId":17,"cycle":18,"description":3908,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3909,"url":3910},{"cveId":3907,"releaseId":25,"cycle":26,"description":3908,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3909,"url":3910},{"cveId":3914,"releaseId":31,"cycle":32,"description":3915,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3916,"url":3917},"CVE-2025-71082","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: revert use of devm_kzalloc in btusb\n\nThis reverts commit 98921dbd00c4e (\"Bluetooth: Use devm_kzalloc in\nbtusb.c file\").\n\nIn btusb_probe(), we use devm_kzalloc() to allocate the btusb data. This\nties the lifetime of all the btusb data to the binding of a driver to\none interface, INTF. In a driver that binds to other interfaces, ISOC\nand DIAG, this is an accident waiting to happen.\n\nThe issue is revealed in btus","2026-01-13T16:16:07.78+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71082",{"cveId":3914,"releaseId":17,"cycle":18,"description":3915,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3916,"url":3917},{"cveId":3914,"releaseId":25,"cycle":26,"description":3915,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3916,"url":3917},{"cveId":3921,"releaseId":31,"cycle":32,"description":3922,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3923,"url":3924},"CVE-2025-71079","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write\n\nA deadlock can occur between nfc_unregister_device() and rfkill_fop_write()\ndue to lock ordering inversion between device_lock and rfkill_global_mutex.\n\nThe problematic lock order is:\n\nThread A (rfkill_fop_write):\n  rfkill_fop_write()\n    mutex_lock(&rfkill_global_mutex)\n      rfkill_set_block()\n        nfc_rfkill_set_block()\n          nfc_dev_down()\n   ","2026-01-13T16:16:07.433+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71079",{"cveId":3921,"releaseId":25,"cycle":26,"description":3922,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3923,"url":3924},{"cveId":3921,"releaseId":17,"cycle":18,"description":3922,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":3923,"url":3924},{"cveId":3928,"releaseId":31,"cycle":32,"description":3929,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3930,"url":3931},"CVE-2025-71075","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: aic94xx: fix use-after-free in device removal path\n\nThe asd_pci_remove() function fails to synchronize with pending tasklets\nbefore freeing the asd_ha structure, leading to a potential\nuse-after-free vulnerability.\n\nWhen a device removal is triggered (via hot-unplug or module unload),\nrace condition can occur.\n\nThe fix adds tasklet_kill() before freeing the asd_ha structure,\nensuring all scheduled tasklets complete before","2026-01-13T16:16:06.977+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71075",{"cveId":3928,"releaseId":17,"cycle":18,"description":3929,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3930,"url":3931},{"cveId":3928,"releaseId":25,"cycle":26,"description":3929,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3930,"url":3931},{"cveId":3935,"releaseId":31,"cycle":32,"description":3936,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3937,"url":3938},"CVE-2025-71074","In the Linux kernel, the following vulnerability has been resolved:\n\nfunctionfs: fix the open\u002Fremoval races\n\nffs_epfile_open() can race with removal, ending up with file->private_data\npointing to freed object.\n\nThere is a total count of opened files on functionfs (both ep0 and\ndynamic ones) and when it hits zero, dynamic files get removed.\nUnfortunately, that removal can happen while another thread is\nin ffs_epfile_open(), but has not incremented the count yet.\nIn that case open will succeed, le","2026-01-13T16:16:06.86+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71074",{"cveId":3935,"releaseId":17,"cycle":18,"description":3936,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3937,"url":3938},{"cveId":3935,"releaseId":25,"cycle":26,"description":3936,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3937,"url":3938},{"cveId":3942,"releaseId":31,"cycle":32,"description":3943,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3944,"url":3945},"CVE-2025-68340","In the Linux kernel, the following vulnerability has been resolved:\n\nteam: Move team device type change at the end of team_port_add\n\nAttempting to add a port device that is already up will expectedly fail,\nbut not before modifying the team device header_ops.\n\nIn the case of the syzbot reproducer the gre0 device is\nalready in state UP when it attempts to add it as a\nport device of team0, this fails but before that\nheader_ops->create of team0 is changed from eth_header to ipgre_header\nin the call ","2025-12-23T14:16:40.58+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-68340",{"cveId":3942,"releaseId":17,"cycle":18,"description":3943,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3944,"url":3945},{"cveId":3942,"releaseId":25,"cycle":26,"description":3943,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3944,"url":3945},{"cveId":3949,"releaseId":17,"cycle":18,"description":3950,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3951,"url":3952},"CVE-2025-40149","In the Linux kernel, the following vulnerability has been resolved:\n\ntls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().\n\nget_netdev_for_sock() is called during setsockopt(),\nso not under RCU.\n\nUsing sk_dst_get(sk)->dev could trigger UAF.\n\nLet's use __sk_dst_get() and dst_dev_rcu().\n\nNote that the only ->ndo_sk_get_lower_dev() user is\nbond_sk_get_lower_dev(), which uses RCU.","2025-11-12T11:15:44.817+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-40149",{"cveId":3954,"releaseId":31,"cycle":32,"description":3955,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3956,"url":3957},"CVE-2025-40040","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fksm: fix flag-dropping behavior in ksm_madvise\n\nsyzkaller discovered the following crash: (kernel BUG)\n\n[   44.607039] ------------[ cut here ]------------\n[   44.607422] kernel BUG at mm\u002Fuserfaultfd.c:2067!\n[   44.608148] Oops: invalid opcode: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI\n[   44.608814] CPU: 1 UID: 0 PID: 2475 Comm: reproducer Not tainted 6.16.0-rc6 #1 PREEMPT(none)\n[   44.609635] Hardware name: QEMU Standard P","2025-10-28T12:15:37.967+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-40040",{"cveId":3954,"releaseId":17,"cycle":18,"description":3955,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3956,"url":3957},{"cveId":3954,"releaseId":25,"cycle":26,"description":3955,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3956,"url":3957},{"cveId":3961,"releaseId":31,"cycle":32,"description":3962,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3963,"url":3964},"CVE-2025-39967","In the Linux kernel, the following vulnerability has been resolved:\n\nfbcon: fix integer overflow in fbcon_do_set_font\n\nFix integer overflow vulnerabilities in fbcon_do_set_font() where font\nsize calculations could overflow when handling user-controlled font\nparameters.\n\nThe vulnerabilities occur when:\n1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount\n   multiplication with user-controlled values that can overflow.\n2. FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflo","2025-10-15T08:15:34.21+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39967",{"cveId":3961,"releaseId":25,"cycle":26,"description":3962,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3963,"url":3964},{"cveId":3961,"releaseId":17,"cycle":18,"description":3962,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3963,"url":3964},{"cveId":3968,"releaseId":31,"cycle":32,"description":3969,"severity":3970,"cvssScore":3971,"epssScore":9,"inKev":42,"publishedAt":3972,"url":3973},"CVE-2025-39964","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing.","LOW",3.3,"2025-10-13T14:15:34.737+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39964",{"cveId":3968,"releaseId":17,"cycle":18,"description":3969,"severity":3970,"cvssScore":3971,"epssScore":9,"inKev":42,"publishedAt":3972,"url":3973},{"cveId":3968,"releaseId":25,"cycle":26,"description":3969,"severity":3970,"cvssScore":3971,"epssScore":9,"inKev":42,"publishedAt":3972,"url":3973},{"cveId":3977,"releaseId":31,"cycle":32,"description":3978,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3979,"url":3980},"CVE-2025-39961","In the Linux kernel, the following vulnerability has been resolved:\n\niommu\u002Famd\u002Fpgtbl: Fix possible race while increase page table level\n\nThe AMD IOMMU host page table implementation supports dynamic page table levels\n(up to 6 levels), starting with a 3-level configuration that expands based on\nIOVA address. The kernel maintains a root pointer and current page table level\nto enable proper page table walks in alloc_pte()\u002Ffetch_pte() operations.\n\nThe IOMMU IOVA allocator initially starts with 32-bi","2025-10-09T13:15:32.25+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39961",{"cveId":3977,"releaseId":25,"cycle":26,"description":3978,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3979,"url":3980},{"cveId":3977,"releaseId":17,"cycle":18,"description":3978,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":3979,"url":3980},{"cveId":3984,"releaseId":31,"cycle":32,"description":3985,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3986,"url":3987},"CVE-2025-39955","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().\n\nsyzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk\nin the TCP_ESTABLISHED state. [0]\n\nsyzbot reused the server-side TCP Fast Open socket as a new client before\nthe TFO socket completes 3WHS:\n\n  1. accept()\n  2. connect(AF_UNSPEC)\n  3. connect() to another destination\n\nAs of accept(), sk->sk_state is TCP_SYN_RECV, and tcp_disconnect() changes\nit t","2025-10-09T10:15:36.22+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39955",{"cveId":3984,"releaseId":17,"cycle":18,"description":3985,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3986,"url":3987},{"cveId":3984,"releaseId":25,"cycle":26,"description":3985,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3986,"url":3987},{"cveId":3991,"releaseId":25,"cycle":26,"description":3992,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3993,"url":3994},"CVE-2023-53683","In the Linux kernel, the following vulnerability has been resolved:\n\nfs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()\n\nsyzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for\ncrafted filesystem image can contain bogus length. There conditions are\nnot kernel bugs that can justify kernel to panic.","2025-10-07T16:15:52.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53683",{"cveId":3991,"releaseId":17,"cycle":18,"description":3992,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":3993,"url":3994},{"cveId":3997,"releaseId":17,"cycle":18,"description":3998,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3999,"url":4000},"CVE-2023-53680","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL\n\nOPDESC() simply indexes into nfsd4_ops[] by the op's operation\nnumber, without range checking that value. It assumes callers are\ncareful to avoid calling it with an out-of-bounds opnum value.\n\nnfsd4_decode_compound() is not so careful, and can invoke OPDESC()\nwith opnum set to OP_ILLEGAL, which is 10044 -- well beyond the end\nof nfsd4_ops[].","2025-10-07T16:15:52.16+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53680",{"cveId":3997,"releaseId":25,"cycle":26,"description":3998,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":3999,"url":4000},{"cveId":4003,"releaseId":31,"cycle":32,"description":4004,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":4005,"url":4006},"CVE-2023-53679","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt7601u: fix an integer underflow\n\nFix an integer underflow that leads to a null pointer dereference in\n'mt7601u_rx_skb_from_seg()'. The variable 'dma_len' in the URB packet\ncould be manipulated, which could trigger an integer underflow of\n'seg_len' in 'mt7601u_rx_process_seg()'. This underflow subsequently\ncauses the 'bad_frame' checks in 'mt7601u_rx_skb_from_seg()' to be\nbypassed, eventually leading to a dereference of ","2025-10-07T16:15:52.037+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53679",{"cveId":4003,"releaseId":17,"cycle":18,"description":4004,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":4005,"url":4006},{"cveId":4003,"releaseId":25,"cycle":26,"description":4004,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":4005,"url":4006},{"cveId":4010,"releaseId":31,"cycle":32,"description":4011,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4012,"url":4013},"CVE-2023-53676","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show()\n\nThe function lio_target_nacl_info_show() uses sprintf() in a loop to print\ndetails for every iSCSI connection in a session without checking for the\nbuffer length. With enough iSCSI connections it's possible to overflow the\nbuffer provided by configfs and corrupt the memory.\n\nThis patch replaces sprintf() with sysfs_emit_at() that checks for buffer\nboundrie","2025-10-07T16:15:51.653+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53676",{"cveId":4010,"releaseId":25,"cycle":26,"description":4011,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4012,"url":4013},{"cveId":4010,"releaseId":17,"cycle":18,"description":4011,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4012,"url":4013},{"cveId":4017,"releaseId":31,"cycle":32,"description":4018,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4019,"url":4020},"CVE-2023-53675","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ses: Fix possible desc_ptr out-of-bounds accesses\n\nSanitize possible desc_ptr out-of-bounds accesses in\nses_enclosure_data_process().","2025-10-07T16:15:51.503+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53675",{"cveId":4017,"releaseId":25,"cycle":26,"description":4018,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4019,"url":4020},{"cveId":4017,"releaseId":17,"cycle":18,"description":4018,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4019,"url":4020},{"cveId":4024,"releaseId":17,"cycle":18,"description":4025,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4026,"url":4027},"CVE-2023-53651","In the Linux kernel, the following vulnerability has been resolved:\n\nInput: exc3000 - properly stop timer on shutdown\n\nWe need to stop the timer on driver unbind or probe failures, otherwise\nwe get UAF\u002FOops.","2025-10-07T16:15:48.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53651",{"cveId":4029,"releaseId":31,"cycle":32,"description":4030,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":4031,"url":4032},"CVE-2023-53635","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: fix wrong ct->timeout value\n\n(struct nf_conn)->timeout is an interval before the conntrack\nconfirmed.  After confirmed, it becomes a timestamp.\n\nIt is observed that timeout of an unconfirmed conntrack:\n- Set by calling ctnetlink_change_timeout(). As a result,\n  `nfct_time_stamp` was wrongly added to `ct->timeout` twice.\n- Get by calling ctnetlink_dump_timeout(). As a result,\n  `nfct_time_stamp` was wrongly","2025-10-07T16:15:46.643+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53635",{"cveId":4029,"releaseId":17,"cycle":18,"description":4030,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":4031,"url":4032},{"cveId":4029,"releaseId":25,"cycle":26,"description":4030,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":4031,"url":4032},{"cveId":4036,"releaseId":31,"cycle":32,"description":4037,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4038,"url":4039},"CVE-2023-53627","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list\n\nWhen freeing slots in function slot_complete_v3_hw(), it is possible that\nsas_dev.list is being traversed elsewhere, and it may trigger a NULL\npointer exception, such as follows:\n\n==>cq thread                    ==>scsi_eh_6\n\n                                ==>scsi_error_handler()\n\t\t\t\t  ==>sas_eh_handle_sas_errors()\n\t\t\t\t    ==>sas_scsi_find_task()\n\t\t","2025-10-07T16:15:45.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53627",{"cveId":4036,"releaseId":17,"cycle":18,"description":4037,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4038,"url":4039},{"cveId":4036,"releaseId":25,"cycle":26,"description":4037,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4038,"url":4039},{"cveId":4043,"releaseId":31,"cycle":32,"description":4044,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4045,"url":4046},"CVE-2023-53619","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: Avoid nf_ct_helper_hash uses after free\n\nIf nf_conntrack_init_start() fails (for example due to a\nregister_nf_conntrack_bpf() failure), the nf_conntrack_helper_fini()\nclean-up path frees the nf_ct_helper_hash map.\n\nWhen built with NF_CONNTRACK=y, further netfilter modules (e.g:\nnetfilter_conntrack_ftp) can still be loaded and call\nnf_conntrack_helpers_register(), independently of whether nf_conntrack\niniti","2025-10-07T16:15:44.473+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53619",{"cveId":4043,"releaseId":25,"cycle":26,"description":4044,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4045,"url":4046},{"cveId":4043,"releaseId":17,"cycle":18,"description":4044,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4045,"url":4046},{"cveId":4050,"releaseId":17,"cycle":18,"description":4051,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4052,"url":4053},"CVE-2022-50555","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix a null-ptr-deref in tipc_topsrv_accept\n\nsyzbot found a crash in tipc_topsrv_accept:\n\n  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n  Workqueue: tipc_rcv tipc_topsrv_accept\n  RIP: 0010:kernel_accept+0x22d\u002F0x350 net\u002Fsocket.c:3487\n  Call Trace:\n   \u003CTASK>\n   tipc_topsrv_accept+0x197\u002F0x280 net\u002Ftipc\u002Ftopsrv.c:460\n   process_one_work+0x991\u002F0x1610 kernel\u002Fworkqueue.c:2289\n   worker_thread+0x665\u002F0x1080","2025-10-07T16:15:43.85+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50555",{"cveId":4055,"releaseId":17,"cycle":18,"description":4056,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4057,"url":4058},"CVE-2022-50552","In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: use quiesced elevator switch when reinitializing queues\n\nThe hctx's run_work may be racing with the elevator switch when\nreinitializing hardware queues. The queue is merely frozen in this\ncontext, but that only prevents requests from allocating and doesn't\nstop the hctx work from running. The work may get an elevator pointer\nthat's being torn down, and can result in use-after-free errors and\nkernel panics (example below","2025-10-07T16:15:41.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50552",{"cveId":4060,"releaseId":31,"cycle":32,"description":4061,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4062,"url":4063},"CVE-2022-50518","In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Fix locking in pdc_iodc_print() firmware call\n\nUtilize pdc_lock spinlock to protect parallel modifications of the\niodc_dbuf[] buffer, check length to prevent buffer overflow of\niodc_dbuf[], drop the iodc_retbuf[] buffer and fix some wrong\nindentings.","2025-10-07T16:15:35.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50518",{"cveId":4060,"releaseId":17,"cycle":18,"description":4061,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4062,"url":4063},{"cveId":4060,"releaseId":25,"cycle":26,"description":4061,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4062,"url":4063},{"cveId":4067,"releaseId":31,"cycle":32,"description":4068,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4069,"url":4070},"CVE-2023-53616","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount\n\nsyzbot found an invalid-free in diUnmount:\n\nBUG: KASAN: double-free in slab_free mm\u002Fslub.c:3661 [inline]\nBUG: KASAN: double-free in __kmem_cache_free+0x71\u002F0x110 mm\u002Fslub.c:3674\nFree of addr ffff88806f410000 by task syz-executor131\u002F3632\n\n CPU: 0 PID: 3632 Comm: syz-executor131 Not tainted 6.1.0-rc7-syzkaller-00012-gca57f02295f1 #0\n Hardware name: Google Google Compute ","2025-10-04T16:15:58.46+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53616",{"cveId":4067,"releaseId":25,"cycle":26,"description":4068,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4069,"url":4070},{"cveId":4067,"releaseId":17,"cycle":18,"description":4068,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4069,"url":4070},{"cveId":4074,"releaseId":17,"cycle":18,"description":4075,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4076,"url":4077},"CVE-2023-53615","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix deletion race condition\n\nSystem crash when using debug kernel due to link list corruption. The cause\nof the link list corruption is due to session deletion was allowed to queue\nup twice.  Here's the internal trace that show the same port was allowed to\ndouble queue for deletion on different cpu.\n\n20808683956 015 qla2xxx [0000:13:00.1]-e801:4: Scheduling sess ffff93ebf9306800 for deletion 50:06:0e:80:12:48:ff:","2025-10-04T16:15:58.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53615",{"cveId":4074,"releaseId":25,"cycle":26,"description":4075,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4076,"url":4077},{"cveId":4080,"releaseId":31,"cycle":32,"description":4081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4082,"url":4083},"CVE-2023-53608","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()\n\nThe finalization of nilfs_segctor_thread() can race with\nnilfs_segctor_kill_thread() which terminates that thread, potentially\ncausing a use-after-free BUG as KASAN detected.\n\nAt the end of nilfs_segctor_thread(), it assigns NULL to \"sc_task\" member\nof \"struct nilfs_sc_info\" to indicate the thread has finished, and then\nnotifies nilfs_segctor_kill_thre","2025-10-04T16:15:57.527+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53608",{"cveId":4080,"releaseId":25,"cycle":26,"description":4081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4082,"url":4083},{"cveId":4080,"releaseId":17,"cycle":18,"description":4081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4082,"url":4083},{"cveId":4087,"releaseId":31,"cycle":32,"description":4088,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4089,"url":4090},"CVE-2023-53596","In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: base: Free devm resources when unregistering a device\n\nIn the current code, devres_release_all() only gets called if the device\nhas a bus and has been probed.\n\nThis leads to issues when using bus-less or driver-less devices where\nthe device might never get freed if a managed resource holds a reference\nto the device. This is happening in the DRM framework for example.\n\nWe should thus call devres_release_all() in the dev","2025-10-04T16:15:56.153+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53596",{"cveId":4087,"releaseId":25,"cycle":26,"description":4088,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4089,"url":4090},{"cveId":4087,"releaseId":17,"cycle":18,"description":4088,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4089,"url":4090},{"cveId":4094,"releaseId":31,"cycle":32,"description":4095,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4096,"url":4097},"CVE-2023-53589","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don't trust firmware n_channels\n\nIf the firmware sends us a corrupted MCC response with\nn_channels much larger than the command response can be,\nwe might copy far too much (uninitialized) memory and\neven crash if the n_channels is large enough to make it\nrun out of the one page allocated for the FW response.\n\nFix that by checking the lengths. Doing a \u003C comparison\nwould be sufficient, but the firmware should ","2025-10-04T16:15:55.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53589",{"cveId":4094,"releaseId":17,"cycle":18,"description":4095,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4096,"url":4097},{"cveId":4094,"releaseId":25,"cycle":26,"description":4095,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4096,"url":4097},{"cveId":4101,"releaseId":31,"cycle":32,"description":4102,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4103,"url":4104},"CVE-2023-53587","In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Sync IRQ works before buffer destruction\n\nIf something was written to the buffer just before destruction,\nit may be possible (maybe not in a real system, but it did\nhappen in ARCH=um with time-travel) to destroy the ringbuffer\nbefore the IRQ work ran, leading this KASAN report (or a crash\nwithout KASAN):\n\n    BUG: KASAN: slab-use-after-free in irq_work_run_list+0x11a\u002F0x13a\n    Read of size 8 at addr 000000006d640a4","2025-10-04T16:15:55.06+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53587",{"cveId":4101,"releaseId":25,"cycle":26,"description":4102,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4103,"url":4104},{"cveId":4101,"releaseId":17,"cycle":18,"description":4102,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4103,"url":4104},{"cveId":4108,"releaseId":17,"cycle":18,"description":4109,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4110,"url":4111},"CVE-2023-53586","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Fix multiple LUN_RESET handling\n\nThis fixes a bug where an initiator thinks a LUN_RESET has cleaned up\nrunning commands when it hasn't. The bug was added in commit 51ec502a3266\n(\"target: Delete tmr from list before processing\").\n\nThe problem occurs when:\n\n 1. We have N I\u002FO cmds running in the target layer spread over 2 sessions.\n\n 2. The initiator sends a LUN_RESET for each session.\n\n 3. session1's LUN_RESET loops","2025-10-04T16:15:54.837+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53586",{"cveId":4108,"releaseId":25,"cycle":26,"description":4109,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4110,"url":4111},{"cveId":4114,"releaseId":17,"cycle":18,"description":4115,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4116,"url":4117},"CVE-2023-53577","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, cpumap: Make sure kthread is running before map update returns\n\nThe following warning was reported when running stress-mode enabled\nxdp_redirect_cpu with some RT threads:\n\n  ------------[ cut here ]------------\n  WARNING: CPU: 4 PID: 65 at kernel\u002Fbpf\u002Fcpumap.c:135\n  CPU: 4 PID: 65 Comm: kworker\u002F4:1 Not tainted 6.5.0-rc2+ #1\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)\n  Workqueue: events cpu_map_kthread_stop\n  RI","2025-10-04T16:15:53.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53577",{"cveId":4119,"releaseId":17,"cycle":18,"description":4120,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4121,"url":4122},"CVE-2023-53560","In the Linux kernel, the following vulnerability has been resolved:\n\ntracing\u002Fhistograms: Add histograms to hist_vars if they have referenced variables\n\nHist triggers can have referenced variables without having direct\nvariables fields. This can be the case if referenced variables are added\nfor trigger actions. In this case the newly added references will not\nhave field variables. Not taking such referenced variables into\nconsideration can result in a bug where it would be possible to remove\nhist","2025-10-04T16:15:51.397+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53560",{"cveId":4124,"releaseId":31,"cycle":32,"description":4125,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4126,"url":4127},"CVE-2023-53559","In the Linux kernel, the following vulnerability has been resolved:\n\nip_vti: fix potential slab-use-after-free in decode_session6\n\nWhen ip_vti device is set to the qdisc of the sfb type, the cb field\nof the sent skb may be modified during enqueuing. Then,\nslab-use-after-free may occur when ip_vti device sends IPv6 packets.\nAs commit f855691975bb (\"xfrm6: Fix the nexthdr offset in\n_decode_session6.\") showed, xfrm_decode_session was originally intended\nonly for the receive path. IP6CB(skb)->nhoff ","2025-10-04T16:15:51.28+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53559",{"cveId":4124,"releaseId":25,"cycle":26,"description":4125,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4126,"url":4127},{"cveId":4124,"releaseId":17,"cycle":18,"description":4125,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4126,"url":4127},{"cveId":4131,"releaseId":31,"cycle":32,"description":4132,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4133,"url":4134},"CVE-2023-53556","In the Linux kernel, the following vulnerability has been resolved:\n\niavf: Fix use-after-free in free_netdev\n\nWe do netif_napi_add() for all allocated q_vectors[], but potentially\ndo netif_napi_del() for part of them, then kfree q_vectors and leave\ninvalid pointers at dev->napi_list.\n\nReproducer:\n\n  [root@host ~]# cat repro.sh\n  #!\u002Fbin\u002Fbash\n\n  pf_dbsf=\"0000:41:00.0\"\n  vf0_dbsf=\"0000:41:02.0\"\n  g_pids=()\n\n  function do_set_numvf()\n  {\n      echo 2 >\u002Fsys\u002Fbus\u002Fpci\u002Fdevices\u002F${pf_dbsf}\u002Fsriov_numvfs\n   ","2025-10-04T16:15:50.927+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53556",{"cveId":4131,"releaseId":17,"cycle":18,"description":4132,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4133,"url":4134},{"cveId":4131,"releaseId":25,"cycle":26,"description":4132,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4133,"url":4134},{"cveId":4138,"releaseId":25,"cycle":26,"description":4139,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4140,"url":4141},"CVE-2023-53554","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: ks7010: potential buffer overflow in ks_wlan_set_encode_ext()\n\nThe \"exc->key_len\" is a u16 that comes from the user.  If it's over\nIW_ENCODING_TOKEN_MAX (64) that could lead to memory corruption.","2025-10-04T16:15:50.697+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53554",{"cveId":4138,"releaseId":17,"cycle":18,"description":4139,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4140,"url":4141},{"cveId":4144,"releaseId":25,"cycle":26,"description":4145,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4146,"url":4147},"CVE-2023-53545","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: unmap and remove csa_va properly\n\nRoot PD BO should be reserved before unmap and remove\na bo_va from VM otherwise lockdep will complain.\n\nv2: check fpriv->csa_va is not NULL instead of amdgpu_mcbp (christian)\n\n[14616.936827] WARNING: CPU: 6 PID: 1711 at drivers\u002Fgpu\u002Fdrm\u002Famd\u002Famdgpu\u002Famdgpu_vm.c:1762 amdgpu_vm_bo_del+0x399\u002F0x3f0 [amdgpu]\n[14616.937096] Call Trace:\n[14616.937097]  \u003CTASK>\n[14616.937102]  amdgpu_driver_pos","2025-10-04T16:15:49.637+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53545",{"cveId":4144,"releaseId":17,"cycle":18,"description":4145,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4146,"url":4147},{"cveId":4144,"releaseId":31,"cycle":32,"description":4145,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4146,"url":4147},{"cveId":4151,"releaseId":31,"cycle":32,"description":4152,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4153,"url":4154},"CVE-2023-53540","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: reject auth\u002Fassoc to AP with our address\n\nIf the AP uses our own address as its MLD address or BSSID, then\nclearly something's wrong. Reject such connections so we don't\ntry and fail later.","2025-10-04T16:15:49.05+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53540",{"cveId":4151,"releaseId":17,"cycle":18,"description":4152,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4153,"url":4154},{"cveId":4151,"releaseId":25,"cycle":26,"description":4152,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4153,"url":4154},{"cveId":4158,"releaseId":31,"cycle":32,"description":4159,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4160,"url":4161},"CVE-2023-53539","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Frxe: Fix incomplete state save in rxe_requester\n\nIf a send packet is dropped by the IP layer in rxe_requester()\nthe call to rxe_xmit_packet() can fail with err == -EAGAIN.\nTo recover, the state of the wqe is restored to the state before\nthe packet was sent so it can be resent. However, the routines\nthat save and restore the state miss a significnt part of the\nvariable state in the wqe, the dma struct which is used to proce","2025-10-04T16:15:48.93+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53539",{"cveId":4158,"releaseId":17,"cycle":18,"description":4159,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4160,"url":4161},{"cveId":4158,"releaseId":25,"cycle":26,"description":4159,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4160,"url":4161},{"cveId":4165,"releaseId":31,"cycle":32,"description":4166,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4167,"url":4168},"CVE-2023-53535","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmgenet: Add a check for oversized packets\n\nOccasionnaly we may get oversized packets from the hardware which\nexceed the nomimal 2KiB buffer size we allocate SKBs with. Add an early\ncheck which drops the packet to avoid invoking skb_over_panic() and move\non to processing the next packet.","2025-10-04T16:15:48.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53535",{"cveId":4165,"releaseId":25,"cycle":26,"description":4166,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4167,"url":4168},{"cveId":4165,"releaseId":17,"cycle":18,"description":4166,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4167,"url":4168},{"cveId":4172,"releaseId":17,"cycle":18,"description":4173,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4174,"url":4175},"CVE-2022-50492","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fmsm: fix use-after-free on probe deferral\n\nThe bridge counter was never reset when tearing down the DRM device so\nthat stale pointers to deallocated structures would be accessed on the\nnext tear down (e.g. after a second late bind deferral).\n\nGiven enough bridges and a few probe deferrals this could currently also\nlead to data beyond the bridge array being corrupted.\n\nPatchwork: https:\u002F\u002Fpatchwork.freedesktop.org\u002Fpatch\u002F50266","2025-10-04T16:15:46.19+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50492",{"cveId":4172,"releaseId":25,"cycle":26,"description":4173,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4174,"url":4175},{"cveId":4172,"releaseId":31,"cycle":32,"description":4173,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4174,"url":4175},{"cveId":4179,"releaseId":31,"cycle":32,"description":4180,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4181,"url":4182},"CVE-2025-39953","In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: split cgroup_destroy_wq into 3 workqueues\n\nA hung task can occur during [1] LTP cgroup testing when repeatedly\nmounting\u002Funmounting perf_event and net_prio controllers with\nsystemd.unified_cgroup_hierarchy=1. The hang manifests in\ncgroup_lock_and_drain_offline() during root destruction.\n\nRelated case:\ncgroup_fj_function_perf_event cgroup_fj_function.sh perf_event\ncgroup_fj_function_net_prio cgroup_fj_function.sh net_prio","2025-10-04T08:15:48.627+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39953",{"cveId":4179,"releaseId":17,"cycle":18,"description":4180,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4181,"url":4182},{"cveId":4179,"releaseId":25,"cycle":26,"description":4180,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4181,"url":4182},{"cveId":4186,"releaseId":31,"cycle":32,"description":4187,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4188,"url":4189},"CVE-2025-39952","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: avoid buffer overflow in WID string configuration\n\nFix the following copy overflow warning identified by Smatch checker.\n\n drivers\u002Fnet\u002Fwireless\u002Fmicrochip\u002Fwilc1000\u002Fwlan_cfg.c:184 wilc_wlan_parse_response_frame()\n        error: '__memcpy()' 'cfg->s[i]->str' copy overflow (512 vs 65537)\n\nThis patch introduces size check before accessing the memory buffer.\nThe checks are base on the WID type of received data from th","2025-10-04T08:15:48.507+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39952",{"cveId":4186,"releaseId":17,"cycle":18,"description":4187,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4188,"url":4189},{"cveId":4186,"releaseId":25,"cycle":26,"description":4187,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4188,"url":4189},{"cveId":4193,"releaseId":17,"cycle":18,"description":4194,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4195,"url":4196},"CVE-2025-39949","In the Linux kernel, the following vulnerability has been resolved:\n\nqed: Don't collect too many protection override GRC elements\n\nIn the protection override dump path, the firmware can return far too\nmany GRC elements, resulting in attempting to write past the end of the\npreviously-kmalloc'ed dump buffer.\n\nThis will result in a kernel panic with reason:\n\n BUG: unable to handle kernel paging request at ADDRESS\n\nwhere \"ADDRESS\" is just past the end of the protection override dump\nbuffer. The star","2025-10-04T08:15:48.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39949",{"cveId":4198,"releaseId":31,"cycle":32,"description":4199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4200,"url":4201},"CVE-2025-39945","In the Linux kernel, the following vulnerability has been resolved:\n\ncnic: Fix use-after-free bugs in cnic_delete_task\n\nThe original code uses cancel_delayed_work() in cnic_cm_stop_bnx2x_hw(),\nwhich does not guarantee that the delayed work item 'delete_task' has\nfully completed if it was already running. Additionally, the delayed work\nitem is cyclic, the flush_workqueue() in cnic_cm_stop_bnx2x_hw() only\nblocks and waits for work items that were already queued to the\nworkqueue prior to its invoca","2025-10-04T08:15:47.613+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39945",{"cveId":4198,"releaseId":17,"cycle":18,"description":4199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4200,"url":4201},{"cveId":4198,"releaseId":25,"cycle":26,"description":4199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4200,"url":4201},{"cveId":4205,"releaseId":17,"cycle":18,"description":4206,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":4207,"url":4208},"CVE-2025-39933","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: let recv_done verify data_offset, data_length and remaining_data_length\n\nThis is inspired by the related server fixes.","2025-10-04T08:15:46.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39933",{"cveId":4210,"releaseId":17,"cycle":18,"description":4211,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4212,"url":4213},"CVE-2025-39932","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)\n\nIn smbd_destroy() we may destroy the memory so we better\nwait until post_send_credits_work is no longer pending\nand will never be started again.\n\nI actually just hit the case using rxe:\n\nWARNING: CPU: 0 PID: 138 at drivers\u002Finfiniband\u002Fsw\u002Frxe\u002Frxe_verbs.c:1032 rxe_post_recv+0x1ee\u002F0x480 [rdma_rxe]\n...\n[ 5305.686979] [    T138]  smbd_post_recv+0x4","2025-10-04T08:15:45.953+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39932",{"cveId":4215,"releaseId":31,"cycle":32,"description":4216,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4217,"url":4218},"CVE-2025-39931","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Set merge to zero early in af_alg_sendmsg\n\nIf an error causes af_alg_sendmsg to abort, ctx->merge may contain\na garbage value from the previous loop.  This may then trigger a\ncrash on the next entry into af_alg_sendmsg when it attempts to do\na merge that can't be done.\n\nFix this by setting ctx->merge to zero near the start of the loop.","2025-10-04T08:15:45.827+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39931",{"cveId":4215,"releaseId":17,"cycle":18,"description":4216,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4217,"url":4218},{"cveId":4215,"releaseId":25,"cycle":26,"description":4216,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4217,"url":4218},{"cveId":4222,"releaseId":17,"cycle":18,"description":4223,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4224,"url":4225},"CVE-2025-39929","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path\n\nDuring tests of another unrelated patch I was able to trigger this\nerror: Objects remaining on __kmem_cache_shutdown()","2025-10-04T08:15:44.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39929",{"cveId":4227,"releaseId":31,"cycle":32,"description":4228,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4229,"url":4230},"CVE-2023-53518","In the Linux kernel, the following vulnerability has been resolved:\n\nPM \u002F devfreq: Fix leak in devfreq_dev_release()\n\nsrcu_init_notifier_head() allocates resources that need to be released\nwith a srcu_cleanup_notifier_head() call.\n\nReported by kmemleak.","2025-10-01T12:15:56.027+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53518",{"cveId":4227,"releaseId":25,"cycle":26,"description":4228,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4229,"url":4230},{"cveId":4227,"releaseId":17,"cycle":18,"description":4228,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4229,"url":4230},{"cveId":4234,"releaseId":31,"cycle":32,"description":4235,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4236,"url":4237},"CVE-2023-53517","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: do not update mtu if msg_max is too small in mtu negotiation\n\nWhen doing link mtu negotiation, a malicious peer may send Activate msg\nwith a very small mtu, e.g. 4 in Shuang's testing, without checking for\nthe minimum mtu, l->mtu will be set to 4 in tipc_link_proto_rcv(), then\nn->links[bearer_id].mtu is set to 4294967228, which is a overflow of\n'4 - INT_H_SIZE - EMSG_OVERHEAD' in tipc_link_mss().\n\nWith tipc_link.mtu = 4, ","2025-10-01T12:15:55.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53517",{"cveId":4234,"releaseId":17,"cycle":18,"description":4235,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4236,"url":4237},{"cveId":4234,"releaseId":25,"cycle":26,"description":4235,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4236,"url":4237},{"cveId":4241,"releaseId":31,"cycle":32,"description":4242,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4243,"url":4244},"CVE-2023-53510","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix handling of lrbp->cmd\n\nufshcd_queuecommand() may be called two times in a row for a SCSI command\nbefore it is completed. Hence make the following changes:\n\n - In the functions that submit a command, do not check the old value of\n   lrbp->cmd nor clear lrbp->cmd in error paths.\n\n - In ufshcd_release_scsi_cmd(), do not clear lrbp->cmd.\n\nSee also scsi_send_eh_cmnd().\n\nThis commit prevents that the following ap","2025-10-01T12:15:54.88+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53510",{"cveId":4241,"releaseId":17,"cycle":18,"description":4242,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4243,"url":4244},{"cveId":4241,"releaseId":25,"cycle":26,"description":4242,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4243,"url":4244},{"cveId":4248,"releaseId":31,"cycle":32,"description":4249,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4250,"url":4251},"CVE-2023-53506","In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Do not bother merging very long extents\n\nWhen merging very long extents we try to push as much length as possible\nto the first extent. However this is unnecessarily complicated and not\nreally worth the trouble. Furthermore there was a bug in the logic\nresulting in corrupting extents in the file as syzbot reproducer shows.\nSo just don't bother with the merging of extents that are too long\ntogether.","2025-10-01T12:15:54.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53506",{"cveId":4248,"releaseId":25,"cycle":26,"description":4249,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4250,"url":4251},{"cveId":4248,"releaseId":17,"cycle":18,"description":4249,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4250,"url":4251},{"cveId":4255,"releaseId":31,"cycle":32,"description":4256,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4257,"url":4258},"CVE-2023-53500","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix slab-use-after-free in decode_session6\n\nWhen the xfrm device is set to the qdisc of the sfb type, the cb field\nof the sent skb may be modified during enqueuing. Then,\nslab-use-after-free may occur when the xfrm device sends IPv6 packets.\n\nThe stack information is as follows:\nBUG: KASAN: slab-use-after-free in decode_session6+0x103f\u002F0x1890\nRead of size 1 at addr ffff8881111458ef by task swapper\u002F3\u002F0\nCPU: 3 PID: 0 Comm: ","2025-10-01T12:15:53.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53500",{"cveId":4255,"releaseId":17,"cycle":18,"description":4256,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4257,"url":4258},{"cveId":4255,"releaseId":25,"cycle":26,"description":4256,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4257,"url":4258},{"cveId":4262,"releaseId":17,"cycle":18,"description":4263,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":4264,"url":4265},"CVE-2023-53499","In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Fix error unwinding of XDP initialization\n\nWhen initializing XDP in virtnet_open(), some rq xdp initialization\nmay hit an error causing net device open failed. However, previous\nrqs have already initialized XDP and enabled NAPI, which is not the\nexpected behavior. Need to roll back the previous rq initialization\nto avoid leaks in error unwinding of init code.\n\nAlso extract helper functions of disable and enable queu","2025-10-01T12:15:53.35+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53499",{"cveId":4267,"releaseId":31,"cycle":32,"description":4268,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4269,"url":4270},"CVE-2023-53491","In the Linux kernel, the following vulnerability has been resolved:\n\nstart_kernel: Add __no_stack_protector function attribute\n\nBack during the discussion of\ncommit a9a3ed1eff36 (\"x86: Fix early boot crash on gcc-10, third try\")\nwe discussed the need for a function attribute to control the omission\nof stack protectors on a per-function basis; at the time Clang had\nsupport for no_stack_protector but GCC did not. This was fixed in\ngcc-11. Now that the function attribute is available, let's start u","2025-10-01T12:15:52.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53491",{"cveId":4267,"releaseId":17,"cycle":18,"description":4268,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4269,"url":4270},{"cveId":4267,"releaseId":25,"cycle":26,"description":4268,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4269,"url":4270},{"cveId":4274,"releaseId":31,"cycle":32,"description":4275,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4276,"url":4277},"CVE-2023-53485","In the Linux kernel, the following vulnerability has been resolved:\n\nfs: jfs: Fix UBSAN: array-index-out-of-bounds in dbAllocDmapLev\n\nSyzkaller reported the following issue:\n\nUBSAN: array-index-out-of-bounds in fs\u002Fjfs\u002Fjfs_dmap.c:1965:6\nindex -84 is out of range for type 's8[341]' (aka 'signed char[341]')\nCPU: 1 PID: 4995 Comm: syz-executor146 Not tainted 6.4.0-rc6-syzkaller-00037-gb6dad5178cea #0\nHardware name: Google Google Compute Engine\u002FGoogle Compute Engine, BIOS Google 05\u002F27\u002F2023\nCall Trace","2025-10-01T12:15:51.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53485",{"cveId":4274,"releaseId":25,"cycle":26,"description":4275,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4276,"url":4277},{"cveId":4274,"releaseId":17,"cycle":18,"description":4275,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4276,"url":4277},{"cveId":4281,"releaseId":31,"cycle":32,"description":4282,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4283,"url":4284},"CVE-2023-53484","In the Linux kernel, the following vulnerability has been resolved:\n\nlib: cpu_rmap: Avoid use after free on rmap->obj array entries\n\nWhen calling irq_set_affinity_notifier() with NULL at the notify\nargument, it will cause freeing of the glue pointer in the\ncorresponding array entry but will leave the pointer in the array. A\nsubsequent call to free_irq_cpu_rmap() will try to free this entry again\nleading to possible use after free.\n\nFix that by setting NULL to the array entry and checking that we","2025-10-01T12:15:51.18+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53484",{"cveId":4281,"releaseId":25,"cycle":26,"description":4282,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4283,"url":4284},{"cveId":4281,"releaseId":17,"cycle":18,"description":4282,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4283,"url":4284},{"cveId":4288,"releaseId":31,"cycle":32,"description":4289,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4290,"url":4291},"CVE-2023-53481","In the Linux kernel, the following vulnerability has been resolved:\n\nubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed\n\nFollowing process will trigger an infinite loop in ubi_wl_put_peb():\n\n\tubifs_bgt\t\tubi_bgt\nubifs_leb_unmap\n  ubi_leb_unmap\n    ubi_eba_unmap_leb\n      ubi_wl_put_peb\twear_leveling_worker\n                          e1 = rb_entry(rb_first(&ubi->used)\n\t\t\t  e2 = get_peb_for_wl(ubi)\n\t\t\t  ubi_io_read_vid_hdr  \u002F\u002F return err (flash fault)\n\t\t\t  out_error:\n\t\t\t    ubi->m","2025-10-01T12:15:50.743+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53481",{"cveId":4288,"releaseId":25,"cycle":26,"description":4289,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4290,"url":4291},{"cveId":4288,"releaseId":17,"cycle":18,"description":4289,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4290,"url":4291},{"cveId":4295,"releaseId":31,"cycle":32,"description":4296,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4297,"url":4298},"CVE-2023-53454","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Correct devm device reference for hidinput input_dev name\n\nReference the HID device rather than the input device for the devm\nallocation of the input_dev name. Referencing the input_dev would lead to a\nuse-after-free when the input_dev was unregistered and subsequently fires a\nuevent that depends on the name. At the point of firing the uevent, the\nname would be freed by devres management.\n\nUse devm_kasprintf to","2025-10-01T12:15:43.953+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53454",{"cveId":4295,"releaseId":25,"cycle":26,"description":4296,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4297,"url":4298},{"cveId":4295,"releaseId":17,"cycle":18,"description":4296,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4297,"url":4298},{"cveId":4302,"releaseId":31,"cycle":32,"description":4303,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4304,"url":4305},"CVE-2022-50440","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvmwgfx: Validate the box size for the snooped cursor\n\nInvalid userspace dma surface copies could potentially overflow\nthe memcpy from the surface to the snooped image leading to crashes.\nTo fix it the dimensions of the copybox have to be validated\nagainst the expected size of the snooped cursor.","2025-10-01T12:15:36.133+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50440",{"cveId":4302,"releaseId":25,"cycle":26,"description":4303,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4304,"url":4305},{"cveId":4302,"releaseId":17,"cycle":18,"description":4303,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4304,"url":4305},{"cveId":4309,"releaseId":31,"cycle":32,"description":4310,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4311,"url":4312},"CVE-2022-50437","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fmsm\u002Fhdmi: fix memory corruption with too many bridges\n\nAdd the missing sanity check on the bridge counter to avoid corrupting\ndata beyond the fixed-sized bridge array in case there are ever more\nthan eight bridges.\n\nPatchwork: https:\u002F\u002Fpatchwork.freedesktop.org\u002Fpatch\u002F502670\u002F","2025-10-01T12:15:35.693+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50437",{"cveId":4309,"releaseId":25,"cycle":26,"description":4310,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4311,"url":4312},{"cveId":4309,"releaseId":17,"cycle":18,"description":4310,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4311,"url":4312},{"cveId":4316,"releaseId":31,"cycle":32,"description":4317,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4318,"url":4319},"CVE-2022-50432","In the Linux kernel, the following vulnerability has been resolved:\n\nkernfs: fix use-after-free in __kernfs_remove\n\nSyzkaller managed to trigger concurrent calls to\nkernfs_remove_by_name_ns() for the same file resulting in\na KASAN detected use-after-free. The race occurs when the root\nnode is freed during kernfs_drain().\n\nTo prevent this acquire an additional reference for the root\nof the tree that is removed before calling __kernfs_remove().\n\nFound by syzkaller with the following reproducer (sl","2025-10-01T12:15:34.977+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50432",{"cveId":4316,"releaseId":25,"cycle":26,"description":4317,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4318,"url":4319},{"cveId":4316,"releaseId":17,"cycle":18,"description":4317,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4318,"url":4319},{"cveId":4323,"releaseId":31,"cycle":32,"description":4324,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4325,"url":4326},"CVE-2025-39927","In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix race condition validating r_parent before applying state\n\nAdd validation to ensure the cached parent directory inode matches the\ndirectory info in MDS replies. This prevents client-side race conditions\nwhere concurrent operations (e.g. rename) cause r_parent to become stale\nbetween request initiation and reply processing, which could lead to\napplying state changes to incorrect directory inodes.\n\n[ idryomov: folded a k","2025-10-01T08:15:36.097+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39927",{"cveId":4323,"releaseId":17,"cycle":18,"description":4324,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4325,"url":4326},{"cveId":4323,"releaseId":25,"cycle":26,"description":4324,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4325,"url":4326},{"cveId":4330,"releaseId":17,"cycle":18,"description":4331,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4332,"url":4333},"CVE-2025-39913","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork.\n\nsyzbot reported the splat below. [0]\n\nThe repro does the following:\n\n  1. Load a sk_msg prog that calls bpf_msg_cork_bytes(msg, cork_bytes)\n  2. Attach the prog to a SOCKMAP\n  3. Add a socket to the SOCKMAP\n  4. Activate fault injection\n  5. Send data less than cork_bytes\n\nAt 5., the data is carried over to the next sendmsg() as it is\nsmalle","2025-10-01T08:15:34.39+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39913",{"cveId":4335,"releaseId":31,"cycle":32,"description":4336,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4337,"url":4338},"CVE-2025-39902","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fslub: avoid accessing metadata when pointer is invalid in object_err()\n\nobject_err() reports details of an object for further debugging, such as\nthe freelist pointer, redzone, etc. However, if the pointer is invalid,\nattempting to access object metadata can lead to a crash since it does\nnot point to a valid object.\n\nOne known path to the crash is when alloc_consistency_checks()\ndetermines the pointer to the allocated object ","2025-10-01T08:15:32.993+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39902",{"cveId":4335,"releaseId":17,"cycle":18,"description":4336,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4337,"url":4338},{"cveId":4335,"releaseId":25,"cycle":26,"description":4336,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4337,"url":4338},{"cveId":4342,"releaseId":31,"cycle":32,"description":4343,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4344,"url":4345},"CVE-2025-39901","In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: remove read access to debugfs files\n\nThe 'command' and 'netdev_ops' debugfs files are a legacy debugging\ninterface supported by the i40e driver since its early days by commit\n02e9c290814c (\"i40e: debugfs interface\").\n\nBoth of these debugfs files provide a read handler which is mostly useless,\nand which is implemented with questionable logic. They both use a static\n256 byte buffer which is initialized to the empty string. ","2025-10-01T08:15:32.86+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39901",{"cveId":4342,"releaseId":17,"cycle":18,"description":4343,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4344,"url":4345},{"cveId":4342,"releaseId":25,"cycle":26,"description":4343,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4344,"url":4345},{"cveId":4349,"releaseId":17,"cycle":18,"description":4350,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4351,"url":4352},"CVE-2024-58241","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Disable works on hci_unregister_dev\n\nThis make use of disable_work_* on hci_unregister_dev since the hci_dev is\nabout to be freed new submissions are not disarable.","2025-09-24T11:15:31.877+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58241",{"cveId":4354,"releaseId":17,"cycle":18,"description":4355,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4356,"url":4357},"CVE-2025-39873","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB\n\ncan_put_echo_skb() takes ownership of the SKB and it may be freed\nduring or after the call.\n\nHowever, xilinx_can xcan_write_frame() keeps using SKB after the call.\n\nFix that by only calling can_put_echo_skb() after the code is done\ntouching the SKB.\n\nThe tx_lock is held for the entire xcan_write_frame() execution and\nalso on the can_get_echo_skb() side ","2025-09-23T06:15:46.67+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39873",{"cveId":4359,"releaseId":31,"cycle":32,"description":4360,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":4361,"url":4362},"CVE-2025-39869","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: ti: edma: Fix memory allocation size for queue_priority_map\n\nFix a critical memory allocation bug in edma_setup_from_hw() where\nqueue_priority_map was allocated with insufficient memory. The code\ndeclared queue_priority_map as s8 (*)[2] (pointer to array of 2 s8),\nbut allocated memory using sizeof(s8) instead of the correct size.\n\nThis caused out-of-bounds memory writes when accessing:\n  queue_priority_map[i][0] = i;","2025-09-23T06:15:46.097+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39869",{"cveId":4359,"releaseId":17,"cycle":18,"description":4360,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":4361,"url":4362},{"cveId":4359,"releaseId":25,"cycle":26,"description":4360,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":4361,"url":4362},{"cveId":4366,"releaseId":31,"cycle":32,"description":4367,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4368,"url":4369},"CVE-2025-39866","In the Linux kernel, the following vulnerability has been resolved:\n\nfs: writeback: fix use-after-free in __mark_inode_dirty()\n\nAn use-after-free issue occurred when __mark_inode_dirty() get the\nbdi_writeback that was in the progress of switching.\n\nCPU: 1 PID: 562 Comm: systemd-random- Not tainted 6.6.56-gb4403bd46a8e #1\n......\npstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : __mark_inode_dirty+0x124\u002F0x418\nlr : __mark_inode_dirty+0x118\u002F0x418\nsp : ffffffc08c9dbbc0\n........\nCal","2025-09-19T16:15:45.657+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39866",{"cveId":4366,"releaseId":17,"cycle":18,"description":4367,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4368,"url":4369},{"cveId":4366,"releaseId":25,"cycle":26,"description":4367,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4368,"url":4369},{"cveId":4373,"releaseId":25,"cycle":26,"description":4374,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":4375,"url":4376},"CVE-2025-39860","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()\n\nsyzbot reported the splat below without a repro.\n\nIn the splat, a single thread calling bt_accept_dequeue() freed sk\nand touched it after that.\n\nThe root cause would be the racy l2cap_sock_cleanup_listen() call\nadded by the cited commit.\n\nbt_accept_dequeue() is called under lock_sock() except for\nl2cap_sock_release().\n\nTwo threads could see the same socket during the","2025-09-19T16:15:44.973+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39860",{"cveId":4373,"releaseId":17,"cycle":18,"description":4374,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":4375,"url":4376},{"cveId":4379,"releaseId":31,"cycle":32,"description":4380,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4381,"url":4382},"CVE-2025-39848","In the Linux kernel, the following vulnerability has been resolved:\n\nax25: properly unshare skbs in ax25_kiss_rcv()\n\nBernard Pidoux reported a regression apparently caused by commit\nc353e8983e0d (\"net: introduce per netns packet chains\").\n\nskb->dev becomes NULL and we crash in __netif_receive_skb_core().\n\nBefore above commit, different kind of bugs or corruptions could happen\nwithout a major crash.\n\nBut the root cause is that ax25_kiss_rcv() can queue\u002Fmangle input skb\nwithout checking if this sk","2025-09-19T16:15:43.64+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39848",{"cveId":4379,"releaseId":17,"cycle":18,"description":4380,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4381,"url":4382},{"cveId":4379,"releaseId":25,"cycle":26,"description":4380,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4381,"url":4382},{"cveId":4386,"releaseId":31,"cycle":32,"description":4387,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4388,"url":4389},"CVE-2025-39839","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: fix OOB read\u002Fwrite in network-coding decode\n\nbatadv_nc_skb_decode_packet() trusts coded_len and checks only against\nskb->len. XOR starts at sizeof(struct batadv_unicast_packet), reducing\npayload headroom, and the source skb length is not verified, allowing an\nout-of-bounds read and a small out-of-bounds write.\n\nValidate that coded_len fits within the payload area of both destination\nand source sk_buffs before XORing","2025-09-19T16:15:42.57+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39839",{"cveId":4386,"releaseId":17,"cycle":18,"description":4387,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4388,"url":4389},{"cveId":4386,"releaseId":25,"cycle":26,"description":4387,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4388,"url":4389},{"cveId":4393,"releaseId":31,"cycle":32,"description":4394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4395,"url":4396},"CVE-2023-53440","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix sysfs interface lifetime\n\nThe current nilfs2 sysfs support has issues with the timing of creation\nand deletion of sysfs entries, potentially leading to null pointer\ndereferences, use-after-free, and lockdep warnings.\n\nSome of the sysfs attributes for nilfs2 per-filesystem instance refer to\nmetadata file \"cpfile\", \"sufile\", or \"dat\", but\nnilfs_sysfs_create_device_group that creates those attributes is executed\nbefore","2025-09-18T16:15:48.197+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53440",{"cveId":4393,"releaseId":25,"cycle":26,"description":4394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4395,"url":4396},{"cveId":4393,"releaseId":17,"cycle":18,"description":4394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4395,"url":4396},{"cveId":4400,"releaseId":31,"cycle":32,"description":4401,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4402,"url":4403},"CVE-2023-53432","In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: net: fix use after free in fwnet_finish_incoming_packet()\n\nThe netif_rx() function frees the skb so we can't dereference it to\nsave the skb->len.","2025-09-18T16:15:47.2+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53432",{"cveId":4400,"releaseId":17,"cycle":18,"description":4401,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4402,"url":4403},{"cveId":4400,"releaseId":25,"cycle":26,"description":4401,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4402,"url":4403},{"cveId":4407,"releaseId":31,"cycle":32,"description":4408,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4409,"url":4410},"CVE-2023-53431","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ses: Handle enclosure with just a primary component gracefully\n\nThis reverts commit 3fe97ff3d949 (\"scsi: ses: Don't attach if enclosure\nhas no components\") and introduces proper handling of case where there are\nno detected secondary components, but primary component (enumerated in\nnum_enclosures) does exist. That fix was originally proposed by Ding Hui\n\u003Cdinghui@sangfor.com.cn>.\n\nCompletely ignoring devices that have one p","2025-09-18T16:15:47.07+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53431",{"cveId":4407,"releaseId":17,"cycle":18,"description":4408,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4409,"url":4410},{"cveId":4407,"releaseId":25,"cycle":26,"description":4408,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4409,"url":4410},{"cveId":4414,"releaseId":31,"cycle":32,"description":4415,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4416,"url":4417},"CVE-2023-53429","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't check PageError in __extent_writepage\n\n__extent_writepage currenly sets PageError whenever any error happens,\nand the also checks for PageError to decide if to call error handling.\nThis leads to very unclear responsibility for cleaning up on errors.\nIn the VM and generic writeback helpers the basic idea is that once\nI\u002FO is fired off all error handling responsibility is delegated to the\nend I\u002FO handler.  But if that","2025-09-18T16:15:46.847+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53429",{"cveId":4414,"releaseId":17,"cycle":18,"description":4415,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4416,"url":4417},{"cveId":4414,"releaseId":25,"cycle":26,"description":4415,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4416,"url":4417},{"cveId":4421,"releaseId":31,"cycle":32,"description":4422,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4423,"url":4424},"CVE-2022-50419","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sysfs: Fix attempting to call device_add multiple times\n\ndevice_add shall not be called multiple times as stated in its\ndocumentation:\n\n 'Do not call this routine or device_register() more than once for\n any device structure'\n\nSyzkaller reports a bug as follows [1]:\n------------[ cut here ]------------\nkernel BUG at lib\u002Flist_debug.c:33!\ninvalid opcode: 0000 [#1] PREEMPT SMP KASAN\n[...]\nCall Trace:\n \u003CTASK>\n __list","2025-09-18T16:15:45.353+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50419",{"cveId":4421,"releaseId":25,"cycle":26,"description":4422,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4423,"url":4424},{"cveId":4421,"releaseId":17,"cycle":18,"description":4422,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4423,"url":4424},{"cveId":4428,"releaseId":31,"cycle":32,"description":4429,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4430,"url":4431},"CVE-2022-50410","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Protect against send buffer overflow in NFSv2 READ\n\nSince before the git era, NFSD has conserved the number of pages\nheld by each nfsd thread by combining the RPC receive and send\nbuffers into a single array of pages. This works because there are\nno cases where an operation needs a large RPC Call message and a\nlarge RPC Reply at the same time.\n\nOnce an RPC Call has been received, svc_process() updates\nsvc_rqst::rq_res to ","2025-09-18T16:15:44.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50410",{"cveId":4428,"releaseId":17,"cycle":18,"description":4429,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4430,"url":4431},{"cveId":4428,"releaseId":25,"cycle":26,"description":4429,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4430,"url":4431},{"cveId":4435,"releaseId":31,"cycle":32,"description":4436,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4437,"url":4438},"CVE-2022-50405","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Ftunnel: wait until all sk_user_data reader finish before releasing the sock\n\nThere is a race condition in vxlan that when deleting a vxlan device\nduring receiving packets, there is a possibility that the sock is\nreleased after getting vxlan_sock vs from sk_user_data. Then in\nlater vxlan_ecn_decapsulate(), vxlan_get_sk_family() we will got\nNULL pointer dereference. e.g.\n\n   #0 [ffffa25ec6978a38] machine_kexec at ffffffff8c66","2025-09-18T16:15:43.63+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50405",{"cveId":4435,"releaseId":25,"cycle":26,"description":4436,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4437,"url":4438},{"cveId":4435,"releaseId":17,"cycle":18,"description":4436,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4437,"url":4438},{"cveId":4442,"releaseId":31,"cycle":32,"description":4443,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4444,"url":4445},"CVE-2022-50401","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure\n\nOn error situation `clp->cl_cb_conn.cb_xprt` should not be given\na reference to the xprt otherwise both client cleanup and the\nerror handling path of the caller call to put it. Better to\ndelay handing over the reference to a later branch.\n\n[   72.530665] refcount_t: underflow; use-after-free.\n[   72.531933] WARNING: CPU: 0 PID: 173 at lib\u002Frefcount.c:28 refcount","2025-09-18T16:15:42.353+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50401",{"cveId":4442,"releaseId":25,"cycle":26,"description":4443,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4444,"url":4445},{"cveId":4442,"releaseId":17,"cycle":18,"description":4443,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4444,"url":4445},{"cveId":4449,"releaseId":31,"cycle":32,"description":4450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4451,"url":4452},"CVE-2023-53387","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix device management cmd timeout flow\n\nIn the UFS error handling flow, the host will send a device management cmd\n(NOP OUT) to the device for link recovery. If this cmd times out and\nclearing the doorbell fails, ufshcd_wait_for_dev_cmd() will do nothing and\nreturn. hba->dev_cmd.complete struct is not set to NULL.\n\nWhen this happens, if cmd has been completed by device, then we will call\ncomplete() in __ufshcd_","2025-09-18T14:15:41.767+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53387",{"cveId":4449,"releaseId":17,"cycle":18,"description":4450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4451,"url":4452},{"cveId":4449,"releaseId":25,"cycle":26,"description":4450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4451,"url":4452},{"cveId":4456,"releaseId":17,"cycle":18,"description":4457,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":4458,"url":4459},"CVE-2023-53372","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix a potential overflow in sctp_ifwdtsn_skip\n\nCurrently, when traversing ifwdtsn skips with _sctp_walk_ifwdtsn, it only\nchecks the pos against the end of the chunk. However, the data left for\nthe last pos may be \u003C sizeof(struct sctp_ifwdtsn_skip), and dereference\nit as struct sctp_ifwdtsn_skip may cause coverflow.\n\nThis patch fixes it by checking the pos against \"the end of the chunk -\nsizeof(struct sctp_ifwdtsn_skip)\" i","2025-09-18T14:15:39.75+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53372",{"cveId":4461,"releaseId":25,"cycle":26,"description":4462,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4463,"url":4464},"CVE-2022-50399","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: atomisp: prevent integer overflow in sh_css_set_black_frame()\n\nThe \"height\" and \"width\" values come from the user so the \"height * width\"\nmultiplication can overflow.","2025-09-18T14:15:39.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50399",{"cveId":4466,"releaseId":31,"cycle":32,"description":4467,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4468,"url":4469},"CVE-2022-50394","In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: ismt: Fix an out-of-bounds bug in ismt_access()\n\nWhen the driver does not check the data from the user, the variable\n'data->block[0]' may be very large to cause an out-of-bounds bug.\n\nThe following log can reveal it:\n\n[   33.995542] i2c i2c-1: ioctl, cmd=0x720, arg=0x7ffcb3dc3a20\n[   33.995978] ismt_smbus 0000:00:05.0: I2C_SMBUS_BLOCK_DATA:  WRITE\n[   33.996475] =============================================================","2025-09-18T14:15:38.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50394",{"cveId":4466,"releaseId":25,"cycle":26,"description":4467,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4468,"url":4469},{"cveId":4466,"releaseId":17,"cycle":18,"description":4467,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4468,"url":4469},{"cveId":4473,"releaseId":31,"cycle":32,"description":4474,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4475,"url":4476},"CVE-2022-50393","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: SDMA update use unlocked iterator\n\nSDMA update page table may be called from unlocked context, this\ngenerate below warning. Use unlocked iterator to handle this case.\n\nWARNING: CPU: 0 PID: 1475 at\ndrivers\u002Fdma-buf\u002Fdma-resv.c:483 dma_resv_iter_next\nCall Trace:\n dma_resv_iter_first+0x43\u002F0xa0\n amdgpu_vm_sdma_update+0x69\u002F0x2d0 [amdgpu]\n amdgpu_vm_ptes_update+0x29c\u002F0x870 [amdgpu]\n amdgpu_vm_update_range+0x2f6\u002F0x6c0 [amdgp","2025-09-18T14:15:38.38+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50393",{"cveId":4473,"releaseId":17,"cycle":18,"description":4474,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4475,"url":4476},{"cveId":4473,"releaseId":25,"cycle":26,"description":4474,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4475,"url":4476},{"cveId":4480,"releaseId":31,"cycle":32,"description":4481,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4482,"url":4483},"CVE-2022-50386","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix user-after-free\n\nThis uses l2cap_chan_hold_unless_zero() after calling\n__l2cap_get_chan_blah() to prevent the following trace:\n\nBluetooth: l2cap_core.c:static void l2cap_chan_destroy(struct kref\n*kref)\nBluetooth: chan 0000000023c4974d\nBluetooth: parent 00000000ae861c08\n==================================================================\nBUG: KASAN: use-after-free in __mutex_waiter_is_first\nkernel\u002Flocking\u002Fmut","2025-09-18T14:15:37.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50386",{"cveId":4480,"releaseId":25,"cycle":26,"description":4481,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4482,"url":4483},{"cveId":4480,"releaseId":17,"cycle":18,"description":4481,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4482,"url":4483},{"cveId":4487,"releaseId":17,"cycle":18,"description":4488,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4489,"url":4490},"CVE-2023-53354","In the Linux kernel, the following vulnerability has been resolved:\n\nskbuff: skb_segment, Call zero copy functions before using skbuff frags\n\nCommit bf5c25d60861 (\"skbuff: in skb_segment, call zerocopy functions\nonce per nskb\") added the call to zero copy functions in skb_segment().\nThe change introduced a bug in skb_segment() because skb_orphan_frags()\nmay possibly change the number of fragments or allocate new fragments\naltogether leaving nrfrags and frag to point to the old values. This can\nc","2025-09-17T15:15:39.403+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53354",{"cveId":4492,"releaseId":17,"cycle":18,"description":4493,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4494,"url":4495},"CVE-2023-53338","In the Linux kernel, the following vulnerability has been resolved:\n\nlwt: Fix return values of BPF xmit ops\n\nBPF encap ops can return different types of positive values, such like\nNET_RX_DROP, NET_XMIT_CN, NETDEV_TX_BUSY, and so on, from function\nskb_do_redirect and bpf_lwt_xmit_reroute. At the xmit hook, such return\nvalues would be treated implicitly as LWTUNNEL_XMIT_CONTINUE in\nip(6)_finish_output2. When this happens, skbs that have been freed would\ncontinue to the neighbor subsystem, causing ","2025-09-17T15:15:36.913+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53338",{"cveId":4492,"releaseId":25,"cycle":26,"description":4493,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4494,"url":4495},{"cveId":4498,"releaseId":31,"cycle":32,"description":4499,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4500,"url":4501},"CVE-2023-53335","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fcxgb4: Fix potential null-ptr-deref in pass_establish()\n\nIf get_ep_from_tid() fails to lookup non-NULL value for ep, ep is\ndereferenced later regardless of whether it is empty.\nThis patch adds a simple sanity check to fix the issue.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.","2025-09-17T15:15:36.56+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53335",{"cveId":4498,"releaseId":17,"cycle":18,"description":4499,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4500,"url":4501},{"cveId":4498,"releaseId":25,"cycle":26,"description":4499,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4500,"url":4501},{"cveId":4505,"releaseId":31,"cycle":32,"description":4506,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4507,"url":4508},"CVE-2022-50373","In the Linux kernel, the following vulnerability has been resolved:\n\nfs: dlm: fix race in lowcomms\n\nThis patch fixes a race between queue_work() in\n_dlm_lowcomms_commit_msg() and srcu_read_unlock(). The queue_work() can\ntake the final reference of a dlm_msg and so msg->idx can contain\ngarbage which is signaled by the following warning:\n\n[  676.237050] ------------[ cut here ]------------\n[  676.237052] WARNING: CPU: 0 PID: 1060 at include\u002Flinux\u002Fsrcu.h:189 dlm_lowcomms_commit_msg+0x41\u002F0x50\n[  676","2025-09-17T15:15:36.303+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50373",{"cveId":4505,"releaseId":17,"cycle":18,"description":4506,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4507,"url":4508},{"cveId":4505,"releaseId":25,"cycle":26,"description":4506,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4507,"url":4508},{"cveId":4512,"releaseId":17,"cycle":18,"description":4513,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4514,"url":4515},"CVE-2022-50365","In the Linux kernel, the following vulnerability has been resolved:\n\nskbuff: Account for tail adjustment during pull operations\n\nExtending the tail can have some unexpected side effects if a program uses\na helper like BPF_FUNC_skb_pull_data to read partial content beyond the\nhead skb headlen when all the skbs in the gso frag_list are linear with no\nhead_frag -\n\n  kernel BUG at net\u002Fcore\u002Fskbuff.c:4219!\n  pc : skb_segment+0xcf4\u002F0xd2c\n  lr : skb_segment+0x63c\u002F0xd2c\n  Call trace:\n   skb_segment+0xcf4","2025-09-17T15:15:35.343+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50365",{"cveId":4512,"releaseId":31,"cycle":32,"description":4513,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4514,"url":4515},{"cveId":4512,"releaseId":25,"cycle":26,"description":4513,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":4514,"url":4515},{"cveId":4519,"releaseId":17,"cycle":18,"description":4520,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4521,"url":4522},"CVE-2022-50355","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: vt6655: fix some erroneous memory clean-up loops\n\nIn some initialization functions of this driver, memory is allocated with\n'i' acting as an index variable and increasing from 0. The commit in\n\"Fixes\" introduces some clean-up codes in case of allocation failure,\nwhich free memory in reverse order with 'i' decreasing to 0. However,\nthere are some problems:\n  - The case i=0 is left out. Thus memory is leaked.\n  - In case","2025-09-17T15:15:34.15+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50355",{"cveId":4524,"releaseId":31,"cycle":32,"description":4525,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":4526,"url":4527},"CVE-2023-53333","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one\n\nEric Dumazet says:\n  nf_conntrack_dccp_packet() has an unique:\n\n  dh = skb_header_pointer(skb, dataoff, sizeof(_dh), &_dh);\n\n  And nothing more is 'pulled' from the packet, depending on the content.\n  dh->dccph_doff, and\u002For dh->dccph_x ...)\n  So dccp_ack_seq() is happily reading stuff past the _dh buffer.\n\nBUG: KASAN: stack-out-of-bounds in nf_c","2025-09-16T17:15:39.837+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53333",{"cveId":4524,"releaseId":17,"cycle":18,"description":4525,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":4526,"url":4527},{"cveId":4524,"releaseId":25,"cycle":26,"description":4525,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":4526,"url":4527},{"cveId":4531,"releaseId":31,"cycle":32,"description":4532,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4533,"url":4534},"CVE-2023-53322","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Wait for io return on terminate rport\n\nSystem crash due to use after free.\nCurrent code allows terminate_rport_io to exit before making\nsure all IOs has returned. For FCP-2 device, IO's can hang\non in HW because driver has not tear down the session in FW at\nfirst sign of cable pull. When dev_loss_tmo timer pops,\nterminate_rport_io is called and upper layer is about to\nfree various resources. Terminate_rport_io tr","2025-09-16T17:15:38.287+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53322",{"cveId":4531,"releaseId":25,"cycle":26,"description":4532,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4533,"url":4534},{"cveId":4531,"releaseId":17,"cycle":18,"description":4532,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4533,"url":4534},{"cveId":4538,"releaseId":31,"cycle":32,"description":4539,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4540,"url":4541},"CVE-2023-53314","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev\u002Fep93xx-fb: Do not assign to struct fb_info.dev\n\nDo not assing the Linux device to struct fb_info.dev. The call to\nregister_framebuffer() initializes the field to the fbdev device.\nDrivers should not override its value.\n\nFixes a bug where the driver incorrectly decreases the hardware\ndevice's reference counter and leaks the fbdev device.\n\nv2:\n\t* add Fixes tag (Dan)","2025-09-16T17:15:37.36+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53314",{"cveId":4538,"releaseId":25,"cycle":26,"description":4539,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4540,"url":4541},{"cveId":4538,"releaseId":17,"cycle":18,"description":4539,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4540,"url":4541},{"cveId":4545,"releaseId":31,"cycle":32,"description":4546,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4547,"url":4548},"CVE-2023-53305","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix use-after-free\n\nFix potential use-after-free in l2cap_le_command_rej.","2025-09-16T17:15:36.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53305",{"cveId":4545,"releaseId":25,"cycle":26,"description":4546,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4547,"url":4548},{"cveId":4545,"releaseId":17,"cycle":18,"description":4546,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4547,"url":4548},{"cveId":4552,"releaseId":31,"cycle":32,"description":4553,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4554,"url":4555},"CVE-2022-50350","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix a race condition between login_work and the login thread\n\nIn case a malicious initiator sends some random data immediately after a\nlogin PDU; the iscsi_target_sk_data_ready() callback will schedule the\nlogin_work and, at the same time, the negotiation may end without clearing\nthe LOGIN_FLAGS_INITIAL_PDU flag (because no additional PDU exchanges are\nrequired to complete the login).\n\nThe login has been co","2025-09-16T17:15:34.833+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50350",{"cveId":4552,"releaseId":17,"cycle":18,"description":4553,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4554,"url":4555},{"cveId":4552,"releaseId":25,"cycle":26,"description":4553,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4554,"url":4555},{"cveId":4559,"releaseId":31,"cycle":32,"description":4560,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4561,"url":4562},"CVE-2022-50341","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix oops during encryption\n\nWhen running xfstests against Azure the following oops occurred on an\narm64 system\n\n  Unable to handle kernel write to read-only memory at virtual address\n  ffff0001221cf000\n  Mem abort info:\n    ESR = 0x9600004f\n    EC = 0x25: DABT (current EL), IL = 32 bits\n    SET = 0, FnV = 0\n    EA = 0, S1PTW = 0\n    FSC = 0x0f: level 3 permission fault\n  Data abort info:\n    ISV = 0, ISS = 0x0000004f\n    ","2025-09-16T17:15:33.66+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50341",{"cveId":4559,"releaseId":17,"cycle":18,"description":4560,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4561,"url":4562},{"cveId":4559,"releaseId":25,"cycle":26,"description":4560,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4561,"url":4562},{"cveId":4566,"releaseId":31,"cycle":32,"description":4567,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4568,"url":4569},"CVE-2025-39827","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rose: include node references in rose_neigh refcount\n\nCurrent implementation maintains two separate reference counting\nmechanisms: the 'count' field in struct rose_neigh tracks references from\nrose_node structures, while the 'use' field (now refcount_t) tracks\nreferences from rose_sock.\n\nThis patch merges these two reference counting systems using 'use' field\nfor proper reference management. Specifically, this patch adds i","2025-09-16T13:16:02.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39827",{"cveId":4566,"releaseId":17,"cycle":18,"description":4567,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4568,"url":4569},{"cveId":4566,"releaseId":25,"cycle":26,"description":4567,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4568,"url":4569},{"cveId":4573,"releaseId":31,"cycle":32,"description":4574,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":4575,"url":4576},"CVE-2025-39826","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rose: convert 'use' field to refcount_t\n\nThe 'use' field in struct rose_neigh is used as a reference counter but\nlacks atomicity. This can lead to race conditions where a rose_neigh\nstructure is freed while still being referenced by other code paths.\n\nFor example, when rose_neigh->use becomes zero during an ioctl operation\nvia rose_rt_ioctl(), the structure may be removed while its timer is\nstill active, potentially causin","2025-09-16T13:16:02.29+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39826",{"cveId":4573,"releaseId":17,"cycle":18,"description":4574,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":4575,"url":4576},{"cveId":4573,"releaseId":25,"cycle":26,"description":4574,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":4575,"url":4576},{"cveId":4580,"releaseId":31,"cycle":32,"description":4581,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4582,"url":4583},"CVE-2025-39817","In the Linux kernel, the following vulnerability has been resolved:\n\nefivarfs: Fix slab-out-of-bounds in efivarfs_d_compare\n\nObserved on kernel 6.6 (present on master as well):\n\n  BUG: KASAN: slab-out-of-bounds in memcmp+0x98\u002F0xd0\n  Call trace:\n   kasan_check_range+0xe8\u002F0x190\n   __asan_loadN+0x1c\u002F0x28\n   memcmp+0x98\u002F0xd0\n   efivarfs_d_compare+0x68\u002F0xd8\n   __d_lookup_rcu_op_compare+0x178\u002F0x218\n   __d_lookup_rcu+0x1f8\u002F0x228\n   d_alloc_parallel+0x150\u002F0x648\n   lookup_open.isra.0+0x5f0\u002F0x8d0\n   open_","2025-09-16T13:15:57.187+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39817",{"cveId":4580,"releaseId":17,"cycle":18,"description":4581,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4582,"url":4583},{"cveId":4580,"releaseId":25,"cycle":26,"description":4581,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4582,"url":4583},{"cveId":4587,"releaseId":31,"cycle":32,"description":4588,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4589,"url":4590},"CVE-2023-53297","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix \"bad unlock balance\" in l2cap_disconnect_rsp\n\nconn->chan_lock isn't acquired before l2cap_get_chan_by_scid,\nif l2cap_get_chan_by_scid returns NULL, then 'bad unlock balance'\nis triggered.","2025-09-16T08:15:39.053+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53297",{"cveId":4587,"releaseId":25,"cycle":26,"description":4588,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4589,"url":4590},{"cveId":4587,"releaseId":17,"cycle":18,"description":4588,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4589,"url":4590},{"cveId":4594,"releaseId":25,"cycle":26,"description":4595,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4596,"url":4597},"CVE-2023-53292","In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none\n\nAfter grabbing q->sysfs_lock, q->elevator may become NULL because of\nelevator switch.\n\nFix the NULL dereference on q->elevator by checking it with lock.","2025-09-16T08:15:38.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53292",{"cveId":4594,"releaseId":17,"cycle":18,"description":4595,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4596,"url":4597},{"cveId":4594,"releaseId":31,"cycle":32,"description":4595,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4596,"url":4597},{"cveId":4601,"releaseId":31,"cycle":32,"description":4602,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4603,"url":4604},"CVE-2023-53285","In the Linux kernel, the following vulnerability has been resolved:\n\next4: add bounds checking in get_max_inline_xattr_value_size()\n\nNormally the extended attributes in the inode body would have been\nchecked when the inode is first opened, but if someone is writing to\nthe block device while the file system is mounted, it's possible for\nthe inode table to get corrupted.  Add bounds checking to avoid\nreading beyond the end of allocated memory if this happens.","2025-09-16T08:15:37.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53285",{"cveId":4601,"releaseId":25,"cycle":26,"description":4602,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4603,"url":4604},{"cveId":4601,"releaseId":17,"cycle":18,"description":4602,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4603,"url":4604},{"cveId":4608,"releaseId":17,"cycle":18,"description":4609,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4610,"url":4611},"CVE-2023-53257","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: check S1G action frame size\n\nBefore checking the action code, check that it even\nexists in the frame.","2025-09-15T15:15:53.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53257",{"cveId":4608,"releaseId":25,"cycle":26,"description":4609,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4610,"url":4611},{"cveId":4608,"releaseId":31,"cycle":32,"description":4609,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4610,"url":4611},{"cveId":4615,"releaseId":31,"cycle":32,"description":4616,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4617,"url":4618},"CVE-2023-53254","In the Linux kernel, the following vulnerability has been resolved:\n\ncacheinfo: Fix shared_cpu_map to handle shared caches at different levels\n\nThe cacheinfo sets up the shared_cpu_map by checking whether the caches\nwith the same index are shared between CPUs. However, this will trigger\nslab-out-of-bounds access if the CPUs do not have the same cache hierarchy.\nAnother problem is the mismatched shared_cpu_map when the shared cache does\nnot have the same index between CPUs.\n\nCPU0\tI\tD\tL3\nindex\t0\t1","2025-09-15T15:15:52.727+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53254",{"cveId":4615,"releaseId":17,"cycle":18,"description":4616,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4617,"url":4618},{"cveId":4615,"releaseId":25,"cycle":26,"description":4616,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4617,"url":4618},{"cveId":4622,"releaseId":31,"cycle":32,"description":4623,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4624,"url":4625},"CVE-2023-53229","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix invalid drv_sta_pre_rcu_remove calls for non-uploaded sta\n\nAvoid potential data corruption issues caused by uninitialized driver\nprivate data structures.","2025-09-15T15:15:49.837+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53229",{"cveId":4622,"releaseId":25,"cycle":26,"description":4623,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4624,"url":4625},{"cveId":4622,"releaseId":17,"cycle":18,"description":4623,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4624,"url":4625},{"cveId":4629,"releaseId":31,"cycle":32,"description":4630,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4631,"url":4632},"CVE-2023-53226","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Fix OOB and integer underflow when rx packets\n\nMake sure mwifiex_process_mgmt_packet,\nmwifiex_process_sta_rx_packet and mwifiex_process_uap_rx_packet,\nmwifiex_uap_queue_bridged_pkt and mwifiex_process_rx_packet\nnot out-of-bounds access the skb->data buffer.","2025-09-15T15:15:49.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53226",{"cveId":4629,"releaseId":25,"cycle":26,"description":4630,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4631,"url":4632},{"cveId":4629,"releaseId":17,"cycle":18,"description":4630,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4631,"url":4632},{"cveId":4636,"releaseId":31,"cycle":32,"description":4637,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4638,"url":4639},"CVE-2023-53222","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: jfs_dmap: Validate db_l2nbperpage while mounting\n\nIn jfs_dmap.c at line 381, BLKTODMAP is used to get a logical block\nnumber inside dbFree(). db_l2nbperpage, which is the log2 number of\nblocks per page, is passed as an argument to BLKTODMAP which uses it\nfor shifting.\n\nSyzbot reported a shift out-of-bounds crash because db_l2nbperpage is\ntoo big. This happens because the large value is set without any\nvalidation in dbMount","2025-09-15T15:15:48.983+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53222",{"cveId":4636,"releaseId":25,"cycle":26,"description":4637,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4638,"url":4639},{"cveId":4636,"releaseId":17,"cycle":18,"description":4637,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4638,"url":4639},{"cveId":4643,"releaseId":31,"cycle":32,"description":4644,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":4645,"url":4646},"CVE-2023-53213","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()\n\nFix a slab-out-of-bounds read that occurs in kmemdup() called from\nbrcmf_get_assoc_ies().\nThe bug could occur when assoc_info->req_len, data from a URB provided\nby a USB device, is bigger than the size of buffer which is defined as\nWL_EXTRA_BUF_MAX.\n\nAdd the size check for req_len\u002Fresp_len of assoc_info.\n\nFound by a modified version of syzkaller.\n\n[   46.592467][","2025-09-15T15:15:47.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53213",{"cveId":4643,"releaseId":25,"cycle":26,"description":4644,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":4645,"url":4646},{"cveId":4643,"releaseId":17,"cycle":18,"description":4644,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":4645,"url":4646},{"cveId":4650,"releaseId":17,"cycle":18,"description":4651,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4652,"url":4653},"CVE-2022-50335","In the Linux kernel, the following vulnerability has been resolved:\n\n9p: set req refcount to zero to avoid uninitialized usage\n\nWhen a new request is allocated, the refcount will be zero if it is\nreused, but if the request is newly allocated from slab, it is not fully\ninitialized before being added to idr.\n\nIf the p9_read_work got a response before the refcount initiated. It will\nuse a uninitialized req, which will result in a bad request data struct.\n\nHere is the logs from syzbot.\n\nCorrupted me","2025-09-15T15:15:45.817+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50335",{"cveId":4655,"releaseId":31,"cycle":32,"description":4656,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4657,"url":4658},"CVE-2022-50333","In the Linux kernel, the following vulnerability has been resolved:\n\nfs: jfs: fix shift-out-of-bounds in dbDiscardAG\n\nThis should be applied to most URSAN bugs found recently by syzbot,\nby guarding the dbMount. As syzbot feeding rubbish into the bmap\ndescriptor.","2025-09-15T15:15:45.537+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50333",{"cveId":4655,"releaseId":25,"cycle":26,"description":4656,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4657,"url":4658},{"cveId":4655,"releaseId":17,"cycle":18,"description":4656,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4657,"url":4658},{"cveId":4662,"releaseId":25,"cycle":26,"description":4663,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4664,"url":4665},"CVE-2022-50330","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: cavium - prevent integer overflow loading firmware\n\nThe \"code_length\" value comes from the firmware file.  If your firmware\nis untrusted realistically there is probably very little you can do to\nprotect yourself.  Still we try to limit the damage as much as possible.\nAlso Smatch marks any data read from the filesystem as untrusted and\nprints warnings if it not capped correctly.\n\nThe \"ntohl(ucode->code_length) * 2\" multi","2025-09-15T15:15:45.187+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50330",{"cveId":4662,"releaseId":17,"cycle":18,"description":4663,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4664,"url":4665},{"cveId":4668,"releaseId":31,"cycle":32,"description":4669,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4670,"url":4671},"CVE-2022-50328","In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: fix potential use-after-free in jbd2_fc_wait_bufs\n\nIn 'jbd2_fc_wait_bufs' use 'bh' after put buffer head reference count\nwhich may lead to use-after-free.\nSo judge buffer if uptodate before put buffer head reference count.","2025-09-15T15:15:44.953+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50328",{"cveId":4668,"releaseId":17,"cycle":18,"description":4669,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4670,"url":4671},{"cveId":4668,"releaseId":25,"cycle":26,"description":4669,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4670,"url":4671},{"cveId":4675,"releaseId":31,"cycle":32,"description":4676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4677,"url":4678},"CVE-2022-50315","In the Linux kernel, the following vulnerability has been resolved:\n\nata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS\n\nUBSAN complains about array-index-out-of-bounds:\n[ 1.980703] kernel: UBSAN: array-index-out-of-bounds in \u002Fbuild\u002Flinux-9H675w\u002Flinux-5.15.0\u002Fdrivers\u002Fata\u002Flibahci.c:968:41\n[ 1.980709] kernel: index 15 is out of range for type 'ahci_em_priv [8]'\n[ 1.980713] kernel: CPU: 0 PID: 209 Comm: scsi_eh_8 Not tainted 5.15.0-25-generic #25-Ubuntu\n[ 1.980716] kernel: Hardware name: System m","2025-09-15T15:15:43.373+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50315",{"cveId":4675,"releaseId":25,"cycle":26,"description":4676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4677,"url":4678},{"cveId":4675,"releaseId":17,"cycle":18,"description":4676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4677,"url":4678},{"cveId":4682,"releaseId":31,"cycle":32,"description":4683,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4684,"url":4685},"CVE-2022-50306","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix potential out of bound read in ext4_fc_replay_scan()\n\nFor scan loop must ensure that at least EXT4_FC_TAG_BASE_LEN space. If remain\nspace less than EXT4_FC_TAG_BASE_LEN which will lead to out of bound read\nwhen mounting corrupt file system image.\nADD_RANGE\u002FHEAD\u002FTAIL is needed to add extra check when do journal scan, as this\nthree tags will read data during scan, tag length couldn't less than data length\nwhich will rea","2025-09-15T15:15:42.267+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50306",{"cveId":4682,"releaseId":17,"cycle":18,"description":4683,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4684,"url":4685},{"cveId":4682,"releaseId":25,"cycle":26,"description":4683,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4684,"url":4685},{"cveId":4689,"releaseId":31,"cycle":32,"description":4690,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4691,"url":4692},"CVE-2022-50303","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdkfd: Fix double release compute pasid\n\nIf kfd_process_device_init_vm returns failure after vm is converted to\ncompute vm and vm->pasid set to compute pasid, KFD will not take\npdd->drm_file reference. As a result, drm close file handler maybe\ncalled to release the compute pasid before KFD process destroy worker to\nrelease the same pasid and set vm->pasid to zero, this generates below\nWARNING backtrace and NULL pointer acc","2025-09-15T15:15:41.84+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50303",{"cveId":4689,"releaseId":17,"cycle":18,"description":4690,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4691,"url":4692},{"cveId":4689,"releaseId":25,"cycle":26,"description":4690,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4691,"url":4692},{"cveId":4696,"releaseId":17,"cycle":18,"description":4697,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4698,"url":4699},"CVE-2022-50300","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix extent map use-after-free when handling missing device in read_one_chunk\n\nStore the error code before freeing the extent_map. Though it's\nreference counted structure, in that function it's the first and last\nallocation so this would lead to a potential use-after-free.\n\nThe error can happen eg. when chunk is stored on a missing device and\nthe degraded mount option is missing.\n\nBugzilla: https:\u002F\u002Fbugzilla.kernel.org\u002Fsho","2025-09-15T15:15:41.483+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50300",{"cveId":4701,"releaseId":31,"cycle":32,"description":4702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4703,"url":4704},"CVE-2022-50286","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline\n\nWhen converting files with inline data to extents, delayed allocations\nmade on a file system created with both the bigalloc and inline options\ncan result in invalid extent status cache content, incorrect reserved\ncluster counts, kernel memory leaks, and potential kernel panics.\n\nWith bigalloc, the code that determines whether a block must be\ndelayed allo","2025-09-15T15:15:39.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50286",{"cveId":4701,"releaseId":17,"cycle":18,"description":4702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4703,"url":4704},{"cveId":4701,"releaseId":25,"cycle":26,"description":4702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4703,"url":4704},{"cveId":4708,"releaseId":31,"cycle":32,"description":4709,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4710,"url":4711},"CVE-2022-50274","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvbdev: adopts refcnt to avoid UAF\n\ndvb_unregister_device() is known that prone to use-after-free.\nThat is, the cleanup from dvb_unregister_device() releases the dvb_device\neven if there are pointers stored in file->private_data still refer to it.\n\nThis patch adds a reference counter into struct dvb_device and delays its\ndeallocation until no pointer refers to the object.","2025-09-15T15:15:38.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50274",{"cveId":4708,"releaseId":25,"cycle":26,"description":4709,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4710,"url":4711},{"cveId":4708,"releaseId":17,"cycle":18,"description":4709,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4710,"url":4711},{"cveId":4715,"releaseId":31,"cycle":32,"description":4716,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4717,"url":4718},"CVE-2023-53189","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6\u002Faddrconf: fix a potential refcount underflow for idev\n\nNow in addrconf_mod_rs_timer(), reference idev depends on whether\nrs_timer is not pending. Then modify rs_timer timeout.\n\nThere is a time gap in [1], during which if the pending rs_timer\nbecomes not pending. It will miss to hold idev, but the rs_timer\nis activated. Thus rs_timer callback function addrconf_rs_timer()\nwill be executed and put idev later without holding i","2025-09-15T14:15:41.15+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53189",{"cveId":4715,"releaseId":25,"cycle":26,"description":4716,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4717,"url":4718},{"cveId":4715,"releaseId":17,"cycle":18,"description":4716,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4717,"url":4718},{"cveId":4722,"releaseId":31,"cycle":32,"description":4723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4724,"url":4725},"CVE-2023-53179","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c\n\nThe missing IP_SET_HASH_WITH_NET0 macro in ip_set_hash_netportnet can\nlead to the use of wrong `CIDR_POS(c)` for calculating array offsets,\nwhich can lead to integer underflow. As a result, it leads to slab\nout-of-bound access.\nThis patch adds back the IP_SET_HASH_WITH_NET0 macro to\nip_set_hash_netportnet to address the issue.","2025-09-15T14:15:39.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53179",{"cveId":4722,"releaseId":25,"cycle":26,"description":4723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4724,"url":4725},{"cveId":4722,"releaseId":17,"cycle":18,"description":4723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4724,"url":4725},{"cveId":4729,"releaseId":31,"cycle":32,"description":4730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4731,"url":4732},"CVE-2023-53178","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix zswap writeback race condition\n\nThe zswap writeback mechanism can cause a race condition resulting in\nmemory corruption, where a swapped out page gets swapped in with data that\nwas written to a different page.\n\nThe race unfolds like this:\n1. a page with data A and swap offset X is stored in zswap\n2. page A is removed off the LRU by zpool driver for writeback in\n   zswap-shrink work, data for A is mapped by zpool driver\n","2025-09-15T14:15:39.803+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53178",{"cveId":4729,"releaseId":17,"cycle":18,"description":4730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4731,"url":4732},{"cveId":4729,"releaseId":25,"cycle":26,"description":4730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4731,"url":4732},{"cveId":4736,"releaseId":31,"cycle":32,"description":4737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4738,"url":4739},"CVE-2023-53176","In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250: Reinit port->pm on port specific driver unbind\n\nWhen we unbind a serial port hardware specific 8250 driver, the generic\nserial8250 driver takes over the port. After that we see an oops about 10\nseconds later. This can produce the following at least on some TI SoCs:\n\nUnhandled fault: imprecise external abort (0x1406)\nInternal error: : 1406 [#1] SMP ARM\n\nTurns out that we may still have the serial port hardware spec","2025-09-15T14:15:39.527+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53176",{"cveId":4736,"releaseId":25,"cycle":26,"description":4737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4738,"url":4739},{"cveId":4736,"releaseId":17,"cycle":18,"description":4737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4738,"url":4739},{"cveId":4743,"releaseId":31,"cycle":32,"description":4744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4745,"url":4746},"CVE-2022-50252","In the Linux kernel, the following vulnerability has been resolved:\n\nigb: Do not free q_vector unless new one was allocated\n\nAvoid potential use-after-free condition under memory pressure. If the\nkzalloc() fails, q_vector will be freed but left in the original\nadapter->q_vector[v_idx] array position.","2025-09-15T14:15:35.877+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50252",{"cveId":4743,"releaseId":25,"cycle":26,"description":4744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4745,"url":4746},{"cveId":4743,"releaseId":17,"cycle":18,"description":4744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4745,"url":4746},{"cveId":4750,"releaseId":17,"cycle":18,"description":4751,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4752,"url":4753},"CVE-2022-50243","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: handle the error returned from sctp_auth_asoc_init_active_key\n\nWhen it returns an error from sctp_auth_asoc_init_active_key(), the\nactive_key is actually not updated. The old sh_key will be freeed\nwhile it's still used as active key in asoc. Then an use-after-free\nwill be triggered when sending patckets, as found by syzbot:\n\n  sctp_auth_shkey_hold+0x22\u002F0xa0 net\u002Fsctp\u002Fauth.c:112\n  sctp_set_owner_w net\u002Fsctp\u002Fsocket.c:132 [inl","2025-09-15T14:15:34.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50243",{"cveId":4755,"releaseId":31,"cycle":32,"description":4756,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4757,"url":4758},"CVE-2022-50241","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: fix use-after-free on source server when doing inter-server copy\n\nUse-after-free occurred when the laundromat tried to free expired\ncpntf_state entry on the s2s_cp_stateids list after inter-server\ncopy completed. The sc_cp_list that the expired copy state was\ninserted on was already freed.\n\nWhen COPY completes, the Linux client normally sends LOCKU(lock_state x),\nFREE_STATEID(lock_state x) and CLOSE(open_state y) to the s","2025-09-15T14:15:34.36+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50241",{"cveId":4755,"releaseId":17,"cycle":18,"description":4756,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4757,"url":4758},{"cveId":4755,"releaseId":25,"cycle":26,"description":4756,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":4757,"url":4758},{"cveId":4762,"releaseId":31,"cycle":32,"description":4763,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4764,"url":4765},"CVE-2025-39800","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: abort transaction on unexpected eb generation at btrfs_copy_root()\n\nIf we find an unexpected generation for the extent buffer we are cloning\nat btrfs_copy_root(), we just WARN_ON() and don't error out and abort the\ntransaction, meaning we allow to persist metadata with an unexpected\ngeneration. Instead of warning only, abort the transaction and return\n-EUCLEAN.","2025-09-15T13:15:35.467+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39800",{"cveId":4762,"releaseId":17,"cycle":18,"description":4763,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4764,"url":4765},{"cveId":4762,"releaseId":25,"cycle":26,"description":4763,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4764,"url":4765},{"cveId":4769,"releaseId":31,"cycle":32,"description":4770,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4771,"url":4772},"CVE-2025-39798","In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix the setting of capabilities when automounting a new filesystem\n\nCapabilities cannot be inherited when we cross into a new filesystem.\nThey need to be reset to the minimal defaults, and then probed for\nagain.","2025-09-12T16:15:34.267+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39798",{"cveId":4769,"releaseId":17,"cycle":18,"description":4770,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4771,"url":4772},{"cveId":4769,"releaseId":25,"cycle":26,"description":4770,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4771,"url":4772},{"cveId":4776,"releaseId":17,"cycle":18,"description":4777,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4778,"url":4779},"CVE-2025-40300","In the Linux kernel, the following vulnerability has been resolved:\n\nx86\u002Fvmscape: Add conditional IBPB mitigation\n\nVMSCAPE is a vulnerability that exploits insufficient branch predictor\nisolation between a guest and a userspace hypervisor (like QEMU). Existing\nmitigations already protect kernel\u002FKVM from a malicious guest. Userspace\ncan additionally be protected by flushing the branch predictors after a\nVMexit.\n\nSince it is the userspace that consumes the poisoned branch predictors,\nconditionally","2025-09-11T17:15:45.68+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-40300",{"cveId":4781,"releaseId":17,"cycle":18,"description":4782,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4783,"url":4784},"CVE-2025-39789","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: x86\u002Faegis - Add missing error checks\n\nThe skcipher_walk functions can allocate memory and can fail, so\nchecking for errors is necessary.","2025-09-11T17:15:45.22+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39789",{"cveId":4786,"releaseId":17,"cycle":18,"description":4787,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4788,"url":4789},"CVE-2025-39787","In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: mdt_loader: Ensure we don't read past the ELF header\n\nWhen the MDT loader is used in remoteproc, the ELF header is sanitized\nbeforehand, but that's not necessary the case for other clients.\n\nValidate the size of the firmware buffer to ensure that we don't read\npast the end as we iterate over the header. e_phentsize and e_shentsize\nare validated as well, to ensure that the assumptions about step size in\nthe traversal ","2025-09-11T17:15:44.907+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39787",{"cveId":4786,"releaseId":25,"cycle":26,"description":4787,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4788,"url":4789},{"cveId":4792,"releaseId":31,"cycle":32,"description":4793,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4794,"url":4795},"CVE-2025-39782","In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: prevent softlockup in jbd2_log_do_checkpoint()\n\nBoth jbd2_log_do_checkpoint() and jbd2_journal_shrink_checkpoint_list()\nperiodically release j_list_lock after processing a batch of buffers to\navoid long hold times on the j_list_lock. However, since both functions\ncontend for j_list_lock, the combined time spent waiting and processing\ncan be significant.\n\njbd2_journal_shrink_checkpoint_list() explicitly calls cond_resched(","2025-09-11T17:15:44.173+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39782",{"cveId":4792,"releaseId":17,"cycle":18,"description":4793,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4794,"url":4795},{"cveId":4792,"releaseId":25,"cycle":26,"description":4793,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4794,"url":4795},{"cveId":4799,"releaseId":31,"cycle":32,"description":4800,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4801,"url":4802},"CVE-2025-39773","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: fix soft lockup in br_multicast_query_expired()\n\nWhen set multicast_query_interval to a large value, the local variable\n'time' in br_multicast_send_query() may overflow. If the time is smaller\nthan jiffies, the timer will expire immediately, and then call mod_timer()\nagain, which creates a loop and may trigger the following soft lockup\nissue.\n\n  watchdog: BUG: soft lockup - CPU#1 stuck for 221s! [rb_consumer:66]\n  ","2025-09-11T17:15:43.01+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39773",{"cveId":4799,"releaseId":17,"cycle":18,"description":4800,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4801,"url":4802},{"cveId":4799,"releaseId":25,"cycle":26,"description":4800,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4801,"url":4802},{"cveId":4806,"releaseId":17,"cycle":18,"description":4807,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4808,"url":4809},"CVE-2025-39770","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM\n\nWhen performing Generic Segmentation Offload (GSO) on an IPv6 packet that\ncontains extension headers, the kernel incorrectly requests checksum offload\nif the egress device only advertises NETIF_F_IPV6_CSUM feature, which has\na strict contract: it supports checksum offload only for plain TCP or UDP\nover IPv6 and explicitly does not support packets with ext","2025-09-11T17:15:42.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39770",{"cveId":4811,"releaseId":31,"cycle":32,"description":4812,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4813,"url":4814},"CVE-2025-39764","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: remove refcounting in expectation dumpers\n\nSame pattern as previous patch: do not keep the expectation object\nalive via refcount, only store a cookie value and then use that\nas the skip hint for dump resumption.\n\nAFAICS this has the same issue as the one resolved in the conntrack\ndumper, when we do\n  if (!refcount_inc_not_zero(&exp->use))\n\nto increment the refcount, there is a chance that exp == last, whic","2025-09-11T17:15:40.653+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39764",{"cveId":4811,"releaseId":17,"cycle":18,"description":4812,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4813,"url":4814},{"cveId":4811,"releaseId":25,"cycle":26,"description":4812,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4813,"url":4814},{"cveId":4818,"releaseId":31,"cycle":32,"description":4819,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4820,"url":4821},"CVE-2025-39756","In the Linux kernel, the following vulnerability has been resolved:\n\nfs: Prevent file descriptor table allocations exceeding INT_MAX\n\nWhen sysctl_nr_open is set to a very high value (for example, 1073741816\nas set by systemd), processes attempting to use file descriptors near\nthe limit can trigger massive memory allocation attempts that exceed\nINT_MAX, resulting in a WARNING in mm\u002Fslub.c:\n\n  WARNING: CPU: 0 PID: 44 at mm\u002Fslub.c:5027 __kvmalloc_node_noprof+0x21a\u002F0x288\n\nThis happens because kvmall","2025-09-11T17:15:39.343+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39756",{"cveId":4818,"releaseId":17,"cycle":18,"description":4819,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4820,"url":4821},{"cveId":4818,"releaseId":25,"cycle":26,"description":4819,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4820,"url":4821},{"cveId":4825,"releaseId":31,"cycle":32,"description":4826,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4827,"url":4828},"CVE-2025-39748","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Forget ranges when refining tnum after JSET\n\nSyzbot reported a kernel warning due to a range invariant violation on\nthe following BPF program.\n\n  0: call bpf_get_netns_cookie\n  1: if r0 == 0 goto \u003Cexit>\n  2: if r0 & Oxffffffff goto \u003Cexit>\n\nThe issue is on the path where we fall through both jumps.\n\nThat path is unreachable at runtime: after insn 1, we know r0 != 0, but\nwith the sign extension on the jset, we would only fal","2025-09-11T17:15:38.237+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39748",{"cveId":4825,"releaseId":17,"cycle":18,"description":4826,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4827,"url":4828},{"cveId":4825,"releaseId":25,"cycle":26,"description":4826,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4827,"url":4828},{"cveId":4832,"releaseId":17,"cycle":18,"description":4833,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4834,"url":4835},"CVE-2025-39726","In the Linux kernel, the following vulnerability has been resolved:\n\ns390\u002Fism: fix concurrency management in ism_cmd()\n\nThe s390x ISM device data sheet clearly states that only one\nrequest-response sequence is allowable per ISM function at any point in\ntime.  Unfortunately as of today the s390\u002Fism driver in Linux does not\nhonor that requirement. This patch aims to rectify that.\n\nThis problem was discovered based on Aliaksei's bug report which states\nthat for certain workloads the ISM functions e","2025-09-05T18:15:50.447+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39726",{"cveId":4837,"releaseId":31,"cycle":32,"description":4838,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4839,"url":4840},"CVE-2025-39714","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: usbtv: Lock resolution while streaming\n\nWhen an program is streaming (ffplay) and another program (qv4l2)\nchanges the TV standard from NTSC to PAL, the kernel crashes due to trying\nto copy to unmapped memory.\n\nChanging from NTSC to PAL increases the resolution in the usbtv struct,\nbut the video plane buffer isn't adjusted, so it overflows.\n\n[hverkuil: call vb2_is_busy instead of vb2_is_streaming]","2025-09-05T18:15:48.85+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39714",{"cveId":4837,"releaseId":17,"cycle":18,"description":4838,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4839,"url":4840},{"cveId":4837,"releaseId":25,"cycle":26,"description":4838,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4839,"url":4840},{"cveId":4844,"releaseId":17,"cycle":18,"description":4845,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4846,"url":4847},"CVE-2025-39710","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: Add a check for packet size after reading from shared memory\n\nAdd a check to ensure that the packet size does not exceed the number of\navailable words after reading the packet header from shared memory. This\nensures that the size provided by the firmware is safe to process and\nprevent potential out-of-bounds memory access.","2025-09-05T18:15:48.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39710",{"cveId":4844,"releaseId":25,"cycle":26,"description":4845,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4846,"url":4847},{"cveId":4850,"releaseId":25,"cycle":26,"description":4851,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4852,"url":4853},"CVE-2025-39709","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: protect against spurious interrupts during probe\n\nMake sure the interrupt handler is initialized before the interrupt is\nregistered.\n\nIf the IRQ is registered before hfi_create(), it's possible that an\ninterrupt fires before the handler setup is complete, leading to a NULL\ndereference.\n\nThis error condition has been observed during system boot on Rb3Gen2.","2025-09-05T18:15:48.18+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39709",{"cveId":4850,"releaseId":17,"cycle":18,"description":4851,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4852,"url":4853},{"cveId":4856,"releaseId":17,"cycle":18,"description":4857,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4858,"url":4859},"CVE-2025-39702","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant time.\nUse the appropriate helper function for this.","2025-09-05T18:15:47.27+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39702",{"cveId":4856,"releaseId":25,"cycle":26,"description":4857,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4858,"url":4859},{"cveId":4862,"releaseId":17,"cycle":18,"description":4863,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4864,"url":4865},"CVE-2025-39697","In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix a race when updating an existing write\n\nAfter nfs_lock_and_join_requests() tests for whether the request is\nstill attached to the mapping, nothing prevents a call to\nnfs_inode_remove_request() from succeeding until we actually lock the\npage group.\nThe reason is that whoever called nfs_inode_remove_request() doesn't\nnecessarily have a lock on the page group head.\n\nSo in order to avoid races, let's take the page group lo","2025-09-05T18:15:46.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39697",{"cveId":4862,"releaseId":25,"cycle":26,"description":4863,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4864,"url":4865},{"cveId":4868,"releaseId":31,"cycle":32,"description":4869,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4870,"url":4871},"CVE-2025-39691","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Fbuffer: fix use-after-free when call bh_read() helper\n\nThere's issue as follows:\nBUG: KASAN: stack-out-of-bounds in end_buffer_read_sync+0xe3\u002F0x110\nRead of size 8 at addr ffffc9000168f7f8 by task swapper\u002F3\u002F0\nCPU: 3 UID: 0 PID: 0 Comm: swapper\u002F3 Not tainted 6.16.0-862.14.0.6.x86_64\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996)\nCall Trace:\n \u003CIRQ>\n dump_stack_lvl+0x55\u002F0x70\n print_address_description.constprop.0+0x2c\u002F0x3","2025-09-05T18:15:45.84+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39691",{"cveId":4868,"releaseId":17,"cycle":18,"description":4869,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4870,"url":4871},{"cveId":4868,"releaseId":25,"cycle":26,"description":4869,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4870,"url":4871},{"cveId":4875,"releaseId":17,"cycle":18,"description":4876,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4877,"url":4878},"CVE-2025-39689","In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Also allocate and copy hash for reading of filter files\n\nCurrently the reader of set_ftrace_filter and set_ftrace_notrace just adds\nthe pointer to the global tracer hash to its iterator. Unlike the writer\nthat allocates a copy of the hash, the reader keeps the pointer to the\nfilter hashes. This is problematic because this pointer is static across\nfunction calls that release the locks that can update the global tracer\nha","2025-09-05T18:15:45.573+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39689",{"cveId":4875,"releaseId":25,"cycle":26,"description":4876,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4877,"url":4878},{"cveId":4881,"releaseId":31,"cycle":32,"description":4882,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4883,"url":4884},"CVE-2025-39683","In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Limit access to parser->buffer when trace_get_user failed\n\nWhen the length of the string written to set_ftrace_filter exceeds\nFTRACE_BUFF_MAX, the following KASAN alarm will be triggered:\n\nBUG: KASAN: slab-out-of-bounds in strsep+0x18c\u002F0x1b0\nRead of size 1 at addr ffff0000d00bd5ba by task ash\u002F165\n\nCPU: 1 UID: 0 PID: 165 Comm: ash Not tainted 6.16.0-g6bcdbd62bd56-dirty\nHardware name: linux,dummy-virt (DT)\nCall trace:\n s","2025-09-05T18:15:44.81+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39683",{"cveId":4881,"releaseId":25,"cycle":26,"description":4882,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4883,"url":4884},{"cveId":4881,"releaseId":17,"cycle":18,"description":4882,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4883,"url":4884},{"cveId":4888,"releaseId":31,"cycle":32,"description":4889,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4890,"url":4891},"CVE-2025-39677","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: Fix backlog accounting in qdisc_dequeue_internal\n\nThis issue applies for the following qdiscs: hhf, fq, fq_codel, and\nfq_pie, and occurs in their change handlers when adjusting to the new\nlimit. The problem is the following in the values passed to the\nsubsequent qdisc_tree_reduce_backlog call given a tbf parent:\n\n   When the tbf parent runs out of tokens, skbs of these qdiscs will\n   be placed in gso_skb. Their peek ","2025-09-05T18:15:44.043+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-39677",{"cveId":4888,"releaseId":17,"cycle":18,"description":4889,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4890,"url":4891},{"cveId":4888,"releaseId":25,"cycle":26,"description":4889,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4890,"url":4891},{"cveId":4895,"releaseId":17,"cycle":18,"description":4896,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4897,"url":4898},"CVE-2025-38734","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: fix UAF on smcsk after smc_listen_out()\n\nBPF CI testing report a UAF issue:\n\n  [   16.446633] BUG: kernel NULL pointer dereference, address: 000000000000003  0\n  [   16.447134] #PF: supervisor read access in kernel mod  e\n  [   16.447516] #PF: error_code(0x0000) - not-present pag  e\n  [   16.447878] PGD 0 P4D   0\n  [   16.448063] Oops: Oops: 0000 [#1] PREEMPT SMP NOPT  I\n  [   16.448409] CPU: 0 UID: 0 PID: 9 Comm: kwor","2025-09-05T18:15:42.677+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38734",{"cveId":4900,"releaseId":17,"cycle":18,"description":4901,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":4902,"url":4903},"CVE-2025-38728","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb3: fix for slab out of bounds on mount to ksmbd\n\nWith KASAN enabled, it is possible to get a slab out of bounds\nduring mount to ksmbd due to missing check in parse_server_interfaces()\n(see below):\n\n BUG: KASAN: slab-out-of-bounds in\n parse_server_interfaces+0x14ee\u002F0x1880 [cifs]\n Read of size 4 at addr ffff8881433dba98 by task mount\u002F9827\n\n CPU: 5 UID: 0 PID: 9827 Comm: mount Tainted: G\n OE       6.16.0-rc2-kasan #2 PREEMPT(vo","2025-09-04T16:15:42.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38728",{"cveId":4905,"releaseId":31,"cycle":32,"description":4906,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4907,"url":4908},"CVE-2025-38724","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()\n\nLei Lu recently reported that nfsd4_setclientid_confirm() did not check\nthe return value from get_client_locked(). a SETCLIENTID_CONFIRM could\nrace with a confirmed client expiring and fail to get a reference. That\ncould later lead to a UAF.\n\nFix this by getting a reference early in the case where there is an\nextant confirmed client. If that fails then tre","2025-09-04T16:15:42.273+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38724",{"cveId":4905,"releaseId":17,"cycle":18,"description":4906,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4907,"url":4908},{"cveId":4905,"releaseId":25,"cycle":26,"description":4906,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4907,"url":4908},{"cveId":4912,"releaseId":31,"cycle":32,"description":4913,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4914,"url":4915},"CVE-2025-38721","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: fix refcount leak on table dump\n\nThere is a reference count leak in ctnetlink_dump_table():\n      if (res \u003C 0) {\n                nf_conntrack_get(&ct->ct_general); \u002F\u002F HERE\n                cb->args[1] = (unsigned long)ct;\n                ...\n\nWhile its very unlikely, its possible that ct == last.\nIf this happens, then the refcount of ct was already incremented.\nThis 2nd increment is never undone.\n\nThis prev","2025-09-04T16:15:41.843+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38721",{"cveId":4912,"releaseId":17,"cycle":18,"description":4913,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4914,"url":4915},{"cveId":4912,"releaseId":25,"cycle":26,"description":4913,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4914,"url":4915},{"cveId":4919,"releaseId":31,"cycle":32,"description":4920,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4921,"url":4922},"CVE-2025-38718","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: linearize cloned gso packets in sctp_rcv\n\nA cloned head skb still shares these frag skbs in fraglist with the\noriginal head skb. It's not safe to access these frag skbs.\n\nsyzbot reported two use-of-uninitialized-memory bugs caused by this:\n\n  BUG: KMSAN: uninit-value in sctp_inq_pop+0x15b7\u002F0x1920 net\u002Fsctp\u002Finqueue.c:211\n   sctp_inq_pop+0x15b7\u002F0x1920 net\u002Fsctp\u002Finqueue.c:211\n   sctp_assoc_bh_rcv+0x1a7\u002F0xc50 net\u002Fsctp\u002Fassociola","2025-09-04T16:15:41.413+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38718",{"cveId":4919,"releaseId":17,"cycle":18,"description":4920,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4921,"url":4922},{"cveId":4919,"releaseId":25,"cycle":26,"description":4920,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4921,"url":4922},{"cveId":4926,"releaseId":31,"cycle":32,"description":4927,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4928,"url":4929},"CVE-2025-38717","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: kcm: Fix race condition in kcm_unattach()\n\nsyzbot found a race condition when kcm_unattach(psock)\nand kcm_release(kcm) are executed at the same time.\n\nkcm_unattach() is missing a check of the flag\nkcm->tx_stopped before calling queue_work().\n\nIf the kcm has a reserved psock, kcm_unattach() might get executed\nbetween cancel_work_sync() and unreserve_psock() in kcm_release(),\nrequeuing kcm->tx_work right before kcm gets free","2025-09-04T16:15:41.257+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38717",{"cveId":4926,"releaseId":17,"cycle":18,"description":4927,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4928,"url":4929},{"cveId":4926,"releaseId":25,"cycle":26,"description":4927,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4928,"url":4929},{"cveId":4933,"releaseId":31,"cycle":32,"description":4934,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4935,"url":4936},"CVE-2025-38715","In the Linux kernel, the following vulnerability has been resolved:\n\nhfs: fix slab-out-of-bounds in hfs_bnode_read()\n\nThis patch introduces is_bnode_offset_valid() method that checks\nthe requested offset value. Also, it introduces\ncheck_and_correct_requested_length() method that checks and\ncorrect the requested length (if it is necessary). These methods\nare used in hfs_bnode_read(), hfs_bnode_write(), hfs_bnode_clear(),\nhfs_bnode_copy(), and hfs_bnode_move() with the goal to prevent\nthe access o","2025-09-04T16:15:40.97+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38715",{"cveId":4933,"releaseId":17,"cycle":18,"description":4934,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4935,"url":4936},{"cveId":4933,"releaseId":25,"cycle":26,"description":4934,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4935,"url":4936},{"cveId":4940,"releaseId":31,"cycle":32,"description":4941,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4942,"url":4943},"CVE-2025-38714","In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()\n\nThe hfsplus_bnode_read() method can trigger the issue:\n\n[  174.852007][ T9784] ==================================================================\n[  174.852709][ T9784] BUG: KASAN: slab-out-of-bounds in hfsplus_bnode_read+0x2f4\u002F0x360\n[  174.853412][ T9784] Read of size 8 at addr ffff88810b5fc6c0 by task repro\u002F9784\n[  174.854059][ T9784]\n[  174.854272][ T9784] CPU: 1 UID: ","2025-09-04T16:15:40.82+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38714",{"cveId":4940,"releaseId":17,"cycle":18,"description":4941,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4942,"url":4943},{"cveId":4940,"releaseId":25,"cycle":26,"description":4941,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4942,"url":4943},{"cveId":4947,"releaseId":31,"cycle":32,"description":4948,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4949,"url":4950},"CVE-2025-38713","In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()\n\nThe hfsplus_readdir() method is capable to crash by calling\nhfsplus_uni2asc():\n\n[  667.121659][ T9805] ==================================================================\n[  667.122651][ T9805] BUG: KASAN: slab-out-of-bounds in hfsplus_uni2asc+0x902\u002F0xa10\n[  667.123627][ T9805] Read of size 2 at addr ffff88802592f40c by task repro\u002F9805\n[  667.124578][ T9805]\n[  667.12487","2025-09-04T16:15:40.657+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38713",{"cveId":4947,"releaseId":17,"cycle":18,"description":4948,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4949,"url":4950},{"cveId":4947,"releaseId":25,"cycle":26,"description":4948,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":4949,"url":4950},{"cveId":4954,"releaseId":25,"cycle":26,"description":4955,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4956,"url":4957},"CVE-2025-38710","In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Validate i_depth for exhash directories\n\nA fuzzer test introduced corruption that ends up with a depth of 0 in\ndir_e_read(), causing an undefined shift by 32 at:\n\n  index = hash >> (32 - dip->i_depth);\n\nAs calculated in an open-coded way in dir_make_exhash(), the minimum\ndepth for an exhash directory is ilog2(sdp->sd_hash_ptrs) and 0 is\ninvalid as sdp->sd_hash_ptrs is fixed as sdp->bsize \u002F 16 at mount time.\n\nSo we can avo","2025-09-04T16:15:40.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38710",{"cveId":4954,"releaseId":17,"cycle":18,"description":4955,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4956,"url":4957},{"cveId":4954,"releaseId":31,"cycle":32,"description":4955,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":4956,"url":4957},{"cveId":4961,"releaseId":31,"cycle":32,"description":4962,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4963,"url":4964},"CVE-2025-38708","In the Linux kernel, the following vulnerability has been resolved:\n\ndrbd: add missing kref_get in handle_write_conflicts\n\nWith `two-primaries` enabled, DRBD tries to detect \"concurrent\" writes\nand handle write conflicts, so that even if you write to the same sector\nsimultaneously on both nodes, they end up with the identical data once\nthe writes are completed.\n\nIn handling \"superseeded\" writes, we forgot a kref_get,\nresulting in a premature drbd_destroy_device and use after free,\nand further to","2025-09-04T16:15:39.847+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38708",{"cveId":4961,"releaseId":17,"cycle":18,"description":4962,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4963,"url":4964},{"cveId":4961,"releaseId":25,"cycle":26,"description":4962,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":4963,"url":4964},{"cveId":4968,"releaseId":31,"cycle":32,"description":4969,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4970,"url":4971},"CVE-2025-38704","In the Linux kernel, the following vulnerability has been resolved:\n\nrcu\u002Fnocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access\n\nIn the preparation stage of CPU online, if the corresponding\nthe rdp's->nocb_cb_kthread does not exist, will be created,\nthere is a situation where the rdp's rcuop kthreads creation fails,\nand then de-offload this CPU's rdp, does not assign this CPU's\nrdp->nocb_cb_kthread pointer, but this rdp's->nocb_gp_rdp and\nrdp's->rdp_gp->nocb_gp_kthread is still valid.\n","2025-09-04T16:15:39.263+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38704",{"cveId":4968,"releaseId":17,"cycle":18,"description":4969,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4970,"url":4971},{"cveId":4968,"releaseId":25,"cycle":26,"description":4969,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4970,"url":4971},{"cveId":4975,"releaseId":31,"cycle":32,"description":4976,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4977,"url":4978},"CVE-2025-38697","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: upper bound check of tree index in dbAllocAG\n\nWhen computing the tree index in dbAllocAG, we never check if we are\nout of bounds realative to the size of the stree.\nThis could happen in a scenario where the filesystem metadata are\ncorrupted.","2025-09-04T16:15:38.21+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38697",{"cveId":4975,"releaseId":17,"cycle":18,"description":4976,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4977,"url":4978},{"cveId":4975,"releaseId":25,"cycle":26,"description":4976,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4977,"url":4978},{"cveId":4982,"releaseId":31,"cycle":32,"description":4983,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4984,"url":4985},"CVE-2025-38687","In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: fix race between polling and detaching\n\nsyzbot reports a use-after-free in comedi in the below link, which is\ndue to comedi gladly removing the allocated async area even though poll\nrequests are still active on the wait_queue_head inside of it. This can\ncause a use-after-free when the poll entries are later triggered or\nremoved, as the memory for the wait_queue_head has been freed.  We need\nto check there are no tasks q","2025-09-04T16:15:36.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38687",{"cveId":4982,"releaseId":17,"cycle":18,"description":4983,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4984,"url":4985},{"cveId":4982,"releaseId":25,"cycle":26,"description":4983,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4984,"url":4985},{"cveId":4989,"releaseId":31,"cycle":32,"description":4990,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4991,"url":4992},"CVE-2025-38685","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Fix vmalloc out-of-bounds write in fast_imageblit\n\nThis issue triggers when a userspace program does an ioctl\nFBIOPUT_CON2FBMAP by passing console number and frame buffer number.\nIdeally this maps console to frame buffer and updates the screen if\nconsole is visible.\n\nAs part of mapping it has to do resize of console according to frame\nbuffer info. if this resize fails and returns from vc_do_resize() and\ncontinues further","2025-09-04T16:15:36.397+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38685",{"cveId":4989,"releaseId":17,"cycle":18,"description":4990,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4991,"url":4992},{"cveId":4989,"releaseId":25,"cycle":26,"description":4990,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":4991,"url":4992},{"cveId":4996,"releaseId":17,"cycle":18,"description":4997,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4998,"url":4999},"CVE-2025-38679","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: Fix OOB read due to missing payload bound check\n\nCurrently, The event_seq_changed() handler processes a variable number\nof properties sent by the firmware. The number of properties is indicated\nby the firmware and used to iterate over the payload. However, the\npayload size is not being validated against the actual message length.\n\nThis can lead to out-of-bounds memory access if the firmware provides a\nproperty cou","2025-09-04T16:15:35.387+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38679",{"cveId":4996,"releaseId":25,"cycle":26,"description":4997,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":4998,"url":4999},{"cveId":5002,"releaseId":31,"cycle":32,"description":5003,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5004,"url":5005},"CVE-2025-38677","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid out-of-boundary access in dnode page\n\nAs Jiaming Zhang reported:\n\n \u003CTASK>\n __dump_stack lib\u002Fdump_stack.c:94 [inline]\n dump_stack_lvl+0x1c1\u002F0x2a0 lib\u002Fdump_stack.c:120\n print_address_description mm\u002Fkasan\u002Freport.c:378 [inline]\n print_report+0x17e\u002F0x800 mm\u002Fkasan\u002Freport.c:480\n kasan_report+0x147\u002F0x180 mm\u002Fkasan\u002Freport.c:593\n data_blkaddr fs\u002Ff2fs\u002Ff2fs.h:3053 [inline]\n f2fs_data_blkaddr fs\u002Ff2fs\u002Ff2fs.h:3058 [inline]\n ","2025-08-30T10:15:36.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38677",{"cveId":5002,"releaseId":17,"cycle":18,"description":5003,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5004,"url":5005},{"cveId":5002,"releaseId":25,"cycle":26,"description":5003,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5004,"url":5005},{"cveId":5009,"releaseId":17,"cycle":18,"description":5010,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5011,"url":5012},"CVE-2024-58240","In the Linux kernel, the following vulnerability has been resolved:\n\ntls: separate no-async decryption request handling from async\n\nIf we're not doing async, the handling is much simpler. There's no\nreference counting, we just need to wait for the completion to wake us\nup and return its result.\n\nWe should preferably also use a separate crypto_wait. I'm not seeing a\nUAF as I did in the past, I think aec7961916f3 (\"tls: fix race between\nasync notify and socket close\") took care of it.\n\nThis will m","2025-08-28T10:15:31.78+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58240",{"cveId":5009,"releaseId":25,"cycle":26,"description":5010,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5011,"url":5012},{"cveId":5015,"releaseId":25,"cycle":26,"description":5016,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":5017,"url":5018},"CVE-2025-38652","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid out-of-boundary access in devs.path\n\n- touch \u002Fmnt\u002Ff2fs\u002F012345678901234567890123456789012345678901234567890123\n- truncate -s $((1024*1024*1024)) \\\n  \u002Fmnt\u002Ff2fs\u002F012345678901234567890123456789012345678901234567890123\n- touch \u002Fmnt\u002Ff2fs\u002Ffile\n- truncate -s $((1024*1024*1024)) \u002Fmnt\u002Ff2fs\u002Ffile\n- mkfs.f2fs \u002Fmnt\u002Ff2fs\u002F012345678901234567890123456789012345678901234567890123 \\\n  -c \u002Fmnt\u002Ff2fs\u002Ffile\n- mount \u002Fmnt\u002Ff2fs\u002F0123456789","2025-08-22T16:15:40.057+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38652",{"cveId":5015,"releaseId":17,"cycle":18,"description":5016,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":5017,"url":5018},{"cveId":5021,"releaseId":25,"cycle":26,"description":5022,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5023,"url":5024},"CVE-2025-38643","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()\n\nCallers of wdev_chandef() must hold the wiphy mutex.\n\nBut the worker cfg80211_propagate_cac_done_wk() never takes the lock.\nWhich triggers the warning below with the mesh_peer_connected_dfs\ntest from hostapd and not (yet) released mac80211 code changes:\n\nWARNING: CPU: 0 PID: 495 at net\u002Fwireless\u002Fchan.c:1552 wdev_chandef+0x60\u002F0x165\nModules linked in:\nCPU: 0 UID: 0 ","2025-08-22T16:15:38.417+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38643",{"cveId":5021,"releaseId":17,"cycle":18,"description":5022,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5023,"url":5024},{"cveId":5027,"releaseId":31,"cycle":32,"description":5028,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5029,"url":5030},"CVE-2025-38639","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_nfacct: don't assume acct name is null-terminated\n\nBUG: KASAN: slab-out-of-bounds in .. lib\u002Fvsprintf.c:721\nRead of size 1 at addr ffff88801eac95c8 by task syz-executor183\u002F5851\n[..]\n string+0x231\u002F0x2b0 lib\u002Fvsprintf.c:721\n vsnprintf+0x739\u002F0xf00 lib\u002Fvsprintf.c:2874\n [..]\n nfacct_mt_checkentry+0xd2\u002F0xe0 net\u002Fnetfilter\u002Fxt_nfacct.c:41\n xt_check_match+0x3d1\u002F0xab0 net\u002Fnetfilter\u002Fx_tables.c:523\n\nnfnl_acct_find_get() handles ","2025-08-22T16:15:37.85+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38639",{"cveId":5027,"releaseId":17,"cycle":18,"description":5028,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5029,"url":5030},{"cveId":5027,"releaseId":25,"cycle":26,"description":5028,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5029,"url":5030},{"cveId":5034,"releaseId":25,"cycle":26,"description":5035,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5036,"url":5037},"CVE-2025-38626","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode\n\nw\u002F \"mode=lfs\" mount option, generic\u002F299 will cause system panic as below:\n\n------------[ cut here ]------------\nkernel BUG at fs\u002Ff2fs\u002Fsegment.c:2835!\nCall Trace:\n \u003CTASK>\n f2fs_allocate_data_block+0x6f4\u002F0xc50\n f2fs_map_blocks+0x970\u002F0x1550\n f2fs_iomap_begin+0xb2\u002F0x1e0\n iomap_iter+0x1d6\u002F0x430\n __iomap_dio_rw+0x208\u002F0x9a0\n f2fs_file_write_iter+0x6b3\u002F0xfa0\n aio_","2025-08-22T16:15:36.193+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38626",{"cveId":5034,"releaseId":17,"cycle":18,"description":5035,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5036,"url":5037},{"cveId":5034,"releaseId":31,"cycle":32,"description":5035,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5036,"url":5037},{"cveId":5041,"releaseId":31,"cycle":32,"description":5042,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5043,"url":5044},"CVE-2025-38618","In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Do not allow binding to VMADDR_PORT_ANY\n\nIt is possible for a vsock to autobind to VMADDR_PORT_ANY. This can\ncause a use-after-free when a connection is made to the bound socket.\nThe socket returned by accept() also has port VMADDR_PORT_ANY but is not\non the list of unbound sockets. Binding it will result in an extra\nrefcount decrement similar to the one fixed in fcdd2242c023 (vsock: Keep\nthe binding until socket destruc","2025-08-22T14:15:46.303+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38618",{"cveId":5041,"releaseId":17,"cycle":18,"description":5042,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5043,"url":5044},{"cveId":5041,"releaseId":25,"cycle":26,"description":5042,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5043,"url":5044},{"cveId":5048,"releaseId":31,"cycle":32,"description":5049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5050,"url":5051},"CVE-2025-38617","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fpacket: fix a race in packet_set_ring() and packet_notifier()\n\nWhen packet_set_ring() releases po->bind_lock, another thread can\nrun packet_notifier() and process an NETDEV_UP event.\n\nThis race and the fix are both similar to that of commit 15fe076edea7\n(\"net\u002Fpacket: fix a race in packet_bind() and packet_notifier()\").\n\nThere too the packet_notifier NETDEV_UP event managed to run while a\npo->bind_lock critical section had t","2025-08-22T14:15:46.16+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38617",{"cveId":5048,"releaseId":17,"cycle":18,"description":5049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5050,"url":5051},{"cveId":5048,"releaseId":25,"cycle":26,"description":5049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5050,"url":5051},{"cveId":5055,"releaseId":31,"cycle":32,"description":5056,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5057,"url":5058},"CVE-2025-38614","In the Linux kernel, the following vulnerability has been resolved:\n\neventpoll: Fix semi-unbounded recursion\n\nEnsure that epoll instances can never form a graph deeper than\nEP_MAX_NESTS+1 links.\n\nCurrently, ep_loop_check_proc() ensures that the graph is loop-free and\ndoes some recursion depth checks, but those recursion depth checks don't\nlimit the depth of the resulting tree for two reasons:\n\n - They don't look upwards in the tree.\n - If there are multiple downwards paths of different lengths, ","2025-08-19T17:15:40.04+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38614",{"cveId":5055,"releaseId":17,"cycle":18,"description":5056,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5057,"url":5058},{"cveId":5055,"releaseId":25,"cycle":26,"description":5056,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5057,"url":5058},{"cveId":5062,"releaseId":31,"cycle":32,"description":5063,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5064,"url":5065},"CVE-2025-38604","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtl818x: Kill URBs before clearing tx status queue\n\nIn rtl8187_stop() move the call of usb_kill_anchored_urbs() before clearing\nb_tx_status.queue. This change prevents callbacks from using already freed\nskb due to anchor was not killed before freeing such skb.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000080\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D","2025-08-19T17:15:38.647+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38604",{"cveId":5062,"releaseId":17,"cycle":18,"description":5063,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5064,"url":5065},{"cveId":5062,"releaseId":25,"cycle":26,"description":5063,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5064,"url":5065},{"cveId":5069,"releaseId":17,"cycle":18,"description":5070,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5071,"url":5072},"CVE-2025-38595","In the Linux kernel, the following vulnerability has been resolved:\n\nxen: fix UAF in dmabuf_exp_from_pages()\n\n[dma_buf_fd() fixes; no preferences regarding the tree it goes through -\nup to xen folks]\n\nAs soon as we'd inserted a file reference into descriptor table, another\nthread could close it.  That's fine for the case when all we are doing is\nreturning that descriptor to userland (it's a race, but it's a userland\nrace and there's nothing the kernel can do about it).  However, if we\nfollow fd_","2025-08-19T17:15:37.343+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38595",{"cveId":5074,"releaseId":17,"cycle":18,"description":5075,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5076,"url":5077},"CVE-2025-38591","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject narrower access to pointer ctx fields\n\nThe following BPF program, simplified from a syzkaller repro, causes a\nkernel warning:\n\n    r0 = *(u8 *)(r1 + 169);\n    exit;\n\nWith pointer field sk being at offset 168 in __sk_buff. This access is\ndetected as a narrower read in bpf_skb_is_valid_access because it\ndoesn't match offsetof(struct __sk_buff, sk). It is therefore allowed\nand later proceeds to bpf_convert_ctx_access. ","2025-08-19T17:15:36.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38591",{"cveId":5074,"releaseId":25,"cycle":26,"description":5075,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5076,"url":5077},{"cveId":5080,"releaseId":25,"cycle":26,"description":5081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5082,"url":5083},"CVE-2025-38584","In the Linux kernel, the following vulnerability has been resolved:\n\npadata: Fix pd UAF once and for all\n\nThere is a race condition\u002FUAF in padata_reorder that goes back\nto the initial commit.  A reference count is taken at the start\nof the process in padata_do_parallel, and released at the end in\npadata_serial_worker.\n\nThis reference count is (and only is) required for padata_replace\nto function correctly.  If padata_replace is never called then\nthere is no issue.\n\nIn the function padata_reorder","2025-08-19T17:15:35.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38584",{"cveId":5080,"releaseId":17,"cycle":18,"description":5081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5082,"url":5083},{"cveId":5080,"releaseId":31,"cycle":32,"description":5081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5082,"url":5083},{"cveId":5087,"releaseId":31,"cycle":32,"description":5088,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5089,"url":5090},"CVE-2025-38578","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid UAF in f2fs_sync_inode_meta()\n\nsyzbot reported an UAF issue as below: [1] [2]\n\n[1] https:\u002F\u002Fsyzkaller.appspot.com\u002Ftext?tag=CrashReport&x=16594c60580000\n\n==================================================================\nBUG: KASAN: use-after-free in __list_del_entry_valid+0xa6\u002F0x130 lib\u002Flist_debug.c:62\nRead of size 8 at addr ffff888100567dc8 by task kworker\u002Fu4:0\u002F8\n\nCPU: 1 PID: 8 Comm: kworker\u002Fu4:0 Tainted: G  ","2025-08-19T17:15:34.87+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38578",{"cveId":5087,"releaseId":17,"cycle":18,"description":5088,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5089,"url":5090},{"cveId":5087,"releaseId":25,"cycle":26,"description":5088,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5089,"url":5090},{"cveId":5094,"releaseId":31,"cycle":32,"description":5095,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5096,"url":5097},"CVE-2025-38577","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid panic in f2fs_evict_inode\n\nAs syzbot [1] reported as below:\n\nR10: 0000000000000100 R11: 0000000000000206 R12: 00007ffe17473450\nR13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520\n \u003C\u002FTASK>\n---[ end trace 0000000000000000 ]---\n==================================================================\nBUG: KASAN: use-after-free in __list_del_entry_valid+0xa6\u002F0x130 lib\u002Flist_debug.c:62\nRead of size 8 at addr","2025-08-19T17:15:34.72+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38577",{"cveId":5094,"releaseId":17,"cycle":18,"description":5095,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5096,"url":5097},{"cveId":5094,"releaseId":25,"cycle":26,"description":5095,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5096,"url":5097},{"cveId":5101,"releaseId":31,"cycle":32,"description":5102,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":5103,"url":5104},"CVE-2025-38574","In the Linux kernel, the following vulnerability has been resolved:\n\npptp: ensure minimal skb length in pptp_xmit()\n\nCommit aabc6596ffb3 (\"net: ppp: Add bound checking for skb data\non ppp_sync_txmung\") fixed ppp_sync_txmunge()\n\nWe need a similar fix in pptp_xmit(), otherwise we might\nread uninit data as reported by syzbot.\n\nBUG: KMSAN: uninit-value in pptp_xmit+0xc34\u002F0x2720 drivers\u002Fnet\u002Fppp\u002Fpptp.c:193\n  pptp_xmit+0xc34\u002F0x2720 drivers\u002Fnet\u002Fppp\u002Fpptp.c:193\n  ppp_channel_bridge_input drivers\u002Fnet\u002Fppp\u002Fp","2025-08-19T17:15:34.427+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38574",{"cveId":5101,"releaseId":17,"cycle":18,"description":5102,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":5103,"url":5104},{"cveId":5101,"releaseId":25,"cycle":26,"description":5102,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":5103,"url":5104},{"cveId":5108,"releaseId":31,"cycle":32,"description":5109,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5110,"url":5111},"CVE-2025-38572","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: reject malicious packets in ipv6_gso_segment()\n\nsyzbot was able to craft a packet with very long IPv6 extension headers\nleading to an overflow of skb->transport_header.\n\nThis 16bit field has a limited range.\n\nAdd skb_reset_transport_header_careful() helper and use it\nfrom ipv6_gso_segment()\n\nWARNING: CPU: 0 PID: 5871 at .\u002Finclude\u002Flinux\u002Fskbuff.h:3032 skb_reset_transport_header include\u002Flinux\u002Fskbuff.h:3032 [inline]\nWARNING: ","2025-08-19T17:15:34.117+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38572",{"cveId":5108,"releaseId":17,"cycle":18,"description":5109,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5110,"url":5111},{"cveId":5108,"releaseId":25,"cycle":26,"description":5109,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5110,"url":5111},{"cveId":5115,"releaseId":31,"cycle":32,"description":5116,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5117,"url":5118},"CVE-2025-38555","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget : fix use-after-free in composite_dev_cleanup()\n\n1. In func configfs_composite_bind() -> composite_os_desc_req_prepare():\nif kmalloc fails, the pointer cdev->os_desc_req will be freed but not\nset to NULL. Then it will return a failure to the upper-level function.\n2. in func configfs_composite_bind() -> composite_dev_cleanup():\nit will checks whether cdev->os_desc_req is NULL. If it is not NULL, it\nwill attempt to us","2025-08-19T17:15:31.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38555",{"cveId":5115,"releaseId":17,"cycle":18,"description":5116,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5117,"url":5118},{"cveId":5115,"releaseId":25,"cycle":26,"description":5116,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5117,"url":5118},{"cveId":5122,"releaseId":31,"cycle":32,"description":5123,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5124,"url":5125},"CVE-2025-38542","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: appletalk: Fix device refcount leak in atrtr_create()\n\nWhen updating an existing route entry in atrtr_create(), the old device\nreference was not being released before assigning the new device,\nleading to a device refcount leak. Fix this by calling dev_put() to\nrelease the old device reference before holding the new one.","2025-08-16T12:15:30.083+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38542",{"cveId":5122,"releaseId":17,"cycle":18,"description":5123,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5124,"url":5125},{"cveId":5122,"releaseId":25,"cycle":26,"description":5123,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5124,"url":5125},{"cveId":5129,"releaseId":31,"cycle":32,"description":5130,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5131,"url":5132},"CVE-2025-38539","In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Add down_write(trace_event_sem) when adding trace event\n\nWhen a module is loaded, it adds trace events defined by the module. It\nmay also need to modify the modules trace printk formats to replace enum\nnames with their values.\n\nIf two modules are loaded at the same time, the adding of the event to the\nftrace_events list can corrupt the walking of the list in the code that is\nmodifying the printk format strings and cras","2025-08-16T12:15:29.717+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38539",{"cveId":5129,"releaseId":17,"cycle":18,"description":5130,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5131,"url":5132},{"cveId":5129,"releaseId":25,"cycle":26,"description":5130,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5131,"url":5132},{"cveId":5136,"releaseId":31,"cycle":32,"description":5137,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5138,"url":5139},"CVE-2025-38527","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in cifs_oplock_break\n\nA race condition can occur in cifs_oplock_break() leading to a\nuse-after-free of the cinode structure when unmounting:\n\n  cifs_oplock_break()\n    _cifsFileInfo_put(cfile)\n      cifsFileInfo_put_final()\n        cifs_sb_deactive()\n          [last ref, start releasing sb]\n            kill_sb()\n              kill_anon_super()\n                generic_shutdown_super()\n            ","2025-08-16T12:15:28.183+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38527",{"cveId":5136,"releaseId":17,"cycle":18,"description":5137,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5138,"url":5139},{"cveId":5136,"releaseId":25,"cycle":26,"description":5137,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5138,"url":5139},{"cveId":5143,"releaseId":17,"cycle":18,"description":5144,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5145,"url":5146},"CVE-2025-38524","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix recv-recv race of completed call\n\nIf a call receives an event (such as incoming data), the call gets placed\non the socket's queue and a thread in recvmsg can be awakened to go and\nprocess it.  Once the thread has picked up the call off of the queue,\nfurther events will cause it to be requeued, and once the socket lock is\ndropped (recvmsg uses call->user_mutex to allow the socket to be used in\nparallel), a second thre","2025-08-16T12:15:27.8+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38524",{"cveId":5143,"releaseId":25,"cycle":26,"description":5144,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5145,"url":5146},{"cveId":5143,"releaseId":31,"cycle":32,"description":5144,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5145,"url":5146},{"cveId":5150,"releaseId":31,"cycle":32,"description":5151,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5152,"url":5153},"CVE-2025-38514","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix oops due to non-existence of prealloc backlog struct\n\nIf an AF_RXRPC service socket is opened and bound, but calls are\npreallocated, then rxrpc_alloc_incoming_call() will oops because the\nrxrpc_backlog struct doesn't get allocated until the first preallocation is\nmade.\n\nFix this by returning NULL from rxrpc_alloc_incoming_call() if there is no\nbacklog struct.  This will cause the incoming call to be aborted.","2025-08-16T11:15:44.51+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38514",{"cveId":5150,"releaseId":25,"cycle":26,"description":5151,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5152,"url":5153},{"cveId":5150,"releaseId":17,"cycle":18,"description":5151,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5152,"url":5153},{"cveId":5157,"releaseId":31,"cycle":32,"description":5158,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5159,"url":5160},"CVE-2025-38499","In the Linux kernel, the following vulnerability has been resolved:\n\nclone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns\n\nWhat we want is to verify there is that clone won't expose something\nhidden by a mount we wouldn't be able to undo.  \"Wouldn't be able to undo\"\nmay be a result of MNT_LOCKED on a child, but it may also come from\nlacking admin rights in the userns of the namespace mount belongs to.\n\nclone_private_mnt() checks the former, but not the latter.\n\nThere'","2025-08-11T16:15:30.057+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38499",{"cveId":5157,"releaseId":25,"cycle":26,"description":5158,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5159,"url":5160},{"cveId":5157,"releaseId":17,"cycle":18,"description":5158,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5159,"url":5160},{"cveId":5164,"releaseId":25,"cycle":26,"description":5165,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5166,"url":5167},"CVE-2022-50233","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: eir: Fix using strlen with hdev->{dev_name,short_name}\n\nBoth dev_name and short_name are not guaranteed to be NULL terminated so\nthis instead use strnlen and then attempt to determine if the resulting\nstring needs to be truncated or not.","2025-08-09T15:15:27.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50233",{"cveId":5164,"releaseId":17,"cycle":18,"description":5165,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5166,"url":5167},{"cveId":5170,"releaseId":25,"cycle":26,"description":5171,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5172,"url":5173},"CVE-2025-38498","In the Linux kernel, the following vulnerability has been resolved:\n\ndo_change_type(): refuse to operate on unmounted\u002Fnot ours mounts\n\nEnsure that propagation settings can only be changed for mounts located\nin the caller's mount namespace. This change aligns permission checking\nwith the rest of mount(2).","2025-07-30T06:15:27.527+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38498",{"cveId":5170,"releaseId":17,"cycle":18,"description":5171,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5172,"url":5173},{"cveId":5170,"releaseId":31,"cycle":32,"description":5171,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5172,"url":5173},{"cveId":5177,"releaseId":31,"cycle":32,"description":5178,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5179,"url":5180},"CVE-2025-38495","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: ensure the allocated report buffer can contain the reserved report ID\n\nWhen the report ID is not used, the low level transport drivers expect\nthe first byte to be 0. However, currently the allocated buffer not\naccount for that extra byte, meaning that instead of having 8 guaranteed\nbytes for implement to be working, we only have 7.","2025-07-28T12:15:31.727+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38495",{"cveId":5177,"releaseId":17,"cycle":18,"description":5178,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5179,"url":5180},{"cveId":5177,"releaseId":25,"cycle":26,"description":5178,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5179,"url":5180},{"cveId":5184,"releaseId":31,"cycle":32,"description":5185,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5186,"url":5187},"CVE-2025-38494","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: do not bypass hid_hw_raw_request\n\nhid_hw_raw_request() is actually useful to ensure the provided buffer\nand length are valid. Directly calling in the low level transport driver\nfunction bypassed those checks and allowed invalid paramto be used.","2025-07-28T12:15:31.607+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38494",{"cveId":5184,"releaseId":25,"cycle":26,"description":5185,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5186,"url":5187},{"cveId":5184,"releaseId":17,"cycle":18,"description":5185,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5186,"url":5187},{"cveId":5191,"releaseId":25,"cycle":26,"description":5192,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5193,"url":5194},"CVE-2025-38478","In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: Fix initialization of data for instructions that write to subdevice\n\nSome Comedi subdevice instruction handlers are known to access\ninstruction data elements beyond the first `insn->n` elements in some\ncases.  The `do_insn_ioctl()` and `do_insnlist_ioctl()` functions\nallocate at least `MIN_SAMPLES` (16) data elements to deal with this,\nbut they do not initialize all of that.  For Comedi instruction codes\nthat write to t","2025-07-28T12:15:29.733+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38478",{"cveId":5191,"releaseId":17,"cycle":18,"description":5192,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5193,"url":5194},{"cveId":5191,"releaseId":31,"cycle":32,"description":5192,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5193,"url":5194},{"cveId":5198,"releaseId":31,"cycle":32,"description":5199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5200,"url":5201},"CVE-2025-38477","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: sch_qfq: Fix race condition on qfq_aggregate\n\nA race condition can occur when 'agg' is modified in qfq_change_agg\n(called during qfq_enqueue) while other threads access it\nconcurrently. For example, qfq_dump_class may trigger a NULL\ndereference, and qfq_delete_class may cause a use-after-free.\n\nThis patch addresses the issue by:\n\n1. Moved qfq_destroy_class into the critical section.\n\n2. Added sch_tree_lock protection","2025-07-28T12:15:29.617+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38477",{"cveId":5198,"releaseId":17,"cycle":18,"description":5199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5200,"url":5201},{"cveId":5198,"releaseId":25,"cycle":26,"description":5199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5200,"url":5201},{"cveId":5205,"releaseId":25,"cycle":26,"description":5206,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5207,"url":5208},"CVE-2025-38470","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime\n\nAssuming the \"rx-vlan-filter\" feature is enabled on a net device, the\n8021q module will automatically add or remove VLAN 0 when the net device\nis put administratively up or down, respectively. There are a couple of\nproblems with the above scheme.\n\nThe first problem is a memory leak that can happen if the \"rx-vlan-filter\"\nfeature is disabled while the","2025-07-28T12:15:28.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38470",{"cveId":5205,"releaseId":31,"cycle":32,"description":5206,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5207,"url":5208},{"cveId":5205,"releaseId":17,"cycle":18,"description":5206,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5207,"url":5208},{"cveId":5212,"releaseId":25,"cycle":26,"description":5213,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5214,"url":5215},"CVE-2025-38464","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Fix use-after-free in tipc_conn_close().\n\nsyzbot reported a null-ptr-deref in tipc_conn_close() during netns\ndismantle. [0]\n\ntipc_topsrv_stop() iterates tipc_net(net)->topsrv->conn_idr and calls\ntipc_conn_close() for each tipc_conn.\n\nThe problem is that tipc_conn_close() is called after releasing the\nIDR lock.\n\nAt the same time, there might be tipc_conn_recv_work() running and it\ncould call tipc_conn_close() for the same ","2025-07-25T16:15:32.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38464",{"cveId":5212,"releaseId":31,"cycle":32,"description":5213,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5214,"url":5215},{"cveId":5212,"releaseId":17,"cycle":18,"description":5213,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5214,"url":5215},{"cveId":5219,"releaseId":31,"cycle":32,"description":5220,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5221,"url":5222},"CVE-2025-38460","In the Linux kernel, the following vulnerability has been resolved:\n\natm: clip: Fix potential null-ptr-deref in to_atmarpd().\n\natmarpd is protected by RTNL since commit f3a0592b37b8 (\"[ATM]: clip\ncauses unregister hang\").\n\nHowever, it is not enough because to_atmarpd() is called without RTNL,\nespecially clip_neigh_solicit() \u002F neigh_ops->solicit() is unsleepable.\n\nAlso, there is no RTNL dependency around atmarpd.\n\nLet's use a private mutex and RCU to protect access to atmarpd in\nto_atmarpd().","2025-07-25T16:15:31.787+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38460",{"cveId":5219,"releaseId":17,"cycle":18,"description":5220,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5221,"url":5222},{"cveId":5219,"releaseId":25,"cycle":26,"description":5220,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5221,"url":5222},{"cveId":5226,"releaseId":31,"cycle":32,"description":5227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5228,"url":5229},"CVE-2025-38449","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fgem: Acquire references on GEM handles for framebuffers\n\nA GEM handle can be released while the GEM buffer object is attached\nto a DRM framebuffer. This leads to the release of the dma-buf backing\nthe buffer object, if any. [1] Trying to use the framebuffer in further\nmode-setting operations leads to a segmentation fault. Most easily\nhappens with driver that use shadow planes for vmap-ing the dma-buf\nduring a page flip. An ","2025-07-25T16:15:30.443+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38449",{"cveId":5226,"releaseId":25,"cycle":26,"description":5227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5228,"url":5229},{"cveId":5226,"releaseId":17,"cycle":18,"description":5227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5228,"url":5229},{"cveId":5233,"releaseId":31,"cycle":32,"description":5234,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5235,"url":5236},"CVE-2025-38430","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: nfsd4_spo_must_allow() must check this is a v4 compound request\n\nIf the request being processed is not a v4 compound request, then\nexamining the cstate can have undefined results.\n\nThis patch adds a check that the rpc procedure being executed\n(rq_procinfo) is the NFSPROC4_COMPOUND procedure.","2025-07-25T15:15:27.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38430",{"cveId":5233,"releaseId":17,"cycle":18,"description":5234,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5235,"url":5236},{"cveId":5233,"releaseId":25,"cycle":26,"description":5234,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5235,"url":5236},{"cveId":5240,"releaseId":25,"cycle":26,"description":5241,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5242,"url":5243},"CVE-2025-38425","In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: tegra: check msg length in SMBUS block read\n\nFor SMBUS block read, do not continue to read if the message length\npassed from the device is '0' or greater than the maximum allowed bytes.","2025-07-25T15:15:27.39+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38425",{"cveId":5240,"releaseId":31,"cycle":32,"description":5241,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5242,"url":5243},{"cveId":5240,"releaseId":17,"cycle":18,"description":5241,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5242,"url":5243},{"cveId":5247,"releaseId":25,"cycle":26,"description":5248,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5249,"url":5250},"CVE-2025-38424","In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix sample vs do_exit()\n\nBaisheng Gao reported an ARM64 crash, which Mark decoded as being a\nsynchronous external abort -- most likely due to trying to access\nMMIO in bad ways.\n\nThe crash further shows perf trying to do a user stack sample while in\nexit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address\nspace it is trying to access.\n\nIt turns out that we stop perf after we tear down the userspace mm; a\nrecei","2025-07-25T15:15:27.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38424",{"cveId":5247,"releaseId":31,"cycle":32,"description":5248,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5249,"url":5250},{"cveId":5247,"releaseId":17,"cycle":18,"description":5248,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5249,"url":5250},{"cveId":5254,"releaseId":17,"cycle":18,"description":5255,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5256,"url":5257},"CVE-2025-38422","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices\n\nMaximum OTP and EEPROM size for hearthstone PCI1xxxx devices are 8 Kb\nand 64 Kb respectively. Adjust max size definitions and return correct\nEEPROM length based on device. Also prevent out-of-bound read\u002Fwrite.","2025-07-25T15:15:27.037+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38422",{"cveId":5259,"releaseId":31,"cycle":32,"description":5260,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5261,"url":5262},"CVE-2025-38416","In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: nci: uart: Set tty->disc_data only in success path\n\nSetting tty->disc_data before opening the NCI device means we need to\nclean it up on error paths.  This also opens some short window if device\nstarts sending data, even before NCIUARTSETDRIVER IOCTL succeeded\n(broken hardware?).  Close the window by exposing tty->disc_data only on\nthe success path, when opening of the NCI device and try_module_get()\nsucceeds.\n\nThe code di","2025-07-25T14:15:33.373+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38416",{"cveId":5259,"releaseId":17,"cycle":18,"description":5260,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5261,"url":5262},{"cveId":5259,"releaseId":25,"cycle":26,"description":5260,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5261,"url":5262},{"cveId":5266,"releaseId":31,"cycle":32,"description":5267,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5268,"url":5269},"CVE-2025-38401","In the Linux kernel, the following vulnerability has been resolved:\n\nmtk-sd: Prevent memory corruption from DMA map failure\n\nIf msdc_prepare_data() fails to map the DMA region, the request is\nnot prepared for data receiving, but msdc_start_data() proceeds\nthe DMA with previous setting.\nSince this will lead a memory corruption, we have to stop the\nrequest operation soon after the msdc_prepare_data() fails to\nprepare it.","2025-07-25T13:15:29.66+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38401",{"cveId":5266,"releaseId":17,"cycle":18,"description":5267,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5268,"url":5269},{"cveId":5266,"releaseId":25,"cycle":26,"description":5267,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5268,"url":5269},{"cveId":5273,"releaseId":31,"cycle":32,"description":5274,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5275,"url":5276},"CVE-2025-38386","In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: Refuse to evaluate a method if arguments are missing\n\nAs reported in [1], a platform firmware update that increased the number\nof method parameters and forgot to update a least one of its callers,\ncaused ACPICA to crash due to use-after-free.\n\nSince this a result of a clear AML issue that arguably cannot be fixed\nup by the interpreter (it cannot produce missing data out of thin air),\naddress it by making ACPICA refuse t","2025-07-25T13:15:27.877+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38386",{"cveId":5273,"releaseId":17,"cycle":18,"description":5274,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5275,"url":5276},{"cveId":5273,"releaseId":25,"cycle":26,"description":5274,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5275,"url":5276},{"cveId":5280,"releaseId":31,"cycle":32,"description":5281,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5282,"url":5283},"CVE-2025-38377","In the Linux kernel, the following vulnerability has been resolved:\n\nrose: fix dangling neighbour pointers in rose_rt_device_down()\n\nThere are two bugs in rose_rt_device_down() that can cause\nuse-after-free:\n\n1. The loop bound `t->count` is modified within the loop, which can\n   cause the loop to terminate early and miss some entries.\n\n2. When removing an entry from the neighbour array, the subsequent entries\n   are moved up to fill the gap, but the loop index `i` is still\n   incremented, causin","2025-07-25T13:15:26.78+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38377",{"cveId":5280,"releaseId":25,"cycle":26,"description":5281,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5282,"url":5283},{"cveId":5280,"releaseId":17,"cycle":18,"description":5281,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5282,"url":5283},{"cveId":5287,"releaseId":25,"cycle":26,"description":5288,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":5289,"url":5290},"CVE-2025-38375","In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-net: ensure the received length does not exceed allocated size\n\nIn xdp_linearize_page, when reading the following buffers from the ring,\nwe forget to check the received length with the true allocate size. This\ncan lead to an out-of-bound read. This commit adds that missing check.","2025-07-25T13:15:26.517+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38375",{"cveId":5287,"releaseId":17,"cycle":18,"description":5288,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":5289,"url":5290},{"cveId":5293,"releaseId":17,"cycle":18,"description":5294,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5295,"url":5296},"CVE-2025-38352","In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()\n\nIf an exiting non-autoreaping task has already passed exit_notify() and\ncalls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent\nor debugger right after unlock_task_sighand().\n\nIf a concurrent posix_cpu_timer_del() runs at that moment, it won't be\nable to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and\u002For\nlock_task","2025-07-22T08:15:23.577+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38352",{"cveId":5293,"releaseId":25,"cycle":26,"description":5294,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5295,"url":5296},{"cveId":5293,"releaseId":31,"cycle":32,"description":5294,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5295,"url":5296},{"cveId":5300,"releaseId":17,"cycle":18,"description":5301,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5302,"url":5303},"CVE-2025-38346","In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Fix UAF when lookup kallsym after ftrace disabled\n\nThe following issue happens with a buggy module:\n\nBUG: unable to handle page fault for address: ffffffffc05d0218\nPGD 1bd66f067 P4D 1bd66f067 PUD 1bd671067 PMD 101808067 PTE 0\nOops: Oops: 0000 [#1] SMP KASAN PTI\nTainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\nRIP: 0010:sized_strscpy+0x81\u002F0x2f0\nRSP: 0018:ffff88812d7","2025-07-10T09:15:29.573+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38346",{"cveId":5305,"releaseId":25,"cycle":26,"description":5306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5307,"url":5308},"CVE-2025-38333","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to bail out in get_new_segment()\n\n------------[ cut here ]------------\nWARNING: CPU: 3 PID: 579 at fs\u002Ff2fs\u002Fsegment.c:2832 new_curseg+0x5e8\u002F0x6dc\npc : new_curseg+0x5e8\u002F0x6dc\nCall trace:\n new_curseg+0x5e8\u002F0x6dc\n f2fs_allocate_data_block+0xa54\u002F0xe28\n do_write_page+0x6c\u002F0x194\n f2fs_do_write_node_page+0x38\u002F0x78\n __write_node_page+0x248\u002F0x6d4\n f2fs_sync_node_pages+0x524\u002F0x72c\n f2fs_write_checkpoint+0x4bc\u002F0x9b0\n __checkpoint","2025-07-10T09:15:27.827+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38333",{"cveId":5305,"releaseId":31,"cycle":32,"description":5306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5307,"url":5308},{"cveId":5305,"releaseId":17,"cycle":18,"description":5306,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5307,"url":5308},{"cveId":5312,"releaseId":17,"cycle":18,"description":5313,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5314,"url":5315},"CVE-2025-38331","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: cortina: Use TOE\u002FTSO on all TCP\n\nIt is desireable to push the hardware accelerator to also\nprocess non-segmented TCP frames: we pass the skb->len\nto the \"TOE\u002FTSO\" offloader and it will handle them.\n\nWithout this quirk the driver becomes unstable and lock\nup and and crash.\n\nI do not know exactly why, but it is probably due to the\nTOE (TCP offload engine) feature that is coupled with the\nsegmentation feature - it i","2025-07-10T09:15:27.533+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38331",{"cveId":5317,"releaseId":31,"cycle":32,"description":5318,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5319,"url":5320},"CVE-2025-38321","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Log an error when close_all_cached_dirs fails\n\nUnder low-memory conditions, close_all_cached_dirs() can't move the\ndentries to a separate list to dput() them once the locks are dropped.\nThis will result in a \"Dentry still in use\" error, so add an error\nmessage that makes it clear this is what happened:\n\n[  495.281119] CIFS: VFS: \\\\otters.example.com\\share Out of memory while dropping dentries\n[  495.281595] ------------[ c","2025-07-10T09:15:26.103+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38321",{"cveId":5317,"releaseId":17,"cycle":18,"description":5318,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5319,"url":5320},{"cveId":5317,"releaseId":25,"cycle":26,"description":5318,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5319,"url":5320},{"cveId":5324,"releaseId":25,"cycle":26,"description":5325,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5326,"url":5327},"CVE-2025-38262","In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: uartlite: register uart driver in init\n\nWhen two instances of uart devices are probing, a concurrency race can\noccur. If one thread calls uart_register_driver function, which first\nallocates and assigns memory to 'uart_state' member of uart_driver\nstructure, the other instance can bypass uart driver registration and\ncall ulite_assign. This calls uart_add_one_port, which expects the uart\ndriver to be fully initializ","2025-07-09T11:15:28.57+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38262",{"cveId":5324,"releaseId":31,"cycle":32,"description":5325,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5326,"url":5327},{"cveId":5324,"releaseId":17,"cycle":18,"description":5325,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5326,"url":5327},{"cveId":5331,"releaseId":17,"cycle":18,"description":5332,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5333,"url":5334},"CVE-2025-38261","In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: save the SR_SUM status over switches\n\nWhen threads\u002Ftasks are switched we need to ensure the old execution's\nSR_SUM state is saved and the new thread has the old SR_SUM state\nrestored.\n\nThe issue was seen under heavy load especially with the syz-stress tool\nrunning, with crashes as follows in schedule_tail:\n\nUnable to handle kernel access to user memory without uaccess routines\nat virtual address 000000002749f0d0\nOops [#1","2025-07-09T11:15:28.46+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38261",{"cveId":5336,"releaseId":31,"cycle":32,"description":5337,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5338,"url":5339},"CVE-2025-38250","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix use-after-free in vhci_flush()\n\nsyzbot reported use-after-free in vhci_flush() without repro. [0]\n\nFrom the splat, a thread close()d a vhci file descriptor while\nits device was being used by iotcl() on another thread.\n\nOnce the last fd refcnt is released, vhci_release() calls\nhci_unregister_dev(), hci_free_dev(), and kfree() for struct\nvhci_data, which is set to hci_dev->dev->driver_data.\n\nThe problem i","2025-07-09T11:15:27.193+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38250",{"cveId":5336,"releaseId":25,"cycle":26,"description":5337,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5338,"url":5339},{"cveId":5336,"releaseId":17,"cycle":18,"description":5337,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5338,"url":5339},{"cveId":5343,"releaseId":31,"cycle":32,"description":5344,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5345,"url":5346},"CVE-2025-38234","In the Linux kernel, the following vulnerability has been resolved:\n\nsched\u002Frt: Fix race in push_rt_task\n\nOverview\n========\nWhen a CPU chooses to call push_rt_task and picks a task to push to\nanother CPU's runqueue then it will call find_lock_lowest_rq method\nwhich would take a double lock on both CPUs' runqueues. If one of the\nlocks aren't readily available, it may lead to dropping the current\nrunqueue lock and reacquiring both the locks at once. During this window\nit is possible that the task i","2025-07-04T14:15:33.087+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38234",{"cveId":5343,"releaseId":25,"cycle":26,"description":5344,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5345,"url":5346},{"cveId":5343,"releaseId":17,"cycle":18,"description":5344,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5345,"url":5346},{"cveId":5350,"releaseId":17,"cycle":18,"description":5351,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":5352,"url":5353},"CVE-2025-38232","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: fix race between nfsd registration and exports_proc\n\nAs of now nfsd calls create_proc_exports_entry() at start of init_nfsd\nand cleanup by remove_proc_entry() at last of exit_nfsd.\n\nWhich causes kernel OOPs if there is race between below 2 operations:\n(i) exportfs -r\n(ii) mount -t nfsd none \u002Fproc\u002Ffs\u002Fnfsd\n\nfor 5.4 kernel ARM64:\n\nCPU 1:\nel1_irq+0xbc\u002F0x180\narch_counter_get_cntvct+0x14\u002F0x18\nrunning_clock+0xc\u002F0x18\npreempt_coun","2025-07-04T14:15:32.81+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38232",{"cveId":5350,"releaseId":31,"cycle":32,"description":5351,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":5352,"url":5353},{"cveId":5350,"releaseId":25,"cycle":26,"description":5351,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":5352,"url":5353},{"cveId":5357,"releaseId":25,"cycle":26,"description":5358,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5359,"url":5360},"CVE-2025-38230","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: validate AG parameters in dbMount() to prevent crashes\n\nValidate db_agheight, db_agwidth, and db_agstart in dbMount to catch\ncorrupted metadata early and avoid undefined behavior in dbAllocAG.\nLimits are derived from L2LPERCTL, LPERCTL\u002FMAXAG, and CTLTREESIZE:\n\n- agheight: 0 to L2LPERCTL\u002F2 (0 to 5) ensures shift\n  (L2LPERCTL - 2*agheight) >= 0.\n- agwidth: 1 to min(LPERCTL\u002FMAXAG, 2^(L2LPERCTL - 2*agheight))\n  ensures agperle","2025-07-04T14:15:32.55+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38230",{"cveId":5357,"releaseId":17,"cycle":18,"description":5358,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5359,"url":5360},{"cveId":5357,"releaseId":31,"cycle":32,"description":5358,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5359,"url":5360},{"cveId":5364,"releaseId":17,"cycle":18,"description":5365,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5366,"url":5367},"CVE-2025-38226","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: Change the siize of the composing\n\nsyzkaller found a bug:\n\nBUG: KASAN: vmalloc-out-of-bounds in tpg_fill_plane_pattern drivers\u002Fmedia\u002Fcommon\u002Fv4l2-tpg\u002Fv4l2-tpg-core.c:2608 [inline]\nBUG: KASAN: vmalloc-out-of-bounds in tpg_fill_plane_buffer+0x1a9c\u002F0x5af0 drivers\u002Fmedia\u002Fcommon\u002Fv4l2-tpg\u002Fv4l2-tpg-core.c:2705\nWrite of size 1440 at addr ffffc9000d0ffda0 by task vivid-000-vid-c\u002F5304\n\nCPU: 0 UID: 0 PID: 5304 Comm: vivid-000-","2025-07-04T14:15:31.367+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38226",{"cveId":5364,"releaseId":25,"cycle":26,"description":5365,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5366,"url":5367},{"cveId":5364,"releaseId":31,"cycle":32,"description":5365,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5366,"url":5367},{"cveId":5371,"releaseId":31,"cycle":32,"description":5372,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5373,"url":5374},"CVE-2025-38218","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on sit_bitmap_size\n\nw\u002F below testcase, resize will generate a corrupted image which\ncontains inconsistent metadata, so when mounting such image, it\nwill trigger kernel panic:\n\ntouch img\ntruncate -s $((512*1024*1024*1024)) img\nmkfs.f2fs -f img $((256*1024*1024))\nresize.f2fs -s -i img -t $((1024*1024*1024))\nmount img \u002Fmnt\u002Ff2fs\n\n------------[ cut here ]------------\nkernel BUG at fs\u002Ff2fs\u002Fsegment.h:863!\n","2025-07-04T14:15:30.353+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38218",{"cveId":5371,"releaseId":25,"cycle":26,"description":5372,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5373,"url":5374},{"cveId":5371,"releaseId":17,"cycle":18,"description":5372,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5373,"url":5374},{"cveId":5378,"releaseId":17,"cycle":18,"description":5379,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5380,"url":5381},"CVE-2025-38212","In the Linux kernel, the following vulnerability has been resolved:\n\nipc: fix to protect IPCS lookups using RCU\n\nsyzbot reported that it discovered a use-after-free vulnerability, [0]\n\n[0]: https:\u002F\u002Flore.kernel.org\u002Fall\u002F67af13f8.050a0220.21dd3.0038.GAE@google.com\u002F\n\nidr_for_each() is protected by rwsem, but this is not enough.  If it is\nnot protected by RCU read-critical region, when idr_for_each() calls\nradix_tree_node_free() through call_rcu() to free the radix_tree_node\nstructure, the node will ","2025-07-04T14:15:29.473+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38212",{"cveId":5378,"releaseId":31,"cycle":32,"description":5379,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5380,"url":5381},{"cveId":5378,"releaseId":25,"cycle":26,"description":5379,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5380,"url":5381},{"cveId":5385,"releaseId":25,"cycle":26,"description":5386,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5387,"url":5388},"CVE-2025-38211","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fiwcm: Fix use-after-free of work objects after cm_id destruction\n\nThe commit 59c68ac31e15 (\"iw_cm: free cm_id resources on the last\nderef\") simplified cm_id resource management by freeing cm_id once all\nreferences to the cm_id were removed. The references are removed either\nupon completion of iw_cm event handlers or when the application destroys\nthe cm_id. This commit introduced the use-after-free condition where\ncm_id_pri","2025-07-04T14:15:29.337+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38211",{"cveId":5385,"releaseId":17,"cycle":18,"description":5386,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5387,"url":5388},{"cveId":5385,"releaseId":31,"cycle":32,"description":5386,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5387,"url":5388},{"cveId":5392,"releaseId":25,"cycle":26,"description":5393,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5394,"url":5395},"CVE-2025-38204","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds read in add_missing_indices\n\nstbl is s8 but it must contain offsets into slot which can go from 0 to\n127.\n\nAdded a bound check for that error and return -EIO if the check fails.\nAlso make jfs_readdir return with error if add_missing_indices returns\nwith an error.","2025-07-04T14:15:28.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38204",{"cveId":5392,"releaseId":31,"cycle":32,"description":5393,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5394,"url":5395},{"cveId":5392,"releaseId":17,"cycle":18,"description":5393,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5394,"url":5395},{"cveId":5399,"releaseId":31,"cycle":32,"description":5400,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5401,"url":5402},"CVE-2025-38193","In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: sch_sfq: reject invalid perturb period\n\nGerrard Tai reported that SFQ perturb_period has no range check yet,\nand this can be used to trigger a race condition fixed in a separate patch.\n\nWe want to make sure ctl->perturb_period * HZ will not overflow\nand is positive.\n\n\ntc qd add dev lo root sfq perturb -10   # negative value : error\nError: sch_sfq: invalid perturb period.\n\ntc qd add dev lo root sfq perturb 1000000000 ","2025-07-04T14:15:26.403+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38193",{"cveId":5399,"releaseId":25,"cycle":26,"description":5400,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5401,"url":5402},{"cveId":5399,"releaseId":17,"cycle":18,"description":5400,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5401,"url":5402},{"cveId":5406,"releaseId":31,"cycle":32,"description":5407,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5408,"url":5409},"CVE-2025-38192","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: clear the dst when changing skb protocol\n\nA not-so-careful NAT46 BPF program can crash the kernel\nif it indiscriminately flips ingress packets from v4 to v6:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n    ip6_rcv_core (net\u002Fipv6\u002Fip6_input.c:190:20)\n    ipv6_rcv (net\u002Fipv6\u002Fip6_input.c:306:8)\n    process_backlog (net\u002Fcore\u002Fdev.c:6186:4)\n    napi_poll (net\u002Fcore\u002Fdev.c:6906:9)\n    net_rx_action (net\u002Fcore\u002Fde","2025-07-04T14:15:26.28+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38192",{"cveId":5406,"releaseId":25,"cycle":26,"description":5407,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5408,"url":5409},{"cveId":5406,"releaseId":17,"cycle":18,"description":5407,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5408,"url":5409},{"cveId":5413,"releaseId":17,"cycle":18,"description":5414,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5415,"url":5416},"CVE-2025-38189","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fv3d: Avoid NULL pointer dereference in `v3d_job_update_stats()`\n\nThe following kernel Oops was recently reported by Mesa CI:\n\n[  800.139824] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000588\n[  800.148619] Mem abort info:\n[  800.151402]   ESR = 0x0000000096000005\n[  800.155141]   EC = 0x25: DABT (current EL), IL = 32 bits\n[  800.160444]   SET = 0, FnV = 0\n[  800.163488]   EA = 0, S1PTW = 0","2025-07-04T14:15:25.883+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38189",{"cveId":5418,"releaseId":25,"cycle":26,"description":5419,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5420,"url":5421},"CVE-2025-38184","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer\n\nThe reproduction steps:\n1. create a tun interface\n2. enable l2 bearer\n3. TIPC_NL_UDP_GET_REMOTEIP with media name set to tun\n\ntipc: Started in network mode\ntipc: Node identity 8af312d38a21, cluster identity 4711\ntipc: Enabled bearer \u003Ceth:syz_tun>, priority 1\nOops: general protection fault\nKASAN: null-ptr-deref in range\nCPU: 1 UID: 1000 PID: 559 Comm: poc Not ","2025-07-04T14:15:25.237+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38184",{"cveId":5418,"releaseId":17,"cycle":18,"description":5419,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5420,"url":5421},{"cveId":5418,"releaseId":31,"cycle":32,"description":5419,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5420,"url":5421},{"cveId":5425,"releaseId":31,"cycle":32,"description":5426,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5427,"url":5428},"CVE-2025-38181","In the Linux kernel, the following vulnerability has been resolved:\n\ncalipso: Fix null-ptr-deref in calipso_req_{set,del}attr().\n\nsyzkaller reported a null-ptr-deref in sock_omalloc() while allocating\na CALIPSO option.  [0]\n\nThe NULL is of struct sock, which was fetched by sk_to_full_sk() in\ncalipso_req_setattr().\n\nSince commit a1a5344ddbe8 (\"tcp: avoid two atomic ops for syncookies\"),\nreqsk->rsk_listener could be NULL when SYN Cookie is returned to its\nclient, as hinted by the leading SYN Cooki","2025-07-04T14:15:24.86+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38181",{"cveId":5425,"releaseId":25,"cycle":26,"description":5426,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5427,"url":5428},{"cveId":5425,"releaseId":17,"cycle":18,"description":5426,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5427,"url":5428},{"cveId":5432,"releaseId":31,"cycle":32,"description":5433,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5434,"url":5435},"CVE-2025-38180","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atm: fix \u002Fproc\u002Fnet\u002Fatm\u002Flec handling\n\n\u002Fproc\u002Fnet\u002Fatm\u002Flec must ensure safety against dev_lec[] changes.\n\nIt appears it had dev_put() calls without prior dev_hold(),\nleading to imbalance and UAF.","2025-07-04T14:15:24.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38180",{"cveId":5432,"releaseId":17,"cycle":18,"description":5433,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5434,"url":5435},{"cveId":5432,"releaseId":25,"cycle":26,"description":5433,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5434,"url":5435},{"cveId":5439,"releaseId":31,"cycle":32,"description":5440,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5441,"url":5442},"CVE-2025-38177","In the Linux kernel, the following vulnerability has been resolved:\n\nsch_hfsc: make hfsc_qlen_notify() idempotent\n\nhfsc_qlen_notify() is not idempotent either and not friendly\nto its callers, like fq_codel_dequeue(). Let's make it idempotent\nto ease qdisc_tree_reduce_backlog() callers' life:\n\n1. update_vf() decreases cl->cl_nactive, so we can check whether it is\nnon-zero before calling it.\n\n2. eltree_remove() always removes RB node cl->el_node, but we can use\n   RB_EMPTY_NODE() + RB_CLEAR_NODE()","2025-07-04T13:15:24.033+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38177",{"cveId":5439,"releaseId":25,"cycle":26,"description":5440,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5441,"url":5442},{"cveId":5439,"releaseId":17,"cycle":18,"description":5440,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5441,"url":5442},{"cveId":5446,"releaseId":25,"cycle":26,"description":5447,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5448,"url":5449},"CVE-2025-38174","In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Do not double dequeue a configuration request\n\nSome of our devices crash in tb_cfg_request_dequeue():\n\n general protection fault, probably for non-canonical address 0xdead000000000122\n\n CPU: 6 PID: 91007 Comm: kworker\u002F6:2 Tainted: G U W 6.6.65\n RIP: 0010:tb_cfg_request_dequeue+0x2d\u002F0xa0\n Call Trace:\n \u003CTASK>\n ? tb_cfg_request_dequeue+0x2d\u002F0xa0\n tb_cfg_request_work+0x33\u002F0x80\n worker_thread+0x386\u002F0x8f0\n kthread+0xed\u002F0","2025-07-04T11:15:51.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38174",{"cveId":5446,"releaseId":17,"cycle":18,"description":5447,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5448,"url":5449},{"cveId":5446,"releaseId":31,"cycle":32,"description":5447,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5448,"url":5449},{"cveId":5453,"releaseId":25,"cycle":26,"description":5454,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5455,"url":5456},"CVE-2025-38173","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: marvell\u002Fcesa - Handle zero-length skcipher requests\n\nDo not access random memory for zero-length skcipher requests.\nJust return 0.","2025-07-03T09:15:33.05+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38173",{"cveId":5453,"releaseId":31,"cycle":32,"description":5454,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5455,"url":5456},{"cveId":5453,"releaseId":17,"cycle":18,"description":5454,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5455,"url":5456},{"cveId":5460,"releaseId":31,"cycle":32,"description":5461,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5462,"url":5463},"CVE-2025-38161","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fmlx5: Fix error flow upon firmware failure for RQ destruction\n\nUpon RQ destruction if the firmware command fails which is the\nlast resource to be destroyed some SW resources were already cleaned\nregardless of the failure.\n\nNow properly rollback the object to its original state upon such failure.\n\nIn order to avoid a use-after free in case someone tries to destroy the\nobject again, which results in the following kernel trac","2025-07-03T09:15:31.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38161",{"cveId":5460,"releaseId":25,"cycle":26,"description":5461,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5462,"url":5463},{"cveId":5460,"releaseId":17,"cycle":18,"description":5461,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5462,"url":5463},{"cveId":5467,"releaseId":17,"cycle":18,"description":5468,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5469,"url":5470},"CVE-2025-38129","In the Linux kernel, the following vulnerability has been resolved:\n\npage_pool: Fix use-after-free in page_pool_recycle_in_ring\n\nsyzbot reported a uaf in page_pool_recycle_in_ring:\n\nBUG: KASAN: slab-use-after-free in lock_release+0x151\u002F0xa30 kernel\u002Flocking\u002Flockdep.c:5862\nRead of size 8 at addr ffff8880286045a0 by task syz.0.284\u002F6943\n\nCPU: 0 UID: 0 PID: 6943 Comm: syz.0.284 Not tainted 6.13.0-rc3-syzkaller-gdfa94ce54f41 #0\nHardware name: Google Google Compute Engine\u002FGoogle Compute Engine, BIOS Go","2025-07-03T09:15:27.17+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38129",{"cveId":5472,"releaseId":31,"cycle":32,"description":5473,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5474,"url":5475},"CVE-2025-38117","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Protect mgmt_pending list with its own lock\n\nThis uses a mutex to protect from concurrent access of mgmt_pending\nlist which can cause crashes like:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60\u002F0x68 net\u002Fbluetooth\u002Fhci_sock.c:91\nRead of size 2 at addr ffff0000c48885b2 by task syz.4.334\u002F7318\n\nCPU: 0 UID: 0 PID: 7318 Comm: syz.4.334 ","2025-07-03T09:15:25.617+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38117",{"cveId":5472,"releaseId":25,"cycle":26,"description":5473,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5474,"url":5475},{"cveId":5472,"releaseId":17,"cycle":18,"description":5473,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5474,"url":5475},{"cveId":5479,"releaseId":17,"cycle":18,"description":5480,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5481,"url":5482},"CVE-2025-38115","In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: sch_sfq: fix a potential crash on gso_skb handling\n\nSFQ has an assumption of always being able to queue at least one packet.\n\nHowever, after the blamed commit, sch->q.len can be inflated by packets\nin sch->gso_skb, and an enqueue() on an empty SFQ qdisc can be followed\nby an immediate drop.\n\nFix sfq_drop() to properly clear q->tail in this situation.\n\n\nip netns add lb\nip link add dev to-lb type veth peer name in-lb n","2025-07-03T09:15:25.35+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38115",{"cveId":5484,"releaseId":31,"cycle":32,"description":5485,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5486,"url":5487},"CVE-2025-38105","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Kill timer properly at removal\n\nThe USB-audio MIDI code initializes the timer, but in a rare case, the\ndriver might be freed without the disconnect call.  This leaves the\ntimer in an active state while the assigned object is released via\nsnd_usbmidi_free(), which ends up with a kernel warning when the debug\nconfiguration is enabled, as spotted by fuzzer.\n\nFor avoiding the problem, put timer_shutdown_sync() at\ns","2025-07-03T09:15:23.997+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38105",{"cveId":5484,"releaseId":17,"cycle":18,"description":5485,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5486,"url":5487},{"cveId":5484,"releaseId":25,"cycle":26,"description":5485,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5486,"url":5487},{"cveId":5491,"releaseId":17,"cycle":18,"description":5492,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5493,"url":5494},"CVE-2025-38102","In the Linux kernel, the following vulnerability has been resolved:\n\nVMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify\n\nDuring our test, it is found that a warning can be trigger in try_grab_folio\nas follow:\n\n  ------------[ cut here ]------------\n  WARNING: CPU: 0 PID: 1678 at mm\u002Fgup.c:147 try_grab_folio+0x106\u002F0x130\n  Modules linked in:\n  CPU: 0 UID: 0 PID: 1678 Comm: syz.3.31 Not tainted 6.15.0-rc5 #163 PREEMPT(undef)\n  RIP: 0010:try_grab_folio+0x106\u002F0x130\n  Call Trace:\n ","2025-07-03T09:15:23.71+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38102",{"cveId":5491,"releaseId":31,"cycle":32,"description":5492,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5493,"url":5494},{"cveId":5491,"releaseId":25,"cycle":26,"description":5492,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5493,"url":5494},{"cveId":5498,"releaseId":17,"cycle":18,"description":5499,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5500,"url":5501},"CVE-2025-38090","In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers\u002Frapidio\u002Frio_cm.c: prevent possible heap overwrite\n\nIn\n\nriocm_cdev_ioctl(RIO_CM_CHAN_SEND)\n   -> cm_chan_msg_send()\n      -> riocm_ch_send()\n\ncm_chan_msg_send() checks that userspace didn't send too much data but\nriocm_ch_send() failed to check that userspace sent sufficient data.  The\nresult is that riocm_ch_send() can write to fields in the rio_ch_chan_hdr\nwhich were outside the bounds of the space which cm_chan_msg_se","2025-06-30T08:15:23.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38090",{"cveId":5498,"releaseId":31,"cycle":32,"description":5499,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5500,"url":5501},{"cveId":5498,"releaseId":25,"cycle":26,"description":5499,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5500,"url":5501},{"cveId":5505,"releaseId":25,"cycle":26,"description":5506,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5507,"url":5508},"CVE-2025-38085","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fhugetlb: fix huge_pmd_unshare() vs GUP-fast race\n\nhuge_pmd_unshare() drops a reference on a page table that may have\npreviously been shared across processes, potentially turning it into a\nnormal page table used in another process in which unrelated VMAs can\nafterwards be installed.\n\nIf this happens in the middle of a concurrent gup_fast(), gup_fast() could\nend up walking the page tables of another process.  While I don't see","2025-06-28T08:15:24.843+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38085",{"cveId":5505,"releaseId":17,"cycle":18,"description":5506,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5507,"url":5508},{"cveId":5505,"releaseId":31,"cycle":32,"description":5506,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5507,"url":5508},{"cveId":5512,"releaseId":31,"cycle":32,"description":5513,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5514,"url":5515},"CVE-2025-38084","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fhugetlb: unshare page tables during VMA split, not before\n\nCurrently, __split_vma() triggers hugetlb page table unsharing through\nvm_ops->may_split().  This happens before the VMA lock and rmap locks are\ntaken - which is too early, it allows racing VMA-locked page faults in our\nprocess and racing rmap walks from other processes to cause page tables to\nbe shared again before we actually perform the split.\n\nFix it by explicitl","2025-06-28T08:15:23.97+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38084",{"cveId":5512,"releaseId":25,"cycle":26,"description":5513,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5514,"url":5515},{"cveId":5512,"releaseId":17,"cycle":18,"description":5513,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5514,"url":5515},{"cveId":5519,"releaseId":25,"cycle":26,"description":5520,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5521,"url":5522},"CVE-2022-50215","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: sg: Allow waiting for commands to complete on removed device\n\nWhen a SCSI device is removed while in active use, currently sg will\nimmediately return -ENODEV on any attempt to wait for active commands that\nwere sent before the removal.  This is problematic for commands that use\nSG_FLAG_DIRECT_IO since the data buffer may still be in use by the kernel\nwhen userspace frees or reuses it after getting ENODEV, leading to\ncorru","2025-06-18T11:15:52.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50215",{"cveId":5519,"releaseId":31,"cycle":32,"description":5520,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5521,"url":5522},{"cveId":5519,"releaseId":17,"cycle":18,"description":5520,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5521,"url":5522},{"cveId":5526,"releaseId":17,"cycle":18,"description":5527,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5528,"url":5529},"CVE-2022-50213","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: do not allow SET_ID to refer to another table\n\nWhen doing lookups for sets on the same batch by using its ID, a set from a\ndifferent table can be used.\n\nThen, when the table is removed, a reference to the set may be kept after\nthe set is freed, leading to a potential use-after-free.\n\nWhen looking for sets by ID, use the table that was used for the lookup by\nname, and only return sets belonging to that same","2025-06-18T11:15:52.197+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50213",{"cveId":5526,"releaseId":31,"cycle":32,"description":5527,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5528,"url":5529},{"cveId":5526,"releaseId":25,"cycle":26,"description":5527,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5528,"url":5529},{"cveId":5533,"releaseId":17,"cycle":18,"description":5534,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5535,"url":5536},"CVE-2022-50200","In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: Add boundary check in put_entry()\n\nJust like next_entry(), boundary check is necessary to prevent memory\nout-of-bound access.","2025-06-18T11:15:50.697+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50200",{"cveId":5533,"releaseId":31,"cycle":32,"description":5534,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5535,"url":5536},{"cveId":5533,"releaseId":25,"cycle":26,"description":5534,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5535,"url":5536},{"cveId":5540,"releaseId":17,"cycle":18,"description":5541,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5542,"url":5543},"CVE-2022-50156","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: cp2112: prevent a buffer overflow in cp2112_xfer()\n\nSmatch warnings:\ndrivers\u002Fhid\u002Fhid-cp2112.c:793 cp2112_xfer() error: __memcpy()\n'data->block[1]' too small (33 vs 255)\ndrivers\u002Fhid\u002Fhid-cp2112.c:793 cp2112_xfer() error: __memcpy() 'buf' too\nsmall (64 vs 255)\n\nThe 'read_length' variable is provided by 'data->block[0]' which comes\nfrom user and it(read_length) can take a value between 0-255. Add an\nupper bound to 'read_length","2025-06-18T11:15:45.747+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50156",{"cveId":5545,"releaseId":31,"cycle":32,"description":5546,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5547,"url":5548},"CVE-2022-50129","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fsrpt: Fix a use-after-free\n\nChange the LIO port members inside struct srpt_port from regular members\ninto pointers. Allocate the LIO port data structures from inside\nsrpt_make_tport() and free these from inside srpt_make_tport(). Keep\nstruct srpt_device as long as either an RDMA port or a LIO target port is\nassociated with it. This patch decouples the lifetime of struct srpt_port\n(controlled by the RDMA core) and struct sr","2025-06-18T11:15:42.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50129",{"cveId":5545,"releaseId":25,"cycle":26,"description":5546,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5547,"url":5548},{"cveId":5545,"releaseId":17,"cycle":18,"description":5546,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5547,"url":5548},{"cveId":5552,"releaseId":31,"cycle":32,"description":5553,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5554,"url":5555},"CVE-2022-50116","In the Linux kernel, the following vulnerability has been resolved:\n\ntty: n_gsm: fix deadlock and link starvation in outgoing data path\n\nThe current implementation queues up new control and user packets as needed\nand processes this queue down to the ldisc in the same code path.\nThat means that the upper and the lower layer are hard coupled in the code.\nDue to this deadlocks can happen as seen below while transmitting data,\nespecially during ldisc congestion. Furthermore, the data channels starve","2025-06-18T11:15:41.257+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50116",{"cveId":5552,"releaseId":17,"cycle":18,"description":5553,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5554,"url":5555},{"cveId":5552,"releaseId":25,"cycle":26,"description":5553,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5554,"url":5555},{"cveId":5559,"releaseId":17,"cycle":18,"description":5560,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5561,"url":5562},"CVE-2022-50114","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: 9p: fix refcount leak in p9_read_work() error handling\n\np9_req_put need to be called when m->rreq->rc.sdata is NULL to avoid\ntemporary refcount leak.\n\n[Dominique: commit wording adjustments, p9_req_put argument fixes for rebase]","2025-06-18T11:15:41.03+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50114",{"cveId":5564,"releaseId":31,"cycle":32,"description":5565,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5566,"url":5567},"CVE-2022-50101","In the Linux kernel, the following vulnerability has been resolved:\n\nvideo: fbdev: vt8623fb: Check the size of screen before memset_io()\n\nIn the function vt8623fb_set_par(), the value of 'screen_size' is\ncalculated by the user input. If the user provides the improper value,\nthe value of 'screen_size' may larger than 'info->screen_size', which\nmay cause the following bug:\n\n[  583.339036] BUG: unable to handle page fault for address: ffffc90005000000\n[  583.339049] #PF: supervisor write access in ","2025-06-18T11:15:39.437+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50101",{"cveId":5564,"releaseId":25,"cycle":26,"description":5565,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5566,"url":5567},{"cveId":5564,"releaseId":17,"cycle":18,"description":5565,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5566,"url":5567},{"cveId":5571,"releaseId":31,"cycle":32,"description":5572,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5573,"url":5574},"CVE-2022-50099","In the Linux kernel, the following vulnerability has been resolved:\n\nvideo: fbdev: arkfb: Check the size of screen before memset_io()\n\nIn the function arkfb_set_par(), the value of 'screen_size' is\ncalculated by the user input. If the user provides the improper value,\nthe value of 'screen_size' may larger than 'info->screen_size', which\nmay cause the following bug:\n\n[  659.399066] BUG: unable to handle page fault for address: ffffc90003000000\n[  659.399077] #PF: supervisor write access in kernel","2025-06-18T11:15:39.2+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50099",{"cveId":5571,"releaseId":25,"cycle":26,"description":5572,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5573,"url":5574},{"cveId":5571,"releaseId":17,"cycle":18,"description":5572,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5573,"url":5574},{"cveId":5578,"releaseId":17,"cycle":18,"description":5579,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5580,"url":5581},"CVE-2022-50098","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix crash due to stale SRB access around I\u002FO timeouts\n\nEnsure SRB is returned during I\u002FO timeout error escalation. If that is not\npossible fail the escalation path.\n\nFollowing crash stack was seen:\n\nBUG: unable to handle kernel paging request at 0000002f56aa90f8\nIP: qla_chk_edif_rx_sa_delete_pending+0x14\u002F0x30 [qla2xxx]\nCall Trace:\n ? qla2x00_status_entry+0x19f\u002F0x1c50 [qla2xxx]\n ? qla2x00_start_sp+0x116\u002F0x1170 [ql","2025-06-18T11:15:39.083+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50098",{"cveId":5578,"releaseId":25,"cycle":26,"description":5579,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5580,"url":5581},{"cveId":5584,"releaseId":31,"cycle":32,"description":5585,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5586,"url":5587},"CVE-2022-50097","In the Linux kernel, the following vulnerability has been resolved:\n\nvideo: fbdev: s3fb: Check the size of screen before memset_io()\n\nIn the function s3fb_set_par(), the value of 'screen_size' is\ncalculated by the user input. If the user provides the improper value,\nthe value of 'screen_size' may larger than 'info->screen_size', which\nmay cause the following bug:\n\n[   54.083733] BUG: unable to handle page fault for address: ffffc90003000000\n[   54.083742] #PF: supervisor write access in kernel m","2025-06-18T11:15:38.963+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50097",{"cveId":5584,"releaseId":17,"cycle":18,"description":5585,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5586,"url":5587},{"cveId":5584,"releaseId":25,"cycle":26,"description":5585,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5586,"url":5587},{"cveId":5591,"releaseId":25,"cycle":26,"description":5592,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5593,"url":5594},"CVE-2022-50087","In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scpi: Ensure scpi_info is not assigned if the probe fails\n\nWhen scpi probe fails, at any point, we need to ensure that the scpi_info\nis not set and will remain NULL until the probe succeeds. If it is not\ntaken care, then it could result use-after-free as the value is exported\nvia get_scpi_ops() and could refer to a memory allocated via devm_kzalloc()\nbut freed when the probe fails.","2025-06-18T11:15:37.803+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50087",{"cveId":5591,"releaseId":17,"cycle":18,"description":5592,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5593,"url":5594},{"cveId":5591,"releaseId":31,"cycle":32,"description":5592,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5593,"url":5594},{"cveId":5598,"releaseId":25,"cycle":26,"description":5599,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5600,"url":5601},"CVE-2022-50073","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null\n\nFixes a NULL pointer derefence bug triggered from tap driver.\nWhen tap_get_user calls virtio_net_hdr_to_skb the skb->dev is null\n(in tap.c skb->dev is set after the call to virtio_net_hdr_to_skb)\nvirtio_net_hdr_to_skb calls dev_parse_header_protocol which\nneeds skb->dev field to be valid.\n\nThe line that trigers the bug is in dev_parse_header_pr","2025-06-18T11:15:36.173+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50073",{"cveId":5598,"releaseId":17,"cycle":18,"description":5599,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5600,"url":5601},{"cveId":5604,"releaseId":17,"cycle":18,"description":5605,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5606,"url":5607},"CVE-2022-50072","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4\u002Fpnfs: Fix a use-after-free bug in open\n\nIf someone cancels the open RPC call, then we must not try to free\neither the open slot or the layoutget operation arguments, since they\nare likely still in use by the hung RPC call.","2025-06-18T11:15:36.057+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50072",{"cveId":5609,"releaseId":25,"cycle":26,"description":5610,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5611,"url":5612},"CVE-2022-50062","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bgmac: Fix a BUG triggered by wrong bytes_compl\n\nOn one of our machines we got:\n\nkernel BUG at lib\u002Fdynamic_queue_limits.c:27!\nInternal error: Oops - BUG: 0 [#1] PREEMPT SMP ARM\nCPU: 0 PID: 1166 Comm: irq\u002F41-bgmac Tainted: G        W  O    4.14.275-rt132 #1\nHardware name: BRCM XGS iProc\ntask: ee3415c0 task.stack: ee32a000\nPC is at dql_completed+0x168\u002F0x178\nLR is at bgmac_poll+0x18c\u002F0x6d8\npc : [\u003Cc03b9430>]    lr : [\u003Cc04b5a18","2025-06-18T11:15:34.93+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50062",{"cveId":5609,"releaseId":31,"cycle":32,"description":5610,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5611,"url":5612},{"cveId":5609,"releaseId":17,"cycle":18,"description":5610,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5611,"url":5612},{"cveId":5616,"releaseId":31,"cycle":32,"description":5617,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5618,"url":5619},"CVE-2022-50028","In the Linux kernel, the following vulnerability has been resolved:\n\ngadgetfs: ep_io - wait until IRQ finishes\n\nafter usb_ep_queue() if wait_for_completion_interruptible() is\ninterrupted we need to wait until IRQ gets finished.\n\nOtherwise complete() from epio_complete() can corrupt stack.","2025-06-18T11:15:31.097+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50028",{"cveId":5616,"releaseId":17,"cycle":18,"description":5617,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5618,"url":5619},{"cveId":5616,"releaseId":25,"cycle":26,"description":5617,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5618,"url":5619},{"cveId":5623,"releaseId":17,"cycle":18,"description":5624,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5625,"url":5626},"CVE-2022-50022","In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers:md:fix a potential use-after-free bug\n\nIn line 2884, \"raid5_release_stripe(sh);\" drops the reference to sh and\nmay cause sh to be released. However, sh is subsequently used in lines\n2886 \"if (sh->batch_head && sh != sh->batch_head)\". This may result in an\nuse-after-free bug.\n\nIt can be fixed by moving \"raid5_release_stripe(sh);\" to the bottom of\nthe function.","2025-06-18T11:15:30.39+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-50022",{"cveId":5623,"releaseId":25,"cycle":26,"description":5624,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5625,"url":5626},{"cveId":5623,"releaseId":31,"cycle":32,"description":5624,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5625,"url":5626},{"cveId":5630,"releaseId":17,"cycle":18,"description":5631,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5632,"url":5633},"CVE-2022-49998","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix locking in rxrpc's sendmsg\n\nFix three bugs in the rxrpc's sendmsg implementation:\n\n (1) rxrpc_new_client_call() should release the socket lock when returning\n     an error from rxrpc_get_call_slot().\n\n (2) rxrpc_wait_for_tx_window_intr() will return without the call mutex\n     held in the event that we're interrupted by a signal whilst waiting\n     for tx space on the socket or relocking the call mutex afterwards.\n\n ","2025-06-18T11:15:27.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49998",{"cveId":5635,"releaseId":25,"cycle":26,"description":5636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5637,"url":5638},"CVE-2022-49990","In the Linux kernel, the following vulnerability has been resolved:\n\ns390: fix double free of GS and RI CBs on fork() failure\n\nThe pointers for guarded storage and runtime instrumentation control\nblocks are stored in the thread_struct of the associated task. These\npointers are initially copied on fork() via arch_dup_task_struct()\nand then cleared via copy_thread() before fork() returns. If fork()\nhappens to fail after the initial task dup and before copy_thread(),\nthe newly allocated task and as","2025-06-18T11:15:26.637+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49990",{"cveId":5635,"releaseId":31,"cycle":32,"description":5636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5637,"url":5638},{"cveId":5635,"releaseId":17,"cycle":18,"description":5636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5637,"url":5638},{"cveId":5642,"releaseId":25,"cycle":26,"description":5643,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5644,"url":5645},"CVE-2022-49979","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix refcount bug in sk_psock_get (2)\n\nSyzkaller reports refcount bug as follows:\n------------[ cut here ]------------\nrefcount_t: saturated; leaking memory.\nWARNING: CPU: 1 PID: 3605 at lib\u002Frefcount.c:19 refcount_warn_saturate+0xf4\u002F0x1e0 lib\u002Frefcount.c:19\nModules linked in:\nCPU: 1 PID: 3605 Comm: syz-executor208 Not tainted 5.18.0-syzkaller-03023-g7e062cda7d90 #0\n \u003CTASK>\n __refcount_add_not_zero include\u002Flinux\u002Frefcount.h:16","2025-06-18T11:15:25.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49979",{"cveId":5642,"releaseId":31,"cycle":32,"description":5643,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5644,"url":5645},{"cveId":5642,"releaseId":17,"cycle":18,"description":5643,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5644,"url":5645},{"cveId":5649,"releaseId":17,"cycle":18,"description":5650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5651,"url":5652},"CVE-2022-49977","In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead\n\nftrace_startup does not remove ops from ftrace_ops_list when\nftrace_startup_enable fails:\n\nregister_ftrace_function\n  ftrace_startup\n    __register_ftrace_function\n      ...\n      add_ftrace_ops(&ftrace_ops_list, ops)\n      ...\n    ...\n    ftrace_startup_enable \u002F\u002F if ftrace failed to modify, ftrace_disabled is set to 1\n    ...\n  return 0 \u002F\u002F ops is","2025-06-18T11:15:25.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49977",{"cveId":5649,"releaseId":31,"cycle":32,"description":5650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5651,"url":5652},{"cveId":5649,"releaseId":25,"cycle":26,"description":5650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5651,"url":5652},{"cveId":5656,"releaseId":17,"cycle":18,"description":5657,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":5658,"url":5659},"CVE-2022-49968","In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154\u002Fadf7242: defer destroy_workqueue call\n\nThere is a possible race condition (use-after-free) like below\n\n  (FREE)                     |  (USE)\n  adf7242_remove             |  adf7242_channel\n   cancel_delayed_work_sync  |\n    destroy_workqueue (1)    |   adf7242_cmd_rx\n                             |    mod_delayed_work (2)\n                             |\n\nThe root cause for this race is that the upper layer (ieee802154)","2025-06-18T11:15:24.123+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49968",{"cveId":5661,"releaseId":31,"cycle":32,"description":5662,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5663,"url":5664},"CVE-2022-49956","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8712: fix use after free bugs\n\n_Read\u002FWrite_MACREG callbacks are NULL so the read\u002Fwrite_macreg_hdl()\nfunctions don't do anything except free the \"pcmd\" pointer.  It\nresults in a use after free.  Delete them.","2025-06-18T11:15:22.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49956",{"cveId":5661,"releaseId":17,"cycle":18,"description":5662,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5663,"url":5664},{"cveId":5661,"releaseId":25,"cycle":26,"description":5662,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":5663,"url":5664},{"cveId":5668,"releaseId":17,"cycle":18,"description":5669,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5670,"url":5671},"CVE-2022-49948","In the Linux kernel, the following vulnerability has been resolved:\n\nvt: Clear selection before changing the font\n\nWhen changing the console font with ioctl(KDFONTOP) the new font size\ncan be bigger than the previous font. A previous selection may thus now\nbe outside of the new screen size and thus trigger out-of-bounds\naccesses to graphics memory if the selection is removed in\nvc_do_resize().\n\nPrevent such out-of-memory accesses by dropping the selection before the\nvarious con_font_set() consol","2025-06-18T11:15:21.827+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49948",{"cveId":5668,"releaseId":25,"cycle":26,"description":5669,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5670,"url":5671},{"cveId":5668,"releaseId":31,"cycle":32,"description":5669,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5670,"url":5671},{"cveId":5675,"releaseId":17,"cycle":18,"description":5676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5677,"url":5678},"CVE-2022-49939","In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF of ref->proc caused by race condition\n\nA transaction of type BINDER_TYPE_WEAK_HANDLE can fail to increment the\nreference for a node. In this case, the target proc normally releases\nthe failed reference upon close as expected. However, if the target is\ndying in parallel the call will race with binder_deferred_release(), so\nthe target could have released all of its references by now leaving the\ncleanup of the new ","2025-06-18T11:15:20.793+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49939",{"cveId":5675,"releaseId":25,"cycle":26,"description":5676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5677,"url":5678},{"cveId":5675,"releaseId":31,"cycle":32,"description":5676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5677,"url":5678},{"cveId":5682,"releaseId":31,"cycle":32,"description":5683,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5684,"url":5685},"CVE-2022-49934","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: Fix UAF in ieee80211_scan_rx()\n\nieee80211_scan_rx() tries to access scan_req->flags after a\nnull check, but a UAF is observed when the scan is completed\nand __ieee80211_scan_completed() executes, which then calls\ncfg80211_scan_done() leading to the freeing of scan_req.\n\nSince scan_req is rcu_dereference()'d, prevent the racing in\n__ieee80211_scan_completed() by ensuring that from mac80211's\nPOV it is no longer a","2025-06-18T11:15:19.4+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49934",{"cveId":5682,"releaseId":25,"cycle":26,"description":5683,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5684,"url":5685},{"cveId":5682,"releaseId":17,"cycle":18,"description":5683,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5684,"url":5685},{"cveId":5689,"releaseId":17,"cycle":18,"description":5690,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5691,"url":5692},"CVE-2025-38080","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Increase block_sequence array size\n\n[Why]\nIt's possible to generate more than 50 steps in hwss_build_fast_sequence,\nfor example with a 6-pipe asic where all pipes are in one MPC chain. This\noverflows the block_sequence buffer and corrupts block_sequence_steps,\ncausing a crash.\n\n[How]\nExpand block_sequence to 100 items. A naive upper bound on the possible\nnumber of steps for a 6-pipe asic, ignoring the potential","2025-06-18T10:15:41.647+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38080",{"cveId":5694,"releaseId":31,"cycle":32,"description":5695,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5696,"url":5697},"CVE-2025-38079","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_hash - fix double free in hash_accept\n\nIf accept(2) is called on socket type algif_hash with\nMSG_MORE flag set and crypto_ahash_import fails,\nsk2 is freed. However, it is also freed in af_alg_release,\nleading to slab-use-after-free error.","2025-06-18T10:15:41.51+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38079",{"cveId":5694,"releaseId":25,"cycle":26,"description":5695,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5696,"url":5697},{"cveId":5694,"releaseId":17,"cycle":18,"description":5695,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5696,"url":5697},{"cveId":5701,"releaseId":25,"cycle":26,"description":5702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5703,"url":5704},"CVE-2025-38078","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Fix race of buffer access at PCM OSS layer\n\nThe PCM OSS layer tries to clear the buffer with the silence data at\ninitialization (or reconfiguration) of a stream with the explicit call\nof snd_pcm_format_set_silence() with runtime->dma_area.  But this may\nlead to a UAF because the accessed runtime->dma_area might be freed\nconcurrently, as it's performed outside the PCM ops.\n\nFor avoiding it, move the code into the PCM ","2025-06-18T10:15:41.38+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38078",{"cveId":5701,"releaseId":31,"cycle":32,"description":5702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5703,"url":5704},{"cveId":5701,"releaseId":17,"cycle":18,"description":5702,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5703,"url":5704},{"cveId":5708,"releaseId":31,"cycle":32,"description":5709,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5710,"url":5711},"CVE-2025-38075","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix timeout on deleted connection\n\nNOPIN response timer may expire on a deleted connection and crash with\nsuch logs:\n\nDid not receive response to NOPIN on CID: 0, failing connection for I_T Nexus (null),i,0x00023d000125,iqn.2017-01.com.iscsi.target,t,0x3d\n\nBUG: Kernel NULL pointer dereference on read at 0x00000000\nNIP  strlcpy+0x8\u002F0xb0\nLR iscsit_fill_cxn_timeout_err_stats+0x5c\u002F0xc0 [iscsi_target_mod]\nCall T","2025-06-18T10:15:40.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38075",{"cveId":5708,"releaseId":17,"cycle":18,"description":5709,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5710,"url":5711},{"cveId":5708,"releaseId":25,"cycle":26,"description":5709,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5710,"url":5711},{"cveId":5715,"releaseId":31,"cycle":32,"description":5716,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5717,"url":5718},"CVE-2025-38074","In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-scsi: protect vq->log_used with vq->mutex\n\nThe vhost-scsi completion path may access vq->log_base when vq->log_used is\nalready set to false.\n\n    vhost-thread                       QEMU-thread\n\nvhost_scsi_complete_cmd_work()\n-> vhost_add_used()\n   -> vhost_add_used_n()\n      if (unlikely(vq->log_used))\n                                      QEMU disables vq->log_used\n                                      via VHOST_SET_VRIN","2025-06-18T10:15:40.85+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38074",{"cveId":5715,"releaseId":25,"cycle":26,"description":5716,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5717,"url":5718},{"cveId":5715,"releaseId":17,"cycle":18,"description":5716,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5717,"url":5718},{"cveId":5722,"releaseId":25,"cycle":26,"description":5723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5724,"url":5725},"CVE-2025-38068","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: lzo - Fix compression buffer overrun\n\nUnlike the decompression code, the compression code in LZO never\nchecked for output overruns.  It instead assumes that the caller\nalways provides enough buffer space, disregarding the buffer length\nprovided by the caller.\n\nAdd a safe compression interface that checks for the end of buffer\nbefore each write.  Use the safe interface in crypto\u002Flzo.","2025-06-18T10:15:39.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38068",{"cveId":5722,"releaseId":31,"cycle":32,"description":5723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5724,"url":5725},{"cveId":5722,"releaseId":17,"cycle":18,"description":5723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5724,"url":5725},{"cveId":5729,"releaseId":31,"cycle":32,"description":5730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5731,"url":5732},"CVE-2025-38065","In the Linux kernel, the following vulnerability has been resolved:\n\norangefs: Do not truncate file size\n\n'len' is used to store the result of i_size_read(), so making 'len'\na size_t results in truncation to 4GiB on 32-bit systems.","2025-06-18T10:15:39.46+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38065",{"cveId":5729,"releaseId":17,"cycle":18,"description":5730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5731,"url":5732},{"cveId":5729,"releaseId":25,"cycle":26,"description":5730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5731,"url":5732},{"cveId":5736,"releaseId":17,"cycle":18,"description":5737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5738,"url":5739},"CVE-2025-38064","In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: break and reset virtio devices on device_shutdown()\n\nHongyu reported a hang on kexec in a VM. QEMU reported invalid memory\naccesses during the hang.\n\n\tInvalid read at addr 0x102877002, size 2, region '(null)', reason: rejected\n\tInvalid write at addr 0x102877A44, size 2, region '(null)', reason: rejected\n\t...\n\nIt was traced down to virtio-console. Kexec works fine if virtio-console\nis not in use.\n\nThe issue is that virti","2025-06-18T10:15:39.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38064",{"cveId":5736,"releaseId":31,"cycle":32,"description":5737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5738,"url":5739},{"cveId":5736,"releaseId":25,"cycle":26,"description":5737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5738,"url":5739},{"cveId":5743,"releaseId":31,"cycle":32,"description":5744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5745,"url":5746},"CVE-2025-38058","In the Linux kernel, the following vulnerability has been resolved:\n\n__legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock\n\n... or we risk stealing final mntput from sync umount - raising mnt_count\nafter umount(2) has verified that victim is not busy, but before it\nhas set MNT_SYNC_UMOUNT; in that case __legitimize_mnt() doesn't see\nthat it's safe to quietly undo mnt_count increment and leaves dropping\nthe reference to caller, where it'll be a full-blown mntput().\n\nCheck under","2025-06-18T10:15:38.59+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38058",{"cveId":5743,"releaseId":25,"cycle":26,"description":5744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5745,"url":5746},{"cveId":5743,"releaseId":17,"cycle":18,"description":5744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5745,"url":5746},{"cveId":5750,"releaseId":31,"cycle":32,"description":5751,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5752,"url":5753},"CVE-2025-38051","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_fill_dirent\n\nThere is a race condition in the readdir concurrency process, which may\naccess the rsp buffer after it has been released, triggering the\nfollowing KASAN warning.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in cifs_fill_dirent+0xb03\u002F0xb60 [cifs]\n Read of size 4 at addr ffff8880099b819c by task a.out\u002F342975\n\n CPU: 2 UID:","2025-06-18T10:15:37.693+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38051",{"cveId":5750,"releaseId":25,"cycle":26,"description":5751,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5752,"url":5753},{"cveId":5750,"releaseId":17,"cycle":18,"description":5751,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5752,"url":5753},{"cveId":5757,"releaseId":25,"cycle":26,"description":5758,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5759,"url":5760},"CVE-2025-38024","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Frxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug\n\nCall Trace:\n \u003CTASK>\n __dump_stack lib\u002Fdump_stack.c:94 [inline]\n dump_stack_lvl+0x7d\u002F0xa0 lib\u002Fdump_stack.c:120\n print_address_description mm\u002Fkasan\u002Freport.c:378 [inline]\n print_report+0xcf\u002F0x610 mm\u002Fkasan\u002Freport.c:489\n kasan_report+0xb5\u002F0xe0 mm\u002Fkasan\u002Freport.c:602\n rxe_queue_cleanup+0xd0\u002F0xe0 drivers\u002Finfiniband\u002Fsw\u002Frxe\u002Frxe_queue.c:195\n rxe_cq_cleanup+0x3f\u002F0x50 drivers\u002F","2025-06-18T10:15:34.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38024",{"cveId":5757,"releaseId":31,"cycle":32,"description":5758,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5759,"url":5760},{"cveId":5757,"releaseId":17,"cycle":18,"description":5758,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5759,"url":5760},{"cveId":5764,"releaseId":31,"cycle":32,"description":5765,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":5766,"url":5767},"CVE-2025-38004","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add locking for bcm_op runtime updates\n\nThe CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via\nhrtimer. The content and also the length of the sequence can be changed\nresp reduced at runtime where the 'currframe' counter is then set to zero.\n\nAlthough this appeared to be a safe operation the updates of 'currframe'\ncan be triggered from user space and hrtimer context in bcm_can_tx().\nAnderson Nascime","2025-06-08T11:15:22.21+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38004",{"cveId":5764,"releaseId":17,"cycle":18,"description":5765,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":5766,"url":5767},{"cveId":5764,"releaseId":25,"cycle":26,"description":5765,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":5766,"url":5767},{"cveId":5771,"releaseId":17,"cycle":18,"description":5772,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5773,"url":5774},"CVE-2025-38003","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add missing rcu read protection for procfs content\n\nWhen the procfs content is generated for a bcm_op which is in the process\nto be removed the procfs output might show unreliable data (UAF).\n\nAs the removal of bcm_op's is already implemented with rcu handling this\npatch adds the missing rcu_read_lock() and makes sure the list entries\nare properly removed under rcu protection.","2025-06-08T11:15:20.99+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38003",{"cveId":5776,"releaseId":25,"cycle":26,"description":5777,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5778,"url":5779},"CVE-2025-38000","In the Linux kernel, the following vulnerability has been resolved:\n\nsch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()\n\nWhen enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the\nchild qdisc's peek() operation before incrementing sch->q.qlen and\nsch->qstats.backlog. If the child qdisc uses qdisc_peek_dequeued(), this may\ntrigger an immediate dequeue and potential packet drop. In such cases,\nqdisc_tree_reduce_backlog() is called, but the HFSC qdisc's qlen and bac","2025-06-06T13:15:39.87+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-38000",{"cveId":5776,"releaseId":17,"cycle":18,"description":5777,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5778,"url":5779},{"cveId":5776,"releaseId":31,"cycle":32,"description":5777,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5778,"url":5779},{"cveId":5783,"releaseId":25,"cycle":26,"description":5784,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":5785,"url":5786},"CVE-2025-4598","A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as \u002Fetc\u002Fshadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the proc","2025-05-30T14:15:23.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-4598",{"cveId":5783,"releaseId":17,"cycle":18,"description":5784,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":5785,"url":5786},{"cveId":5783,"releaseId":31,"cycle":32,"description":5784,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":5785,"url":5786},{"cveId":5790,"releaseId":31,"cycle":32,"description":5791,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5792,"url":5793},"CVE-2025-37998","In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: Fix unsafe attribute parsing in output_userspace()\n\nThis patch replaces the manual Netlink attribute iteration in\noutput_userspace() with nla_for_each_nested(), which ensures that only\nwell-formed attributes are processed.","2025-05-29T14:15:36.45+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37998",{"cveId":5790,"releaseId":25,"cycle":26,"description":5791,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5792,"url":5793},{"cveId":5790,"releaseId":17,"cycle":18,"description":5791,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5792,"url":5793},{"cveId":5797,"releaseId":31,"cycle":32,"description":5798,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5799,"url":5800},"CVE-2025-37980","In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix resource leak in blk_register_queue() error path\n\nWhen registering a queue fails after blk_mq_sysfs_register() is\nsuccessful but the function later encounters an error, we need\nto clean up the blk_mq_sysfs resources.\n\nAdd the missing blk_mq_sysfs_unregister() call in the error path\nto properly clean up these resources and prevent a memory leak.","2025-05-20T17:15:48.65+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37980",{"cveId":5797,"releaseId":17,"cycle":18,"description":5798,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5799,"url":5800},{"cveId":5797,"releaseId":25,"cycle":26,"description":5798,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5799,"url":5800},{"cveId":5804,"releaseId":31,"cycle":32,"description":5805,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5806,"url":5807},"CVE-2025-37954","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Avoid race in open_cached_dir with lease breaks\n\nA pre-existing valid cfid returned from find_or_create_cached_dir might\nrace with a lease break, meaning open_cached_dir doesn't consider it\nvalid, and thinks it's newly-constructed. This leaks a dentry reference\nif the allocation occurs before the queued lease break work runs.\n\nAvoid the race by extending holding the cfid_list_lock across\nfind_or_create_cached_dir a","2025-05-20T16:15:33.603+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37954",{"cveId":5804,"releaseId":25,"cycle":26,"description":5805,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5806,"url":5807},{"cveId":5804,"releaseId":17,"cycle":18,"description":5805,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5806,"url":5807},{"cveId":5811,"releaseId":25,"cycle":26,"description":5812,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5813,"url":5814},"CVE-2025-37949","In the Linux kernel, the following vulnerability has been resolved:\n\nxenbus: Use kref to track req lifetime\n\nMarek reported seeing a NULL pointer fault in the xenbus_thread\ncallstack:\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: e030:__wake_up_common+0x4c\u002F0x180\nCall Trace:\n \u003CTASK>\n __wake_up_common_lock+0x82\u002F0xd0\n process_msg+0x18e\u002F0x2f0\n xenbus_thread+0x165\u002F0x1c0\n\nprocess_msg+0x18e is req->cb(req).  req->cb is set to xs_wake_up(), a\nthin wrapper around wake_up(), or xenb","2025-05-20T16:15:32.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37949",{"cveId":5811,"releaseId":17,"cycle":18,"description":5812,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5813,"url":5814},{"cveId":5817,"releaseId":17,"cycle":18,"description":5818,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5819,"url":5820},"CVE-2025-37923","In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix oob write in trace_seq_to_buffer()\n\nsyzbot reported this bug:\n==================================================================\nBUG: KASAN: slab-out-of-bounds in trace_seq_to_buffer kernel\u002Ftrace\u002Ftrace.c:1830 [inline]\nBUG: KASAN: slab-out-of-bounds in tracing_splice_read_pipe+0x6be\u002F0xdd0 kernel\u002Ftrace\u002Ftrace.c:6822\nWrite of size 4507 at addr ffff888032b6b000 by task syz.2.320\u002F7260\n\nCPU: 1 UID: 0 PID: 7260 Comm: syz.2","2025-05-20T16:15:28.93+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37923",{"cveId":5817,"releaseId":25,"cycle":26,"description":5818,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5819,"url":5820},{"cveId":5817,"releaseId":31,"cycle":32,"description":5818,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5819,"url":5820},{"cveId":5824,"releaseId":17,"cycle":18,"description":5825,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5826,"url":5827},"CVE-2025-37911","In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix out-of-bound memcpy() during ethtool -w\n\nWhen retrieving the FW coredump using ethtool, it can sometimes cause\nmemory corruption:\n\nBUG: KFENCE: memory corruption in __bnxt_get_coredump+0x3ef\u002F0x670 [bnxt_en]\nCorrupted memory at 0x000000008f0f30e8 [ ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ] (in kfence-#45):\n__bnxt_get_coredump+0x3ef\u002F0x670 [bnxt_en]\nethtool_get_dump_data+0xdc\u002F0x1a0\n__dev_ethtool+0xa1e\u002F0x1af0\ndev_ethtool+0xa8\u002F","2025-05-20T16:15:27.61+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37911",{"cveId":5829,"releaseId":17,"cycle":18,"description":5830,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":5831,"url":5832},"CVE-2025-37909","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: Fix memleak issue when GSO enabled\n\nAlways map the `skb` to the LS descriptor. Previously skb was\nmapped to EXT descriptor when the number of fragments is zero with\nGSO enabled. Mapping the skb to EXT descriptor prevents it from\nbeing freed, leading to a memory leak","2025-05-20T16:15:27.39+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37909",{"cveId":5834,"releaseId":25,"cycle":26,"description":5835,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5836,"url":5837},"CVE-2025-37885","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Reset IRTE to host control if *new* route isn't postable\n\nRestore an IRTE back to host control (remapped or posted MSI mode) if the\n*new* GSI route prevents posting the IRQ directly to a vCPU, regardless of\nthe GSI routing type.  Updating the IRTE if and only if the new GSI is an\nMSI results in KVM leaving an IRTE posting to a vCPU.\n\nThe dangling IRTE can result in interrupts being incorrectly delivered to\nthe guest, ","2025-05-09T07:16:09.843+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37885",{"cveId":5834,"releaseId":17,"cycle":18,"description":5835,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5836,"url":5837},{"cveId":5834,"releaseId":31,"cycle":32,"description":5835,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5836,"url":5837},{"cveId":5841,"releaseId":31,"cycle":32,"description":5842,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5843,"url":5844},"CVE-2025-37882","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix isochronous Ring Underrun\u002FOverrun event handling\n\nThe TRB pointer of these events points at enqueue at the time of error\noccurrence on xHCI 1.1+ HCs or it's NULL on older ones. By the time we\nare handling the event, a new TD may be queued at this ring position.\n\nI can trigger this race by rising interrupt moderation to increase IRQ\nhandling delay. Similar delay may occur naturally due to system load.\n\nIf this eve","2025-05-09T07:16:09.497+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37882",{"cveId":5841,"releaseId":25,"cycle":26,"description":5842,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5843,"url":5844},{"cveId":5841,"releaseId":17,"cycle":18,"description":5842,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5843,"url":5844},{"cveId":5848,"releaseId":25,"cycle":26,"description":5849,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5850,"url":5851},"CVE-2025-37879","In the Linux kernel, the following vulnerability has been resolved:\n\n9p\u002Fnet: fix improper handling of bogus negative read\u002Fwrite replies\n\nIn p9_client_write() and p9_client_read_once(), if the server\nincorrectly replies with success but a negative write\u002Fread count then we\nwould consider written (negative) \u003C= rsize (positive) because both\nvariables were signed.\n\nMake variables unsigned to avoid this problem.\n\nThe reproducer linked below now fails with the following error instead\nof a null pointer ","2025-05-09T07:16:09.143+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37879",{"cveId":5848,"releaseId":17,"cycle":18,"description":5849,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5850,"url":5851},{"cveId":5848,"releaseId":31,"cycle":32,"description":5849,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5850,"url":5851},{"cveId":5855,"releaseId":25,"cycle":26,"description":5856,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5857,"url":5858},"CVE-2025-37856","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: harden block_group::bg_list against list_del() races\n\nAs far as I can tell, these calls of list_del_init() on bg_list cannot\nrun concurrently with btrfs_mark_bg_unused() or btrfs_mark_bg_to_reclaim(),\nas they are in transaction error paths and situations where the block\ngroup is readonly.\n\nHowever, if there is any chance at all of racing with mark_bg_unused(),\nor a different future user of bg_list, better to be safe than","2025-05-09T07:16:06.593+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37856",{"cveId":5855,"releaseId":17,"cycle":18,"description":5856,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5857,"url":5858},{"cveId":5855,"releaseId":31,"cycle":32,"description":5856,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5857,"url":5858},{"cveId":5862,"releaseId":25,"cycle":26,"description":5863,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5864,"url":5865},"CVE-2025-37849","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Tear down vGIC on failed vCPU creation\n\nIf kvm_arch_vcpu_create() fails to share the vCPU page with the\nhypervisor, we propagate the error back to the ioctl but leave the\nvGIC vCPU data initialised. Note only does this leak the corresponding\nmemory when the vCPU is destroyed but it can also lead to use-after-free\nif the redistributor device handling tries to walk into the vCPU.\n\nAdd the missing cleanup to kvm_arch_v","2025-05-09T07:16:05.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37849",{"cveId":5862,"releaseId":17,"cycle":18,"description":5863,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5864,"url":5865},{"cveId":5862,"releaseId":31,"cycle":32,"description":5863,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5864,"url":5865},{"cveId":5869,"releaseId":17,"cycle":18,"description":5870,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5871,"url":5872},"CVE-2025-37823","In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too\n\nSimilarly to the previous patch, we need to safe guard hfsc_dequeue()\ntoo. But for this one, we don't have a reliable reproducer.","2025-05-08T07:15:53.52+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37823",{"cveId":5869,"releaseId":25,"cycle":26,"description":5870,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5871,"url":5872},{"cveId":5869,"releaseId":31,"cycle":32,"description":5870,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5871,"url":5872},{"cveId":5876,"releaseId":25,"cycle":26,"description":5877,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5878,"url":5879},"CVE-2025-37802","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix WARNING \"do not call blocking ops when !TASK_RUNNING\"\n\nwait_event_timeout() will set the state of the current\ntask to TASK_UNINTERRUPTIBLE, before doing the condition check. This\nmeans that ksmbd_durable_scavenger_alive() will try to acquire the mutex\nwhile already in a sleeping state. The scheduler warns us by giving\nthe following warning:\n\ndo not call blocking ops when !TASK_RUNNING; state=2 set at\n [\u003C0000000061515","2025-05-08T07:15:51.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37802",{"cveId":5876,"releaseId":17,"cycle":18,"description":5877,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5878,"url":5879},{"cveId":5876,"releaseId":31,"cycle":32,"description":5877,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5878,"url":5879},{"cveId":5883,"releaseId":25,"cycle":26,"description":5884,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5885,"url":5886},"CVE-2025-37801","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-imx: Add check for spi_imx_setupxfer()\n\nAdd check for the return value of spi_imx_setupxfer().\nspi_imx->rx and spi_imx->tx function pointer can be NULL when\nspi_imx_setupxfer() return error, and make NULL pointer dereference.\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Call trace:\n  0x0\n  spi_imx_pio_transfer+0x50\u002F0xd8\n  spi_imx_transfer_one+0x18c\u002F0x858\n  spi_transfer_one_mes","2025-05-08T07:15:51.257+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37801",{"cveId":5883,"releaseId":17,"cycle":18,"description":5884,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5885,"url":5886},{"cveId":5883,"releaseId":31,"cycle":32,"description":5884,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5885,"url":5886},{"cveId":5890,"releaseId":25,"cycle":26,"description":5891,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5892,"url":5893},"CVE-2025-37800","In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: fix potential NULL pointer dereference in dev_uevent()\n\nIf userspace reads \"uevent\" device attribute at the same time as another\nthreads unbinds the device from its driver, change to dev->driver from a\nvalid pointer to NULL may result in crash. Fix this by using READ_ONCE()\nwhen fetching the pointer, and take bus' drivers klist lock to make sure\ndriver instance will not disappear while we access it.\n\nUse WRITE_ONCE","2025-05-08T07:15:50.42+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37800",{"cveId":5890,"releaseId":17,"cycle":18,"description":5891,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5892,"url":5893},{"cveId":5890,"releaseId":31,"cycle":32,"description":5891,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":5892,"url":5893},{"cveId":5897,"releaseId":31,"cycle":32,"description":5898,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5899,"url":5900},"CVE-2020-36791","In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: keep alloc_hash updated after hash allocation\n\nIn commit 599be01ee567 (\"net_sched: fix an OOB access in cls_tcindex\")\nI moved cp->hash calculation before the first\ntcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched.\nThis difference could lead to another out of bound access.\n\ncp->alloc_hash should always be the size allocated, we should\nupdate it after this tcindex_alloc_perfect_hash().","2025-05-07T14:15:28.513+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2020-36791",{"cveId":5897,"releaseId":25,"cycle":26,"description":5898,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5899,"url":5900},{"cveId":5897,"releaseId":17,"cycle":18,"description":5898,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5899,"url":5900},{"cveId":5904,"releaseId":25,"cycle":26,"description":5905,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5906,"url":5907},"CVE-2022-21546","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Fix WRITE_SAME No Data Buffer crash\n\nIn newer version of the SBC specs, we have a NDOB bit that indicates there\nis no data buffer that gets written out. If this bit is set using commands\nlike \"sg_write_same --ndob\" we will crash in target_core_iblock\u002Ffile's\nexecute_write_same handlers when we go to access the se_cmd->t_data_sg\nbecause its NULL.\n\nThis patch adds a check for the NDOB bit in the common WRITE SAME cod","2025-05-02T22:15:15.29+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-21546",{"cveId":5904,"releaseId":17,"cycle":18,"description":5905,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5906,"url":5907},{"cveId":5904,"releaseId":31,"cycle":32,"description":5905,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":5906,"url":5907},{"cveId":5911,"releaseId":17,"cycle":18,"description":5912,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5913,"url":5914},"CVE-2023-53138","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: caif: Fix use-after-free in cfusbl_device_notify()\n\nsyzbot reported use-after-free in cfusbl_device_notify() [1].  This\ncauses a stack trace like below:\n\nBUG: KASAN: use-after-free in cfusbl_device_notify+0x7c9\u002F0x870 net\u002Fcaif\u002Fcaif_usb.c:138\nRead of size 8 at addr ffff88807ac4e6f0 by task kworker\u002Fu4:6\u002F1214\n\nCPU: 0 PID: 1214 Comm: kworker\u002Fu4:6 Not tainted 5.19.0-rc3-syzkaller-00146-g92f20ff72066 #0\nHardware name: Google Goog","2025-05-02T16:15:32.72+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53138",{"cveId":5911,"releaseId":25,"cycle":26,"description":5912,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5913,"url":5914},{"cveId":5911,"releaseId":31,"cycle":32,"description":5912,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5913,"url":5914},{"cveId":5918,"releaseId":31,"cycle":32,"description":5919,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5920,"url":5921},"CVE-2023-53116","In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: avoid potential UAF in nvmet_req_complete()\n\nAn nvme target ->queue_response() operation implementation may free the\nrequest passed as argument. Such implementation potentially could result\nin a use after free of the request pointer when percpu_ref_put() is\ncalled in nvmet_req_complete().\n\nAvoid such problem by using a local variable to save the sq pointer\nbefore calling __nvmet_req_complete(), thus avoiding dereferencin","2025-05-02T16:15:30.68+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53116",{"cveId":5918,"releaseId":25,"cycle":26,"description":5919,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5920,"url":5921},{"cveId":5918,"releaseId":17,"cycle":18,"description":5919,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":5920,"url":5921},{"cveId":5925,"releaseId":25,"cycle":26,"description":5926,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5927,"url":5928},"CVE-2023-53111","In the Linux kernel, the following vulnerability has been resolved:\n\nloop: Fix use-after-free issues\n\ndo_req_filebacked() calls blk_mq_complete_request() synchronously or\nasynchronously when using asynchronous I\u002FO unless memory allocation fails.\nHence, modify loop_handle_cmd() such that it does not dereference 'cmd' nor\n'rq' after do_req_filebacked() finished unless we are sure that the request\nhas not yet been completed. This patch fixes the following kernel crash:\n\nUnable to handle kernel NULL","2025-05-02T16:15:30.027+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53111",{"cveId":5925,"releaseId":17,"cycle":18,"description":5926,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5927,"url":5928},{"cveId":5925,"releaseId":31,"cycle":32,"description":5926,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5927,"url":5928},{"cveId":5932,"releaseId":25,"cycle":26,"description":5933,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5934,"url":5935},"CVE-2023-53100","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix WARNING in ext4_update_inline_data\n\nSyzbot found the following issue:\nEXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 without journal. Quota mode: none.\nfscrypt: AES-256-CTS-CBC using implementation \"cts-cbc-aes-aesni\"\nfscrypt: AES-256-XTS using implementation \"xts-aes-aesni\"\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 5071 at mm\u002Fpage_alloc.c:5525 __alloc_pages+0x30a\u002F0x560 mm\u002Fpag","2025-05-02T16:15:28.923+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53100",{"cveId":5932,"releaseId":17,"cycle":18,"description":5933,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5934,"url":5935},{"cveId":5932,"releaseId":31,"cycle":32,"description":5933,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5934,"url":5935},{"cveId":5939,"releaseId":17,"cycle":18,"description":5940,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5941,"url":5942},"CVE-2023-53094","In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: fsl_lpuart: fix race on RX DMA shutdown\n\nFrom time to time DMA completion can come in the middle of DMA shutdown:\n\n\u003Cprocess ctx>:\t\t\t\t\u003CIRQ>:\nlpuart32_shutdown()\n  lpuart_dma_shutdown()\n    del_timer_sync()\n\t\t\t\t\tlpuart_dma_rx_complete()\n\t\t\t\t\t  lpuart_copy_rx_to_tty()\n\t\t\t\t\t    mod_timer()\n    lpuart_dma_rx_free()\n\nWhen the timer fires a bit later, sport->dma_rx_desc is NULL:\n\nUnable to handle kernel NULL pointer deref","2025-05-02T16:15:28.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53094",{"cveId":5939,"releaseId":25,"cycle":26,"description":5940,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5941,"url":5942},{"cveId":5939,"releaseId":31,"cycle":32,"description":5940,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5941,"url":5942},{"cveId":5946,"releaseId":17,"cycle":18,"description":5947,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5948,"url":5949},"CVE-2023-53090","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdkfd: Fix an illegal memory access\n\nIn the kfd_wait_on_events() function, the kfd_event_waiter structure is\nallocated by alloc_event_waiters(), but the event field of the waiter\nstructure is not initialized; When copy_from_user() fails in the\nkfd_wait_on_events() function, it will enter exception handling to\nrelease the previously allocated memory of the waiter structure;\nDue to the event field of the waiters structure be","2025-05-02T16:15:27.957+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53090",{"cveId":5946,"releaseId":31,"cycle":32,"description":5947,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5948,"url":5949},{"cveId":5946,"releaseId":25,"cycle":26,"description":5947,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5948,"url":5949},{"cveId":5953,"releaseId":17,"cycle":18,"description":5954,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5955,"url":5956},"CVE-2023-53080","In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: Add missing overflow check in xdp_umem_reg\n\nThe number of chunks can overflow u32. Make sure to return -EINVAL on\noverflow. Also remove a redundant u32 cast assigning umem->npgs.","2025-05-02T16:15:27.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53080",{"cveId":5958,"releaseId":25,"cycle":26,"description":5959,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5960,"url":5961},"CVE-2023-53039","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: intel-ish-hid: ipc: Fix potential use-after-free in work function\n\nWhen a reset notify IPC message is received, the ISR schedules a work\nfunction and passes the ISHTP device to it via a global pointer\nishtp_dev. If ish_probe() fails, the devm-managed device resources\nincluding ishtp_dev are freed, but the work is not cancelled, causing a\nuse-after-free when the work function tries to access ishtp_dev. Use\ndevm_work_autocan","2025-05-02T16:15:23.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53039",{"cveId":5958,"releaseId":17,"cycle":18,"description":5959,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5960,"url":5961},{"cveId":5958,"releaseId":31,"cycle":32,"description":5959,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5960,"url":5961},{"cveId":5965,"releaseId":25,"cycle":26,"description":5966,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5967,"url":5968},"CVE-2025-37798","In the Linux kernel, the following vulnerability has been resolved:\n\ncodel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()\n\nAfter making all ->qlen_notify() callbacks idempotent, now it is safe to\nremove the check of qlen!=0 from both fq_codel_dequeue() and\ncodel_qdisc_dequeue().","2025-05-02T15:15:48.657+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37798",{"cveId":5965,"releaseId":17,"cycle":18,"description":5966,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5967,"url":5968},{"cveId":5965,"releaseId":31,"cycle":32,"description":5966,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5967,"url":5968},{"cveId":5972,"releaseId":25,"cycle":26,"description":5973,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5974,"url":5975},"CVE-2025-37797","In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: hfsc: Fix a UAF vulnerability in class handling\n\nThis patch fixes a Use-After-Free vulnerability in the HFSC qdisc class\nhandling. The issue occurs due to a time-of-check\u002Ftime-of-use condition\nin hfsc_change_class() when working with certain child qdiscs like netem\nor codel.\n\nThe vulnerability works as follows:\n1. hfsc_change_class() checks if a class has packets (q.qlen != 0)\n2. It then calls qdisc_peek_len(), which","2025-05-02T15:15:48.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37797",{"cveId":5972,"releaseId":17,"cycle":18,"description":5973,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5974,"url":5975},{"cveId":5978,"releaseId":25,"cycle":26,"description":5979,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5980,"url":5981},"CVE-2022-49910","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu\n\nFix the race condition between the following two flows that run in\nparallel:\n\n1. l2cap_reassemble_sdu -> chan->ops->recv (l2cap_sock_recv_cb) ->\n   __sock_queue_rcv_skb.\n\n2. bt_sock_recvmsg -> skb_recv_datagram, skb_free_datagram.\n\nAn SKB can be queued by the first flow and immediately dequeued and\nfreed by the second flow, therefore the callers of l2cap_reass","2025-05-01T15:16:16.147+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49910",{"cveId":5978,"releaseId":17,"cycle":18,"description":5979,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5980,"url":5981},{"cveId":5978,"releaseId":31,"cycle":32,"description":5979,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":5980,"url":5981},{"cveId":5985,"releaseId":17,"cycle":18,"description":5986,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5987,"url":5988},"CVE-2022-49898","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix tree mod log mishandling of reallocated nodes\n\nWe have been seeing the following panic in production\n\n  kernel BUG at fs\u002Fbtrfs\u002Ftree-mod-log.c:677!\n  invalid opcode: 0000 [#1] SMP\n  RIP: 0010:tree_mod_log_rewind+0x1b4\u002F0x200\n  RSP: 0000:ffffc9002c02f890 EFLAGS: 00010293\n  RAX: 0000000000000003 RBX: ffff8882b448c700 RCX: 0000000000000000\n  RDX: 0000000000008000 RSI: 00000000000000a7 RDI: ffff88877d831c00\n  RBP: 00000000","2025-05-01T15:16:14.85+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49898",{"cveId":5985,"releaseId":25,"cycle":26,"description":5986,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5987,"url":5988},{"cveId":5985,"releaseId":31,"cycle":32,"description":5986,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5987,"url":5988},{"cveId":5992,"releaseId":25,"cycle":26,"description":5993,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5994,"url":5995},"CVE-2022-49892","In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Fix use-after-free for dynamic ftrace_ops\n\nKASAN reported a use-after-free with ftrace ops [1]. It was found from\nvmcore that perf had registered two ops with the same content\nsuccessively, both dynamic. After unregistering the second ops, a\nuse-after-free occurred.\n\nIn ftrace_shutdown(), when the second ops is unregistered, the\nFTRACE_UPDATE_CALLS command is not set because there is another enabled\nops with the same co","2025-05-01T15:16:14.21+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49892",{"cveId":5992,"releaseId":17,"cycle":18,"description":5993,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5994,"url":5995},{"cveId":5992,"releaseId":31,"cycle":32,"description":5993,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":5994,"url":5995},{"cveId":5999,"releaseId":25,"cycle":26,"description":6000,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6001,"url":6002},"CVE-2022-49872","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: fix panic on frag_list with mixed head alloc types\n\nSince commit 3dcbdb134f32 (\"net: gso: Fix skb_segment splat when\nsplitting gso_size mangled skb having linear-headed frag_list\"), it is\nallowed to change gso_size of a GRO packet. However, that commit assumes\nthat \"checking the first list_skb member suffices; i.e if either of the\nlist_skb members have non head_frag head, then the first one has too\".\n\nIt turns out thi","2025-05-01T15:16:12.133+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49872",{"cveId":5999,"releaseId":17,"cycle":18,"description":6000,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6001,"url":6002},{"cveId":5999,"releaseId":31,"cycle":32,"description":6000,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6001,"url":6002},{"cveId":6006,"releaseId":25,"cycle":26,"description":6007,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6008,"url":6009},"CVE-2022-49834","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix use-after-free bug of ns_writer on remount\n\nIf a nilfs2 filesystem is downgraded to read-only due to metadata\ncorruption on disk and is remounted read\u002Fwrite, or if emergency read-only\nremount is performed, detaching a log writer and synchronizing the\nfilesystem can be done at the same time.\n\nIn these cases, use-after-free of the log writer (hereinafter\nnilfs->ns_writer) can happen as shown in the scenario below:\n\n T","2025-05-01T15:16:06.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49834",{"cveId":6006,"releaseId":31,"cycle":32,"description":6007,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6008,"url":6009},{"cveId":6006,"releaseId":17,"cycle":18,"description":6007,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6008,"url":6009},{"cveId":6013,"releaseId":17,"cycle":18,"description":6014,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6015,"url":6016},"CVE-2022-49826","In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-transport: fix double ata_host_put() in ata_tport_add()\n\nIn the error path in ata_tport_add(), when calling put_device(),\nata_tport_release() is called, it will put the refcount of 'ap->host'.\n\nAnd then ata_host_put() is called again, the refcount is decreased\nto 0, ata_host_release() is called, all ports are freed and set to\nnull.\n\nWhen unbinding the device after failure, ata_host_stop() is called\nto release the re","2025-05-01T15:16:06.043+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49826",{"cveId":6018,"releaseId":17,"cycle":18,"description":6019,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6020,"url":6021},"CVE-2022-49814","In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: close race conditions on sk_receive_queue\n\nsk->sk_receive_queue is protected by skb queue lock, but for KCM\nsockets its RX path takes mux->rx_lock to protect more than just\nskb queue. However, kcm_recvmsg() still only grabs the skb queue\nlock, so race conditions still exist.\n\nWe can teach kcm_recvmsg() to grab mux->rx_lock too but this would\nintroduce a potential performance regression as struct kcm_mux can\nbe shared by mu","2025-05-01T15:16:04.787+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49814",{"cveId":6018,"releaseId":25,"cycle":26,"description":6019,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6020,"url":6021},{"cveId":6018,"releaseId":31,"cycle":32,"description":6019,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6020,"url":6021},{"cveId":6025,"releaseId":31,"cycle":32,"description":6026,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6027,"url":6028},"CVE-2022-49789","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: zfcp: Fix double free of FSF request when qdio send fails\n\nWe used to use the wrong type of integer in 'zfcp_fsf_req_send()' to cache\nthe FSF request ID when sending a new FSF request. This is used in case the\nsending fails and we need to remove the request from our internal hash\ntable again (so we don't keep an invalid reference and use it when we free\nthe request again).\n\nIn 'zfcp_fsf_req_send()' we used to cache the ID","2025-05-01T15:16:02.143+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49789",{"cveId":6025,"releaseId":25,"cycle":26,"description":6026,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6027,"url":6028},{"cveId":6025,"releaseId":17,"cycle":18,"description":6026,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6027,"url":6028},{"cveId":6032,"releaseId":17,"cycle":18,"description":6033,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6034,"url":6035},"CVE-2022-49775","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: cdg: allow tcp_cdg_release() to be called multiple times\n\nApparently, mptcp is able to call tcp_disconnect() on an already\ndisconnected flow. This is generally fine, unless current congestion\ncontrol is CDG, because it might trigger a double-free [1]\n\nInstead of fixing MPTCP, and future bugs, we can make tcp_disconnect()\nmore resilient.\n\n[1]\nBUG: KASAN: double-free in slab_free mm\u002Fslub.c:3539 [inline]\nBUG: KASAN: double-fr","2025-05-01T15:16:00.65+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49775",{"cveId":6032,"releaseId":25,"cycle":26,"description":6033,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6034,"url":6035},{"cveId":6032,"releaseId":31,"cycle":32,"description":6033,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6034,"url":6035},{"cveId":6039,"releaseId":17,"cycle":18,"description":6040,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6041,"url":6042},"CVE-2022-49770","In the Linux kernel, the following vulnerability has been resolved:\n\nceph: avoid putting the realm twice when decoding snaps fails\n\nWhen decoding the snaps fails it maybe leaving the 'first_realm'\nand 'realm' pointing to the same snaprealm memory. And then it'll\nput it twice and could cause random use-after-free, BUG_ON, etc\nissues.","2025-05-01T15:15:59.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49770",{"cveId":6039,"releaseId":31,"cycle":32,"description":6040,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6041,"url":6042},{"cveId":6039,"releaseId":25,"cycle":26,"description":6040,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6041,"url":6042},{"cveId":6046,"releaseId":31,"cycle":32,"description":6047,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6048,"url":6049},"CVE-2022-49768","In the Linux kernel, the following vulnerability has been resolved:\n\n9p: trans_fd\u002Fp9_conn_cancel: drop client lock earlier\n\nsyzbot reported a double-lock here and we no longer need this\nlock after requests have been moved off to local list:\njust drop the lock earlier.","2025-05-01T15:15:59.597+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49768",{"cveId":6046,"releaseId":25,"cycle":26,"description":6047,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6048,"url":6049},{"cveId":6046,"releaseId":17,"cycle":18,"description":6047,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6048,"url":6049},{"cveId":6053,"releaseId":17,"cycle":18,"description":6054,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6055,"url":6056},"CVE-2022-49763","In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: fix use-after-free in ntfs_attr_find()\n\nPatch series \"ntfs: fix bugs about Attribute\", v2.\n\nThis patchset fixes three bugs relative to Attribute in record:\n\nPatch 1 adds a sanity check to ensure that, attrs_offset field in first\nmft record loading from disk is within bounds.\n\nPatch 2 moves the ATTR_RECORD's bounds checking earlier, to avoid\ndereferencing ATTR_RECORD before checking this ATTR_RECORD is within\nbounds.\n\nPatc","2025-05-01T15:15:59.047+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49763",{"cveId":6053,"releaseId":25,"cycle":26,"description":6054,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6055,"url":6056},{"cveId":6053,"releaseId":31,"cycle":32,"description":6054,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6055,"url":6056},{"cveId":6060,"releaseId":17,"cycle":18,"description":6061,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6062,"url":6063},"CVE-2025-37789","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix nested key length validation in the set() action\n\nIt's not safe to access nla_len(ovs_key) if the data is smaller than\nthe netlink header.  Check that the attribute is OK first.","2025-05-01T14:15:43.29+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37789",{"cveId":6060,"releaseId":25,"cycle":26,"description":6061,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6062,"url":6063},{"cveId":6060,"releaseId":31,"cycle":32,"description":6061,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6062,"url":6063},{"cveId":6067,"releaseId":25,"cycle":26,"description":6068,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6069,"url":6070},"CVE-2025-37765","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fnouveau: prime: fix ttm_bo_delayed_delete oops\n\nFix an oops in ttm_bo_delayed_delete which results from dererencing a\ndangling pointer:\n\nOops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b7b: 0000 [#1] PREEMPT SMP\nCPU: 4 UID: 0 PID: 1082 Comm: kworker\u002Fu65:2 Not tainted 6.14.0-rc4-00267-g505460b44513-dirty #216\nHardware name: LENOVO 82N6\u002FLNVNB161216, BIOS GKCN65WW 01\u002F16\u002F2024\nWorkqueue: ttm ttm","2025-05-01T14:15:39.417+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37765",{"cveId":6067,"releaseId":17,"cycle":18,"description":6068,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6069,"url":6070},{"cveId":6067,"releaseId":31,"cycle":32,"description":6068,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6069,"url":6070},{"cveId":6074,"releaseId":25,"cycle":26,"description":6075,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6076,"url":6077},"CVE-2025-37757","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix memory leak in tipc_link_xmit\n\nIn case the backlog transmit queue for system-importance messages is overloaded,\ntipc_link_xmit() returns -ENOBUFS but the skb list is not purged. This leads to\nmemory leak and failure when a skb is allocated.\n\nThis commit fixes this issue by purging the skb list before tipc_link_xmit()\nreturns.","2025-05-01T13:15:54.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37757",{"cveId":6074,"releaseId":17,"cycle":18,"description":6075,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6076,"url":6077},{"cveId":6080,"releaseId":17,"cycle":18,"description":6081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6082,"url":6083},"CVE-2025-37756","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: explicitly disallow disconnect\n\nsyzbot discovered that it can disconnect a TLS socket and then\nrun into all sort of unexpected corner cases. I have a vague\nrecollection of Eric pointing this out to us a long time ago.\nSupporting disconnect is really hard, for one thing if offload\nis enabled we'd need to wait for all packets to be _acked_.\nDisconnect is not commonly used, disallow it.\n\nThe immediate problem syzbot run ","2025-05-01T13:15:54.37+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37756",{"cveId":6080,"releaseId":25,"cycle":26,"description":6081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6082,"url":6083},{"cveId":6086,"releaseId":31,"cycle":32,"description":6087,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":6088,"url":6089},"CVE-2025-37749","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ppp: Add bound checking for skb data on ppp_sync_txmung\n\nEnsure we have enough data in linear buffer from skb before accessing\ninitial bytes. This prevents potential out-of-bounds accesses\nwhen processing short packets.\n\nWhen ppp_sync_txmung receives an incoming package with an empty\npayload:\n(remote) gef➤  p *(struct pppoe_hdr *) (skb->head + skb->network_header)\n$18 = {\n\ttype = 0x1,\n\tver = 0x1,\n\tcode = 0x0,\n\tsid = 0x2,\n ","2025-05-01T13:15:53.633+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37749",{"cveId":6086,"releaseId":25,"cycle":26,"description":6087,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":6088,"url":6089},{"cveId":6086,"releaseId":17,"cycle":18,"description":6087,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":6088,"url":6089},{"cveId":6093,"releaseId":25,"cycle":26,"description":6094,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6095,"url":6096},"CVE-2025-37741","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Prevent copying of nlink with value 0 from disk inode\n\nsyzbot report a deadlock in diFree. [1]\n\nWhen calling \"ioctl$LOOP_SET_STATUS64\", the offset value passed in is 4,\nwhich does not match the mounted loop device, causing the mapping of the\nmounted loop device to be invalidated.\n\nWhen creating the directory and creating the inode of iag in diReadSpecial(),\nread the page of fixed disk inode (AIT) in raw mode in read_metapa","2025-05-01T13:15:52.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37741",{"cveId":6093,"releaseId":31,"cycle":32,"description":6094,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6095,"url":6096},{"cveId":6093,"releaseId":17,"cycle":18,"description":6094,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6095,"url":6096},{"cveId":6100,"releaseId":25,"cycle":26,"description":6101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6102,"url":6103},"CVE-2025-37738","In the Linux kernel, the following vulnerability has been resolved:\n\next4: ignore xattrs past end\n\nOnce inside 'ext4_xattr_inode_dec_ref_all' we should\nignore xattrs entries past the 'end' entry.\n\nThis fixes the following KASAN reported issue:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in ext4_xattr_inode_dec_ref_all+0xb8c\u002F0xe90\nRead of size 4 at addr ffff888012c120c4 by task repro\u002F2065\n\nCPU: 1 UID: 0 PID: 2065 Comm: repro Not tainted 6.13","2025-05-01T13:15:52.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37738",{"cveId":6100,"releaseId":31,"cycle":32,"description":6101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6102,"url":6103},{"cveId":6100,"releaseId":17,"cycle":18,"description":6101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6102,"url":6103},{"cveId":6107,"releaseId":25,"cycle":26,"description":6108,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":6109,"url":6110},"CVE-2025-23159","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi: add a check to handle OOB in sfr region\n\nsfr->buf_size is in shared memory and can be modified by malicious user.\nOOB write is possible when the size is made higher than actual sfr data\nbuffer. Cap the size to allocated size for such cases.","2025-05-01T13:15:51.843+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23159",{"cveId":6107,"releaseId":17,"cycle":18,"description":6108,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":6109,"url":6110},{"cveId":6113,"releaseId":17,"cycle":18,"description":6114,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6115,"url":6116},"CVE-2025-23158","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi: add check to handle incorrect queue size\n\nqsize represents size of shared queued between driver and video\nfirmware. Firmware can modify this value to an invalid large value. In\nsuch situation, empty_space will be bigger than the space actually\navailable. Since new_wr_idx is not checked, so the following code will\nresult in an OOB write.\n...\nqsize = qhdr->q_size\n\nif (wr_idx >= rd_idx)\n empty_space = qsize - (w","2025-05-01T13:15:51.733+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23158",{"cveId":6113,"releaseId":25,"cycle":26,"description":6114,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6115,"url":6116},{"cveId":6119,"releaseId":17,"cycle":18,"description":6120,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6121,"url":6122},"CVE-2025-23157","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi_parser: add check to avoid out of bound access\n\nThere is a possibility that init_codecs is invoked multiple times during\nmanipulated payload from video firmware. In such case, if codecs_count\ncan get incremented to value more than MAX_CODEC_NUM, there can be OOB\naccess. Reset the count so that it always starts from beginning.","2025-05-01T13:15:51.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23157",{"cveId":6124,"releaseId":17,"cycle":18,"description":6125,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6126,"url":6127},"CVE-2025-23156","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi_parser: refactor hfi packet parsing logic\n\nwords_count denotes the number of words in total payload, while data\npoints to payload of various property within it. When words_count\nreaches last word, data can access memory beyond the total payload. This\ncan lead to OOB access. With this patch, the utility api for handling\nindividual properties now returns the size of data consumed. Accordingly\nremaining bytes are","2025-05-01T13:15:51.517+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23156",{"cveId":6129,"releaseId":31,"cycle":32,"description":6130,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6131,"url":6132},"CVE-2025-23150","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix off-by-one error in do_split\n\nSyzkaller detected a use-after-free issue in ext4_insert_dentry that was\ncaused by out-of-bounds access due to incorrect splitting in do_split.\n\nBUG: KASAN: use-after-free in ext4_insert_dentry+0x36a\u002F0x6d0 fs\u002Fext4\u002Fnamei.c:2109\nWrite of size 251 at addr ffff888074572f14 by task syz-executor335\u002F5847\n\nCPU: 0 UID: 0 PID: 5847 Comm: syz-executor335 Not tainted 6.12.0-rc6-syzkaller-00318-ga9cda","2025-05-01T13:15:50.893+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23150",{"cveId":6129,"releaseId":25,"cycle":26,"description":6130,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6131,"url":6132},{"cveId":6129,"releaseId":17,"cycle":18,"description":6130,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6131,"url":6132},{"cveId":6136,"releaseId":25,"cycle":26,"description":6137,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6138,"url":6139},"CVE-2025-23143","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod.\n\nWhen I ran the repro [0] and waited a few seconds, I observed two\nLOCKDEP splats: a warning immediately followed by a null-ptr-deref. [1]\n\nReproduction Steps:\n\n  1) Mount CIFS\n  2) Add an iptables rule to drop incoming FIN packets for CIFS\n  3) Unmount CIFS\n  4) Unload the CIFS module\n  5) Remove the iptables rule\n\nAt step 3), the CIFS module calls sock_rele","2025-05-01T13:15:50.127+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23143",{"cveId":6136,"releaseId":17,"cycle":18,"description":6137,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6138,"url":6139},{"cveId":6136,"releaseId":31,"cycle":32,"description":6137,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6138,"url":6139},{"cveId":6143,"releaseId":25,"cycle":26,"description":6144,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6145,"url":6146},"CVE-2025-23142","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: detect and prevent references to a freed transport in sendmsg\n\nsctp_sendmsg() re-uses associations and transports when possible by\ndoing a lookup based on the socket endpoint and the message destination\naddress, and then sctp_sendmsg_to_asoc() sets the selected transport in\nall the message chunks to be sent.\n\nThere's a possible race condition if another thread triggers the removal\nof that selected transport, for instance,","2025-05-01T13:15:50.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23142",{"cveId":6143,"releaseId":17,"cycle":18,"description":6144,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6145,"url":6146},{"cveId":6143,"releaseId":31,"cycle":32,"description":6144,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6145,"url":6146},{"cveId":6150,"releaseId":17,"cycle":18,"description":6151,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6152,"url":6153},"CVE-2025-23141","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses\n\nAcquire a lock on kvm->srcu when userspace is getting MP state to handle a\nrather extreme edge case where \"accepting\" APIC events, i.e. processing\npending INIT or SIPI, can trigger accesses to guest memory.  If the vCPU\nis in L2 with INIT *and* a TRIPLE_FAULT request pending, then getting MP\nstate will trigger a nested VM-Exit by way of ->check_nested_","2025-05-01T13:15:49.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23141",{"cveId":6150,"releaseId":25,"cycle":26,"description":6151,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6152,"url":6153},{"cveId":6150,"releaseId":31,"cycle":32,"description":6151,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6152,"url":6153},{"cveId":6157,"releaseId":17,"cycle":18,"description":6158,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6159,"url":6160},"CVE-2025-37785","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix OOB read when checking dotdot dir\n\nMounting a corrupted filesystem with directory which contains '.' dir\nentry with rec_len == block size results in out-of-bounds read (later\non, when the corrupted directory is removed).\n\next4_empty_dir() assumes every ext4 directory contains at least '.'\nand '..' as directory entries in the first data block. It first loads\nthe '.' dir entry, performs sanity checks by calling ext4_che","2025-04-18T07:15:42.693+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-37785",{"cveId":6157,"releaseId":31,"cycle":32,"description":6158,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6159,"url":6160},{"cveId":6157,"releaseId":25,"cycle":26,"description":6158,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6159,"url":6160},{"cveId":6164,"releaseId":31,"cycle":32,"description":6165,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6166,"url":6167},"CVE-2021-47670","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: fix use after free bugs\n\nAfter calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe.\nEspecially, the can_frame cf which aliases skb memory is accessed\nafter the peak_usb_netif_rx_ni().\n\nReordering the lines solves the issue.","2025-04-17T18:15:43.833+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47670",{"cveId":6164,"releaseId":17,"cycle":18,"description":6165,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6166,"url":6167},{"cveId":6164,"releaseId":25,"cycle":26,"description":6165,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6166,"url":6167},{"cveId":6171,"releaseId":25,"cycle":26,"description":6172,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6173,"url":6174},"CVE-2021-47668","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: dev: can_restart: fix use after free bug\n\nAfter calling netif_rx_ni(skb), dereferencing skb is unsafe.\nEspecially, the can_frame cf which aliases skb memory is accessed\nafter the netif_rx_ni() in:\n      stats->rx_bytes += cf->len;\n\nReordering the lines solves the issue.","2025-04-17T18:15:43.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47668",{"cveId":6171,"releaseId":17,"cycle":18,"description":6172,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6173,"url":6174},{"cveId":6171,"releaseId":31,"cycle":32,"description":6172,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6173,"url":6174},{"cveId":6178,"releaseId":17,"cycle":18,"description":6179,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6180,"url":6181},"CVE-2025-23136","In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: int340x: Add NULL check for adev\n\nNot all devices have an ACPI companion fwnode, so adev might be NULL.\nThis is similar to the commit cd2fd6eab480\n(\"platform\u002Fx86: int3472: Check for adev == NULL\").\n\nAdd a check for adev not being set and return -ENODEV in that case to\navoid a possible NULL pointer deref in int3402_thermal_probe().\n\nNote, under the same directory, int3400_thermal_probe() has such a\ncheck.\n\n[ rjw: Subjec","2025-04-16T15:16:07.97+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23136",{"cveId":6178,"releaseId":31,"cycle":32,"description":6179,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6180,"url":6181},{"cveId":6178,"releaseId":25,"cycle":26,"description":6179,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6180,"url":6181},{"cveId":6185,"releaseId":17,"cycle":18,"description":6186,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6187,"url":6188},"CVE-2025-23131","In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: prevent NPD when writing a positive value to event_done\n\ndo_uevent returns the value written to event_done. In case it is a\npositive value, new_lockspace would undo all the work, and lockspace\nwould not be set. __dlm_new_lockspace, however, would treat that\npositive value as a success due to commit 8511a2728ab8 (\"dlm: fix use\ncount with multiple joins\").\n\nDown the line, device_create_lockspace would pass that NULL lockspac","2025-04-16T15:16:07.547+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-23131",{"cveId":6185,"releaseId":25,"cycle":26,"description":6186,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6187,"url":6188},{"cveId":6185,"releaseId":31,"cycle":32,"description":6186,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6187,"url":6188},{"cveId":6192,"releaseId":17,"cycle":18,"description":6193,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6194,"url":6195},"CVE-2025-22121","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()\n\nThere's issue as follows:\nBUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff\u002F0x790\nRead of size 4 at addr ffff88807b003000 by task syz-executor.0\u002F15172\n\nCPU: 3 PID: 15172 Comm: syz-executor.0\nCall Trace:\n __dump_stack lib\u002Fdump_stack.c:82 [inline]\n dump_stack+0xbe\u002F0xfd lib\u002Fdump_stack.c:123\n print_address_description.constprop.0+0x1e\u002F0x280 mm\u002Fkasan\u002Frepor","2025-04-16T15:16:06.277+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22121",{"cveId":6192,"releaseId":25,"cycle":26,"description":6193,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6194,"url":6195},{"cveId":6198,"releaseId":25,"cycle":26,"description":6199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6200,"url":6201},"CVE-2025-22109","In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Remove broken autobind\n\nBinding AX25 socket by using the autobind feature leads to memory leaks\nin ax25_connect() and also refcount leaks in ax25_release(). Memory\nleak was detected with kmemleak:\n\n================================================================\nunreferenced object 0xffff8880253cd680 (size 96):\nbacktrace:\n__kmalloc_node_track_caller_noprof (.\u002Finclude\u002Flinux\u002Fkmemleak.h:43)\nkmemdup_noprof (mm\u002Futil.c:136)\nax2","2025-04-16T15:16:05.167+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22109",{"cveId":6198,"releaseId":31,"cycle":32,"description":6199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6200,"url":6201},{"cveId":6198,"releaseId":17,"cycle":18,"description":6199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6200,"url":6201},{"cveId":6205,"releaseId":25,"cycle":26,"description":6206,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6207,"url":6208},"CVE-2025-22090","In the Linux kernel, the following vulnerability has been resolved:\n\nx86\u002Fmm\u002Fpat: Fix VM_PAT handling when fork() fails in copy_page_range()\n\nIf track_pfn_copy() fails, we already added the dst VMA to the maple\ntree. As fork() fails, we'll cleanup the maple tree, and stumble over\nthe dst VMA for which we neither performed any reservation nor copied\nany page tables.\n\nConsequently untrack_pfn() will see VM_PAT and try obtaining the\nPAT information from the page table -- which fails because the page","2025-04-16T15:16:03.213+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22090",{"cveId":6205,"releaseId":17,"cycle":18,"description":6206,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6207,"url":6208},{"cveId":6205,"releaseId":31,"cycle":32,"description":6206,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6207,"url":6208},{"cveId":6212,"releaseId":17,"cycle":18,"description":6213,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6214,"url":6215},"CVE-2025-22086","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fmlx5: Fix mlx5_poll_one() cur_qp update flow\n\nWhen cur_qp isn't NULL, in order to avoid fetching the QP from\nthe radix tree again we check if the next cqe QP is identical to\nthe one we already have.\n\nThe bug however is that we are checking if the QP is identical by\nchecking the QP number inside the CQE against the QP number inside the\nmlx5_ib_qp, but that's wrong since the QP number from the CQE is from\nFW so it should be ","2025-04-16T15:16:02.8+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22086",{"cveId":6212,"releaseId":25,"cycle":26,"description":6213,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6214,"url":6215},{"cveId":6212,"releaseId":31,"cycle":32,"description":6213,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6214,"url":6215},{"cveId":6219,"releaseId":17,"cycle":18,"description":6220,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6221,"url":6222},"CVE-2025-22083","In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint\n\nIf vhost_scsi_set_endpoint is called multiple times without a\nvhost_scsi_clear_endpoint between them, we can hit multiple bugs\nfound by Haoran Zhang:\n\n1. Use-after-free when no tpgs are found:\n\nThis fixes a use after free that occurs when vhost_scsi_set_endpoint is\ncalled more than once and calls after the first call do not find any\ntpgs to add to the vs_tpg","2025-04-16T15:16:02.51+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22083",{"cveId":6219,"releaseId":31,"cycle":32,"description":6220,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6221,"url":6222},{"cveId":6219,"releaseId":25,"cycle":26,"description":6220,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6221,"url":6222},{"cveId":6226,"releaseId":25,"cycle":26,"description":6227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6228,"url":6229},"CVE-2025-22079","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate l_tree_depth to avoid out-of-bounds access\n\nThe l_tree_depth field is 16-bit (__le16), but the actual maximum depth is\nlimited to OCFS2_MAX_PATH_DEPTH.\n\nAdd a check to prevent out-of-bounds access if l_tree_depth has an invalid\nvalue, which may occur when reading from a corrupted mounted disk [1].","2025-04-16T15:16:02.113+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22079",{"cveId":6226,"releaseId":31,"cycle":32,"description":6227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6228,"url":6229},{"cveId":6226,"releaseId":17,"cycle":18,"description":6227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6228,"url":6229},{"cveId":6233,"releaseId":25,"cycle":26,"description":6234,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6235,"url":6236},"CVE-2025-22072","In the Linux kernel, the following vulnerability has been resolved:\n\nspufs: fix gang directory lifetimes\n\nprior to \"[POWERPC] spufs: Fix gang destroy leaks\" we used to have\na problem with gang lifetimes - creation of a gang returns opened\ngang directory, which normally gets removed when that gets closed,\nbut if somebody has created a context belonging to that gang and\nkept it alive until the gang got closed, removal failed and we\nended up with a leak.\n\nUnfortunately, it had been fixed the wrong ","2025-04-16T15:16:01.39+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22072",{"cveId":6233,"releaseId":17,"cycle":18,"description":6234,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6235,"url":6236},{"cveId":6233,"releaseId":31,"cycle":32,"description":6234,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6235,"url":6236},{"cveId":6240,"releaseId":25,"cycle":26,"description":6241,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":6242,"url":6243},"CVE-2025-22060","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvpp2: Prevent parser TCAM memory corruption\n\nProtect the parser TCAM\u002FSRAM memory, and the cached (shadow) SRAM\ninformation, from concurrent modifications.\n\nBoth the TCAM and SRAM tables are indirectly accessed by configuring\nan index register that selects the row to read or write to. This means\nthat operations must be atomic in order to, e.g., avoid spreading\nwrites across multiple rows. Since the shadow SRAM array is use","2025-04-16T15:15:59.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22060",{"cveId":6240,"releaseId":31,"cycle":32,"description":6241,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":6242,"url":6243},{"cveId":6240,"releaseId":17,"cycle":18,"description":6241,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":6242,"url":6243},{"cveId":6247,"releaseId":17,"cycle":18,"description":6248,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6249,"url":6250},"CVE-2025-22057","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: decrease cached dst counters in dst_release\n\nUpstream fix ac888d58869b (\"net: do not delay dst_entries_add() in\ndst_release()\") moved decrementing the dst count from dst_destroy to\ndst_release to avoid accessing already freed data in case of netns\ndismantle. However in case CONFIG_DST_CACHE is enabled and OvS+tunnels\nare used, this fix is incomplete as the same issue will be seen for\ncached dsts:\n\n  Unable to handle kernel","2025-04-16T15:15:59.183+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22057",{"cveId":6247,"releaseId":31,"cycle":32,"description":6248,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6249,"url":6250},{"cveId":6247,"releaseId":25,"cycle":26,"description":6248,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6249,"url":6250},{"cveId":6254,"releaseId":17,"cycle":18,"description":6255,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6256,"url":6257},"CVE-2025-22055","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix geneve_opt length integer overflow\n\nstruct geneve_opt uses 5 bit length for each single option, which\nmeans every vary size option should be smaller than 128 bytes.\n\nHowever, all current related Netlink policies cannot promise this\nlength condition and the attacker can exploit a exact 128-byte size\noption to *fake* a zero length option and confuse the parsing logic,\nfurther achieve heap out-of-bounds read.\n\nOne example","2025-04-16T15:15:58.983+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22055",{"cveId":6259,"releaseId":17,"cycle":18,"description":6260,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":6261,"url":6262},"CVE-2025-22038","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate zero num_subauth before sub_auth is accessed\n\nAccess psid->sub_auth[psid->num_subauth - 1] without checking\nif num_subauth is non-zero leads to an out-of-bounds read.\nThis patch adds a validation step to ensure num_subauth != 0\nbefore sub_auth is accessed.","2025-04-16T15:15:56.4+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22038",{"cveId":6259,"releaseId":31,"cycle":32,"description":6260,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":6261,"url":6262},{"cveId":6259,"releaseId":25,"cycle":26,"description":6260,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":6261,"url":6262},{"cveId":6266,"releaseId":31,"cycle":32,"description":6267,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6268,"url":6269},"CVE-2025-22037","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix null pointer dereference in alloc_preauth_hash()\n\nThe Client send malformed smb2 negotiate request. ksmbd return error\nresponse. Subsequently, the client can send smb2 session setup even\nthought conn->preauth_info is not allocated.\nThis patch add KSMBD_SESS_NEED_SETUP status of connection to ignore\nsession setup request if smb2 negotiate phase is not complete.","2025-04-16T15:15:56.31+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22037",{"cveId":6266,"releaseId":25,"cycle":26,"description":6267,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6268,"url":6269},{"cveId":6266,"releaseId":17,"cycle":18,"description":6267,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6268,"url":6269},{"cveId":6273,"releaseId":25,"cycle":26,"description":6274,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6275,"url":6276},"CVE-2025-22025","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: put dl_stid if fail to queue dl_recall\n\nBefore calling nfsd4_run_cb to queue dl_recall to the callback_wq, we\nincrement the reference count of dl_stid.\nWe expect that after the corresponding work_struct is processed, the\nreference count of dl_stid will be decremented through the callback\nfunction nfsd4_cb_recall_release.\nHowever, if the call to nfsd4_run_cb fails, the incremented reference\ncount of dl_stid will not be dec","2025-04-16T15:15:55.127+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22025",{"cveId":6273,"releaseId":17,"cycle":18,"description":6274,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6275,"url":6276},{"cveId":6273,"releaseId":31,"cycle":32,"description":6274,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6275,"url":6276},{"cveId":6280,"releaseId":31,"cycle":32,"description":6281,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6282,"url":6283},"CVE-2024-58094","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add check read-only before truncation in jfs_truncate_nolock()\n\nAdded a check for \"read-only\" mode in the `jfs_truncate_nolock`\nfunction to avoid errors related to writing to a read-only\nfilesystem.\n\nCall stack:\n\nblock_write_begin() {\n  jfs_write_failed() {\n    jfs_truncate() {\n      jfs_truncate_nolock() {\n        txEnd() {\n          ...\n          log = JFS_SBI(tblk->sb)->log;\n          \u002F\u002F (log == NULL)\n\nIf the `isReadOnl","2025-04-16T15:15:53.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58094",{"cveId":6280,"releaseId":17,"cycle":18,"description":6281,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6282,"url":6283},{"cveId":6280,"releaseId":25,"cycle":26,"description":6281,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6282,"url":6283},{"cveId":6287,"releaseId":17,"cycle":18,"description":6288,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6289,"url":6290},"CVE-2023-53034","In the Linux kernel, the following vulnerability has been resolved:\n\nntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans\n\nThere is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and\nsize. This would make xlate_pos negative.\n\n[   23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000\n[   23.734158] ================================================================================\n[   23.734172] UBSAN: shift-out-of-bounds in dri","2025-04-16T15:15:52.717+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53034",{"cveId":6292,"releaseId":31,"cycle":32,"description":6293,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6294,"url":6295},"CVE-2025-22022","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Apply the link chain quirk on NEC isoc endpoints\n\nTwo clearly different specimens of NEC uPD720200 (one with start\u002Fstop\nbug, one without) were seen to cause IOMMU faults after some Missed\nService Errors. Faulting address is immediately after a transfer ring\nsegment and patched dynamic debug messages revealed that the MSE was\nreceived when waiting for a TD near the end of that segment:\n\n[ 1.041954] xhci_hcd: Miss serv","2025-04-16T11:15:42.883+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22022",{"cveId":6292,"releaseId":17,"cycle":18,"description":6293,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6294,"url":6295},{"cveId":6292,"releaseId":25,"cycle":26,"description":6293,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6294,"url":6295},{"cveId":6299,"releaseId":31,"cycle":32,"description":6300,"severity":101,"cvssScore":6301,"epssScore":9,"inKev":42,"publishedAt":6302,"url":6303},"CVE-2025-22021","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: socket: Lookup orig tuple for IPv6 SNAT\n\nnf_sk_lookup_slow_v4 does the conntrack lookup for IPv4 packets to\nrestore the original 5-tuple in case of SNAT, to be able to find the\nright socket (if any). Then socket_match() can correctly check whether\nthe socket was transparent.\n\nHowever, the IPv6 counterpart (nf_sk_lookup_slow_v6) lacks this\nconntrack lookup, making xt_socket fail to match on the socket when the\npacket ",10,"2025-04-16T11:15:42.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22021",{"cveId":6299,"releaseId":17,"cycle":18,"description":6300,"severity":101,"cvssScore":6301,"epssScore":9,"inKev":42,"publishedAt":6302,"url":6303},{"cveId":6299,"releaseId":25,"cycle":26,"description":6300,"severity":101,"cvssScore":6301,"epssScore":9,"inKev":42,"publishedAt":6302,"url":6303},{"cveId":6307,"releaseId":31,"cycle":32,"description":6308,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":6309,"url":6310},"CVE-2025-22004","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atm: fix use after free in lec_send()\n\nThe ->send() operation frees skb so save the length before calling\n->send() to avoid a use after free.","2025-04-03T08:15:15.96+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-22004",{"cveId":6307,"releaseId":17,"cycle":18,"description":6308,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":6309,"url":6310},{"cveId":6307,"releaseId":25,"cycle":26,"description":6308,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":6309,"url":6310},{"cveId":6314,"releaseId":17,"cycle":18,"description":6315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6316,"url":6317},"CVE-2025-21999","In the Linux kernel, the following vulnerability has been resolved:\n\nproc: fix UAF in proc_get_inode()\n\nFix race between rmmod and \u002Fproc\u002FXXX's inode instantiation.\n\nThe bug is that pde->proc_ops don't belong to \u002Fproc, it belongs to a\nmodule, therefore dereferencing it after \u002Fproc entry has been registered\nis a bug unless use_pde\u002Funuse_pde() pair has been used.\n\nuse_pde\u002Funuse_pde can be avoided (2 atomic ops!) because pde->proc_ops\nnever changes so information necessary for inode instantiation ca","2025-04-03T08:15:15.36+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21999",{"cveId":6314,"releaseId":25,"cycle":26,"description":6315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6316,"url":6317},{"cveId":6314,"releaseId":31,"cycle":32,"description":6315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6316,"url":6317},{"cveId":6321,"releaseId":17,"cycle":18,"description":6322,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6323,"url":6324},"CVE-2025-21985","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix out-of-bound accesses\n\n[WHAT & HOW]\nhpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4),\nbut location can have size up to 6. As a result, it is necessary to\ncheck location against MAX_HPO_DP2_ENCODERS.\n\nSimiliarly, disp_cfg_stream_location can be used as an array index which\nshould be 0..5, so the ASSERT's conditions should be less without equal.","2025-04-01T16:15:29.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21985",{"cveId":6326,"releaseId":17,"cycle":18,"description":6327,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6328,"url":6329},"CVE-2025-21976","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: hyperv_fb: Allow graceful removal of framebuffer\n\nWhen a Hyper-V framebuffer device is unbind, hyperv_fb driver tries to\nrelease the framebuffer forcefully. If this framebuffer is in use it\nproduce the following WARN and hence this framebuffer is never released.\n\n[   44.111220] WARNING: CPU: 35 PID: 1882 at drivers\u002Fvideo\u002Ffbdev\u002Fcore\u002Ffb_info.c:70 framebuffer_release+0x2c\u002F0x40\n\u003C snip >\n[   44.111289] Call Trace:\n[   44.1112","2025-04-01T16:15:28.973+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21976",{"cveId":6326,"releaseId":25,"cycle":26,"description":6327,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6328,"url":6329},{"cveId":6326,"releaseId":31,"cycle":32,"description":6327,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6328,"url":6329},{"cveId":6333,"releaseId":17,"cycle":18,"description":6334,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6335,"url":6336},"CVE-2025-21971","In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: Prevent creation of classes with TC_H_ROOT\n\nThe function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination\ncondition when traversing up the qdisc tree to update parent backlog\ncounters. However, if a class is created with classid TC_H_ROOT, the\ntraversal terminates prematurely at this class instead of reaching the\nactual root qdisc, causing parent statistics to be incorrectly maintained.\nIn case of DRR, thi","2025-04-01T16:15:28.44+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21971",{"cveId":6333,"releaseId":31,"cycle":32,"description":6334,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6335,"url":6336},{"cveId":6333,"releaseId":25,"cycle":26,"description":6334,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6335,"url":6336},{"cveId":6340,"releaseId":31,"cycle":32,"description":6341,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6342,"url":6343},"CVE-2025-21969","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd\n\nAfter the hci sync command releases l2cap_conn, the hci receive data work\nqueue references the released l2cap_conn when sending to the upper layer.\nAdd hci dev lock to the hci receive data work queue to synchronize the two.\n\n[1]\nBUG: KASAN: slab-use-after-free in l2cap_send_cmd+0x187\u002F0x8d0 net\u002Fbluetooth\u002Fl2cap_core.c:954\nRead of size 8 at addr ffff8880271a4000 by ","2025-04-01T16:15:28.207+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21969",{"cveId":6340,"releaseId":25,"cycle":26,"description":6341,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6342,"url":6343},{"cveId":6340,"releaseId":17,"cycle":18,"description":6341,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6342,"url":6343},{"cveId":6347,"releaseId":17,"cycle":18,"description":6348,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6349,"url":6350},"CVE-2025-21959","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()\n\nSince commit b36e4523d4d5 (\"netfilter: nf_conncount: fix garbage\ncollection confirm race\"), `cpu` and `jiffies32` were introduced to\nthe struct nf_conncount_tuple.\n\nThe commit made nf_conncount_add() initialize `conn->cpu` and\n`conn->jiffies32` when allocating the struct.\nIn contrast, count_tree() was not changed to initialize them.\n\nBy commit","2025-04-01T16:15:27.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21959",{"cveId":6347,"releaseId":25,"cycle":26,"description":6348,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6349,"url":6350},{"cveId":6353,"releaseId":17,"cycle":18,"description":6354,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6355,"url":6356},"CVE-2025-21926","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: fix ownership in __udp_gso_segment\n\nIn __udp_gso_segment the skb destructor is removed before segmenting the\nskb but the socket reference is kept as-is. This is an issue if the\noriginal skb is later orphaned as we can hit the following bug:\n\n  kernel BUG at .\u002Finclude\u002Flinux\u002Fskbuff.h:3312!  (skb_orphan)\n  RIP: 0010:ip_rcv_core+0x8b2\u002F0xca0\n  Call Trace:\n   ip_rcv+0xab\u002F0x6e0\n   __netif_receive_skb_one_core+0x168\u002F0x1b0\n   ","2025-04-01T16:15:23.35+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21926",{"cveId":6358,"releaseId":31,"cycle":32,"description":6359,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6360,"url":6361},"CVE-2025-21925","In the Linux kernel, the following vulnerability has been resolved:\n\nllc: do not use skb_get() before dev_queue_xmit()\n\nsyzbot is able to crash hosts [1], using llc and devices\nnot supporting IFF_TX_SKB_SHARING.\n\nIn this case, e1000 driver calls eth_skb_pad(), while\nthe skb is shared.\n\nSimply replace skb_get() by skb_clone() in net\u002Fllc\u002Fllc_s_ac.c\n\nNote that e1000 driver might have an issue with pktgen,\nbecause it does not clear IFF_TX_SKB_SHARING, this is an\northogonal change.\n\nWe need to audit ","2025-04-01T16:15:23.227+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21925",{"cveId":6358,"releaseId":17,"cycle":18,"description":6359,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6360,"url":6361},{"cveId":6358,"releaseId":25,"cycle":26,"description":6359,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6360,"url":6361},{"cveId":6365,"releaseId":17,"cycle":18,"description":6366,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6367,"url":6368},"CVE-2025-21914","In the Linux kernel, the following vulnerability has been resolved:\n\nslimbus: messaging: Free transaction ID in delayed interrupt scenario\n\nIn case of interrupt delay for any reason, slim_do_transfer()\nreturns timeout error but the transaction ID (TID) is not freed.\nThis results into invalid memory access inside\nqcom_slim_ngd_rx_msgq_cb() due to invalid TID.\n\nFix the issue by freeing the TID in slim_do_transfer() before\nreturning timeout error to avoid invalid memory access.\n\nCall trace:\n__memcp","2025-04-01T16:15:21.997+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21914",{"cveId":6370,"releaseId":17,"cycle":18,"description":6371,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6372,"url":6373},"CVE-2025-21899","In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix bad hist from corrupting named_triggers list\n\nThe following commands causes a crash:\n\n ~# cd \u002Fsys\u002Fkernel\u002Ftracing\u002Fevents\u002Frcu\u002Frcu_callback\n ~# echo 'hist:name=bad:keys=common_pid:onmax(bogus).save(common_pid)' > trigger\n bash: echo: write error: Invalid argument\n ~# echo 'hist:name=bad:keys=common_pid' > trigger\n\nBecause the following occurs:\n\nevent_trigger_write() {\n  trigger_process_regex() {\n    event_hist_trigger","2025-04-01T16:15:20.327+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21899",{"cveId":6375,"releaseId":17,"cycle":18,"description":6376,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6377,"url":6378},"CVE-2023-53006","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix oops due to uncleared server->smbd_conn in reconnect\n\nIn smbd_destroy(), clear the server->smbd_conn pointer after freeing the\nsmbd_connection struct that it points to so that reconnection doesn't get\nconfused.","2025-03-27T17:15:49.543+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-53006",{"cveId":6380,"releaseId":17,"cycle":18,"description":6381,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6382,"url":6383},"CVE-2022-49743","In the Linux kernel, the following vulnerability has been resolved:\n\novl: Use \"buf\" flexible array for memcpy() destination\n\nThe \"buf\" flexible array needs to be the memcpy() destination to avoid\nfalse positive run-time warning from the recent FORTIFY_SOURCE\nhardening:\n\n  memcpy: detected field-spanning write (size 93) of single field \"&fh->fb\"\n  at fs\u002Foverlayfs\u002Fexport.c:799 (size 21)","2025-03-27T17:15:38.967+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49743",{"cveId":6380,"releaseId":31,"cycle":32,"description":6381,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6382,"url":6383},{"cveId":6380,"releaseId":25,"cycle":26,"description":6381,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6382,"url":6383},{"cveId":6387,"releaseId":17,"cycle":18,"description":6388,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6389,"url":6390},"CVE-2022-49739","In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Always check inode size of inline inodes\n\nCheck if the inode size of stuffed (inline) inodes is within the allowed\nrange when reading inodes from disk (gfs2_dinode_in()).  This prevents\nus from on-disk corruption.\n\nThe two checks in stuffed_readpage() and gfs2_unstuffer_page() that just\ntruncate inline data to the maximum allowed size don't actually make\nsense, and they can be removed now as well.","2025-03-27T17:15:38.46+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49739",{"cveId":6387,"releaseId":25,"cycle":26,"description":6388,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6389,"url":6390},{"cveId":6387,"releaseId":31,"cycle":32,"description":6388,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6389,"url":6390},{"cveId":6394,"releaseId":25,"cycle":26,"description":6395,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6396,"url":6397},"CVE-2025-21861","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fmigrate_device: don't add folio to be freed to LRU in migrate_device_finalize()\n\nIf migration succeeded, we called\nfolio_migrate_flags()->mem_cgroup_migrate() to migrate the memcg from the\nold to the new folio.  This will set memcg_data of the old folio to 0.\n\nSimilarly, if migration failed, memcg_data of the dst folio is left unset.\n\nIf we call folio_putback_lru() on such folios (memcg_data == 0), we will\nadd the folio to b","2025-03-12T10:15:19.117+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21861",{"cveId":6394,"releaseId":17,"cycle":18,"description":6395,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6396,"url":6397},{"cveId":6400,"releaseId":31,"cycle":32,"description":6401,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":6402,"url":6403},"CVE-2025-21855","In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: Don't reference skb after sending to VIOS\n\nPreviously, after successfully flushing the xmit buffer to VIOS,\nthe tx_bytes stat was incremented by the length of the skb.\n\nIt is invalid to access the skb memory after sending the buffer to\nthe VIOS because, at any point after sending, the VIOS can trigger\nan interrupt to free this memory. A race between reading skb->len\nand freeing the skb is possible (especially during LP","2025-03-12T10:15:18.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21855",{"cveId":6400,"releaseId":17,"cycle":18,"description":6401,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":6402,"url":6403},{"cveId":6400,"releaseId":25,"cycle":26,"description":6401,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":6402,"url":6403},{"cveId":6407,"releaseId":25,"cycle":26,"description":6408,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6409,"url":6410},"CVE-2025-21846","In the Linux kernel, the following vulnerability has been resolved:\n\nacct: perform last write from workqueue\n\nIn [1] it was reported that the acct(2) system call can be used to\ntrigger NULL deref in cases where it is set to write to a file that\ntriggers an internal lookup. This can e.g., happen when pointing acc(2)\nto \u002Fsys\u002Fpower\u002Fresume. At the point the where the write to this file\nhappens the calling task has already exited and called exit_fs(). A\nlookup will thus trigger a NULL-deref when acce","2025-03-12T10:15:16.96+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21846",{"cveId":6407,"releaseId":17,"cycle":18,"description":6408,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6409,"url":6410},{"cveId":6407,"releaseId":31,"cycle":32,"description":6408,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6409,"url":6410},{"cveId":6414,"releaseId":17,"cycle":18,"description":6415,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6416,"url":6417},"CVE-2024-58089","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix double accounting race when btrfs_run_delalloc_range() failed\n\n[BUG]\nWhen running btrfs with block size (4K) smaller than page size (64K,\naarch64), there is a very high chance to crash the kernel at\ngeneric\u002F750, with the following messages:\n(before the call traces, there are 3 extra debug messages added)\n\n  BTRFS warning (device dm-3): read-write for sector size 4096 with page size 65536 is experimental\n  BTRFS info ","2025-03-12T10:15:16.44+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58089",{"cveId":6419,"releaseId":31,"cycle":32,"description":6420,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6421,"url":6422},"CVE-2024-58058","In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: skip dumping tnc tree when zroot is null\n\nClearing slab cache will free all znode in memory and make\nc->zroot.znode = NULL, then dumping tnc tree will access\nc->zroot.znode which cause null pointer dereference.","2025-03-06T16:15:52.037+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58058",{"cveId":6419,"releaseId":25,"cycle":26,"description":6420,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6421,"url":6422},{"cveId":6419,"releaseId":17,"cycle":18,"description":6420,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6421,"url":6422},{"cveId":6426,"releaseId":17,"cycle":18,"description":6427,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6428,"url":6429},"CVE-2024-58053","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix handling of received connection abort\n\nFix the handling of a connection abort that we've received.  Though the\nabort is at the connection level, it needs propagating to the calls on that\nconnection.  Whilst the propagation bit is performed, the calls aren't then\nwoken up to go and process their termination, and as no further input is\nforthcoming, they just hang.\n\nAlso add some tracing for the logging of connection ab","2025-03-06T16:15:51.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58053",{"cveId":6426,"releaseId":25,"cycle":26,"description":6427,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6428,"url":6429},{"cveId":6426,"releaseId":31,"cycle":32,"description":6427,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6428,"url":6429},{"cveId":6433,"releaseId":17,"cycle":18,"description":6434,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6435,"url":6436},"CVE-2022-49733","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC\n\nThere is a small race window at snd_pcm_oss_sync() that is called from\nOSS PCM SNDCTL_DSP_SYNC ioctl; namely the function calls\nsnd_pcm_oss_make_ready() at first, then takes the params_lock mutex\nfor the rest.  When the stream is set up again by another thread\nbetween them, it leads to inconsistency, and may result in unexpected\nresults such as NULL dereference of OSS buffer as a fuz","2025-03-02T15:15:11.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49733",{"cveId":6433,"releaseId":25,"cycle":26,"description":6434,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6435,"url":6436},{"cveId":6433,"releaseId":31,"cycle":32,"description":6434,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6435,"url":6436},{"cveId":6440,"releaseId":25,"cycle":26,"description":6441,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6442,"url":6443},"CVE-2025-21823","In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: Drop unmanaged ELP metric worker\n\nThe ELP worker needs to calculate new metric values for all neighbors\n\"reachable\" over an interface. Some of the used metric sources require\nlocks which might need to sleep. This sleep is incompatible with the RCU\nlist iterator used for the recorded neighbors. The initial approach to work\naround of this problem was to queue another work item per neighbor and then\nrun this in a new c","2025-02-27T20:16:04.793+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21823",{"cveId":6440,"releaseId":31,"cycle":32,"description":6441,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6442,"url":6443},{"cveId":6440,"releaseId":17,"cycle":18,"description":6441,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6442,"url":6443},{"cveId":6447,"releaseId":25,"cycle":26,"description":6448,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6449,"url":6450},"CVE-2025-21814","In the Linux kernel, the following vulnerability has been resolved:\n\nptp: Ensure info->enable callback is always set\n\nThe ioctl and sysfs handlers unconditionally call the ->enable callback.\nNot all drivers implement that callback, leading to NULL dereferences.\nExample of affected drivers: ptp_s390.c, ptp_vclock.c and ptp_mock.c.\n\nInstead use a dummy callback if no better was specified by the driver.","2025-02-27T20:16:03.973+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21814",{"cveId":6447,"releaseId":31,"cycle":32,"description":6448,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6449,"url":6450},{"cveId":6447,"releaseId":17,"cycle":18,"description":6448,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6449,"url":6450},{"cveId":6454,"releaseId":17,"cycle":18,"description":6455,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6456,"url":6457},"CVE-2025-21802","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix oops when unload drivers paralleling\n\nWhen unload hclge driver, it tries to disable sriov first for each\nae_dev node from hnae3_ae_dev_list. If user unloads hns3 driver at\nthe time, because it removes all the ae_dev nodes, and it may cause\noops.\n\nBut we can't simply use hnae3_common_lock for this. Because in the\nprocess flow of pci_disable_sriov(), it will trigger the remove flow\nof VF, which will also take hnae3","2025-02-27T20:16:02.847+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21802",{"cveId":6459,"releaseId":17,"cycle":18,"description":6460,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6461,"url":6462},"CVE-2025-21801","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: Fix missing rtnl lock in suspend\u002Fresume path\n\nFix the suspend\u002Fresume path by ensuring the rtnl lock is held where\nrequired. Calls to ravb_open, ravb_close and wol operations must be\nperformed under the rtnl lock to prevent conflicts with ongoing ndo\noperations.\n\nWithout this fix, the following warning is triggered:\n[   39.032969] =============================\n[   39.032983] WARNING: suspicious RCU usage\n[   39.033019","2025-02-27T20:16:02.753+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21801",{"cveId":6459,"releaseId":31,"cycle":32,"description":6460,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6461,"url":6462},{"cveId":6459,"releaseId":25,"cycle":26,"description":6460,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6461,"url":6462},{"cveId":6466,"releaseId":17,"cycle":18,"description":6467,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6468,"url":6469},"CVE-2025-21796","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: clear acl_access\u002Facl_default after releasing them\n\nIf getting acl_default fails, acl_access and acl_default will be released\nsimultaneously. However, acl_access will still retain a pointer pointing\nto the released posix_acl, which will trigger a WARNING in\nnfs3svc_release_getacl like this:\n\n------------[ cut here ]------------\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 26 PID: 3199 at lib\u002Frefcount.c:28\nrefcount_","2025-02-27T03:15:20.497+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21796",{"cveId":6466,"releaseId":31,"cycle":32,"description":6467,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6468,"url":6469},{"cveId":6466,"releaseId":25,"cycle":26,"description":6467,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6468,"url":6469},{"cveId":6473,"releaseId":17,"cycle":18,"description":6474,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6475,"url":6476},"CVE-2025-21792","In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt\n\nIf an AX25 device is bound to a socket by setting the SO_BINDTODEVICE\nsocket option, a refcount leak will occur in ax25_release().\n\nCommit 9fd75b66b8f6 (\"ax25: Fix refcount leaks caused by ax25_cb_del()\")\nadded decrement of device refcounts in ax25_release(). In order for that\nto work correctly the refcounts must already be incremented when the\ndevice is bound t","2025-02-27T03:15:20.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21792",{"cveId":6473,"releaseId":25,"cycle":26,"description":6474,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6475,"url":6476},{"cveId":6479,"releaseId":25,"cycle":26,"description":6480,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6481,"url":6482},"CVE-2025-21785","In the Linux kernel, the following vulnerability has been resolved:\n\narm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array\n\nThe loop that detects\u002Fpopulates cache information already has a bounds\ncheck on the array size but does not account for cache levels with\nseparate data\u002Finstructions cache. Fix this by incrementing the index\nfor any populated leaf (instead of any populated level).","2025-02-27T03:15:19.35+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21785",{"cveId":6479,"releaseId":17,"cycle":18,"description":6480,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6481,"url":6482},{"cveId":6479,"releaseId":31,"cycle":32,"description":6480,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6481,"url":6482},{"cveId":6486,"releaseId":31,"cycle":32,"description":6487,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6488,"url":6489},"CVE-2025-21780","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()\n\nIt malicious user provides a small pptable through sysfs and then\na bigger pptable, it may cause buffer overflow attack in function\nsmu_sys_set_pp_table().","2025-02-27T03:15:18.827+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21780",{"cveId":6486,"releaseId":25,"cycle":26,"description":6487,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6488,"url":6489},{"cveId":6486,"releaseId":17,"cycle":18,"description":6487,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6488,"url":6489},{"cveId":6493,"releaseId":31,"cycle":32,"description":6494,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6495,"url":6496},"CVE-2025-21772","In the Linux kernel, the following vulnerability has been resolved:\n\npartitions: mac: fix handling of bogus partition table\n\nFix several issues in partition probing:\n\n - The bailout for a bad partoffset must use put_dev_sector(), since the\n   preceding read_part_sector() succeeded.\n - If the partition table claims a silly sector size like 0xfff bytes\n   (which results in partition table entries straddling sector boundaries),\n   bail out instead of accessing out-of-bounds memory.\n - We must not a","2025-02-27T03:15:17.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21772",{"cveId":6493,"releaseId":25,"cycle":26,"description":6494,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6495,"url":6496},{"cveId":6493,"releaseId":17,"cycle":18,"description":6494,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6495,"url":6496},{"cveId":6500,"releaseId":17,"cycle":18,"description":6501,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":6502,"url":6503},"CVE-2025-21766","In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: use RCU protection in __ip_rt_update_pmtu()\n\n__ip_rt_update_pmtu() must use RCU protection to make\nsure the net structure it reads does not disappear.","2025-02-27T03:15:17.273+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21766",{"cveId":6500,"releaseId":25,"cycle":26,"description":6501,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":6502,"url":6503},{"cveId":6506,"releaseId":31,"cycle":32,"description":6507,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6508,"url":6509},"CVE-2025-21765","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: use RCU protection in ip6_default_advmss()\n\nip6_default_advmss() needs rcu protection to make\nsure the net structure it reads does not disappear.","2025-02-27T03:15:17.173+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21765",{"cveId":6506,"releaseId":17,"cycle":18,"description":6507,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6508,"url":6509},{"cveId":6506,"releaseId":25,"cycle":26,"description":6507,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6508,"url":6509},{"cveId":6513,"releaseId":31,"cycle":32,"description":6514,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6515,"url":6516},"CVE-2025-21764","In the Linux kernel, the following vulnerability has been resolved:\n\nndisc: use RCU protection in ndisc_alloc_skb()\n\nndisc_alloc_skb() can be called without RTNL or RCU being held.\n\nAdd RCU protection to avoid possible UAF.","2025-02-27T03:15:17.063+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21764",{"cveId":6513,"releaseId":25,"cycle":26,"description":6514,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6515,"url":6516},{"cveId":6513,"releaseId":17,"cycle":18,"description":6514,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6515,"url":6516},{"cveId":6520,"releaseId":17,"cycle":18,"description":6521,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":6522,"url":6523},"CVE-2025-21762","In the Linux kernel, the following vulnerability has been resolved:\n\narp: use RCU protection in arp_xmit()\n\narp_xmit() can be called without RTNL or RCU protection.\n\nUse RCU protection to avoid potential UAF.","2025-02-27T03:15:16.857+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21762",{"cveId":6520,"releaseId":31,"cycle":32,"description":6521,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":6522,"url":6523},{"cveId":6520,"releaseId":25,"cycle":26,"description":6521,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":6522,"url":6523},{"cveId":6527,"releaseId":17,"cycle":18,"description":6528,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6529,"url":6530},"CVE-2025-21760","In the Linux kernel, the following vulnerability has been resolved:\n\nndisc: extend RCU protection in ndisc_send_skb()\n\nndisc_send_skb() can be called without RTNL or RCU held.\n\nAcquire rcu_read_lock() earlier, so that we can use dev_net_rcu()\nand avoid a potential UAF.","2025-02-27T03:15:16.653+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21760",{"cveId":6527,"releaseId":31,"cycle":32,"description":6528,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6529,"url":6530},{"cveId":6527,"releaseId":25,"cycle":26,"description":6528,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6529,"url":6530},{"cveId":6534,"releaseId":25,"cycle":26,"description":6535,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6536,"url":6537},"CVE-2025-21758","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: add RCU protection to mld_newpack()\n\nmld_newpack() can be called without RTNL or RCU being held.\n\nNote that we no longer can use sock_alloc_send_skb() because\nipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.\n\nInstead use alloc_skb() and charge the net->ipv6.igmp_sk\nsocket under RCU protection.","2025-02-27T03:15:16.45+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21758",{"cveId":6534,"releaseId":17,"cycle":18,"description":6535,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6536,"url":6537},{"cveId":6534,"releaseId":31,"cycle":32,"description":6535,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6536,"url":6537},{"cveId":6541,"releaseId":25,"cycle":26,"description":6542,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6543,"url":6544},"CVE-2025-21738","In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-sff: Ensure that we cannot write outside the allocated buffer\n\nreveliofuzzing reported that a SCSI_IOCTL_SEND_COMMAND ioctl with out_len\nset to 0xd42, SCSI command set to ATA_16 PASS-THROUGH, ATA command set to\nATA_NOP, and protocol set to ATA_PROT_PIO, can cause ata_pio_sector() to\nwrite outside the allocated buffer, overwriting random memory.\n\nWhile a ATA device is supposed to abort a ATA_NOP command, there does s","2025-02-27T03:15:14.427+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21738",{"cveId":6541,"releaseId":31,"cycle":32,"description":6542,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6543,"url":6544},{"cveId":6541,"releaseId":17,"cycle":18,"description":6542,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6543,"url":6544},{"cveId":6548,"releaseId":25,"cycle":26,"description":6549,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6550,"url":6551},"CVE-2025-21735","In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: nci: Add bounds checking in nci_hci_create_pipe()\n\nThe \"pipe\" variable is a u8 which comes from the network.  If it's more\nthan 127, then it results in memory corruption in the caller,\nnci_hci_connect_gate().","2025-02-27T03:15:14.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21735",{"cveId":6548,"releaseId":17,"cycle":18,"description":6549,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6550,"url":6551},{"cveId":6548,"releaseId":31,"cycle":32,"description":6549,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6550,"url":6551},{"cveId":6555,"releaseId":17,"cycle":18,"description":6556,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6557,"url":6558},"CVE-2024-58020","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: Add NULL check in mt_input_configured\n\ndevm_kasprintf() can return a NULL pointer on failure,but this\nreturned value in mt_input_configured() is not checked.\nAdd NULL check in mt_input_configured(), to handle kernel NULL\npointer dereference error.","2025-02-27T03:15:12.997+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58020",{"cveId":6555,"releaseId":25,"cycle":26,"description":6556,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6557,"url":6558},{"cveId":6561,"releaseId":25,"cycle":26,"description":6562,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6563,"url":6564},"CVE-2024-58011","In the Linux kernel, the following vulnerability has been resolved:\n\nplatform\u002Fx86: int3472: Check for adev == NULL\n\nNot all devices have an ACPI companion fwnode, so adev might be NULL. This\ncan e.g. (theoretically) happen when a user manually binds one of\nthe int3472 drivers to another i2c\u002Fplatform device through sysfs.\n\nAdd a check for adev not being set and return -ENODEV in that case to\navoid a possible NULL pointer deref in skl_int3472_get_acpi_buffer().","2025-02-27T03:15:12.087+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58011",{"cveId":6561,"releaseId":17,"cycle":18,"description":6562,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6563,"url":6564},{"cveId":6561,"releaseId":31,"cycle":32,"description":6562,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6563,"url":6564},{"cveId":6568,"releaseId":25,"cycle":26,"description":6569,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6570,"url":6571},"CVE-2024-58010","In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_flat: Fix integer overflow bug on 32 bit systems\n\nMost of these sizes and counts are capped at 256MB so the math doesn't\nresult in an integer overflow.  The \"relocs\" count needs to be checked\nas well.  Otherwise on 32bit systems the calculation of \"full_data\"\ncould be wrong.\n\n\tfull_data = data_len + relocs * sizeof(unsigned long);","2025-02-27T03:15:11.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58010",{"cveId":6568,"releaseId":31,"cycle":32,"description":6569,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6570,"url":6571},{"cveId":6568,"releaseId":17,"cycle":18,"description":6569,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6570,"url":6571},{"cveId":6575,"releaseId":17,"cycle":18,"description":6576,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6577,"url":6578},"CVE-2024-58002","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: uvcvideo: Remove dangling pointers\n\nWhen an async control is written, we copy a pointer to the file handle\nthat started the operation. That pointer will be used when the device is\ndone. Which could be anytime in the future.\n\nIf the user closes that file descriptor, its structure will be freed,\nand there will be one dangling pointer per pending async control, that\nthe driver will try to use.\n\nClean all the dangling pointe","2025-02-27T03:15:11.18+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-58002",{"cveId":6580,"releaseId":31,"cycle":32,"description":6581,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6582,"url":6583},"CVE-2024-54458","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: bsg: Set bsg_queue to NULL after removal\n\nCurrently, this does not cause any issues, but I believe it is necessary to\nset bsg_queue to NULL after removing it to prevent potential use-after-free\n(UAF) access.","2025-02-27T03:15:10.77+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-54458",{"cveId":6580,"releaseId":17,"cycle":18,"description":6581,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6582,"url":6583},{"cveId":6580,"releaseId":25,"cycle":26,"description":6581,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6582,"url":6583},{"cveId":6587,"releaseId":17,"cycle":18,"description":6588,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6589,"url":6590},"CVE-2024-52559","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fmsm\u002Fgem: prevent integer overflow in msm_ioctl_gem_submit()\n\nThe \"submit->cmd[i].size\" and \"submit->cmd[i].offset\" variables are u32\nvalues that come from the user via the submit_lookup_cmds() function.\nThis addition could lead to an integer wrapping bug so use size_add()\nto prevent that.\n\nPatchwork: https:\u002F\u002Fpatchwork.freedesktop.org\u002Fpatch\u002F624696\u002F","2025-02-27T03:15:10.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-52559",{"cveId":6587,"releaseId":31,"cycle":32,"description":6588,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6589,"url":6590},{"cveId":6587,"releaseId":25,"cycle":26,"description":6588,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6589,"url":6590},{"cveId":6594,"releaseId":17,"cycle":18,"description":6595,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6596,"url":6597},"CVE-2025-21731","In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: don't allow reconnect after disconnect\n\nFollowing process can cause nbd_config UAF:\n\n1) grab nbd_config temporarily;\n\n2) nbd_genl_disconnect() flush all recv_work() and release the\ninitial reference:\n\n  nbd_genl_disconnect\n   nbd_disconnect_and_put\n    nbd_disconnect\n     flush_workqueue(nbd->recv_workq)\n    if (test_and_clear_bit(NBD_RT_HAS_CONFIG_REF, ...))\n     nbd_config_put\n     -> due to step 1), reference is still n","2025-02-27T02:15:16.833+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21731",{"cveId":6594,"releaseId":25,"cycle":26,"description":6595,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6596,"url":6597},{"cveId":6600,"releaseId":25,"cycle":26,"description":6601,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6602,"url":6603},"CVE-2025-21718","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rose: fix timer races against user threads\n\nRose timers only acquire the socket spinlock, without\nchecking if the socket is owned by one user thread.\n\nAdd a check and rearm the timers if needed.\n\nBUG: KASAN: slab-use-after-free in rose_timer_expiry+0x31d\u002F0x360 net\u002Frose\u002Frose_timer.c:174\nRead of size 2 at addr ffff88802f09b82a by task swapper\u002F0\u002F0\n\nCPU: 0 UID: 0 PID: 0 Comm: swapper\u002F0 Not tainted 6.13.0-rc5-syzkaller-00172-gd","2025-02-27T02:15:15.473+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21718",{"cveId":6600,"releaseId":17,"cycle":18,"description":6601,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6602,"url":6603},{"cveId":6600,"releaseId":31,"cycle":32,"description":6601,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6602,"url":6603},{"cveId":6607,"releaseId":17,"cycle":18,"description":6608,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6609,"url":6610},"CVE-2025-21712","In the Linux kernel, the following vulnerability has been resolved:\n\nmd\u002Fmd-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime\n\nAfter commit ec6bb299c7c3 (\"md\u002Fmd-bitmap: add 'sync_size' into struct\nmd_bitmap_stats\"), following panic is reported:\n\nOops: general protection fault, probably for non-canonical address\nRIP: 0010:bitmap_get_stats+0x2b\u002F0xa0\nCall Trace:\n \u003CTASK>\n md_seq_show+0x2d2\u002F0x5b0\n seq_read_iter+0x2b9\u002F0x470\n seq_read+0x12f\u002F0x180\n proc_reg_read+0x57\u002F0xb0\n vfs_read+0xf6\u002F0x380\n ","2025-02-27T02:15:14.863+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21712",{"cveId":6607,"releaseId":25,"cycle":26,"description":6608,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6609,"url":6610},{"cveId":6607,"releaseId":31,"cycle":32,"description":6608,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6609,"url":6610},{"cveId":6614,"releaseId":25,"cycle":26,"description":6615,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6616,"url":6617},"CVE-2024-57996","In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: sch_sfq: don't allow 1 packet limit\n\nThe current implementation does not work correctly with a limit of\n1. iproute2 actually checks for this and this patch adds the check in\nkernel as well.\n\nThis fixes the following syzkaller reported crash:\n\nUBSAN: array-index-out-of-bounds in net\u002Fsched\u002Fsch_sfq.c:210:6\nindex 65535 is out of range for type 'struct sfq_head[128]'\nCPU: 0 PID: 2569 Comm: syz-executor101 Not tainted 5.10","2025-02-27T02:15:13.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57996",{"cveId":6614,"releaseId":17,"cycle":18,"description":6615,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6616,"url":6617},{"cveId":6614,"releaseId":31,"cycle":32,"description":6615,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6616,"url":6617},{"cveId":6621,"releaseId":25,"cycle":26,"description":6622,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6623,"url":6624},"CVE-2024-57982","In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: state: fix out-of-bounds read during lookup\n\nlookup and resize can run in parallel.\n\nThe xfrm_state_hash_generation seqlock ensures a retry, but the hash\nfunctions can observe a hmask value that is too large for the new hlist\narray.\n\nrehash does:\n  rcu_assign_pointer(net->xfrm.state_bydst, ndst) [..]\n  net->xfrm.state_hmask = nhashmask;\n\nWhile state lookup does:\n  h = xfrm_dst_hash(net, daddr, saddr, tmpl->reqid, encap_fa","2025-02-27T02:15:11.397+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57982",{"cveId":6621,"releaseId":17,"cycle":18,"description":6622,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6623,"url":6624},{"cveId":6621,"releaseId":31,"cycle":32,"description":6622,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6623,"url":6624},{"cveId":6628,"releaseId":31,"cycle":32,"description":6629,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6630,"url":6631},"CVE-2024-57979","In the Linux kernel, the following vulnerability has been resolved:\n\npps: Fix a use-after-free\n\nOn a board running ntpd and gpsd, I'm seeing a consistent use-after-free\nin sys_exit() from gpsd when rebooting:\n\n    pps pps1: removed\n    ------------[ cut here ]------------\n    kobject: '(null)' (00000000db4bec24): is not initialized, yet kobject_put() is being called.\n    WARNING: CPU: 2 PID: 440 at lib\u002Fkobject.c:734 kobject_put+0x120\u002F0x150\n    CPU: 2 UID: 299 PID: 440 Comm: gpsd Not tainted 6.11","2025-02-27T02:15:11.087+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57979",{"cveId":6628,"releaseId":17,"cycle":18,"description":6629,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6630,"url":6631},{"cveId":6628,"releaseId":25,"cycle":26,"description":6629,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6630,"url":6631},{"cveId":6635,"releaseId":25,"cycle":26,"description":6636,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6637,"url":6638},"CVE-2024-57977","In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: fix soft lockup in the OOM process\n\nA soft lockup issue was found in the product with about 56,000 tasks were\nin the OOM cgroup, it was traversing them when the soft lockup was\ntriggered.\n\nwatchdog: BUG: soft lockup - CPU#2 stuck for 23s! [VM Thread:1503066]\nCPU: 2 PID: 1503066 Comm: VM Thread Kdump: loaded Tainted: G\nHardware name: Huawei Cloud OpenStack Nova, BIOS\nRIP: 0010:console_unlock+0x343\u002F0x540\nRSP: 0000:ffffb751","2025-02-27T02:15:10.89+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57977",{"cveId":6635,"releaseId":17,"cycle":18,"description":6636,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6637,"url":6638},{"cveId":6635,"releaseId":31,"cycle":32,"description":6636,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6637,"url":6638},{"cveId":6642,"releaseId":17,"cycle":18,"description":6643,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6644,"url":6645},"CVE-2024-57976","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do proper folio cleanup when cow_file_range() failed\n\n[BUG]\nWhen testing with COW fixup marked as BUG_ON() (this is involved with the\nnew pin_user_pages*() change, which should not result new out-of-band\ndirty pages), I hit a crash triggered by the BUG_ON() from hitting COW\nfixup path.\n\nThis BUG_ON() happens just after a failed btrfs_run_delalloc_range():\n\n  BTRFS error (device dm-2): failed to run delalloc range, root 3","2025-02-27T02:15:10.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57976",{"cveId":6642,"releaseId":25,"cycle":26,"description":6643,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6644,"url":6645},{"cveId":6642,"releaseId":31,"cycle":32,"description":6643,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6644,"url":6645},{"cveId":6649,"releaseId":17,"cycle":18,"description":6650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6651,"url":6652},"CVE-2024-57975","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do proper folio cleanup when run_delalloc_nocow() failed\n\n[BUG]\nWith CONFIG_DEBUG_VM set, test case generic\u002F476 has some chance to crash\nwith the following VM_BUG_ON_FOLIO():\n\n  BTRFS error (device dm-3): cow_file_range failed, start 1146880 end 1253375 len 106496 ret -28\n  BTRFS error (device dm-3): run_delalloc_nocow failed, start 1146880 end 1253375 len 106496 ret -28\n  page: refcount:4 mapcount:0 mapping:000000005927","2025-02-27T02:15:10.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57975",{"cveId":6649,"releaseId":25,"cycle":26,"description":6650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6651,"url":6652},{"cveId":6649,"releaseId":31,"cycle":32,"description":6650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6651,"url":6652},{"cveId":6656,"releaseId":31,"cycle":32,"description":6657,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6658,"url":6659},"CVE-2024-57973","In the Linux kernel, the following vulnerability has been resolved:\n\nrdma\u002Fcxgb4: Prevent potential integer overflow on 32bit\n\nThe \"gl->tot_len\" variable is controlled by the user.  It comes from\nprocess_responses().  On 32bit systems, the \"gl->tot_len + sizeof(struct\ncpl_pass_accept_req) + sizeof(struct rss_header)\" addition could have an\ninteger wrapping bug.  Use size_add() to prevent this.","2025-02-27T02:15:10.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57973",{"cveId":6656,"releaseId":17,"cycle":18,"description":6657,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6658,"url":6659},{"cveId":6656,"releaseId":25,"cycle":26,"description":6657,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6658,"url":6659},{"cveId":6663,"releaseId":31,"cycle":32,"description":6664,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6665,"url":6666},"CVE-2022-49725","In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix call trace in setup_tx_descriptors\n\nAfter PF reset and ethtool -t there was call trace in dmesg\nsometimes leading to panic. When there was some time, around 5\nseconds, between reset and test there were no errors.\n\nProblem was that pf reset calls i40e_vsi_close in prep_for_reset\nand ethtool -t calls i40e_vsi_close in diag_test. If there was not\nenough time between those commands the second i40e_vsi_close starts\nbefore ","2025-02-26T07:01:48.167+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49725",{"cveId":6663,"releaseId":17,"cycle":18,"description":6664,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6665,"url":6666},{"cveId":6663,"releaseId":25,"cycle":26,"description":6664,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6665,"url":6666},{"cveId":6670,"releaseId":17,"cycle":18,"description":6671,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6672,"url":6673},"CVE-2022-49672","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tun: unlink NAPI from device on destruction\n\nSyzbot found a race between tun file and device destruction.\nNAPIs live in struct tun_file which can get destroyed before\nthe netdev so we have to del them explicitly. The current\ncode is missing deleting the NAPI if the queue was detached\nfirst.","2025-02-26T07:01:42.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49672",{"cveId":6675,"releaseId":17,"cycle":18,"description":6676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6677,"url":6678},"CVE-2022-49581","In the Linux kernel, the following vulnerability has been resolved:\n\nbe2net: Fix buffer overflow in be_get_module_eeprom\n\nbe_cmd_read_port_transceiver_data assumes that it is given a buffer that\nis at least PAGE_DATA_LEN long, or twice that if the module supports SFF\n8472. However, this is not always the case.\n\nFix this by passing the desired offset and length to\nbe_cmd_read_port_transceiver_data so that we only copy the bytes once.","2025-02-26T07:01:33.703+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49581",{"cveId":6675,"releaseId":25,"cycle":26,"description":6676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6677,"url":6678},{"cveId":6675,"releaseId":31,"cycle":32,"description":6676,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6677,"url":6678},{"cveId":6682,"releaseId":25,"cycle":26,"description":6683,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6684,"url":6685},"CVE-2022-49564","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - add param check for DH\n\nReject requests with a source buffer that is bigger than the size of the\nkey. This is to prevent a possible integer underflow that might happen\nwhen copying the source scatterlist into a linear buffer.","2025-02-26T07:01:32.15+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49564",{"cveId":6682,"releaseId":17,"cycle":18,"description":6683,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6684,"url":6685},{"cveId":6682,"releaseId":31,"cycle":32,"description":6683,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6684,"url":6685},{"cveId":6689,"releaseId":31,"cycle":32,"description":6690,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6691,"url":6692},"CVE-2022-49563","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - add param check for RSA\n\nReject requests with a source buffer that is bigger than the size of the\nkey. This is to prevent a possible integer underflow that might happen\nwhen copying the source scatterlist into a linear buffer.","2025-02-26T07:01:32.06+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49563",{"cveId":6689,"releaseId":17,"cycle":18,"description":6690,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6691,"url":6692},{"cveId":6689,"releaseId":25,"cycle":26,"description":6690,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6691,"url":6692},{"cveId":6696,"releaseId":25,"cycle":26,"description":6697,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6698,"url":6699},"CVE-2022-49561","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: re-fetch conntrack after insertion\n\nIn case the conntrack is clashing, insertion can free skb->_nfct and\nset skb->_nfct to the already-confirmed entry.\n\nThis wasn't found before because the conntrack entry and the extension\nspace used to free'd after an rcu grace period, plus the race needs\nevents enabled to trigger.","2025-02-26T07:01:31.877+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49561",{"cveId":6696,"releaseId":31,"cycle":32,"description":6697,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6698,"url":6699},{"cveId":6696,"releaseId":17,"cycle":18,"description":6697,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6698,"url":6699},{"cveId":6703,"releaseId":25,"cycle":26,"description":6704,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6705,"url":6706},"CVE-2022-49555","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_qca: Use del_timer_sync() before freeing\n\nWhile looking at a crash report on a timer list being corrupted, which\nusually happens when a timer is freed while still active. This is\ncommonly triggered by code calling del_timer() instead of\ndel_timer_sync() just before freeing.\n\nOne possible culprit is the hci_qca driver, which does exactly that.\n\nEric mentioned that wake_retrans_timer could be rearmed via the work\nq","2025-02-26T07:01:31.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49555",{"cveId":6703,"releaseId":31,"cycle":32,"description":6704,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6705,"url":6706},{"cveId":6703,"releaseId":17,"cycle":18,"description":6704,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6705,"url":6706},{"cveId":6710,"releaseId":25,"cycle":26,"description":6711,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6712,"url":6713},"CVE-2022-49554","In the Linux kernel, the following vulnerability has been resolved:\n\nzsmalloc: fix races between asynchronous zspage free and page migration\n\nThe asynchronous zspage free worker tries to lock a zspage's entire page\nlist without defending against page migration.  Since pages which haven't\nyet been locked can concurrently migrate off the zspage page list while\nlock_zspage() churns away, lock_zspage() can suffer from a few different\nlethal races.\n\nIt can lock a page which no longer belongs to the z","2025-02-26T07:01:31.223+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49554",{"cveId":6710,"releaseId":17,"cycle":18,"description":6711,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6712,"url":6713},{"cveId":6716,"releaseId":31,"cycle":32,"description":6717,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6718,"url":6719},"CVE-2022-49545","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Cancel pending work at closing a MIDI substream\n\nAt closing a USB MIDI output substream, there might be still a pending\nwork, which would eventually access the rawmidi runtime object that is\nbeing released.  For fixing the race, make sure to cancel the pending\nwork at closing.","2025-02-26T07:01:30.41+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49545",{"cveId":6716,"releaseId":25,"cycle":26,"description":6717,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6718,"url":6719},{"cveId":6716,"releaseId":17,"cycle":18,"description":6717,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6718,"url":6719},{"cveId":6723,"releaseId":31,"cycle":32,"description":6724,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6725,"url":6726},"CVE-2022-49535","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix null pointer dereference after failing to issue FLOGI and PLOGI\n\nIf lpfc_issue_els_flogi() fails and returns non-zero status, the node\nreference count is decremented to trigger the release of the nodelist\nstructure. However, if there is a prior registration or dev-loss-evt work\npending, the node may be released prematurely.  When dev-loss-evt\ncompletes, the released node is referenced causing a use-after-free nu","2025-02-26T07:01:29.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49535",{"cveId":6723,"releaseId":17,"cycle":18,"description":6724,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6725,"url":6726},{"cveId":6723,"releaseId":25,"cycle":26,"description":6724,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6725,"url":6726},{"cveId":6730,"releaseId":17,"cycle":18,"description":6731,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6732,"url":6733},"CVE-2022-49531","In the Linux kernel, the following vulnerability has been resolved:\n\nloop: implement ->free_disk\n\nEnsure that the lo_device which is stored in the gendisk private\ndata is valid until the gendisk is freed.  Currently the loop driver\nuses a lot of effort to make sure a device is not freed when it is\nstill in use, but to to fix a potential deadlock this will be relaxed\na bit soon.","2025-02-26T07:01:29.067+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49531",{"cveId":6730,"releaseId":25,"cycle":26,"description":6731,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6732,"url":6733},{"cveId":6730,"releaseId":31,"cycle":32,"description":6731,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6732,"url":6733},{"cveId":6737,"releaseId":31,"cycle":32,"description":6738,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6739,"url":6740},"CVE-2022-49519","In the Linux kernel, the following vulnerability has been resolved:\n\nath10k: skip ath10k_halt during suspend for driver state RESTARTING\n\nDouble free crash is observed when FW recovery(caused by wmi\ntimeout\u002Fcrash) is followed by immediate suspend event. The FW recovery\nis triggered by ath10k_core_restart() which calls driver clean up via\nath10k_halt(). When the suspend event occurs between the FW recovery,\nthe restart worker thread is put into frozen state until suspend completes.\nThe suspend ev","2025-02-26T07:01:27.923+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49519",{"cveId":6737,"releaseId":17,"cycle":18,"description":6738,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6739,"url":6740},{"cveId":6737,"releaseId":25,"cycle":26,"description":6738,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6739,"url":6740},{"cveId":6744,"releaseId":25,"cycle":26,"description":6745,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6746,"url":6747},"CVE-2022-49471","In the Linux kernel, the following vulnerability has been resolved:\n\nrtw89: cfo: check mac_id to avoid out-of-bounds\n\nSomehow, hardware reports incorrect mac_id and pollute memory. Check index\nbefore we access the array.\n\n  UBSAN: array-index-out-of-bounds in rtw89\u002Fphy.c:2517:23\n  index 188 is out of range for type 's32 [64]'\n  CPU: 1 PID: 51550 Comm: irq\u002F35-rtw89_pc Tainted: G           OE\n  Call Trace:\n   \u003CIRQ>\n   show_stack+0x52\u002F0x58\n   dump_stack_lvl+0x4c\u002F0x63\n   dump_stack+0x10\u002F0x12\n   ubsa","2025-02-26T07:01:23.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49471",{"cveId":6744,"releaseId":31,"cycle":32,"description":6745,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6746,"url":6747},{"cveId":6744,"releaseId":17,"cycle":18,"description":6745,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6746,"url":6747},{"cveId":6751,"releaseId":17,"cycle":18,"description":6752,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":6753,"url":6754},"CVE-2022-49451","In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix list protocols enumeration in the base protocol\n\nWhile enumerating protocols implemented by the SCMI platform using\nBASE_DISCOVER_LIST_PROTOCOLS, the number of returned protocols is\ncurrently validated in an improper way since the check employs a sum\nbetween unsigned integers that could overflow and cause the check itself\nto be silently bypassed if the returned value 'loop_num_ret' is big\nenough.\n\nFix th","2025-02-26T07:01:21.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49451",{"cveId":6756,"releaseId":25,"cycle":26,"description":6757,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6758,"url":6759},"CVE-2022-49425","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix dereference of stale list iterator after loop body\n\nThe list iterator variable will be a bogus pointer if no break was hit.\nDereferencing it (cur->page in this case) could load an out-of-bounds\u002Fundefined\nvalue making it unsafe to use that in the comparision to determine if the\nspecific element was found.\n\nSince 'cur->page' *can* be out-ouf-bounds it cannot be guaranteed that\nby chance (or intention of an attacker) it ","2025-02-26T07:01:18.977+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49425",{"cveId":6756,"releaseId":17,"cycle":18,"description":6757,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6758,"url":6759},{"cveId":6762,"releaseId":31,"cycle":32,"description":6763,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6764,"url":6765},"CVE-2022-49416","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix use-after-free in chanctx code\n\nIn ieee80211_vif_use_reserved_context(), when we have an\nold context and the new context's replace_state is set to\nIEEE80211_CHANCTX_REPLACE_NONE, we free the old context\nin ieee80211_vif_use_reserved_reassign(). Therefore, we\ncannot check the old_ctx anymore, so we should set it to\nNULL after this point.\n\nHowever, since the new_ctx replace state is clearly not\nIEEE80211_CHANC","2025-02-26T07:01:18.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49416",{"cveId":6762,"releaseId":17,"cycle":18,"description":6763,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6764,"url":6765},{"cveId":6762,"releaseId":25,"cycle":26,"description":6763,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6764,"url":6765},{"cveId":6769,"releaseId":31,"cycle":32,"description":6770,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6771,"url":6772},"CVE-2022-49407","In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: fix plock invalid read\n\nThis patch fixes an invalid read showed by KASAN. A unlock will allocate a\n\"struct plock_op\" and a followed send_op() will append it to a global\nsend_list data structure. In some cases a followed dev_read() moves it\nto recv_list and dev_write() will cast it to \"struct plock_xop\" and access\nfields which are only available in those structures. At this point an\ninvalid read happens by accessing those f","2025-02-26T07:01:17.217+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49407",{"cveId":6769,"releaseId":25,"cycle":26,"description":6770,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6771,"url":6772},{"cveId":6769,"releaseId":17,"cycle":18,"description":6770,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6771,"url":6772},{"cveId":6776,"releaseId":25,"cycle":26,"description":6777,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6778,"url":6779},"CVE-2022-49363","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on block address in f2fs_do_zero_range()\n\nAs Yanming reported in bugzilla:\n\nhttps:\u002F\u002Fbugzilla.kernel.org\u002Fshow_bug.cgi?id=215894\n\nI have encountered a bug in F2FS file system in kernel v5.17.\n\nI have uploaded the system call sequence as case.c, and a fuzzed image can\nbe found in google net disk\n\nThe kernel should enable CONFIG_KASAN=y and CONFIG_KASAN_INLINE=y. You can\nreproduce the bug by running the","2025-02-26T07:01:12.953+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49363",{"cveId":6776,"releaseId":31,"cycle":32,"description":6777,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6778,"url":6779},{"cveId":6776,"releaseId":17,"cycle":18,"description":6777,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6778,"url":6779},{"cveId":6783,"releaseId":17,"cycle":18,"description":6784,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6785,"url":6786},"CVE-2022-49349","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix use-after-free in ext4_rename_dir_prepare\n\nWe got issue as follows:\nEXT4-fs (loop0): mounted filesystem without journal. Opts: ,errors=continue\next4_get_first_dir_block: bh->b_data=0xffff88810bee6000 len=34478\next4_get_first_dir_block: *parent_de=0xffff88810beee6ae bh->b_data=0xffff88810bee6000\next4_rename_dir_prepare: [1] parent_de=0xffff88810beee6ae\n==================================================================\n","2025-02-26T07:01:11.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49349",{"cveId":6783,"releaseId":25,"cycle":26,"description":6784,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6785,"url":6786},{"cveId":6783,"releaseId":31,"cycle":32,"description":6784,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6785,"url":6786},{"cveId":6790,"releaseId":31,"cycle":32,"description":6791,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6792,"url":6793},"CVE-2022-49343","In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid cycles in directory h-tree\n\nA maliciously corrupted filesystem can contain cycles in the h-tree\nstored inside a directory. That can easily lead to the kernel corrupting\ntree nodes that were already verified under its hands while doing a node\nsplit and consequently accessing unallocated memory. Fix the problem by\nverifying traversed block numbers are unique.","2025-02-26T07:01:11.04+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49343",{"cveId":6790,"releaseId":17,"cycle":18,"description":6791,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6792,"url":6793},{"cveId":6790,"releaseId":25,"cycle":26,"description":6791,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6792,"url":6793},{"cveId":6797,"releaseId":17,"cycle":18,"description":6798,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":6799,"url":6800},"CVE-2022-49340","In the Linux kernel, the following vulnerability has been resolved:\n\nip_gre: test csum_start instead of transport header\n\nGRE with TUNNEL_CSUM will apply local checksum offload on\nCHECKSUM_PARTIAL packets.\n\nipgre_xmit must validate csum_start after an optional skb_pull,\nelse lco_csum may trigger an overflow. The original check was\n\n\tif (csum && skb_checksum_start(skb) \u003C skb->data)\n\t\treturn -EINVAL;\n\nThis had false positives when skb_checksum_start is undefined:\nwhen ip_summed is not CHECKSUM_PAR","2025-02-26T07:01:10.753+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49340",{"cveId":6802,"releaseId":31,"cycle":32,"description":6803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6804,"url":6805},"CVE-2022-49337","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: dlmfs: fix error handling of user_dlm_destroy_lock\n\nWhen user_dlm_destroy_lock failed, it didn't clean up the flags it set\nbefore exit.  For USER_LOCK_IN_TEARDOWN, if this function fails because of\nlock is still in used, next time when unlink invokes this function, it\nwill return succeed, and then unlink will remove inode and dentry if lock\nis not in used(file closed), but the dlm lock is still linked in dlm lock\nresourc","2025-02-26T07:01:10.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49337",{"cveId":6802,"releaseId":25,"cycle":26,"description":6803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6804,"url":6805},{"cveId":6802,"releaseId":17,"cycle":18,"description":6803,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6804,"url":6805},{"cveId":6809,"releaseId":25,"cycle":26,"description":6810,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6811,"url":6812},"CVE-2022-49336","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fetnaviv: check for reaped mapping in etnaviv_iommu_unmap_gem\n\nWhen the mapping is already reaped the unmap must be a no-op, as we\nwould otherwise try to remove the mapping twice, corrupting the involved\ndata structures.","2025-02-26T07:01:10.37+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49336",{"cveId":6809,"releaseId":31,"cycle":32,"description":6810,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6811,"url":6812},{"cveId":6809,"releaseId":17,"cycle":18,"description":6810,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6811,"url":6812},{"cveId":6816,"releaseId":17,"cycle":18,"description":6817,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6818,"url":6819},"CVE-2022-49330","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix tcp_mtup_probe_success vs wrong snd_cwnd\n\nsyzbot got a new report [1] finally pointing to a very old bug,\nadded in initial support for MTU probing.\n\ntcp_mtu_probe() has checks about starting an MTU probe if\ntcp_snd_cwnd(tp) >= 11.\n\nBut nothing prevents tcp_snd_cwnd(tp) to be reduced later\nand before the MTU probe succeeds.\n\nThis bug would lead to potential zero-divides.\n\nDebugging added in commit 40570375356c (\"tcp: ad","2025-02-26T07:01:09.797+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49330",{"cveId":6816,"releaseId":31,"cycle":32,"description":6817,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6818,"url":6819},{"cveId":6816,"releaseId":25,"cycle":26,"description":6817,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6818,"url":6819},{"cveId":6823,"releaseId":31,"cycle":32,"description":6824,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6825,"url":6826},"CVE-2022-49328","In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: fix use-after-free by removing a non-RCU wcid pointer\n\nFixes an issue caught by KASAN about use-after-free in mt76_txq_schedule\nby protecting mtxq->wcid with rcu_lock between mt76_txq_schedule and\nsta_info_[alloc, free].\n\n[18853.876689] ==================================================================\n[18853.876751] BUG: KASAN: use-after-free in mt76_txq_schedule+0x204\u002F0xaf8 [mt76]\n[18853.876773] Read of size 8 at addr f","2025-02-26T07:01:09.61+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49328",{"cveId":6823,"releaseId":25,"cycle":26,"description":6824,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6825,"url":6826},{"cveId":6823,"releaseId":17,"cycle":18,"description":6824,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6825,"url":6826},{"cveId":6830,"releaseId":17,"cycle":18,"description":6831,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6832,"url":6833},"CVE-2022-49325","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: add accessors to read\u002Fset tp->snd_cwnd\n\nWe had various bugs over the years with code\nbreaking the assumption that tp->snd_cwnd is greater\nthan zero.\n\nLately, syzbot reported the WARN_ON_ONCE(!tp->prior_cwnd) added\nin commit 8b8a321ff72c (\"tcp: fix zero cwnd in tcp_cwnd_reduction\")\ncan trigger, and without a repro we would have to spend\nconsiderable time finding the bug.\n\nInstead of complaining too late, we want to catch wh","2025-02-26T07:01:09.323+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49325",{"cveId":6830,"releaseId":25,"cycle":26,"description":6831,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6832,"url":6833},{"cveId":6830,"releaseId":31,"cycle":32,"description":6831,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6832,"url":6833},{"cveId":6837,"releaseId":25,"cycle":26,"description":6838,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6839,"url":6840},"CVE-2022-49321","In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: treat all calls not a bcall when bc_serv is NULL\n\nWhen a rdma server returns a fault format reply, nfs v3 client may\ntreats it as a bcall when bc service is not exist.\n\nThe debug message at rpcrdma_bc_receive_call are,\n\n[56579.837169] RPC:       rpcrdma_bc_receive_call: callback XID\n00000001, length=20\n[56579.837174] RPC:       rpcrdma_bc_receive_call: 00 00 00 01 00 00 00\n00 00 00 00 00 00 00 00 00 00 00 00 04\n\nAfter","2025-02-26T07:01:08.933+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49321",{"cveId":6837,"releaseId":17,"cycle":18,"description":6838,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6839,"url":6840},{"cveId":6837,"releaseId":31,"cycle":32,"description":6838,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6839,"url":6840},{"cveId":6844,"releaseId":31,"cycle":32,"description":6845,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6846,"url":6847},"CVE-2022-49295","In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: call genl_unregister_family() first in nbd_cleanup()\n\nOtherwise there may be race between module removal and the handling of\nnetlink command, which can lead to the oops as shown below:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000098\n  Oops: 0002 [#1] SMP PTI\n  CPU: 1 PID: 31299 Comm: nbd-client Tainted: G            E     5.14.0-rc4\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)\n  RIP: 0010:down","2025-02-26T07:01:06.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49295",{"cveId":6844,"releaseId":17,"cycle":18,"description":6845,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6846,"url":6847},{"cveId":6844,"releaseId":25,"cycle":26,"description":6845,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6846,"url":6847},{"cveId":6851,"releaseId":25,"cycle":26,"description":6852,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6853,"url":6854},"CVE-2022-49292","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: oss: Fix PCM OSS buffer allocation overflow\n\nWe've got syzbot reports hitting INT_MAX overflow at vmalloc()\nallocation that is called from snd_pcm_plug_alloc().  Although we\napply the restrictions to input parameters, it's based only on the\nhw_params of the underlying PCM device.  Since the PCM OSS layer\nallocates a temporary buffer for the data conversion, the size may\nbecome unexpectedly large when more channels or high","2025-02-26T07:01:06.047+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49292",{"cveId":6851,"releaseId":31,"cycle":32,"description":6852,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6853,"url":6854},{"cveId":6851,"releaseId":17,"cycle":18,"description":6852,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6853,"url":6854},{"cveId":6858,"releaseId":17,"cycle":18,"description":6859,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6860,"url":6861},"CVE-2022-49289","In the Linux kernel, the following vulnerability has been resolved:\n\nuaccess: fix integer overflow on access_ok()\n\nThree architectures check the end of a user access against the\naddress limit without taking a possible overflow into account.\nPassing a negative length or another overflow in here returns\nsuccess when it should not.\n\nUse the most common correct implementation here, which optimizes\nfor a constant 'size' argument, and turns the common case into a\nsingle comparison.","2025-02-26T07:01:05.757+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49289",{"cveId":6858,"releaseId":25,"cycle":26,"description":6859,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6860,"url":6861},{"cveId":6858,"releaseId":31,"cycle":32,"description":6859,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6860,"url":6861},{"cveId":6865,"releaseId":17,"cycle":18,"description":6866,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6867,"url":6868},"CVE-2022-49287","In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: fix reference counting for struct tpm_chip\n\nThe following sequence of operations results in a refcount warning:\n\n1. Open device \u002Fdev\u002Ftpmrm.\n2. Remove module tpm_tis_spi.\n3. Write a TPM command to the file descriptor opened at step 1.\n\n------------[ cut here ]------------\nWARNING: CPU: 3 PID: 1161 at lib\u002Frefcount.c:25 kobject_get+0xa0\u002F0xa4\nrefcount_t: addition on 0; use-after-free.\nModules linked in: tpm_tis_spi tpm_tis_cor","2025-02-26T07:01:05.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49287",{"cveId":6865,"releaseId":25,"cycle":26,"description":6866,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":6867,"url":6868},{"cveId":6871,"releaseId":31,"cycle":32,"description":6872,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6873,"url":6874},"CVE-2022-49280","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: prevent underflow in nfssvc_decode_writeargs()\n\nSmatch complains:\n\n\tfs\u002Fnfsd\u002Fnfsxdr.c:341 nfssvc_decode_writeargs()\n\twarn: no lower bound on 'args->len'\n\nChange the type to unsigned to prevent this issue.","2025-02-26T07:01:04.84+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49280",{"cveId":6871,"releaseId":17,"cycle":18,"description":6872,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6873,"url":6874},{"cveId":6871,"releaseId":25,"cycle":26,"description":6872,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6873,"url":6874},{"cveId":6878,"releaseId":25,"cycle":26,"description":6879,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":6880,"url":6881},"CVE-2022-49279","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: prevent integer overflow on 32 bit systems\n\nOn a 32 bit system, the \"len * sizeof(*p)\" operation can have an\ninteger overflow.","2025-02-26T07:01:04.75+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49279",{"cveId":6878,"releaseId":31,"cycle":32,"description":6879,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":6880,"url":6881},{"cveId":6878,"releaseId":17,"cycle":18,"description":6879,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":6880,"url":6881},{"cveId":6885,"releaseId":17,"cycle":18,"description":6886,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6887,"url":6888},"CVE-2022-49264","In the Linux kernel, the following vulnerability has been resolved:\n\nexec: Force single empty string when argv is empty\n\nQuoting[1] Ariadne Conill:\n\n\"In several other operating systems, it is a hard requirement that the\nsecond argument to execve(2) be the name of a program, thus prohibiting\na scenario where argc \u003C 1. POSIX 2017 also recommends this behaviour,\nbut it is not an explicit requirement[2]:\n\n    The argument arg0 should point to a filename string that is\n    associated with the process","2025-02-26T07:01:03.337+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49264",{"cveId":6885,"releaseId":25,"cycle":26,"description":6886,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6887,"url":6888},{"cveId":6885,"releaseId":31,"cycle":32,"description":6886,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6887,"url":6888},{"cveId":6892,"releaseId":25,"cycle":26,"description":6893,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6894,"url":6895},"CVE-2022-49194","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmgenet: Use stronger register read\u002Fwrites to assure ordering\n\nGCC12 appears to be much smarter about its dependency tracking and is\naware that the relaxed variants are just normal loads and stores and\nthis is causing problems like:\n\n[  210.074549] ------------[ cut here ]------------\n[  210.079223] NETDEV WATCHDOG: enabcm6e4ei0 (bcmgenet): transmit queue 1 timed out\n[  210.086717] WARNING: CPU: 1 PID: 0 at net\u002Fsched\u002Fsch_","2025-02-26T07:00:56.483+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49194",{"cveId":6892,"releaseId":17,"cycle":18,"description":6893,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6894,"url":6895},{"cveId":6898,"releaseId":17,"cycle":18,"description":6899,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6900,"url":6901},"CVE-2022-49178","In the Linux kernel, the following vulnerability has been resolved:\n\nmemstick\u002Fmspro_block: fix handling of read-only devices\n\nUse set_disk_ro to propagate the read-only state to the block layer\ninstead of checking for it in ->open and leaking a reference in case\nof a read-only device.","2025-02-26T07:00:54.947+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49178",{"cveId":6898,"releaseId":25,"cycle":26,"description":6899,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6900,"url":6901},{"cveId":6898,"releaseId":31,"cycle":32,"description":6899,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6900,"url":6901},{"cveId":6905,"releaseId":25,"cycle":26,"description":6906,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6907,"url":6908},"CVE-2022-49174","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix ext4_mb_mark_bb() with flex_bg with fast_commit\n\nIn case of flex_bg feature (which is by default enabled), extents for\nany given inode might span across blocks from two different block group.\next4_mb_mark_bb() only reads the buffer_head of block bitmap once for the\nstarting block group, but it fails to read it again when the extent length\nboundary overflows to another block group. Then in this below loop it\naccesses m","2025-02-26T07:00:54.503+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49174",{"cveId":6905,"releaseId":31,"cycle":32,"description":6906,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6907,"url":6908},{"cveId":6905,"releaseId":17,"cycle":18,"description":6906,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6907,"url":6908},{"cveId":6912,"releaseId":25,"cycle":26,"description":6913,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6914,"url":6915},"CVE-2022-49172","In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Fix non-access data TLB cache flush faults\n\nWhen a page is not present, we get non-access data TLB faults from\nthe fdc and fic instructions in flush_user_dcache_range_asm and\nflush_user_icache_range_asm. When these occur, the cache line is\nnot invalidated and potentially we get memory corruption. The\nproblem was hidden by the nullification of the flush instructions.\n\nThese faults also affect performance. With pa8800\u002Fpa8","2025-02-26T07:00:54.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49172",{"cveId":6912,"releaseId":17,"cycle":18,"description":6913,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6914,"url":6915},{"cveId":6912,"releaseId":31,"cycle":32,"description":6913,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6914,"url":6915},{"cveId":6919,"releaseId":31,"cycle":32,"description":6920,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6921,"url":6922},"CVE-2022-49170","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on curseg->alloc_type\n\nAs Wenqing Liu reported in bugzilla:\n\nhttps:\u002F\u002Fbugzilla.kernel.org\u002Fshow_bug.cgi?id=215657\n\n- Overview\nUBSAN: array-index-out-of-bounds in fs\u002Ff2fs\u002Fsegment.c:3460:2 when mount and operate a corrupted image\n\n- Reproduce\ntested on kernel 5.17-rc4, 5.17-rc6\n\n1. mkdir test_crash\n2. cd test_crash\n3. unzip tmp2.zip\n4. mkdir mnt\n5. .\u002Fsingle_test.sh f2fs 2\n\n- Kernel dump\n[   46.434454] l","2025-02-26T07:00:54.11+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49170",{"cveId":6919,"releaseId":17,"cycle":18,"description":6920,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6921,"url":6922},{"cveId":6919,"releaseId":25,"cycle":26,"description":6920,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6921,"url":6922},{"cveId":6926,"releaseId":31,"cycle":32,"description":6927,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6928,"url":6929},"CVE-2022-49162","In the Linux kernel, the following vulnerability has been resolved:\n\nvideo: fbdev: sm712fb: Fix crash in smtcfb_write()\n\nWhen the sm712fb driver writes three bytes to the framebuffer, the\ndriver will crash:\n\n    BUG: unable to handle page fault for address: ffffc90001ffffff\n    RIP: 0010:smtcfb_write+0x454\u002F0x5b0\n    Call Trace:\n     vfs_write+0x291\u002F0xd60\n     ? do_sys_openat2+0x27d\u002F0x350\n     ? __fget_light+0x54\u002F0x340\n     ksys_write+0xce\u002F0x190\n     do_syscall_64+0x43\u002F0x90\n     entry_SYSCALL_64_","2025-02-26T07:00:53.373+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49162",{"cveId":6926,"releaseId":25,"cycle":26,"description":6927,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6928,"url":6929},{"cveId":6926,"releaseId":17,"cycle":18,"description":6927,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6928,"url":6929},{"cveId":6933,"releaseId":17,"cycle":18,"description":6934,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6935,"url":6936},"CVE-2022-49158","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix warning message due to adisc being flushed\n\nFix warning message due to adisc being flushed.  Linux kernel triggered a\nwarning message where a different error code type is not matching up with\nthe expected type. Add additional translation of one error code type to\nanother.\n\nWARNING: CPU: 2 PID: 1131623 at drivers\u002Fscsi\u002Fqla2xxx\u002Fqla_init.c:498\nqla2x00_async_adisc_sp_done+0x294\u002F0x2b0 [qla2xxx]\nCPU: 2 PID: 1131623 ","2025-02-26T07:00:53.013+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49158",{"cveId":6933,"releaseId":25,"cycle":26,"description":6934,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6935,"url":6936},{"cveId":6933,"releaseId":31,"cycle":32,"description":6934,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6935,"url":6936},{"cveId":6940,"releaseId":31,"cycle":32,"description":6941,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6942,"url":6943},"CVE-2022-49154","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: fix panic on out-of-bounds guest IRQ\n\nAs guest_irq is coming from KVM_IRQFD API call, it may trigger\ncrash in svm_update_pi_irte() due to out-of-bounds:\n\ncrash> bt\nPID: 22218  TASK: ffff951a6ad74980  CPU: 73  COMMAND: \"vcpu8\"\n #0 [ffffb1ba6707fa40] machine_kexec at ffffffff8565b397\n #1 [ffffb1ba6707fa90] __crash_kexec at ffffffff85788a6d\n #2 [ffffb1ba6707fb58] crash_kexec at ffffffff8578995d\n #3 [ffffb1ba6707fb70] oop","2025-02-26T07:00:52.627+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49154",{"cveId":6940,"releaseId":25,"cycle":26,"description":6941,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6942,"url":6943},{"cveId":6940,"releaseId":17,"cycle":18,"description":6941,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":6942,"url":6943},{"cveId":6947,"releaseId":17,"cycle":18,"description":6948,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":6949,"url":6950},"CVE-2022-49149","In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix call timer start racing with call destruction\n\nThe rxrpc_call struct has a timer used to handle various timed events\nrelating to a call.  This timer can get started from the packet input\nroutines that are run in softirq mode with just the RCU read lock held.\nUnfortunately, because only the RCU read lock is held - and neither ref or\nother lock is taken - the call can start getting destroyed at the same time\na packet c","2025-02-26T07:00:52.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49149",{"cveId":6952,"releaseId":17,"cycle":18,"description":6953,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6954,"url":6955},"CVE-2022-49142","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: preserve skb_end_offset() in skb_unclone_keeptruesize()\n\nsyzbot found another way to trigger the infamous WARN_ON_ONCE(delta \u003C len)\nin skb_try_coalesce() [1]\n\nI was able to root cause the issue to kfence.\n\nWhen kfence is in action, the following assertion is no longer true:\n\nint size = xxxx;\nvoid *ptr1 = kmalloc(size, gfp);\nvoid *ptr2 = kmalloc(size, gfp);\n\nif (ptr1 && ptr2)\n\tASSERT(ksize(ptr1) == ksize(ptr2));\n\nWe attempt","2025-02-26T07:00:51.42+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49142",{"cveId":6952,"releaseId":25,"cycle":26,"description":6953,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6954,"url":6955},{"cveId":6952,"releaseId":31,"cycle":32,"description":6953,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6954,"url":6955},{"cveId":6959,"releaseId":17,"cycle":18,"description":6960,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6961,"url":6962},"CVE-2022-49138","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: Ignore multiple conn complete events\n\nWhen one of the three connection complete events is received multiple\ntimes for the same handle, the device is registered multiple times which\nleads to memory corruptions. Therefore, consequent events for a single\nconnection are ignored.\n\nThe conn->state can hold different values, therefore HCI_CONN_HANDLE_UNSET\nis introduced to identify new connections. To make sure t","2025-02-26T07:00:51.047+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49138",{"cveId":6959,"releaseId":31,"cycle":32,"description":6960,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6961,"url":6962},{"cveId":6959,"releaseId":25,"cycle":26,"description":6960,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6961,"url":6962},{"cveId":6966,"releaseId":25,"cycle":26,"description":6967,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6968,"url":6969},"CVE-2022-49135","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix memory leak\n\n[why]\nResource release is needed on the error handling path\nto prevent memory leak.\n\n[how]\nFix this by adding kfree on the error handling path.","2025-02-26T07:00:50.77+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49135",{"cveId":6966,"releaseId":17,"cycle":18,"description":6967,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6968,"url":6969},{"cveId":6966,"releaseId":31,"cycle":32,"description":6967,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":6968,"url":6969},{"cveId":6973,"releaseId":17,"cycle":18,"description":6974,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6975,"url":6976},"CVE-2022-49114","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libfc: Fix use after free in fc_exch_abts_resp()\n\nfc_exch_release(ep) will decrease the ep's reference count. When the\nreference count reaches zero, it is freed. But ep is still used in the\nfollowing code, which will lead to a use after free.\n\nReturn after the fc_exch_release() call to avoid use after free.","2025-02-26T07:00:48.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49114",{"cveId":6973,"releaseId":25,"cycle":26,"description":6974,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6975,"url":6976},{"cveId":6973,"releaseId":31,"cycle":32,"description":6974,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6975,"url":6976},{"cveId":6980,"releaseId":17,"cycle":18,"description":6981,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6982,"url":6983},"CVE-2022-49111","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix use after free in hci_send_acl\n\nThis fixes the following trace caused by receiving\nHCI_EV_DISCONN_PHY_LINK_COMPLETE which does call hci_conn_del without\nfirst checking if conn->type is in fact AMP_LINK and in case it is\ndo properly cleanup upper layers with hci_disconn_cfm:\n\n ==================================================================\n    BUG: KASAN: use-after-free in hci_send_acl+0xaba\u002F0xc50\n    Read of s","2025-02-26T07:00:48.47+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49111",{"cveId":6980,"releaseId":25,"cycle":26,"description":6981,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6982,"url":6983},{"cveId":6980,"releaseId":31,"cycle":32,"description":6981,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":6982,"url":6983},{"cveId":6987,"releaseId":17,"cycle":18,"description":6988,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6989,"url":6990},"CVE-2022-49110","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: revisit gc autotuning\n\nas of commit 4608fdfc07e1\n(\"netfilter: conntrack: collect all entries in one cycle\")\nconntrack gc was changed to run every 2 minutes.\n\nOn systems where conntrack hash table is set to large value, most evictions\nhappen from gc worker rather than the packet path due to hash table\ndistribution.\n\nThis causes netlink event overflows when events are collected.\n\nThis change collects average","2025-02-26T07:00:48.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49110",{"cveId":6987,"releaseId":25,"cycle":26,"description":6988,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6989,"url":6990},{"cveId":6987,"releaseId":31,"cycle":32,"description":6988,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6989,"url":6990},{"cveId":6994,"releaseId":17,"cycle":18,"description":6995,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":6996,"url":6997},"CVE-2022-49084","In the Linux kernel, the following vulnerability has been resolved:\n\nqede: confirm skb is allocated before using\n\nqede_build_skb() assumes build_skb() always works and goes straight\nto skb_reserve(). However, build_skb() can fail under memory pressure.\nThis results in a kernel panic because the skb to reserve is NULL.\n\nAdd a check in case build_skb() failed to allocate and return NULL.\n\nThe NULL return is handled correctly in callers to qede_build_skb().","2025-02-26T07:00:45.737+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49084",{"cveId":6999,"releaseId":17,"cycle":18,"description":7000,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":7001,"url":7002},"CVE-2022-49075","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix qgroup reserve overflow the qgroup limit\n\nWe use extent_changeset->bytes_changed in qgroup_reserve_data() to record\nhow many bytes we set for EXTENT_QGROUP_RESERVED state. Currently the\nbytes_changed is set as \"unsigned int\", and it will overflow if we try to\nfallocate a range larger than 4GiB. The result is we reserve less bytes\nand eventually break the qgroup limit.\n\nUnlike regular buffered\u002Fdirect write, which we u","2025-02-26T07:00:44.847+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49075",{"cveId":6999,"releaseId":25,"cycle":26,"description":7000,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":7001,"url":7002},{"cveId":6999,"releaseId":31,"cycle":32,"description":7000,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":7001,"url":7002},{"cveId":7006,"releaseId":17,"cycle":18,"description":7007,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7008,"url":7009},"CVE-2022-49073","In the Linux kernel, the following vulnerability has been resolved:\n\nata: sata_dwc_460ex: Fix crash due to OOB write\n\nthe driver uses libata's \"tag\" values from in various arrays.\nSince the mentioned patch bumped the ATA_TAG_INTERNAL to 32,\nthe value of the SATA_DWC_QCMD_MAX needs to account for that.\n\nOtherwise ATA_TAG_INTERNAL usage cause similar crashes like\nthis as reported by Tice Rex on the OpenWrt Forum and\nreproduced (with symbols) here:\n\n| BUG: Kernel NULL pointer dereference at 0x00000","2025-02-26T07:00:44.647+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49073",{"cveId":7011,"releaseId":17,"cycle":18,"description":7012,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7013,"url":7014},"CVE-2022-49065","In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Fix the svc_deferred_event trace class\n\nFix a NULL deref crash that occurs when an svc_rqst is deferred\nwhile the sunrpc tracing subsystem is enabled. svc_revisit() sets\ndr->xprt to NULL, so it can't be relied upon in the tracepoint to\nprovide the remote's address.\n\nUnfortunately we can't revert the \"svc_deferred_class\" hunk in\ncommit ece200ddd54b (\"sunrpc: Save remote presentation address in\nsvc_xprt for trace events\")","2025-02-26T07:00:43.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49065",{"cveId":7016,"releaseId":25,"cycle":26,"description":7017,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":7018,"url":7019},"CVE-2022-49058","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: potential buffer overflow in handling symlinks\n\nSmatch printed a warning:\n\tarch\u002Fx86\u002Fcrypto\u002Fpoly1305_glue.c:198 poly1305_update_arch() error:\n\t__memcpy() 'dctx->buf' too small (16 vs u32max)\n\nIt's caused because Smatch marks 'link_len' as untrusted since it comes\nfrom sscanf(). Add a check to ensure that 'link_len' is not larger than\nthe size of the 'link_str' buffer.","2025-02-26T07:00:43.047+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49058",{"cveId":7016,"releaseId":17,"cycle":18,"description":7017,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":7018,"url":7019},{"cveId":7016,"releaseId":31,"cycle":32,"description":7017,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":7018,"url":7019},{"cveId":7023,"releaseId":31,"cycle":32,"description":7024,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7025,"url":7026},"CVE-2022-49054","In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: Deactivate sysctl_record_panic_msg by default in isolated guests\n\nhv_panic_page might contain guest-sensitive information, do not dump it\nover to Hyper-V by default in isolated guests.\n\nWhile at it, update some comments in hyperv_{panic,die}_event().","2025-02-26T07:00:42.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49054",{"cveId":7023,"releaseId":17,"cycle":18,"description":7024,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7025,"url":7026},{"cveId":7023,"releaseId":25,"cycle":26,"description":7024,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7025,"url":7026},{"cveId":7030,"releaseId":17,"cycle":18,"description":7031,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7032,"url":7033},"CVE-2022-49052","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix unexpected zeroed page mapping with zram swap\n\nTwo processes under CLONE_VM cloning, user process can be corrupted by\nseeing zeroed page unexpectedly.\n\n      CPU A                        CPU B\n\n  do_swap_page                do_swap_page\n  SWP_SYNCHRONOUS_IO path     SWP_SYNCHRONOUS_IO path\n  swap_readpage valid data\n    swap_slot_free_notify\n      delete zram entry\n                              swap_readpage zeroed(inva","2025-02-26T07:00:42.463+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49052",{"cveId":7035,"releaseId":17,"cycle":18,"description":7036,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7037,"url":7038},"CVE-2022-49048","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix panic when forwarding a pkt with no in6 dev\n\nkongweibin reported a kernel panic in ip6_forward() when input interface\nhas no in6 dev associated.\n\nThe following tc commands were used to reproduce this panic:\ntc qdisc del dev vxlan100 root\ntc qdisc add dev vxlan100 root netem corrupt 5%","2025-02-26T07:00:42.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49048",{"cveId":7040,"releaseId":17,"cycle":18,"description":7041,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7042,"url":7043},"CVE-2021-47656","In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: fix use-after-free in jffs2_clear_xattr_subsystem\n\nWhen we mount a jffs2 image, assume that the first few blocks of\nthe image are normal and contain at least one xattr-related inode,\nbut the next block is abnormal. As a result, an error is returned\nin jffs2_scan_eraseblock(). jffs2_clear_xattr_subsystem() is then\ncalled in jffs2_build_filesystem() and then again in\njffs2_do_fill_super().\n\nFinally we can observe the follo","2025-02-26T06:37:07.36+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47656",{"cveId":7040,"releaseId":25,"cycle":26,"description":7041,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7042,"url":7043},{"cveId":7040,"releaseId":31,"cycle":32,"description":7041,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7042,"url":7043},{"cveId":7047,"releaseId":25,"cycle":26,"description":7048,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7049,"url":7050},"CVE-2021-47638","In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: rename_whiteout: Fix double free for whiteout_ui->data\n\n'whiteout_ui->data' will be freed twice if space budget fail for\nrename whiteout operation as following process:\n\nrename_whiteout\n  dev = kmalloc\n  whiteout_ui->data = dev\n  kfree(whiteout_ui->data)  \u002F\u002F Free first time\n  iput(whiteout)\n    ubifs_free_inode\n      kfree(ui->data)\t    \u002F\u002F Double free!\n\nKASAN reports:\n=====================================================","2025-02-26T06:37:05.58+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47638",{"cveId":7047,"releaseId":31,"cycle":32,"description":7048,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7049,"url":7050},{"cveId":7047,"releaseId":17,"cycle":18,"description":7048,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7049,"url":7050},{"cveId":7054,"releaseId":25,"cycle":26,"description":7055,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7056,"url":7057},"CVE-2021-47635","In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: Fix to add refcount once page is set private\n\nMM defined the rule [1] very clearly that once page was set with PG_private\nflag, we should increment the refcount in that page, also main flows like\npageout(), migrate_page() will assume there is one additional page\nreference count if page_has_private() returns true. Otherwise, we may\nget a BUG in page migration:\n\n  page:0000000080d05b9d refcount:-1 mapcount:0 mapping:000000","2025-02-26T06:37:05.28+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47635",{"cveId":7054,"releaseId":17,"cycle":18,"description":7055,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7056,"url":7057},{"cveId":7054,"releaseId":31,"cycle":32,"description":7055,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7056,"url":7057},{"cveId":7061,"releaseId":25,"cycle":26,"description":7062,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7063,"url":7064},"CVE-2025-21702","In the Linux kernel, the following vulnerability has been resolved:\n\npfifo_tail_enqueue: Drop new packet when sch->limit == 0\n\nExpected behaviour:\nIn case we reach scheduler's limit, pfifo_tail_enqueue() will drop a\npacket in scheduler's queue and decrease scheduler's qlen by one.\nThen, pfifo_tail_enqueue() enqueue new packet and increase\nscheduler's qlen by one. Finally, pfifo_tail_enqueue() return\n`NET_XMIT_CN` status code.\n\nWeird behaviour:\nIn case we set `sch->limit == 0` and trigger pfifo_t","2025-02-18T15:15:18.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21702",{"cveId":7061,"releaseId":31,"cycle":32,"description":7062,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7063,"url":7064},{"cveId":7061,"releaseId":17,"cycle":18,"description":7062,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7063,"url":7064},{"cveId":7068,"releaseId":17,"cycle":18,"description":7069,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7070,"url":7071},"CVE-2025-21699","In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Truncate address space when flipping GFS2_DIF_JDATA flag\n\nTruncate an inode's address space when flipping the GFS2_DIF_JDATA flag:\ndepending on that flag, the pages in the address space will either use\nbuffer heads or iomap_folio_state structs, and we cannot mix the two.","2025-02-12T14:15:33.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21699",{"cveId":7068,"releaseId":25,"cycle":26,"description":7069,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7070,"url":7071},{"cveId":7068,"releaseId":31,"cycle":32,"description":7069,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7070,"url":7071},{"cveId":7075,"releaseId":17,"cycle":18,"description":7076,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7077,"url":7078},"CVE-2025-21697","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fv3d: Ensure job pointer is set to NULL after job completion\n\nAfter a job completes, the corresponding pointer in the device must\nbe set to NULL. Failing to do so triggers a warning when unloading\nthe driver, as it appears the job is still active. To prevent this,\nassign the job pointer to NULL after completing the job, indicating\nthe job has finished.","2025-02-12T14:15:32.787+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21697",{"cveId":7080,"releaseId":17,"cycle":18,"description":7081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7082,"url":7083},"CVE-2025-21687","In the Linux kernel, the following vulnerability has been resolved:\n\nvfio\u002Fplatform: check the bounds of read\u002Fwrite syscalls\n\ncount and offset are passed from user space and not checked, only\noffset is capped to 40 bits, which can be used to read\u002Fwrite out of\nbounds of the device.","2025-02-10T16:15:38.207+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21687",{"cveId":7080,"releaseId":25,"cycle":26,"description":7081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7082,"url":7083},{"cveId":7080,"releaseId":31,"cycle":32,"description":7081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7082,"url":7083},{"cveId":7087,"releaseId":17,"cycle":18,"description":7088,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7089,"url":7090},"CVE-2025-21682","In the Linux kernel, the following vulnerability has been resolved:\n\neth: bnxt: always recalculate features after XDP clearing, fix null-deref\n\nRecalculate features when XDP is detached.\n\nBefore:\n  # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp\n  # ip li set dev eth0 xdp off\n  # ethtool -k eth0 | grep gro\n  rx-gro-hw: off [requested on]\n\nAfter:\n  # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp\n  # ip li set dev eth0 xdp off\n  # ethtool -k eth0 | grep gro\n  rx-gro-hw: on\n\nThe fact that","2025-01-31T12:15:29.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21682",{"cveId":7092,"releaseId":17,"cycle":18,"description":7093,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7094,"url":7095},"CVE-2025-21678","In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: Destroy device along with udp socket's netns dismantle.\n\ngtp_newlink() links the device to a list in dev_net(dev) instead of\nsrc_net, where a udp tunnel socket is created.\n\nEven when src_net is removed, the device stays alive on dev_net(dev).\nThen, removing src_net triggers the splat below. [0]\n\nIn this example, gtp0 is created in ns2, and the udp socket is created\nin ns1.\n\n  ip netns add ns1\n  ip netns add ns2\n  ip -n ns1","2025-01-31T12:15:28.97+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21678",{"cveId":7092,"releaseId":31,"cycle":32,"description":7093,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7094,"url":7095},{"cveId":7092,"releaseId":25,"cycle":26,"description":7093,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7094,"url":7095},{"cveId":7099,"releaseId":17,"cycle":18,"description":7100,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7101,"url":7102},"CVE-2025-21664","In the Linux kernel, the following vulnerability has been resolved:\n\ndm thin: make get_first_thin use rcu-safe list first function\n\nThe documentation in rculist.h explains the absence of list_empty_rcu()\nand cautions programmers against relying on a list_empty() ->\nlist_first() sequence in RCU safe code.  This is because each of these\nfunctions performs its own READ_ONCE() of the list head.  This can lead\nto a situation where the list_empty() sees a valid list entry, but the\nsubsequent list_firs","2025-01-21T13:15:10.053+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21664",{"cveId":7099,"releaseId":25,"cycle":26,"description":7100,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7101,"url":7102},{"cveId":7099,"releaseId":31,"cycle":32,"description":7100,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7101,"url":7102},{"cveId":7106,"releaseId":31,"cycle":32,"description":7107,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7108,"url":7109},"CVE-2023-52923","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: adapt set backend to use GC transaction API\n\nUse the GC transaction API to replace the old and buggy gc API and the\nbusy mark approach.\n\nNo set elements are removed from async garbage collection anymore,\ninstead the _DEAD bit is set on so the set element is not visible from\nlookup path anymore. Async GC enqueues transaction work that might be\naborted and retried later.\n\nrbtree and pipapo set backends does ","2025-01-20T11:15:07.67+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52923",{"cveId":7106,"releaseId":17,"cycle":18,"description":7107,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7108,"url":7109},{"cveId":7106,"releaseId":25,"cycle":26,"description":7107,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7108,"url":7109},{"cveId":7113,"releaseId":31,"cycle":32,"description":7114,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7115,"url":7116},"CVE-2024-57929","In the Linux kernel, the following vulnerability has been resolved:\n\ndm array: fix releasing a faulty array block twice in dm_array_cursor_end\n\nWhen dm_bm_read_lock() fails due to locking or checksum errors, it\nreleases the faulty block implicitly while leaving an invalid output\npointer behind. The caller of dm_bm_read_lock() should not operate on\nthis invalid dm_block pointer, or it will lead to undefined result.\nFor example, the dm_array_cursor incorrectly caches the invalid pointer\non reading","2025-01-19T12:15:27.013+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57929",{"cveId":7113,"releaseId":17,"cycle":18,"description":7114,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7115,"url":7116},{"cveId":7113,"releaseId":25,"cycle":26,"description":7114,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7115,"url":7116},{"cveId":7120,"releaseId":25,"cycle":26,"description":7121,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7122,"url":7123},"CVE-2024-57924","In the Linux kernel, the following vulnerability has been resolved:\n\nfs: relax assertions on failure to encode file handles\n\nEncoding file handles is usually performed by a filesystem >encode_fh()\nmethod that may fail for various reasons.\n\nThe legacy users of exportfs_encode_fh(), namely, nfsd and\nname_to_handle_at(2) syscall are ready to cope with the possibility\nof failure to encode a file handle.\n\nThere are a few other users of exportfs_encode_{fh,fid}() that\ncurrently have a WARN_ON() assert","2025-01-19T12:15:26.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57924",{"cveId":7120,"releaseId":31,"cycle":32,"description":7121,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7122,"url":7123},{"cveId":7120,"releaseId":17,"cycle":18,"description":7121,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7122,"url":7123},{"cveId":7127,"releaseId":17,"cycle":18,"description":7128,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7129,"url":7130},"CVE-2025-21648","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: clamp maximum hashtable size to INT_MAX\n\nUse INT_MAX as maximum size for the conntrack hashtable. Otherwise, it\nis possible to hit WARN_ON_ONCE in __kvmalloc_node_noprof() when\nresizing hashtable because __GFP_NOWARN is unset. See:\n\n  0708a0afe291 (\"mm: Consider __GFP_NOWARN flag for oversized kvmalloc() calls\")\n\nNote: hashtable resize is only possible from init_netns.","2025-01-19T11:15:10.41+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21648",{"cveId":7127,"releaseId":31,"cycle":32,"description":7128,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7129,"url":7130},{"cveId":7127,"releaseId":25,"cycle":26,"description":7128,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7129,"url":7130},{"cveId":7134,"releaseId":17,"cycle":18,"description":7135,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7136,"url":7137},"CVE-2025-21640","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's\u002Fwriter's netns vs only\n  from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n  (null-ptr-deref), e.g. when the current task is exiting, as spotted","2025-01-19T11:15:09.537+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21640",{"cveId":7134,"releaseId":25,"cycle":26,"description":7135,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7136,"url":7137},{"cveId":7134,"releaseId":31,"cycle":32,"description":7135,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7136,"url":7137},{"cveId":7141,"releaseId":17,"cycle":18,"description":7142,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7143,"url":7144},"CVE-2025-21638","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: sysctl: auth_enable: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's\u002Fwriter's netns vs only\n  from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n  (null-ptr-deref), e.g. when the current task is exiting, as spotted by\n","2025-01-19T11:15:09.317+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21638",{"cveId":7141,"releaseId":25,"cycle":26,"description":7142,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7143,"url":7144},{"cveId":7141,"releaseId":31,"cycle":32,"description":7142,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7143,"url":7144},{"cveId":7148,"releaseId":17,"cycle":18,"description":7149,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":7150,"url":7151},"CVE-2025-21629","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets\n\nThe blamed commit disabled hardware offoad of IPv6 packets with\nextension headers on devices that advertise NETIF_F_IPV6_CSUM,\nbased on the definition of that feature in skbuff.h:\n\n *   * - %NETIF_F_IPV6_CSUM\n *     - Driver (device) is only able to checksum plain\n *       TCP or UDP packets over IPv6. These are specifically\n *       unencapsulated packets of the form","2025-01-15T13:15:15.22+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-21629",{"cveId":7153,"releaseId":17,"cycle":18,"description":7154,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7155,"url":7156},"CVE-2024-57902","In the Linux kernel, the following vulnerability has been resolved:\n\naf_packet: fix vlan_get_tci() vs MSG_PEEK\n\nBlamed commit forgot MSG_PEEK case, allowing a crash [1] as found\nby syzbot.\n\nRework vlan_get_tci() to not touch skb at all,\nso that it can be used from many cpus on the same skb.\n\nAdd a const qualifier to skb argument.\n\n[1]\nskbuff: skb_under_panic: text:ffffffff8a8da482 len:32 put:14 head:ffff88807a1d5800 data:ffff88807a1d5810 tail:0x14 end:0x140 dev:\u003CNULL>\n------------[ cut here ]---","2025-01-15T13:15:14.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57902",{"cveId":7158,"releaseId":17,"cycle":18,"description":7159,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7160,"url":7161},"CVE-2024-57901","In the Linux kernel, the following vulnerability has been resolved:\n\naf_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK\n\nBlamed commit forgot MSG_PEEK case, allowing a crash [1] as found\nby syzbot.\n\nRework vlan_get_protocol_dgram() to not touch skb at all,\nso that it can be used from many cpus on the same skb.\n\nAdd a const qualifier to skb argument.\n\n[1]\nskbuff: skb_under_panic: text:ffffffff8a8ccd05 len:29 put:14 head:ffff88807fc8e400 data:ffff88807fc8e3f4 tail:0x11 end:0x140 dev:\u003CNULL>\n-----","2025-01-15T13:15:14.747+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57901",{"cveId":7163,"releaseId":17,"cycle":18,"description":7164,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":7166,"url":7167},"CVE-2024-57899","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix mbss changed flags corruption on 32 bit systems\n\nOn 32-bit systems, the size of an unsigned long is 4 bytes,\nwhile a u64 is 8 bytes. Therefore, when using\nor_each_set_bit(bit, &bits, sizeof(changed) * BITS_PER_BYTE),\nthe code is incorrectly searching for a bit in a 32-bit\nvariable that is expected to be 64 bits in size,\nleading to incorrect bit finding.\n\nSolution: Ensure that the size of the bits variable is",7.6,"2025-01-15T13:15:14.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57899",{"cveId":7163,"releaseId":31,"cycle":32,"description":7164,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":7166,"url":7167},{"cveId":7163,"releaseId":25,"cycle":26,"description":7164,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":7166,"url":7167},{"cveId":7171,"releaseId":25,"cycle":26,"description":7172,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7173,"url":7174},"CVE-2024-57893","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: oss: Fix races at processing SysEx messages\n\nOSS sequencer handles the SysEx messages split in 6 bytes packets, and\nALSA sequencer OSS layer tries to combine those.  It stores the data\nin the internal buffer and this access is racy as of now, which may\nlead to the out-of-bounds access.\n\nAs a temporary band-aid fix, introduce a mutex for serializing the\nprocess of the SysEx message packets.","2025-01-15T13:15:13.82+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57893",{"cveId":7171,"releaseId":17,"cycle":18,"description":7172,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7173,"url":7174},{"cveId":7171,"releaseId":31,"cycle":32,"description":7172,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7173,"url":7174},{"cveId":7178,"releaseId":31,"cycle":32,"description":7179,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7180,"url":7181},"CVE-2024-57883","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: hugetlb: independent PMD page table shared count\n\nThe folio refcount may be increased unexpectly through try_get_folio() by\ncaller such as split_huge_pages.  In huge_pmd_unshare(), we use refcount\nto check whether a pmd page table is shared.  The check is incorrect if\nthe refcount is increased by the above caller, and this can cause the page\ntable leaked:\n\n BUG: Bad page state in process sh  pfn:109324\n page: refcount:0 map","2025-01-15T13:15:12.637+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57883",{"cveId":7178,"releaseId":17,"cycle":18,"description":7179,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7180,"url":7181},{"cveId":7178,"releaseId":25,"cycle":26,"description":7179,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7180,"url":7181},{"cveId":7185,"releaseId":31,"cycle":32,"description":7186,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":7187,"url":7188},"CVE-2024-57802","In the Linux kernel, the following vulnerability has been resolved:\n\nnetrom: check buffer length before accessing it\n\nSyzkaller reports an uninit value read from ax25cmp when sending raw message\nthrough ieee802154 implementation.\n\n=====================================================\nBUG: KMSAN: uninit-value in ax25cmp+0x3a5\u002F0x460 net\u002Fax25\u002Fax25_addr.c:119\n ax25cmp+0x3a5\u002F0x460 net\u002Fax25\u002Fax25_addr.c:119\n nr_dev_get+0x20e\u002F0x450 net\u002Fnetrom\u002Fnr_route.c:601\n nr_route_frame+0x1a2\u002F0xfc0 net\u002Fnetrom\u002Fnr_rout","2025-01-15T13:15:11.853+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57802",{"cveId":7185,"releaseId":17,"cycle":18,"description":7186,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":7187,"url":7188},{"cveId":7185,"releaseId":25,"cycle":26,"description":7186,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":7187,"url":7188},{"cveId":7192,"releaseId":31,"cycle":32,"description":7193,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7194,"url":7195},"CVE-2024-57875","In the Linux kernel, the following vulnerability has been resolved:\n\nblock: RCU protect disk->conv_zones_bitmap\n\nEnsure that a disk revalidation changing the conventional zones bitmap\nof a disk does not cause invalid memory references when using the\ndisk_zone_is_conv() helper by RCU protecting the disk->conv_zones_bitmap\npointer.\n\ndisk_zone_is_conv() is modified to operate under the RCU read lock and\nthe function disk_set_conv_zones_bitmap() is added to update a disk\nconv_zones_bitmap pointer us","2025-01-11T15:15:07.803+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57875",{"cveId":7192,"releaseId":25,"cycle":26,"description":7193,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7194,"url":7195},{"cveId":7192,"releaseId":17,"cycle":18,"description":7193,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7194,"url":7195},{"cveId":7199,"releaseId":31,"cycle":32,"description":7200,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7201,"url":7202},"CVE-2024-57850","In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: Prevent rtime decompress memory corruption\n\nThe rtime decompression routine does not fully check bounds during the\nentirety of the decompression pass and can corrupt memory outside the\ndecompression buffer if the compressed data is corrupted. This adds the\nrequired check to prevent this failure mode.","2025-01-11T15:15:07.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57850",{"cveId":7199,"releaseId":25,"cycle":26,"description":7200,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7201,"url":7202},{"cveId":7199,"releaseId":17,"cycle":18,"description":7200,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7201,"url":7202},{"cveId":7206,"releaseId":25,"cycle":26,"description":7207,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7208,"url":7209},"CVE-2024-57849","In the Linux kernel, the following vulnerability has been resolved:\n\ns390\u002Fcpum_sf: Handle CPU hotplug remove during sampling\n\nCPU hotplug remove handling triggers the following function\ncall sequence:\n\n   CPUHP_AP_PERF_S390_SF_ONLINE  --> s390_pmu_sf_offline_cpu()\n   ...\n   CPUHP_AP_PERF_ONLINE          --> perf_event_exit_cpu()\n\nThe s390 CPUMF sampling CPU hotplug handler invokes:\n\n s390_pmu_sf_offline_cpu()\n +-->  cpusf_pmu_setup()\n       +--> setup_pmc_cpu()\n            +--> deallocate_buffer","2025-01-11T15:15:07.29+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57849",{"cveId":7206,"releaseId":17,"cycle":18,"description":7207,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7208,"url":7209},{"cveId":7206,"releaseId":31,"cycle":32,"description":7207,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7208,"url":7209},{"cveId":7213,"releaseId":17,"cycle":18,"description":7214,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7215,"url":7216},"CVE-2024-57843","In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-net: fix overflow inside virtnet_rq_alloc\n\nWhen the frag just got a page, then may lead to regression on VM.\nSpecially if the sysctl net.core.high_order_alloc_disable value is 1,\nthen the frag always get a page when do refill.\n\nWhich could see reliable crashes or scp failure (scp a file 100M in size\nto VM).\n\nThe issue is that the virtnet_rq_dma takes up 16 bytes at the beginning\nof a new frag. When the frag size is large","2025-01-11T15:15:07.17+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-57843",{"cveId":7213,"releaseId":25,"cycle":26,"description":7214,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7215,"url":7216},{"cveId":7213,"releaseId":31,"cycle":32,"description":7214,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7215,"url":7216},{"cveId":7220,"releaseId":17,"cycle":18,"description":7221,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":7222,"url":7223},"CVE-2024-49571","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: check iparea_offset and ipv6_prefixes_cnt when receiving proposal msg\n\nWhen receiving proposal msg in server, the field iparea_offset\nand the field ipv6_prefixes_cnt in proposal msg are from the\nremote client and can not be fully trusted. Especially the\nfield iparea_offset, once exceed the max value, there has the\nchance to access wrong address, and crash may happen.\n\nThis patch checks iparea_offset and ipv6_prefixes_c","2025-01-11T13:15:24.027+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49571",{"cveId":7225,"releaseId":25,"cycle":26,"description":7226,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7227,"url":7228},"CVE-2024-47809","In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: fix possible lkb_resource null dereference\n\nThis patch fixes a possible null pointer dereference when this function is\ncalled from request_lock() as lkb->lkb_resource is not assigned yet,\nonly after validate_lock_args() by calling attach_lkb(). Another issue\nis that a resource name could be a non printable bytearray and we cannot\nassume to be ASCII coded.\n\nThe log functionality is probably never being hit when DLM is used ","2025-01-11T13:15:22.583+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47809",{"cveId":7225,"releaseId":17,"cycle":18,"description":7226,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7227,"url":7228},{"cveId":7225,"releaseId":31,"cycle":32,"description":7226,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7227,"url":7228},{"cveId":7232,"releaseId":17,"cycle":18,"description":7233,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7234,"url":7235},"CVE-2024-56779","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur\n\nThe action force umount(umount -f) will attempt to kill all rpc_task even\numount operation may ultimately fail if some files remain open.\nConsequently, if an action attempts to open a file, it can potentially\nsend two rpc_task to nfs server.\n\n                   NFS CLIENT\nthread1                             thread2\nopen(\"file\")\n...\nnfs4_do_open\n _nfs4_do_open\n  _nf","2025-01-08T18:15:18.793+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56779",{"cveId":7232,"releaseId":25,"cycle":26,"description":7233,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7234,"url":7235},{"cveId":7232,"releaseId":31,"cycle":32,"description":7233,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7234,"url":7235},{"cveId":7239,"releaseId":31,"cycle":32,"description":7240,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7241,"url":7242},"CVE-2024-56757","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: mediatek: add intf release flow when usb disconnect\n\nMediaTek claim an special usb intr interface for ISO data transmission.\nThe interface need to be released before unregistering hci device when\nusb disconnect. Removing BT usb dongle without properly releasing the\ninterface may cause Kernel panic while unregister hci device.","2025-01-06T17:15:40.297+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56757",{"cveId":7239,"releaseId":25,"cycle":26,"description":7240,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7241,"url":7242},{"cveId":7239,"releaseId":17,"cycle":18,"description":7240,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7241,"url":7242},{"cveId":7246,"releaseId":25,"cycle":26,"description":7247,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":7248,"url":7249},"CVE-2024-56704","In the Linux kernel, the following vulnerability has been resolved:\n\n9p\u002Fxen: fix release of IRQ\n\nKernel logs indicate an IRQ was double-freed.\n\nPass correct device ID during IRQ release.\n\n[Dominique: remove confusing variable reset to 0]","2024-12-28T10:15:18.817+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56704",{"cveId":7246,"releaseId":17,"cycle":18,"description":7247,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":7248,"url":7249},{"cveId":7252,"releaseId":17,"cycle":18,"description":7253,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7254,"url":7255},"CVE-2024-56703","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: Fix soft lockups in fib6_select_path under high next hop churn\n\nSoft lockups have been observed on a cluster of Linux-based edge routers\nlocated in a highly dynamic environment. Using the `bird` service, these\nrouters continuously update BGP-advertised routes due to frequently\nchanging nexthop destinations, while also managing significant IPv6\ntraffic. The lockups occur during the traversal of the multipath\ncircular linke","2024-12-28T10:15:18.433+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56703",{"cveId":7257,"releaseId":17,"cycle":18,"description":7258,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7259,"url":7260},"CVE-2024-56692","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on node blkaddr in truncate_node()\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs\u002Ff2fs\u002Fsegment.c:2534!\nRIP: 0010:f2fs_invalidate_blocks+0x35f\u002F0x370 fs\u002Ff2fs\u002Fsegment.c:2534\nCall Trace:\n truncate_node+0x1ae\u002F0x8c0 fs\u002Ff2fs\u002Fnode.c:909\n f2fs_remove_inode_page+0x5c2\u002F0x870 fs\u002Ff2fs\u002Fnode.c:1288\n f2fs_evict_inode+0x879\u002F0x15c0 fs\u002Ff2fs\u002Finode.c:856\n evict+0x4e8\u002F0x9b0 fs","2024-12-28T10:15:14.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56692",{"cveId":7257,"releaseId":31,"cycle":32,"description":7258,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7259,"url":7260},{"cveId":7257,"releaseId":25,"cycle":26,"description":7258,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7259,"url":7260},{"cveId":7264,"releaseId":25,"cycle":26,"description":7265,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7266,"url":7267},"CVE-2024-56688","In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport\n\nSince transport->sock has been set to NULL during reset transport,\nXPRT_SOCK_UPD_TIMEOUT also needs to be cleared. Otherwise, the\nxs_tcp_set_socket_timeouts() may be triggered in xs_tcp_send_request()\nto dereference the transport->sock that has been set to NULL.","2024-12-28T10:15:12.643+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56688",{"cveId":7264,"releaseId":17,"cycle":18,"description":7265,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7266,"url":7267},{"cveId":7270,"releaseId":17,"cycle":18,"description":7271,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7272,"url":7273},"CVE-2024-56681","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: bcm - add error check in the ahash_hmac_init function\n\nThe ahash_init functions may return fails. The ahash_hmac_init should\nnot return ok when ahash_init returns error. For an example, ahash_init\nwill return -ENOMEM when allocation memory is error.","2024-12-28T10:15:09.967+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56681",{"cveId":7270,"releaseId":25,"cycle":26,"description":7271,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7272,"url":7273},{"cveId":7276,"releaseId":25,"cycle":26,"description":7277,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7278,"url":7279},"CVE-2024-56662","In the Linux kernel, the following vulnerability has been resolved:\n\nacpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl\n\nFix an issue detected by syzbot with KASAN:\n\nBUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers\u002Facpi\u002Fnfit\u002F\ncore.c:416 [inline]\nBUG: KASAN: vmalloc-out-of-bounds in acpi_nfit_ctl+0x20e8\u002F0x24a0\ndrivers\u002Facpi\u002Fnfit\u002Fcore.c:459\n\nThe issue occurs in cmd_to_func when the call_pkg->nd_reserved2\narray is accessed without verifying that call_pkg points to a buffer\nthat is appro","2024-12-27T15:15:26.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56662",{"cveId":7276,"releaseId":17,"cycle":18,"description":7277,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7278,"url":7279},{"cveId":7282,"releaseId":25,"cycle":26,"description":7283,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7284,"url":7285},"CVE-2024-56651","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: hi311x: hi3110_can_ist(): fix potential use-after-free\n\nThe commit a22bd630cfff (\"can: hi311x: do not report txerr and rxerr\nduring bus-off\") removed the reporting of rxerr and txerr even in case\nof correct operation (i. e. not bus-off).\n\nThe error count information added to the CAN frame after netif_rx() is\na potential use after free, since there is no guarantee that the skb\nis in the same state. It might be freed or reus","2024-12-27T15:15:24.917+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56651",{"cveId":7282,"releaseId":17,"cycle":18,"description":7283,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7284,"url":7285},{"cveId":7288,"releaseId":25,"cycle":26,"description":7289,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7290,"url":7291},"CVE-2024-56647","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Fix icmp host relookup triggering ip_rt_bug\n\narp link failure may trigger ip_rt_bug while xfrm enabled, call trace is:\n\nWARNING: CPU: 0 PID: 0 at net\u002Fipv4\u002Froute.c:1241 ip_rt_bug+0x14\u002F0x20\nModules linked in:\nCPU: 0 UID: 0 PID: 0 Comm: swapper\u002F0 Not tainted 6.12.0-rc6-00077-g2e1b3cc9d7f7\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996),\nBIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04\u002F01\u002F2014\nRIP: 0010:ip_rt_bug+0x1","2024-12-27T15:15:24.467+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56647",{"cveId":7288,"releaseId":17,"cycle":18,"description":7289,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7290,"url":7291},{"cveId":7288,"releaseId":31,"cycle":32,"description":7289,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7290,"url":7291},{"cveId":7295,"releaseId":31,"cycle":32,"description":7296,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7297,"url":7298},"CVE-2024-56644","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fipv6: release expired exception dst cached in socket\n\nDst objects get leaked in ip6_negative_advice() when this function is\nexecuted for an expired IPv6 route located in the exception table. There\nare several conditions that must be fulfilled for the leak to occur:\n* an ICMPv6 packet indicating a change of the MTU for the path is received,\n  resulting in an exception dst being created\n* a TCP connection that uses the except","2024-12-27T15:15:24.163+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56644",{"cveId":7295,"releaseId":25,"cycle":26,"description":7296,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7297,"url":7298},{"cveId":7295,"releaseId":17,"cycle":18,"description":7296,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7297,"url":7298},{"cveId":7302,"releaseId":17,"cycle":18,"description":7303,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7304,"url":7305},"CVE-2024-56641","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: initialize close_work early to avoid warning\n\nWe encountered a warning that close_work was canceled before\ninitialization.\n\n  WARNING: CPU: 7 PID: 111103 at kernel\u002Fworkqueue.c:3047 __flush_work+0x19e\u002F0x1b0\n  Workqueue: events smc_lgr_terminate_work [smc]\n  RIP: 0010:__flush_work+0x19e\u002F0x1b0\n  Call Trace:\n   ? __wake_up_common+0x7a\u002F0x190\n   ? work_busy+0x80\u002F0x80\n   __cancel_work_timer+0xe3\u002F0x160\n   smc_close_cancel_work","2024-12-27T15:15:23.83+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56641",{"cveId":7302,"releaseId":25,"cycle":26,"description":7303,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7304,"url":7305},{"cveId":7308,"releaseId":17,"cycle":18,"description":7309,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7310,"url":7311},"CVE-2024-56640","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: fix LGR and link use-after-free issue\n\nWe encountered a LGR\u002Flink use-after-free issue, which manifested as\nthe LGR\u002Flink refcnt reaching 0 early and entering the clear process,\nmaking resource access unsafe.\n\n refcount_t: addition on 0; use-after-free.\n WARNING: CPU: 14 PID: 107447 at lib\u002Frefcount.c:25 refcount_warn_saturate+0x9c\u002F0x140\n Workqueue: events smc_lgr_terminate_work [smc]\n Call trace:\n  refcount_warn_saturate","2024-12-27T15:15:23.73+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56640",{"cveId":7313,"releaseId":25,"cycle":26,"description":7314,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7315,"url":7316},"CVE-2024-56637","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: Hold module reference while requesting a module\n\nUser space may unload ip_set.ko while it is itself requesting a set type\nbackend module, leading to a kernel crash. The race condition may be\nprovoked by inserting an mdelay() right after the nfnl_unlock() call.","2024-12-27T15:15:23.43+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56637",{"cveId":7313,"releaseId":17,"cycle":18,"description":7314,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7315,"url":7316},{"cveId":7313,"releaseId":31,"cycle":32,"description":7314,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7315,"url":7316},{"cveId":7320,"releaseId":25,"cycle":26,"description":7321,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7322,"url":7323},"CVE-2024-56631","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: sg: Fix slab-use-after-free read in sg_release()\n\nFix a use-after-free bug in sg_release(), detected by syzbot with KASAN:\n\nBUG: KASAN: slab-use-after-free in lock_release+0x151\u002F0xa30\nkernel\u002Flocking\u002Flockdep.c:5838\n__mutex_unlock_slowpath+0xe2\u002F0x750 kernel\u002Flocking\u002Fmutex.c:912\nsg_release+0x1f4\u002F0x2e0 drivers\u002Fscsi\u002Fsg.c:407\n\nIn sg_release(), the function kref_put(&sfp->f_ref, sg_remove_sfp) is\ncalled before releasing the open_","2024-12-27T15:15:22.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56631",{"cveId":7320,"releaseId":17,"cycle":18,"description":7321,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7322,"url":7323},{"cveId":7320,"releaseId":31,"cycle":32,"description":7321,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7322,"url":7323},{"cveId":7327,"releaseId":31,"cycle":32,"description":7328,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7329,"url":7330},"CVE-2024-56608","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix out-of-bounds access in 'dcn21_link_encoder_create'\n\nAn issue was identified in the dcn21_link_encoder_create function where\nan out-of-bounds access could occur when the hpd_source index was used\nto reference the link_enc_hpd_regs array. This array has a fixed size\nand the index was not being checked against the array's bounds before\naccessing it.\n\nThis fix adds a conditional check to ensure that the hpd_so","2024-12-27T15:15:20.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56608",{"cveId":7327,"releaseId":17,"cycle":18,"description":7328,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7329,"url":7330},{"cveId":7327,"releaseId":25,"cycle":26,"description":7328,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7329,"url":7330},{"cveId":7334,"releaseId":25,"cycle":26,"description":7335,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":7336,"url":7337},"CVE-2024-56602","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ieee802154: do not leave a dangling sk pointer in ieee802154_create()\n\nsock_init_data() attaches the allocated sk object to the provided sock\nobject. If ieee802154_create() fails later, the allocated sk object is\nfreed, but the dangling pointer remains in the provided sock object, which\nmay allow use-after-free.\n\nClear the sk pointer in the sock object on error.","2024-12-27T15:15:19.65+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56602",{"cveId":7334,"releaseId":17,"cycle":18,"description":7335,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":7336,"url":7337},{"cveId":7334,"releaseId":31,"cycle":32,"description":7335,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":7336,"url":7337},{"cveId":7341,"releaseId":25,"cycle":26,"description":7342,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7343,"url":7344},"CVE-2024-56598","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: array-index-out-of-bounds fix in dtReadFirst\n\nThe value of stbl can be sometimes out of bounds due\nto a bad filesystem. Added a check with appopriate return\nof error code in that case.","2024-12-27T15:15:19.2+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56598",{"cveId":7341,"releaseId":17,"cycle":18,"description":7342,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7343,"url":7344},{"cveId":7341,"releaseId":31,"cycle":32,"description":7342,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7343,"url":7344},{"cveId":7348,"releaseId":25,"cycle":26,"description":7349,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7350,"url":7351},"CVE-2024-56597","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix shift-out-of-bounds in dbSplit\n\nWhen dmt_budmin is less than zero, it causes errors\nin the later stages. Added a check to return an error beforehand\nin dbAllocCtl itself.","2024-12-27T15:15:19.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56597",{"cveId":7348,"releaseId":17,"cycle":18,"description":7349,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7350,"url":7351},{"cveId":7348,"releaseId":31,"cycle":32,"description":7349,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7350,"url":7351},{"cveId":7355,"releaseId":25,"cycle":26,"description":7356,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7357,"url":7358},"CVE-2024-56596","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in jfs_readdir\n\nThe stbl might contain some invalid values. Added a check to\nreturn error code in that case.","2024-12-27T15:15:18.963+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56596",{"cveId":7355,"releaseId":17,"cycle":18,"description":7356,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7357,"url":7358},{"cveId":7355,"releaseId":31,"cycle":32,"description":7356,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7357,"url":7358},{"cveId":7362,"releaseId":31,"cycle":32,"description":7363,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7364,"url":7365},"CVE-2024-56591","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Use disable_delayed_work_sync\n\nThis makes use of disable_delayed_work_sync instead\ncancel_delayed_work_sync as it not only cancel the ongoing work but also\ndisables new submit which is disarable since the object holding the work\nis about to be freed.","2024-12-27T15:15:18.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56591",{"cveId":7362,"releaseId":17,"cycle":18,"description":7363,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7364,"url":7365},{"cveId":7362,"releaseId":25,"cycle":26,"description":7363,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7364,"url":7365},{"cveId":7369,"releaseId":25,"cycle":26,"description":7370,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":7371,"url":7372},"CVE-2024-56590","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix not checking skb length on hci_acldata_packet\n\nThis fixes not checking if skb really contains an ACL header otherwise\nthe code may attempt to access some uninitilized\u002Finvalid memory past the\nvalid skb->data.","2024-12-27T15:15:18.263+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56590",{"cveId":7369,"releaseId":17,"cycle":18,"description":7370,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":7371,"url":7372},{"cveId":7369,"releaseId":31,"cycle":32,"description":7370,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":7371,"url":7372},{"cveId":7376,"releaseId":17,"cycle":18,"description":7377,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":7378,"url":7379},"CVE-2024-56581","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: ref-verify: fix use-after-free after invalid ref action\n\nAt btrfs_ref_tree_mod() after we successfully inserted the new ref entry\n(local variable 'ref') into the respective block entry's rbtree (local\nvariable 'be'), if we find an unexpected action of BTRFS_DROP_DELAYED_REF,\nwe error out and free the ref entry without removing it from the block\nentry's rbtree. Then in the error path of btrfs_ref_tree_mod() we call\nbtrfs_","2024-12-27T15:15:17.207+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56581",{"cveId":7381,"releaseId":17,"cycle":18,"description":7382,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7383,"url":7384},"CVE-2024-56576","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: tc358743: Fix crash in the probe error path when using polling\n\nIf an error occurs in the probe() function, we should remove the polling\ntimer that was alarmed earlier, otherwise the timer is called with\narguments that are already freed, which results in a crash.\n\n------------[ cut here ]------------\nWARNING: CPU: 3 PID: 0 at kernel\u002Ftime\u002Ftimer.c:1830 __run_timers+0x244\u002F0x268\nModules linked in:\nCPU: 3 UID: 0 PID: 0 C","2024-12-27T15:15:16.657+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56576",{"cveId":7381,"releaseId":25,"cycle":26,"description":7382,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7383,"url":7384},{"cveId":7387,"releaseId":17,"cycle":18,"description":7388,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7389,"url":7390},"CVE-2024-56531","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: caiaq: Use snd_card_free_when_closed() at disconnection\n\nThe USB disconnect callback is supposed to be short and not too-long\nwaiting.  OTOH, the current code uses snd_card_free() at\ndisconnection, but this waits for the close of all used fds, hence it\ncan take long.  It eventually blocks the upper layer USB ioctls, which\nmay trigger a soft lockup.\n\nAn easy workaround is to replace snd_card_free() with\nsnd_card_free_when_","2024-12-27T14:15:32.503+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56531",{"cveId":7387,"releaseId":25,"cycle":26,"description":7388,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7389,"url":7390},{"cveId":7387,"releaseId":31,"cycle":32,"description":7388,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7389,"url":7390},{"cveId":7394,"releaseId":17,"cycle":18,"description":7395,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7396,"url":7397},"CVE-2024-53237","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: fix use-after-free in device_for_each_child()\n\nSyzbot has reported the following KASAN splat:\n\nBUG: KASAN: slab-use-after-free in device_for_each_child+0x18f\u002F0x1a0\nRead of size 8 at addr ffff88801f605308 by task kbnepd bnep0\u002F4980\n\nCPU: 0 UID: 0 PID: 4980 Comm: kbnepd bnep0 Not tainted 6.12.0-rc4-00161-gae90f6a6170d #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04\u002F01\u002F2014\nCall Trace:\n \u003CT","2024-12-27T14:15:32.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53237",{"cveId":7399,"releaseId":31,"cycle":32,"description":7400,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7401,"url":7402},"CVE-2024-53224","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fmlx5: Move events notifier registration to be after device registration\n\nMove pkey change work initialization and cleanup from device resources\nstage to notifier stage, since this is the stage which handles this work\nevents.\n\nFix a race between the device deregistration and pkey change work by moving\nMLX5_IB_STAGE_DEVICE_NOTIFIER to be after MLX5_IB_STAGE_IB_REG in order to\nensure that the notifier is deregistered before t","2024-12-27T14:15:30.583+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53224",{"cveId":7399,"releaseId":25,"cycle":26,"description":7400,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7401,"url":7402},{"cveId":7399,"releaseId":17,"cycle":18,"description":7400,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7401,"url":7402},{"cveId":7406,"releaseId":17,"cycle":18,"description":7407,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7408,"url":7409},"CVE-2024-53217","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent NULL dereference in nfsd4_process_cb_update()\n\n@ses is initialized to NULL. If __nfsd4_find_backchannel() finds no\navailable backchannel session, setup_callback_client() will try to\ndereference @ses and segfault.","2024-12-27T14:15:29.693+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53217",{"cveId":7406,"releaseId":31,"cycle":32,"description":7407,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7408,"url":7409},{"cveId":7406,"releaseId":25,"cycle":26,"description":7407,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7408,"url":7409},{"cveId":7413,"releaseId":17,"cycle":18,"description":7414,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7415,"url":7416},"CVE-2024-53198","In the Linux kernel, the following vulnerability has been resolved:\n\nxen: Fix the issue of resource not being properly released in xenbus_dev_probe()\n\nThis patch fixes an issue in the function xenbus_dev_probe(). In the\nxenbus_dev_probe() function, within the if (err) branch at line 313, the\nprogram incorrectly returns err directly without releasing the resources\nallocated by err = drv->probe(dev, id). As the return value is non-zero,\nthe upper layers assume the processing logic has failed. Howe","2024-12-27T14:15:27.497+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53198",{"cveId":7413,"releaseId":31,"cycle":32,"description":7414,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7415,"url":7416},{"cveId":7413,"releaseId":25,"cycle":26,"description":7414,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7415,"url":7416},{"cveId":7420,"releaseId":17,"cycle":18,"description":7421,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7422,"url":7423},"CVE-2024-53179","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free of signing key\n\nCustomers have reported use-after-free in @ses->auth_key.response with\nSMB2.1 + sign mounts which occurs due to following race:\n\ntask A                         task B\ncifs_mount()\n dfs_mount_share()\n  get_session()\n   cifs_mount_get_session()    cifs_send_recv()\n    cifs_get_smb_ses()          compound_send_recv()\n     cifs_setup_session()        smb2_setup_request()\n      kfree_s","2024-12-27T14:15:25.307+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53179",{"cveId":7420,"releaseId":25,"cycle":26,"description":7421,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7422,"url":7423},{"cveId":7420,"releaseId":31,"cycle":32,"description":7421,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7422,"url":7423},{"cveId":7427,"releaseId":25,"cycle":26,"description":7428,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7429,"url":7430},"CVE-2024-53177","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: prevent use-after-free due to open_cached_dir error paths\n\nIf open_cached_dir() encounters an error parsing the lease from the\nserver, the error handling may race with receiving a lease break,\nresulting in open_cached_dir() freeing the cfid while the queued work is\npending.\n\nUpdate open_cached_dir() to drop refs rather than directly freeing the\ncfid.\n\nHave cached_dir_lease_break(), cfids_laundromat_worker(), and\ninvalidate","2024-12-27T14:15:25.067+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53177",{"cveId":7427,"releaseId":17,"cycle":18,"description":7428,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7429,"url":7430},{"cveId":7427,"releaseId":31,"cycle":32,"description":7428,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7429,"url":7430},{"cveId":7434,"releaseId":17,"cycle":18,"description":7435,"severity":40,"cvssScore":7436,"epssScore":9,"inKev":42,"publishedAt":7437,"url":7438},"CVE-2024-53165","In the Linux kernel, the following vulnerability has been resolved:\n\nsh: intc: Fix use-after-free bug in register_intc_controller()\n\nIn the error handling for this function, d is freed without ever\nremoving it from intc_list which would lead to a use after free.\nTo fix this, let's only add it to the list after everything has\nsucceeded.",7.4,"2024-12-27T14:15:23.583+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53165",{"cveId":7434,"releaseId":31,"cycle":32,"description":7435,"severity":40,"cvssScore":7436,"epssScore":9,"inKev":42,"publishedAt":7437,"url":7438},{"cveId":7434,"releaseId":25,"cycle":26,"description":7435,"severity":40,"cvssScore":7436,"epssScore":9,"inKev":42,"publishedAt":7437,"url":7438},{"cveId":7442,"releaseId":25,"cycle":26,"description":7443,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7444,"url":7445},"CVE-2024-53164","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: fix ordering of qlen adjustment\n\nChanges to sch->q.qlen around qdisc_tree_reduce_backlog() need to happen\n_before_ a call to said function because otherwise it may fail to notify\nparent qdiscs when the child is about to become empty.","2024-12-27T14:15:23.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53164",{"cveId":7442,"releaseId":17,"cycle":18,"description":7443,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7444,"url":7445},{"cveId":7442,"releaseId":31,"cycle":32,"description":7443,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7444,"url":7445},{"cveId":7449,"releaseId":25,"cycle":26,"description":7450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7451,"url":7452},"CVE-2024-53148","In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: Flush partial mappings in error case\n\nIf some remap_pfn_range() calls succeeded before one failed, we still have\nbuffer pages mapped into the userspace page tables when we drop the buffer\nreference with comedi_buf_map_put(bm). The userspace mappings are only\ncleaned up later in the mmap error path.\n\nFix it by explicitly flushing all mappings in our VMA on the error path.\n\nSee commit 79a61cc3fc04 (\"mm: avoid leaving part","2024-12-24T12:15:22.887+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53148",{"cveId":7449,"releaseId":17,"cycle":18,"description":7450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7451,"url":7452},{"cveId":7449,"releaseId":31,"cycle":32,"description":7450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7451,"url":7452},{"cveId":7456,"releaseId":25,"cycle":26,"description":7457,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":7458,"url":7459},"CVE-2024-53146","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent a potential integer overflow\n\nIf the tag length is >= U32_MAX - 3 then the \"length + 4\" addition\ncan result in an integer overflow. Address this by splitting the\ndecoding into several steps so that decode_cb_compound4res() does\nnot have to perform arithmetic on the unsafe length value.","2024-12-24T12:15:22.653+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53146",{"cveId":7456,"releaseId":17,"cycle":18,"description":7457,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":7458,"url":7459},{"cveId":7456,"releaseId":31,"cycle":32,"description":7457,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":7458,"url":7459},{"cveId":7463,"releaseId":25,"cycle":26,"description":7464,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7465,"url":7466},"CVE-2024-53144","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: Align BR\u002FEDR JUST_WORKS paring with LE\n\nThis aligned BR\u002FEDR JUST_WORKS method with LE which since 92516cd97fd4\n(\"Bluetooth: Always request for user confirmation for Just Works\")\nalways request user confirmation with confirm_hint set since the\nlikes of bluetoothd have dedicated policy around JUST_WORKS method\n(e.g. main.conf:JustWorksRepairing).\n\nCVE: CVE-2024-8805","2024-12-17T16:15:25.797+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53144",{"cveId":7463,"releaseId":17,"cycle":18,"description":7464,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7465,"url":7466},{"cveId":7463,"releaseId":31,"cycle":32,"description":7464,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7465,"url":7466},{"cveId":7470,"releaseId":31,"cycle":32,"description":7471,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7472,"url":7473},"CVE-2024-53141","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: add missing range check in bitmap_ip_uadt\n\nWhen tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists,\nthe values of ip and ip_to are slightly swapped. Therefore, the range check\nfor ip should be done later, but this part is missing and it seems that the\nvulnerability occurs.\n\nSo we should add missing range checks and remove unnecessary range checks.","2024-12-06T10:15:06.05+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53141",{"cveId":7470,"releaseId":25,"cycle":26,"description":7471,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7472,"url":7473},{"cveId":7470,"releaseId":17,"cycle":18,"description":7471,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7472,"url":7473},{"cveId":7477,"releaseId":25,"cycle":26,"description":7478,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7479,"url":7480},"CVE-2024-53140","In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: terminate outstanding dump on socket close\n\nNetlink supports iterative dumping of data. It provides the families\nthe following ops:\n - start - (optional) kicks off the dumping process\n - dump  - actual dump helper, keeps getting called until it returns 0\n - done  - (optional) pairs with .start, can be used for cleanup\nThe whole process is asynchronous and the repeated calls to .dump\ndon't actually happen in a tight loo","2024-12-04T15:15:16.803+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53140",{"cveId":7477,"releaseId":17,"cycle":18,"description":7478,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7479,"url":7480},{"cveId":7477,"releaseId":31,"cycle":32,"description":7478,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7479,"url":7480},{"cveId":7484,"releaseId":17,"cycle":18,"description":7485,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7486,"url":7487},"CVE-2024-53136","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: revert \"mm: shmem: fix data-race in shmem_getattr()\"\n\nRevert d949d1d14fa2 (\"mm: shmem: fix data-race in shmem_getattr()\") as\nsuggested by Chuck [1].  It is causing deadlocks when accessing tmpfs over\nNFS.\n\nAs Hugh commented, \"added just to silence a syzbot sanitizer splat: added\nwhere there has never been any practical problem\".","2024-12-04T15:15:13.737+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53136",{"cveId":7489,"releaseId":17,"cycle":18,"description":7490,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7491,"url":7492},"CVE-2024-53127","In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K\"\n\nThe commit 8396c793ffdf (\"mmc: dw_mmc: Fix IDMAC operation with pages\nbigger than 4K\") increased the max_req_size, even for 4K pages, causing\nvarious issues:\n- Panic booting the kernel\u002Frootfs from an SD card on Rockchip RK3566\n- Panic booting the kernel\u002Frootfs from an SD card on StarFive JH7100\n- \"swiotlb buffer is full\" and data corruption on StarFive JH7110\n","2024-12-04T15:15:12.637+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53127",{"cveId":7494,"releaseId":31,"cycle":32,"description":7495,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7496,"url":7497},"CVE-2024-53126","In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa: solidrun: Fix UB bug with devres\n\nIn psnet_open_pf_bar() and snet_open_vf_bar() a string later passed to\npcim_iomap_regions() is placed on the stack. Neither\npcim_iomap_regions() nor the functions it calls copy that string.\n\nShould the string later ever be used, this, consequently, causes\nundefined behavior since the stack frame will by then have disappeared.\n\nFix the bug by allocating the strings on the heap through\ndevm","2024-12-04T15:15:12.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53126",{"cveId":7494,"releaseId":25,"cycle":26,"description":7495,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7496,"url":7497},{"cveId":7494,"releaseId":17,"cycle":18,"description":7495,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7496,"url":7497},{"cveId":7501,"releaseId":25,"cycle":26,"description":7502,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":7503,"url":7504},"CVE-2024-53124","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix data-races around sk->sk_forward_alloc\n\nSyzkaller reported this warning:\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 16 at net\u002Fipv4\u002Faf_inet.c:156 inet_sock_destruct+0x1c5\u002F0x1e0\n Modules linked in:\n CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd\u002F0 Not tainted 6.12.0-rc5 #26\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04\u002F01\u002F2014\n RIP: 0010:inet_sock_destruct+0x1c5\u002F0x1e0\n Code: 24 12 4c 89","2024-12-02T14:15:13.22+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53124",{"cveId":7501,"releaseId":17,"cycle":18,"description":7502,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":7503,"url":7504},{"cveId":7501,"releaseId":31,"cycle":32,"description":7502,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":7503,"url":7504},{"cveId":7508,"releaseId":31,"cycle":32,"description":7509,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7510,"url":7511},"CVE-2024-53108","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Adjust VSDB parser for replay feature\n\nAt some point, the IEEE ID identification for the replay check in the\nAMD EDID was added. However, this check causes the following\nout-of-bounds issues when using KASAN:\n\n[   27.804016] BUG: KASAN: slab-out-of-bounds in amdgpu_dm_update_freesync_caps+0xefa\u002F0x17a0 [amdgpu]\n[   27.804788] Read of size 1 at addr ffff8881647fdb00 by task systemd-udevd\u002F383\n\n...\n\n[   27.821207] ","2024-12-02T14:15:11.617+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53108",{"cveId":7508,"releaseId":17,"cycle":18,"description":7509,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7510,"url":7511},{"cveId":7508,"releaseId":25,"cycle":26,"description":7509,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7510,"url":7511},{"cveId":7515,"releaseId":25,"cycle":26,"description":7516,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7517,"url":7518},"CVE-2024-53100","In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: tcp: avoid race between queue_lock lock and destroy\n\nCommit 76d54bf20cdc (\"nvme-tcp: don't access released socket during\nerror recovery\") added a mutex_lock() call for the queue->queue_lock\nin nvme_tcp_get_address(). However, the mutex_lock() races with\nmutex_destroy() in nvme_tcp_free_queue(), and causes the WARN below.\n\nDEBUG_LOCKS_WARN_ON(lock->magic != lock)\nWARNING: CPU: 3 PID: 34077 at kernel\u002Flocking\u002Fmutex.c:587 __m","2024-11-25T22:15:16.763+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53100",{"cveId":7515,"releaseId":17,"cycle":18,"description":7516,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7517,"url":7518},{"cveId":7515,"releaseId":31,"cycle":32,"description":7516,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7517,"url":7518},{"cveId":7522,"releaseId":31,"cycle":32,"description":7523,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7524,"url":7525},"CVE-2024-53099","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check validity of link->type in bpf_link_show_fdinfo()\n\nIf a newly-added link type doesn't invoke BPF_LINK_TYPE(), accessing\nbpf_link_type_strs[link->type] may result in an out-of-bounds access.\n\nTo spot such missed invocations early in the future, checking the\nvalidity of link->type in bpf_link_show_fdinfo() and emitting a warning\nwhen such invocations are missed.","2024-11-25T22:15:16.433+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53099",{"cveId":7522,"releaseId":25,"cycle":26,"description":7523,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7524,"url":7525},{"cveId":7522,"releaseId":17,"cycle":18,"description":7523,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7524,"url":7525},{"cveId":7529,"releaseId":17,"cycle":18,"description":7530,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7531,"url":7532},"CVE-2024-53095","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free of network namespace.\n\nRecently, we got a customer report that CIFS triggers oops while\nreconnecting to a server.  [0]\n\nThe workload runs on Kubernetes, and some pods mount CIFS servers\nin non-root network namespaces.  The problem rarely happened, but\nit was always while the pod was dying.\n\nThe root cause is wrong reference counting for network namespace.\n\nCIFS uses kernel sockets, which do not h","2024-11-21T19:15:12.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53095",{"cveId":7529,"releaseId":31,"cycle":32,"description":7530,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7531,"url":7532},{"cveId":7529,"releaseId":25,"cycle":26,"description":7530,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7531,"url":7532},{"cveId":7536,"releaseId":25,"cycle":26,"description":7537,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7538,"url":7539},"CVE-2024-53094","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fsiw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES\n\nWhile running ISER over SIW, the initiator machine encounters a warning\nfrom skb_splice_from_iter() indicating that a slab page is being used in\nsend_page. To address this, it is better to add a sendpage_ok() check\nwithin the driver itself, and if it returns 0, then MSG_SPLICE_PAGES flag\nshould be disabled before entering the network stack.\n\nA similar issue has been","2024-11-21T19:15:12.68+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53094",{"cveId":7536,"releaseId":31,"cycle":32,"description":7537,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7538,"url":7539},{"cveId":7536,"releaseId":17,"cycle":18,"description":7537,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7538,"url":7539},{"cveId":7543,"releaseId":31,"cycle":32,"description":7544,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7545,"url":7546},"CVE-2024-53093","In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-multipath: defer partition scanning\n\nWe need to suppress the partition scan from occuring within the\ncontroller's scan_work context. If a path error occurs here, the IO will\nwait until a path becomes available or all paths are torn down, but that\naction also occurs within scan_work, so it would deadlock. Defer the\npartion scan to a different context that does not block scan_work.","2024-11-21T19:15:12.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53093",{"cveId":7543,"releaseId":25,"cycle":26,"description":7544,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7545,"url":7546},{"cveId":7543,"releaseId":17,"cycle":18,"description":7544,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7545,"url":7546},{"cveId":7550,"releaseId":31,"cycle":32,"description":7551,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7552,"url":7553},"CVE-2024-53090","In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix lock recursion\n\nafs_wake_up_async_call() can incur lock recursion.  The problem is that it\nis called from AF_RXRPC whilst holding the ->notify_lock, but it tries to\ntake a ref on the afs_call struct in order to pass it to a work queue - but\nif the afs_call is already queued, we then have an extraneous ref that must\nbe put... calling afs_put_call() may call back down into AF_RXRPC through\nrxrpc_kernel_shutdown_call(), h","2024-11-21T19:15:12.01+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53090",{"cveId":7550,"releaseId":25,"cycle":26,"description":7551,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7552,"url":7553},{"cveId":7550,"releaseId":17,"cycle":18,"description":7551,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7552,"url":7553},{"cveId":7557,"releaseId":25,"cycle":26,"description":7558,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7559,"url":7560},"CVE-2024-53088","In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: fix race condition by adding filter's intermediate sync state\n\nFix a race condition in the i40e driver that leads to MAC\u002FVLAN filters\nbecoming corrupted and leaking. Address the issue that occurs under\nheavy load when multiple threads are concurrently modifying MAC\u002FVLAN\nfilters by setting mac and port VLAN.\n\n1. Thread T0 allocates a filter in i40e_add_filter() within\n        i40e_ndo_set_vf_port_vlan().\n2. Thread T1 concu","2024-11-19T18:15:27.95+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53088",{"cveId":7557,"releaseId":17,"cycle":18,"description":7558,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7559,"url":7560},{"cveId":7563,"releaseId":17,"cycle":18,"description":7564,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7565,"url":7566},"CVE-2024-53066","In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: Fix KMSAN warning in decode_getfattr_attrs()\n\nFix the following KMSAN warning:\n\nCPU: 1 UID: 0 PID: 7651 Comm: cp Tainted: G    B\nTainted: [B]=BAD_PAGE\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009)\n=====================================================\n=====================================================\nBUG: KMSAN: uninit-value in decode_getfattr_attrs+0x2d6d\u002F0x2f90\n decode_getfattr_attrs+0x2d6d\u002F0x2f90\n decode_getfatt","2024-11-19T18:15:26.413+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53066",{"cveId":7563,"releaseId":25,"cycle":26,"description":7564,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7565,"url":7566},{"cveId":7563,"releaseId":31,"cycle":32,"description":7564,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7565,"url":7566},{"cveId":7570,"releaseId":17,"cycle":18,"description":7571,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7572,"url":7573},"CVE-2024-53063","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvbdev: prevent the risk of out of memory access\n\nThe dvbdev contains a static variable used to store dvb minors.\n\nThe behavior of it depends if CONFIG_DVB_DYNAMIC_MINORS is set\nor not. When not set, dvb_register_device() won't check for\nboundaries, as it will rely that a previous call to\ndvb_register_adapter() would already be enforcing it.\n\nOn a similar way, dvb_device_open() uses the assumption\nthat the register funct","2024-11-19T18:15:26.18+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53063",{"cveId":7570,"releaseId":31,"cycle":32,"description":7571,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7572,"url":7573},{"cveId":7570,"releaseId":25,"cycle":26,"description":7571,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7572,"url":7573},{"cveId":7577,"releaseId":25,"cycle":26,"description":7578,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7579,"url":7580},"CVE-2024-53061","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: s5p-jpeg: prevent buffer overflows\n\nThe current logic allows word to be less than 2. If this happens,\nthere will be buffer overflows, as reported by smatch. Add extra\nchecks to prevent it.\n\nWhile here, remove an unused word = 0 assignment.","2024-11-19T18:15:25.997+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53061",{"cveId":7577,"releaseId":31,"cycle":32,"description":7578,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7579,"url":7580},{"cveId":7577,"releaseId":17,"cycle":18,"description":7578,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7579,"url":7580},{"cveId":7584,"releaseId":25,"cycle":26,"description":7585,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":7586,"url":7587},"CVE-2024-53058","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: TSO: Fix unbalanced DMA map\u002Funmap for non-paged SKB data\n\nIn case the non-paged data of a SKB carries protocol header and protocol\npayload to be transmitted on a certain platform that the DMA AXI address\nwidth is configured to 40-bit\u002F48-bit, or the size of the non-paged data\nis bigger than TSO_MAX_BUFF_SIZE on a certain platform that the DMA AXI\naddress width is configured to 32-bit, then this SKB requires at least","2024-11-19T18:15:25.767+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-53058",{"cveId":7584,"releaseId":17,"cycle":18,"description":7585,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":7586,"url":7587},{"cveId":7584,"releaseId":31,"cycle":32,"description":7585,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":7586,"url":7587},{"cveId":7591,"releaseId":31,"cycle":32,"description":7592,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7593,"url":7594},"CVE-2024-50301","In the Linux kernel, the following vulnerability has been resolved:\n\nsecurity\u002Fkeys: fix slab-out-of-bounds in key_task_permission\n\nKASAN reports an out of bounds read:\nBUG: KASAN: slab-out-of-bounds in __kuid_val include\u002Flinux\u002Fuidgid.h:36\nBUG: KASAN: slab-out-of-bounds in uid_eq include\u002Flinux\u002Fuidgid.h:63 [inline]\nBUG: KASAN: slab-out-of-bounds in key_task_permission+0x394\u002F0x410\nsecurity\u002Fkeys\u002Fpermission.c:54\nRead of size 4 at addr ffff88813c3ab618 by task stress-ng\u002F4362\n\nCPU: 2 PID: 4362 Comm: st","2024-11-19T02:16:32.23+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50301",{"cveId":7591,"releaseId":25,"cycle":26,"description":7592,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7593,"url":7594},{"cveId":7591,"releaseId":17,"cycle":18,"description":7592,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7593,"url":7594},{"cveId":7598,"releaseId":31,"cycle":32,"description":7599,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":7600,"url":7601},"CVE-2024-50299","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: properly validate chunk size in sctp_sf_ootb()\n\nA size validation fix similar to that in Commit 50619dbf8db7 (\"sctp: add\nsize validation when walking chunks\") is also required in sctp_sf_ootb()\nto address a crash reported by syzbot:\n\n  BUG: KMSAN: uninit-value in sctp_sf_ootb+0x7f5\u002F0xce0 net\u002Fsctp\u002Fsm_statefuns.c:3712\n  sctp_sf_ootb+0x7f5\u002F0xce0 net\u002Fsctp\u002Fsm_statefuns.c:3712\n  sctp_do_sm+0x181\u002F0x93d0 net\u002Fsctp\u002Fsm_sideeffect.c:","2024-11-19T02:16:32.053+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50299",{"cveId":7598,"releaseId":25,"cycle":26,"description":7599,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":7600,"url":7601},{"cveId":7598,"releaseId":17,"cycle":18,"description":7599,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":7600,"url":7601},{"cveId":7605,"releaseId":25,"cycle":26,"description":7606,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7607,"url":7608},"CVE-2024-50286","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix slab-use-after-free in ksmbd_smb2_session_create\n\nThere is a race condition between ksmbd_smb2_session_create and\nksmbd_expire_session. This patch add missing sessions_table_lock\nwhile adding\u002Fdeleting session from global session table.","2024-11-19T02:16:30.86+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50286",{"cveId":7605,"releaseId":31,"cycle":32,"description":7606,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7607,"url":7608},{"cveId":7605,"releaseId":17,"cycle":18,"description":7606,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7607,"url":7608},{"cveId":7612,"releaseId":31,"cycle":32,"description":7613,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7614,"url":7615},"CVE-2024-50285","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: check outstanding simultaneous SMB operations\n\nIf Client send simultaneous SMB operations to ksmbd, It exhausts too much\nmemory through the \"ksmbd_work_cache”. It will cause OOM issue.\nksmbd has a credit mechanism but it can't handle this problem. This patch\nadd the check if it exceeds max credits to prevent this problem by assuming\nthat one smb request consumes at least one credit.","2024-11-19T02:16:30.787+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50285",{"cveId":7612,"releaseId":25,"cycle":26,"description":7613,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7614,"url":7615},{"cveId":7612,"releaseId":17,"cycle":18,"description":7613,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7614,"url":7615},{"cveId":7619,"releaseId":25,"cycle":26,"description":7620,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7621,"url":7622},"CVE-2024-50283","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix slab-use-after-free in smb3_preauth_hash_rsp\n\nksmbd_user_session_put should be called under smb3_preauth_hash_rsp().\nIt will avoid freeing session before calling smb3_preauth_hash_rsp().","2024-11-19T02:16:30.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50283",{"cveId":7619,"releaseId":31,"cycle":32,"description":7620,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7621,"url":7622},{"cveId":7619,"releaseId":17,"cycle":18,"description":7620,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7621,"url":7622},{"cveId":7626,"releaseId":25,"cycle":26,"description":7627,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7628,"url":7629},"CVE-2024-50273","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reinitialize delayed ref list after deleting it from the list\n\nAt insert_delayed_ref() if we need to update the action of an existing\nref to BTRFS_DROP_DELAYED_REF, we delete the ref from its ref head's\nref_add_list using list_del(), which leaves the ref's add_list member\nnot reinitialized, as list_del() sets the next and prev members of the\nlist to LIST_POISON1 and LIST_POISON2, respectively.\n\nIf later we end up calling","2024-11-19T02:16:29.483+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50273",{"cveId":7626,"releaseId":17,"cycle":18,"description":7627,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7628,"url":7629},{"cveId":7632,"releaseId":31,"cycle":32,"description":7633,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7634,"url":7635},"CVE-2024-50256","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6()\n\nI got a syzbot report without a repro [1] crashing in nf_send_reset6()\n\nI think the issue is that dev->hard_header_len is zero, and we attempt\nlater to push an Ethernet header.\n\nUse LL_MAX_HEADER, as other functions in net\u002Fipv6\u002Fnetfilter\u002Fnf_reject_ipv6.c.\n\n[1]\n\nskbuff: skb_under_panic: text:ffffffff89b1d008 len:74 put:14 head:ffff88803123aa00 data:ffff88803123a","2024-11-09T11:15:11.263+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50256",{"cveId":7632,"releaseId":25,"cycle":26,"description":7633,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7634,"url":7635},{"cveId":7632,"releaseId":17,"cycle":18,"description":7633,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7634,"url":7635},{"cveId":7639,"releaseId":17,"cycle":18,"description":7640,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7641,"url":7642},"CVE-2024-50248","In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: Add bounds checking to mi_enum_attr()\n\nAdded bounds checking to make sure that every attr don't stray beyond\nvalid memory region.","2024-11-09T11:15:10.67+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50248",{"cveId":7639,"releaseId":25,"cycle":26,"description":7640,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7641,"url":7642},{"cveId":7639,"releaseId":31,"cycle":32,"description":7640,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7641,"url":7642},{"cveId":7646,"releaseId":31,"cycle":32,"description":7647,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7648,"url":7649},"CVE-2024-50247","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Fntfs3: Check if more than chunk-size bytes are written\n\nA incorrectly formatted chunk may decompress into\nmore than LZNT_CHUNK_SIZE bytes and a index out of bounds\nwill occur in s_max_off.","2024-11-09T11:15:10.6+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50247",{"cveId":7646,"releaseId":25,"cycle":26,"description":7647,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7648,"url":7649},{"cveId":7646,"releaseId":17,"cycle":18,"description":7647,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7648,"url":7649},{"cveId":7653,"releaseId":31,"cycle":32,"description":7654,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7655,"url":7656},"CVE-2024-50246","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Fntfs3: Add rough attr alloc_size check","2024-11-09T11:15:10.537+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50246",{"cveId":7653,"releaseId":25,"cycle":26,"description":7654,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7655,"url":7656},{"cveId":7653,"releaseId":17,"cycle":18,"description":7654,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7655,"url":7656},{"cveId":7660,"releaseId":25,"cycle":26,"description":7661,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7662,"url":7663},"CVE-2024-50237","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: do not pass a stopped vif to the driver in .get_txpower\n\nAvoid potentially crashing in the driver because of uninitialized private data","2024-11-09T11:15:09.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50237",{"cveId":7660,"releaseId":31,"cycle":32,"description":7661,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7662,"url":7663},{"cveId":7660,"releaseId":17,"cycle":18,"description":7661,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7662,"url":7663},{"cveId":7667,"releaseId":17,"cycle":18,"description":7668,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7669,"url":7670},"CVE-2024-50230","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix kernel bug due to missing clearing of checked flag\n\nSyzbot reported that in directory operations after nilfs2 detects\nfilesystem corruption and degrades to read-only,\n__block_write_begin_int(), which is called to prepare block writes, may\nfail the BUG_ON check for accesses exceeding the folio\u002Fpage size,\ntriggering a kernel bug.\n\nThis was found to be because the \"checked\" flag of a page\u002Ffolio was not\ncleared when it ","2024-11-09T11:15:08.973+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50230",{"cveId":7667,"releaseId":25,"cycle":26,"description":7668,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7669,"url":7670},{"cveId":7667,"releaseId":31,"cycle":32,"description":7668,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7669,"url":7670},{"cveId":7674,"releaseId":31,"cycle":32,"description":7675,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7676,"url":7677},"CVE-2024-50217","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()\n\nMounting btrfs from two images (which have the same one fsid and two\ndifferent dev_uuids) in certain executing order may trigger an UAF for\nvariable 'device->bdev_file' in __btrfs_free_extra_devids(). And\nfollowing are the details:\n\n1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs\n   devices by ioctl(BTRFS_IOC_SCAN_DEV):\n\n         ","2024-11-09T11:15:07.103+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50217",{"cveId":7674,"releaseId":17,"cycle":18,"description":7675,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7676,"url":7677},{"cveId":7674,"releaseId":25,"cycle":26,"description":7675,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7676,"url":7677},{"cveId":7681,"releaseId":31,"cycle":32,"description":7682,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7683,"url":7684},"CVE-2024-50211","In the Linux kernel, the following vulnerability has been resolved:\n\nudf: refactor inode_bmap() to handle error\n\nRefactor inode_bmap() to handle error since udf_next_aext() can return\nerror now. On situations like ftruncate, udf_extend_file() can now\ndetect errors and bail out early without resorting to checking for\nparticular offsets and assuming internal behavior of these functions.","2024-11-08T06:15:17.41+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50211",{"cveId":7681,"releaseId":25,"cycle":26,"description":7682,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7683,"url":7684},{"cveId":7681,"releaseId":17,"cycle":18,"description":7682,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7683,"url":7684},{"cveId":7688,"releaseId":31,"cycle":32,"description":7689,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7690,"url":7691},"CVE-2024-50195","In the Linux kernel, the following vulnerability has been resolved:\n\nposix-clock: Fix missing timespec64 check in pc_clock_settime()\n\nAs Andrew pointed out, it will make sense that the PTP core\nchecked timespec64 struct's tv_sec and tv_nsec range before calling\nptp->info->settime64().\n\nAs the man manual of clock_settime() said, if tp.tv_sec is negative or\ntp.tv_nsec is outside the range [0..999,999,999], it should return EINVAL,\nwhich include dynamic clocks which handles PTP clock, and the condi","2024-11-08T06:15:16.28+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50195",{"cveId":7688,"releaseId":25,"cycle":26,"description":7689,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7690,"url":7691},{"cveId":7688,"releaseId":17,"cycle":18,"description":7689,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":7690,"url":7691},{"cveId":7695,"releaseId":17,"cycle":18,"description":7696,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7697,"url":7698},"CVE-2024-50187","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvc4: Stop the active perfmon before being destroyed\n\nUpon closing the file descriptor, the active performance monitor is not\nstopped. Although all perfmons are destroyed in `vc4_perfmon_close_file()`,\nthe active performance monitor's pointer (`vc4->active_perfmon`) is still\nretained.\n\nIf we open a new file descriptor and submit a few jobs with performance\nmonitors, the driver will attempt to stop the active performance moni","2024-11-08T06:15:15.77+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50187",{"cveId":7700,"releaseId":17,"cycle":18,"description":7701,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7702,"url":7703},"CVE-2024-50154","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp\u002Fdccp: Don't use timer_pending() in reqsk_queue_unlink().\n\nMartin KaFai Lau reported use-after-free [0] in reqsk_timer_handler().\n\n  \"\"\"\n  We are seeing a use-after-free from a bpf prog attached to\n  trace_tcp_retransmit_synack. The program passes the req->sk to the\n  bpf_sk_storage_get_tracing kernel helper which does check for null\n  before using it.\n  \"\"\"\n\nThe commit 83fccfc3940c (\"inet: fix potential deadlock in\nreqsk_qu","2024-11-07T10:15:06.987+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50154",{"cveId":7700,"releaseId":31,"cycle":32,"description":7701,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7702,"url":7703},{"cveId":7700,"releaseId":25,"cycle":26,"description":7701,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7702,"url":7703},{"cveId":7707,"releaseId":17,"cycle":18,"description":7708,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7709,"url":7710},"CVE-2024-50143","In the Linux kernel, the following vulnerability has been resolved:\n\nudf: fix uninit-value use in udf_get_fileshortad\n\nCheck for overflow when computing alen in udf_current_aext to mitigate\nlater uninit-value use in udf_get_fileshortad KMSAN bug[1].\nAfter applying the patch reproducer did not trigger any issue[2].\n\n[1] https:\u002F\u002Fsyzkaller.appspot.com\u002Fbug?extid=8901c4560b7ab5c2f9df\n[2] https:\u002F\u002Fsyzkaller.appspot.com\u002Fx\u002Flog.txt?x=10242227980000","2024-11-07T10:15:06.243+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50143",{"cveId":7707,"releaseId":25,"cycle":26,"description":7708,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7709,"url":7710},{"cveId":7707,"releaseId":31,"cycle":32,"description":7708,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7709,"url":7710},{"cveId":7714,"releaseId":25,"cycle":26,"description":7715,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":7716,"url":7717},"CVE-2024-50125","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: Fix UAF on sco_sock_timeout\n\nconn->sk maybe have been unlinked\u002Ffreed while waiting for sco_conn_lock\nso this checks if the conn->sk is still valid by checking if it part of\nsco_sk_list.","2024-11-05T18:15:15.55+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50125",{"cveId":7714,"releaseId":17,"cycle":18,"description":7715,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":7716,"url":7717},{"cveId":7720,"releaseId":25,"cycle":26,"description":7721,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7722,"url":7723},"CVE-2024-50117","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd: Guard against bad data for ATIF ACPI method\n\nIf a BIOS provides bad data in response to an ATIF method call\nthis causes a NULL pointer dereference in the caller.\n\n```\n? show_regs (arch\u002Fx86\u002Fkernel\u002Fdumpstack.c:478 (discriminator 1))\n? __die (arch\u002Fx86\u002Fkernel\u002Fdumpstack.c:423 arch\u002Fx86\u002Fkernel\u002Fdumpstack.c:434)\n? page_fault_oops (arch\u002Fx86\u002Fmm\u002Ffault.c:544 (discriminator 2) arch\u002Fx86\u002Fmm\u002Ffault.c:705 (discriminator 2))\n? do_user_add","2024-11-05T18:15:14.823+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50117",{"cveId":7720,"releaseId":17,"cycle":18,"description":7721,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7722,"url":7723},{"cveId":7720,"releaseId":31,"cycle":32,"description":7721,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7722,"url":7723},{"cveId":7727,"releaseId":31,"cycle":32,"description":7728,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":7729,"url":7730},"CVE-2024-50115","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory\n\nIgnore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits\n4:0 of CR3 are ignored when PAE paging is used, and thus VMRUN doesn't\nenforce 32-byte alignment of nCR3.\n\nIn the absolute worst case scenario, failure to ignore bits 4:0 can result\nin an out-of-bounds read, e.g. if the target page is at the end of a\nmemslot, and the VMM isn't using guard pages.\n","2024-11-05T18:15:14.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50115",{"cveId":7727,"releaseId":25,"cycle":26,"description":7728,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":7729,"url":7730},{"cveId":7727,"releaseId":17,"cycle":18,"description":7728,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":7729,"url":7730},{"cveId":7734,"releaseId":25,"cycle":26,"description":7735,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7736,"url":7737},"CVE-2024-50106","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix race between laundromat and free_stateid\n\nThere is a race between laundromat handling of revoked delegations\nand a client sending free_stateid operation. Laundromat thread\nfinds that delegation has expired and needs to be revoked so it\nmarks the delegation stid revoked and it puts it on a reaper list\nbut then it unlock the state lock and the actual delegation revocation\nhappens without the lock. Once the stid is marke","2024-11-05T18:15:14.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50106",{"cveId":7734,"releaseId":31,"cycle":32,"description":7735,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7736,"url":7737},{"cveId":7734,"releaseId":17,"cycle":18,"description":7735,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7736,"url":7737},{"cveId":7741,"releaseId":17,"cycle":18,"description":7742,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7743,"url":7744},"CVE-2024-50099","In the Linux kernel, the following vulnerability has been resolved:\n\narm64: probes: Remove broken LDR (literal) uprobe support\n\nThe simulate_ldr_literal() and simulate_ldrsw_literal() functions are\nunsafe to use for uprobes. Both functions were originally written for\nuse with kprobes, and access memory with plain C accesses. When uprobes\nwas added, these were reused unmodified even though they cannot safely\naccess user memory.\n\nThere are three key problems:\n\n1) The plain C accesses do not have c","2024-11-05T18:15:13.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50099",{"cveId":7741,"releaseId":25,"cycle":26,"description":7742,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7743,"url":7744},{"cveId":7747,"releaseId":31,"cycle":32,"description":7748,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7749,"url":7750},"CVE-2024-50095","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fmad: Improve handling of timed out WRs of mad agent\n\nCurrent timeout handler of mad agent acquires\u002Freleases mad_agent_priv\nlock for every timed out WRs. This causes heavy locking contention\nwhen higher no. of WRs are to be handled inside timeout handler.\n\nThis leads to softlockup with below trace in some use cases where\nrdma-cm path is used to establish connection between peer nodes\n\nTrace:\n-----\n BUG: soft lockup - CPU#4 ","2024-11-05T17:15:06.797+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50095",{"cveId":7747,"releaseId":25,"cycle":26,"description":7748,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7749,"url":7750},{"cveId":7747,"releaseId":17,"cycle":18,"description":7748,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7749,"url":7750},{"cveId":7754,"releaseId":25,"cycle":26,"description":7755,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7756,"url":7757},"CVE-2024-50091","In the Linux kernel, the following vulnerability has been resolved:\n\ndm vdo: don't refer to dedupe_context after releasing it\n\nClear the dedupe_context pointer in a data_vio whenever ownership of\nthe context is lost, so that vdo can't examine it accidentally.","2024-11-05T17:15:06.533+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50091",{"cveId":7754,"releaseId":17,"cycle":18,"description":7755,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7756,"url":7757},{"cveId":7754,"releaseId":31,"cycle":32,"description":7755,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7756,"url":7757},{"cveId":7761,"releaseId":25,"cycle":26,"description":7762,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7763,"url":7764},"CVE-2024-50090","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fxe\u002Foa: Fix overflow in oa batch buffer\n\nBy default xe_bb_create_job() appends a MI_BATCH_BUFFER_END to batch\nbuffer, this is not a problem if batch buffer is only used once but\noa reuses the batch buffer for the same metric and at each call\nit appends a MI_BATCH_BUFFER_END, printing the warning below and then\noverflowing.\n\n[  381.072016] ------------[ cut here ]------------\n[  381.072019] xe 0000:00:02.0: [drm] Assertion `b","2024-11-05T17:15:06.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50090",{"cveId":7761,"releaseId":17,"cycle":18,"description":7762,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7763,"url":7764},{"cveId":7761,"releaseId":31,"cycle":32,"description":7762,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7763,"url":7764},{"cveId":7768,"releaseId":31,"cycle":32,"description":7769,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7770,"url":7771},"CVE-2023-52920","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: support non-r10 register spill\u002Ffill to\u002Ffrom stack in precision tracking\n\nUse instruction (jump) history to record instructions that performed\nregister spill\u002Ffill to\u002Ffrom stack, regardless if this was done through\nread-only r10 register, or any other register after copying r10 into it\n*and* potentially adjusting offset.\n\nTo make this work reliably, we push extra per-instruction flags into\ninstruction history, encoding stack","2024-11-05T10:15:24.58+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52920",{"cveId":7768,"releaseId":17,"cycle":18,"description":7769,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7770,"url":7771},{"cveId":7768,"releaseId":25,"cycle":26,"description":7769,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7770,"url":7771},{"cveId":7775,"releaseId":17,"cycle":18,"description":7776,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7777,"url":7778},"CVE-2024-50086","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix user-after-free from session log off\n\nThere is racy issue between smb2 session log off and smb2 session setup.\nIt will cause user-after-free from session log off.\nThis add session_lock when setting SMB2_SESSION_EXPIRED and referece\ncount to session struct not to free session while it is being used.","2024-10-29T01:15:05.487+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50086",{"cveId":7775,"releaseId":25,"cycle":26,"description":7776,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7777,"url":7778},{"cveId":7775,"releaseId":31,"cycle":32,"description":7776,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7777,"url":7778},{"cveId":7782,"releaseId":17,"cycle":18,"description":7783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7784,"url":7785},"CVE-2024-50082","In the Linux kernel, the following vulnerability has been resolved:\n\nblk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race\n\nWe're seeing crashes from rq_qos_wake_function that look like this:\n\n  BUG: unable to handle page fault for address: ffffafe180a40084\n  #PF: supervisor write access in kernel mode\n  #PF: error_code(0x0002) - not-present page\n  PGD 100000067 P4D 100000067 PUD 10027c067 PMD 10115d067 PTE 0\n  Oops: Oops: 0002 [#1] PREEMPT SMP PTI\n  CPU: 17 UID: 0 PID: 0 Comm: swap","2024-10-29T01:15:05.147+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50082",{"cveId":7787,"releaseId":25,"cycle":26,"description":7788,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7789,"url":7790},"CVE-2024-50062","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Frtrs-srv: Avoid null pointer deref during path establishment\n\nFor RTRS path establishment, RTRS client initiates and completes con_num\nof connections. After establishing all its connections, the information\nis exchanged between the client and server through the info_req message.\nDuring this exchange, it is essential that all connections have been\nestablished, and the state of the RTRS srv path is CONNECTED.\n\nSo add these s","2024-10-21T20:15:18.28+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50062",{"cveId":7787,"releaseId":31,"cycle":32,"description":7788,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7789,"url":7790},{"cveId":7787,"releaseId":17,"cycle":18,"description":7788,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7789,"url":7790},{"cveId":7794,"releaseId":31,"cycle":32,"description":7795,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7796,"url":7797},"CVE-2024-50059","In the Linux kernel, the following vulnerability has been resolved:\n\nntb: ntb_hw_switchtec: Fix use after free vulnerability in switchtec_ntb_remove due to race condition\n\nIn the switchtec_ntb_add function, it can call switchtec_ntb_init_sndev\nfunction, then &sndev->check_link_status_work is bound with\ncheck_link_status_work. switchtec_ntb_link_notification may be called\nto start the work.\n\nIf we remove the module which will call switchtec_ntb_remove to make\ncleanup, it will free sndev through k","2024-10-21T20:15:18.057+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50059",{"cveId":7794,"releaseId":25,"cycle":26,"description":7795,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7796,"url":7797},{"cveId":7794,"releaseId":17,"cycle":18,"description":7795,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7796,"url":7797},{"cveId":7801,"releaseId":25,"cycle":26,"description":7802,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7803,"url":7804},"CVE-2024-50055","In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: bus: Fix double free in driver API bus_register()\n\nFor bus_register(), any error which happens after kset_register() will\ncause that @priv are freed twice, fixed by setting @priv with NULL after\nthe first free.","2024-10-21T20:15:17.77+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50055",{"cveId":7801,"releaseId":31,"cycle":32,"description":7802,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7803,"url":7804},{"cveId":7801,"releaseId":17,"cycle":18,"description":7802,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7803,"url":7804},{"cveId":7808,"releaseId":31,"cycle":32,"description":7809,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7810,"url":7811},"CVE-2024-50047","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix UAF in async decryption\n\nDoing an async decryption (large read) crashes with a\nslab-use-after-free way down in the crypto API.\n\nReproducer:\n    # mount.cifs -o ...,seal,esize=1 \u002F\u002Fsrv\u002Fshare \u002Fmnt\n    # dd if=\u002Fmnt\u002Flargefile of=\u002Fdev\u002Fnull\n    ...\n    [  194.196391] ==================================================================\n    [  194.196844] BUG: KASAN: slab-use-after-free in gf128mul_4k_lle+0xc1\u002F0x110\n    [","2024-10-21T20:15:17.507+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50047",{"cveId":7808,"releaseId":17,"cycle":18,"description":7809,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7810,"url":7811},{"cveId":7808,"releaseId":25,"cycle":26,"description":7809,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7810,"url":7811},{"cveId":7815,"releaseId":25,"cycle":26,"description":7816,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7817,"url":7818},"CVE-2024-50045","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: br_netfilter: fix panic with metadata_dst skb\n\nFix a kernel panic in the br_netfilter module when sending untagged\ntraffic via a VxLAN device.\nThis happens during the check for fragmentation in br_nf_dev_queue_xmit.\n\nIt is dependent on:\n1) the br_netfilter module being loaded;\n2) net.bridge.bridge-nf-call-iptables set to 1;\n3) a bridge with a VxLAN (single-vxlan-device) netdevice as a bridge port;\n4) untagged frames ","2024-10-21T20:15:17.373+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50045",{"cveId":7815,"releaseId":17,"cycle":18,"description":7816,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":7817,"url":7818},{"cveId":7821,"releaseId":31,"cycle":32,"description":7822,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7823,"url":7824},"CVE-2024-50039","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: accept TCA_STAB only for root qdisc\n\nMost qdiscs maintain their backlog using qdisc_pkt_len(skb)\non the assumption it is invariant between the enqueue()\nand dequeue() handlers.\n\nUnfortunately syzbot can crash a host rather easily using\na TBF + SFQ combination, with an STAB on SFQ [1]\n\nWe can't support TCA_STAB on arbitrary level, this would\nrequire to maintain per-qdisc storage.\n\n[1]\n[   88.796496] BUG: kernel NULL p","2024-10-21T20:15:16.957+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50039",{"cveId":7821,"releaseId":25,"cycle":26,"description":7822,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7823,"url":7824},{"cveId":7821,"releaseId":17,"cycle":18,"description":7822,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7823,"url":7824},{"cveId":7828,"releaseId":17,"cycle":18,"description":7829,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7830,"url":7831},"CVE-2024-50036","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: do not delay dst_entries_add() in dst_release()\n\ndst_entries_add() uses per-cpu data that might be freed at netns\ndismantle from ip6_route_net_exit() calling dst_entries_destroy()\n\nBefore ip6_route_net_exit() can be called, we release all\nthe dsts associated with this netns, via calls to dst_release(),\nwhich waits an rcu grace period before calling dst_destroy()\n\ndst_entries_add() use in dst_destroy() is racy, because\ndst_","2024-10-21T20:15:16.717+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50036",{"cveId":7828,"releaseId":31,"cycle":32,"description":7829,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7830,"url":7831},{"cveId":7828,"releaseId":25,"cycle":26,"description":7829,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7830,"url":7831},{"cveId":7835,"releaseId":25,"cycle":26,"description":7836,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7837,"url":7838},"CVE-2024-50033","In the Linux kernel, the following vulnerability has been resolved:\n\nslip: make slhc_remember() more robust against malicious packets\n\nsyzbot found that slhc_remember() was missing checks against\nmalicious packets [1].\n\nslhc_remember() only checked the size of the packet was at least 20,\nwhich is not good enough.\n\nWe need to make sure the packet includes the IPv4 and TCP header\nthat are supposed to be carried.\n\nAdd iph and th pointers to make the code more readable.\n\n[1]\n\nBUG: KMSAN: uninit-valu","2024-10-21T20:15:16.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50033",{"cveId":7835,"releaseId":17,"cycle":18,"description":7836,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7837,"url":7838},{"cveId":7835,"releaseId":31,"cycle":32,"description":7836,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":7837,"url":7838},{"cveId":7842,"releaseId":25,"cycle":26,"description":7843,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7844,"url":7845},"CVE-2024-50024","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Fix an unsafe loop on the list\n\nThe kernel may crash when deleting a genetlink family if there are still\nlisteners for that family:\n\nOops: Kernel access of bad area, sig: 11 [#1]\n  ...\n  NIP [c000000000c080bc] netlink_update_socket_mc+0x3c\u002F0xc0\n  LR [c000000000c0f764] __netlink_clear_multicast_users+0x74\u002F0xc0\n  Call Trace:\n__netlink_clear_multicast_users+0x74\u002F0xc0\ngenl_unregister_family+0xd4\u002F0x2d0\n\nChange the unsafe loop o","2024-10-21T20:15:15.85+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50024",{"cveId":7842,"releaseId":31,"cycle":32,"description":7843,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7844,"url":7845},{"cveId":7842,"releaseId":17,"cycle":18,"description":7843,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":7844,"url":7845},{"cveId":7849,"releaseId":17,"cycle":18,"description":7850,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7851,"url":7852},"CVE-2022-49029","In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails\n\nSmatch report warning as follows:\n\ndrivers\u002Fhwmon\u002Fibmpex.c:509 ibmpex_register_bmc() warn:\n  '&data->list' not removed from list\n\nIf ibmpex_find_sensors() fails in ibmpex_register_bmc(), data will\nbe freed, but data->list will not be removed from driver_data.bmc_data,\nthen list traversal may cause UAF.\n\nFix by removeing it from driver_data.bmc_data before free().","2024-10-21T20:15:13.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49029",{"cveId":7849,"releaseId":25,"cycle":26,"description":7850,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7851,"url":7852},{"cveId":7849,"releaseId":31,"cycle":32,"description":7850,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7851,"url":7852},{"cveId":7856,"releaseId":31,"cycle":32,"description":7857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7858,"url":7859},"CVE-2022-49026","In the Linux kernel, the following vulnerability has been resolved:\n\ne100: Fix possible use after free in e100_xmit_prepare\n\nIn e100_xmit_prepare(), if we can't map the skb, then return -ENOMEM, so\ne100_xmit_frame() will return NETDEV_TX_BUSY and the upper layer will\nresend the skb. But the skb is already freed, which will cause UAF bug\nwhen the upper layer resends the skb.\n\nRemove the harmful free.","2024-10-21T20:15:13.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49026",{"cveId":7856,"releaseId":17,"cycle":18,"description":7857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7858,"url":7859},{"cveId":7856,"releaseId":25,"cycle":26,"description":7857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7858,"url":7859},{"cveId":7863,"releaseId":17,"cycle":18,"description":7864,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7865,"url":7866},"CVE-2022-49015","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: Fix potential use-after-free\n\nThe skb is delivered to netif_rx() which may free it, after calling this,\ndereferencing skb may trigger use-after-free.","2024-10-21T20:15:12.787+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49015",{"cveId":7863,"releaseId":25,"cycle":26,"description":7864,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7865,"url":7866},{"cveId":7863,"releaseId":31,"cycle":32,"description":7864,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7865,"url":7866},{"cveId":7870,"releaseId":17,"cycle":18,"description":7871,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7872,"url":7873},"CVE-2022-49014","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tun: Fix use-after-free in tun_detach()\n\nsyzbot reported use-after-free in tun_detach() [1].  This causes call\ntrace like below:\n\n==================================================================\nBUG: KASAN: use-after-free in notifier_call_chain+0x1ee\u002F0x200 kernel\u002Fnotifier.c:75\nRead of size 8 at addr ffff88807324e2a8 by task syz-executor.0\u002F3673\n\nCPU: 0 PID: 3673 Comm: syz-executor.0 Not tainted 6.1.0-rc5-syzkaller-00044-g","2024-10-21T20:15:12.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-49014",{"cveId":7875,"releaseId":25,"cycle":26,"description":7876,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7877,"url":7878},"CVE-2022-48991","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fkhugepaged: invoke MMU notifiers in shmem\u002Ffile collapse paths\n\nAny codepath that zaps page table entries must invoke MMU notifiers to\nensure that secondary MMUs (like KVM) don't keep accessing pages which\naren't mapped anymore.  Secondary MMUs don't hold their own references to\npages that are mirrored over, so failing to notify them can lead to page\nuse-after-free.\n\nI'm marking this as addressing an issue introduced in commi","2024-10-21T20:15:11+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48991",{"cveId":7875,"releaseId":17,"cycle":18,"description":7876,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7877,"url":7878},{"cveId":7875,"releaseId":31,"cycle":32,"description":7876,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7877,"url":7878},{"cveId":7882,"releaseId":25,"cycle":26,"description":7883,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7884,"url":7885},"CVE-2022-48990","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: fix use-after-free during gpu recovery\n\n[Why]\n    [  754.862560] refcount_t: underflow; use-after-free.\n    [  754.862898] Call Trace:\n    [  754.862903]  \u003CTASK>\n    [  754.862913]  amdgpu_job_free_cb+0xc2\u002F0xe1 [amdgpu]\n    [  754.863543]  drm_sched_main.cold+0x34\u002F0x39 [amd_sched]\n\n[How]\n    The fw_fence may be not init, check whether dma_fence_init\n    is performed before job free","2024-10-21T20:15:10.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48990",{"cveId":7882,"releaseId":17,"cycle":18,"description":7883,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7884,"url":7885},{"cveId":7882,"releaseId":31,"cycle":32,"description":7883,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7884,"url":7885},{"cveId":7889,"releaseId":17,"cycle":18,"description":7890,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7891,"url":7892},"CVE-2022-48988","In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: fix possible use-after-free in memcg_write_event_control()\n\nmemcg_write_event_control() accesses the dentry->d_name of the specified\ncontrol fd to route the write call.  As a cgroup interface file can't be\nrenamed, it's safe to access d_name as long as the specified file is a\nregular cgroup file.  Also, as these cgroup interface files can't be\nremoved before the directory, it's safe to access the parent too.\n\nPrior to 34","2024-10-21T20:15:10.71+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48988",{"cveId":7889,"releaseId":31,"cycle":32,"description":7890,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7891,"url":7892},{"cveId":7889,"releaseId":25,"cycle":26,"description":7890,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7891,"url":7892},{"cveId":7896,"releaseId":31,"cycle":32,"description":7897,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7898,"url":7899},"CVE-2022-48986","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fgup: fix gup_pud_range() for dax\n\nFor dax pud, pud_huge() returns true on x86. So the function works as long\nas hugetlb is configured. However, dax doesn't depend on hugetlb.\nCommit 414fd080d125 (\"mm\u002Fgup: fix gup_pmd_range() for dax\") fixed\ndevmap-backed huge PMDs, but missed devmap-backed huge PUDs. Fix this as\nwell.\n\nThis fixes the below kernel panic:\n\ngeneral protection fault, probably for non-canonical address 0x69e7c000","2024-10-21T20:15:10.527+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48986",{"cveId":7896,"releaseId":25,"cycle":26,"description":7897,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7898,"url":7899},{"cveId":7896,"releaseId":17,"cycle":18,"description":7897,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7898,"url":7899},{"cveId":7903,"releaseId":25,"cycle":26,"description":7904,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7905,"url":7906},"CVE-2022-48979","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: fix array index out of bound error in DCN32 DML\n\n[Why&How]\nLinkCapacitySupport array is indexed with the number of voltage states and\nnot the number of max DPPs. Fix the error by changing the array\ndeclaration to use the correct (larger) array size of total number of\nvoltage states.","2024-10-21T20:15:09.947+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48979",{"cveId":7903,"releaseId":17,"cycle":18,"description":7904,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7905,"url":7906},{"cveId":7903,"releaseId":31,"cycle":32,"description":7904,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7905,"url":7906},{"cveId":7910,"releaseId":25,"cycle":26,"description":7911,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7912,"url":7913},"CVE-2022-48967","In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: nci: Bounds check struct nfc_target arrays\n\nWhile running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:\n\n  memcpy: detected field-spanning write (size 129) of single field \"target->sensf_res\" at net\u002Fnfc\u002Fnci\u002Fntf.c:260 (size 18)\n\nThis appears to be a legitimate lack of bounds checking in\nnci_add_new_protocol(). Add the missing checks.","2024-10-21T20:15:08.757+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48967",{"cveId":7910,"releaseId":17,"cycle":18,"description":7911,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7912,"url":7913},{"cveId":7910,"releaseId":31,"cycle":32,"description":7911,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7912,"url":7913},{"cveId":7917,"releaseId":31,"cycle":32,"description":7918,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7919,"url":7920},"CVE-2022-48962","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hisilicon: Fix potential use-after-free in hisi_femac_rx()\n\nThe skb is delivered to napi_gro_receive() which may free it, after\ncalling this, dereferencing skb may trigger use-after-free.","2024-10-21T20:15:08.117+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48962",{"cveId":7917,"releaseId":17,"cycle":18,"description":7918,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7919,"url":7920},{"cveId":7917,"releaseId":25,"cycle":26,"description":7918,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7919,"url":7920},{"cveId":7924,"releaseId":25,"cycle":26,"description":7925,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7926,"url":7927},"CVE-2022-48960","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hisilicon: Fix potential use-after-free in hix5hd2_rx()\n\nThe skb is delivered to napi_gro_receive() which may free it, after\ncalling this, dereferencing skb may trigger use-after-free.","2024-10-21T20:15:07.663+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48960",{"cveId":7924,"releaseId":17,"cycle":18,"description":7925,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7926,"url":7927},{"cveId":7924,"releaseId":31,"cycle":32,"description":7925,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7926,"url":7927},{"cveId":7931,"releaseId":17,"cycle":18,"description":7932,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7933,"url":7934},"CVE-2022-48956","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: avoid use-after-free in ip6_fragment()\n\nBlamed commit claimed rcu_read_lock() was held by ip6_fragment() callers.\n\nIt seems to not be always true, at least for UDP stack.\n\nsyzbot reported:\n\nBUG: KASAN: use-after-free in ip6_dst_idev include\u002Fnet\u002Fip6_fib.h:245 [inline]\nBUG: KASAN: use-after-free in ip6_fragment+0x2724\u002F0x2770 net\u002Fipv6\u002Fip6_output.c:951\nRead of size 8 at addr ffff88801d403e80 by task syz-executor.3\u002F7618\n\nCPU: ","2024-10-21T20:15:06.973+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48956",{"cveId":7931,"releaseId":25,"cycle":26,"description":7932,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7933,"url":7934},{"cveId":7937,"releaseId":31,"cycle":32,"description":7938,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7939,"url":7940},"CVE-2022-48950","In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix perf_pending_task() UaF\n\nPer syzbot it is possible for perf_pending_task() to run after the\nevent is free()'d. There are two related but distinct cases:\n\n - the task_work was already queued before destroying the event;\n - destroying the event itself queues the task_work.\n\nThe first cannot be solved using task_work_cancel() since\nperf_release() itself might be called from a task_work (____fput),\nwhich means the current","2024-10-21T20:15:06.44+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48950",{"cveId":7937,"releaseId":25,"cycle":26,"description":7938,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7939,"url":7940},{"cveId":7937,"releaseId":17,"cycle":18,"description":7938,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7939,"url":7940},{"cveId":7944,"releaseId":25,"cycle":26,"description":7945,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7946,"url":7947},"CVE-2024-50014","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix access to uninitialised lock in fc replay path\n\nThe following kernel trace can be triggered with fstest generic\u002F629 when\nexecuted against a filesystem with fast-commit feature enabled:\n\nINFO: trying to register non-static key.\nThe code is fine but needs lockdep annotation, or maybe\nyou didn't initialize this object before use?\nturning off the locking correctness validator.\nCPU: 0 PID: 866 Comm: mount Not tainted 6.10.","2024-10-21T19:15:04.83+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50014",{"cveId":7944,"releaseId":31,"cycle":32,"description":7945,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7946,"url":7947},{"cveId":7944,"releaseId":17,"cycle":18,"description":7945,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7946,"url":7947},{"cveId":7951,"releaseId":25,"cycle":26,"description":7952,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7953,"url":7954},"CVE-2024-50012","In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: Avoid a bad reference count on CPU node\n\nIn the parse_perf_domain function, if the call to\nof_parse_phandle_with_args returns an error, then the reference to the\nCPU device node that was acquired at the start of the function would not\nbe properly decremented.\n\nAddress this by declaring the variable with the __free(device_node)\ncleanup attribute.","2024-10-21T19:15:04.683+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-50012",{"cveId":7951,"releaseId":31,"cycle":32,"description":7952,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7953,"url":7954},{"cveId":7951,"releaseId":17,"cycle":18,"description":7952,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7953,"url":7954},{"cveId":7958,"releaseId":17,"cycle":18,"description":7959,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7960,"url":7961},"CVE-2024-49994","In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix integer overflow in BLKSECDISCARD\n\nI independently rediscovered\n\n\tcommit 22d24a544b0d49bbcbd61c8c0eaf77d3c9297155\n\tblock: fix overflow in blk_ioctl_discard()\n\nbut for secure erase.\n\nSame problem:\n\n\tuint64_t r[2] = {512, 18446744073709551104ULL};\n\tioctl(fd, BLKSECDISCARD, r);\n\nwill enter near infinite loop inside blkdev_issue_secure_erase():\n\n\ta.out: attempt to access beyond end of device\n\tloop0: rw=5, sector=33990430","2024-10-21T18:15:19.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49994",{"cveId":7958,"releaseId":25,"cycle":26,"description":7959,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7960,"url":7961},{"cveId":7958,"releaseId":31,"cycle":32,"description":7959,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":7960,"url":7961},{"cveId":7965,"releaseId":17,"cycle":18,"description":7966,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7967,"url":7968},"CVE-2024-49992","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fstm: Avoid use-after-free issues with crtc and plane\n\nltdc_load() calls functions drm_crtc_init_with_planes(),\ndrm_universal_plane_init() and drm_encoder_init(). These functions\nshould not be called with parameters allocated with devm_kzalloc()\nto avoid use-after-free issues [1].\n\nUse allocations managed by the DRM framework.\n\nFound by Linux Verification Center (linuxtesting.org).\n\n[1]\nhttps:\u002F\u002Flore.kernel.org\u002Flkml\u002Fu366i76e3","2024-10-21T18:15:19.387+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49992",{"cveId":7965,"releaseId":31,"cycle":32,"description":7966,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7967,"url":7968},{"cveId":7965,"releaseId":25,"cycle":26,"description":7966,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7967,"url":7968},{"cveId":7972,"releaseId":31,"cycle":32,"description":7973,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7974,"url":7975},"CVE-2024-49991","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdkfd: amdkfd_free_gtt_mem clear the correct pointer\n\nPass pointer reference to amdgpu_bo_unref to clear the correct pointer,\notherwise amdgpu_bo_unref clear the local variable, the original pointer\nnot set to NULL, this could cause use-after-free bug.","2024-10-21T18:15:19.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49991",{"cveId":7972,"releaseId":25,"cycle":26,"description":7973,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7974,"url":7975},{"cveId":7972,"releaseId":17,"cycle":18,"description":7973,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7974,"url":7975},{"cveId":7979,"releaseId":31,"cycle":32,"description":7980,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7981,"url":7982},"CVE-2024-49988","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add refcnt to ksmbd_conn struct\n\nWhen sending an oplock break request, opinfo->conn is used,\nBut freed ->conn can be used on multichannel.\nThis patch add a reference count to the ksmbd_conn struct\nso that it can be freed when it is no longer used.","2024-10-21T18:15:19.147+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49988",{"cveId":7979,"releaseId":25,"cycle":26,"description":7980,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7981,"url":7982},{"cveId":7979,"releaseId":17,"cycle":18,"description":7980,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7981,"url":7982},{"cveId":7986,"releaseId":17,"cycle":18,"description":7987,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":7988,"url":7989},"CVE-2024-49982","In the Linux kernel, the following vulnerability has been resolved:\n\naoe: fix the potential use-after-free problem in more places\n\nFor fixing CVE-2023-6270, f98364e92662 (\"aoe: fix the potential\nuse-after-free problem in aoecmd_cfg_pkts\") makes tx() calling dev_put()\ninstead of doing in aoecmd_cfg_pkts(). It avoids that the tx() runs\ninto use-after-free.\n\nThen Nicolai Stange found more places in aoe have potential use-after-free\nproblem with tx(). e.g. revalidate(), aoecmd_ata_rw(), resend(), pr","2024-10-21T18:15:18.733+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49982",{"cveId":7991,"releaseId":25,"cycle":26,"description":7992,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7993,"url":7994},"CVE-2024-49981","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: fix use after free bug in venus_remove due to race condition\n\nin venus_probe, core->work is bound with venus_sys_error_handler, which is\nused to handle error. The code use core->sys_err_done to make sync work.\nThe core->work is started in venus_event_notify.\n\nIf we call venus_remove, there might be an unfished work. The possible\nsequence is as follows:\n\nCPU0                  CPU1\n\n                     |venus_sys_e","2024-10-21T18:15:18.67+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49981",{"cveId":7991,"releaseId":17,"cycle":18,"description":7992,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7993,"url":7994},{"cveId":7997,"releaseId":25,"cycle":26,"description":7998,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7999,"url":8000},"CVE-2024-49969","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix index out of bounds in DCN30 color transformation\n\nThis commit addresses a potential index out of bounds issue in the\n`cm3_helper_translate_curve_to_hw_format` function in the DCN30 color\nmanagement module. The issue could occur when the index 'i' exceeds the\nnumber of transfer function points (TRANSFER_FUNC_POINTS).\n\nThe fix adds a check to ensure 'i' is within bounds before accessing the\ntransfer function","2024-10-21T18:15:17.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49969",{"cveId":7997,"releaseId":17,"cycle":18,"description":7998,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7999,"url":8000},{"cveId":7997,"releaseId":31,"cycle":32,"description":7998,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":7999,"url":8000},{"cveId":8004,"releaseId":17,"cycle":18,"description":8005,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8006,"url":8007},"CVE-2024-49968","In the Linux kernel, the following vulnerability has been resolved:\n\next4: filesystems without casefold feature cannot be mounted with siphash\n\nWhen mounting the ext4 filesystem, if the default hash version is set to\nDX_HASH_SIPHASH but the casefold feature is not set, exit the mounting.","2024-10-21T18:15:17.833+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49968",{"cveId":8004,"releaseId":25,"cycle":26,"description":8005,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8006,"url":8007},{"cveId":8004,"releaseId":31,"cycle":32,"description":8005,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8006,"url":8007},{"cveId":8011,"releaseId":17,"cycle":18,"description":8012,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8013,"url":8014},"CVE-2024-49966","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: cancel dqi_sync_work before freeing oinfo\n\nocfs2_global_read_info() will initialize and schedule dqi_sync_work at the\nend, if error occurs after successfully reading global quota, it will\ntrigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled:\n\nODEBUG: free active (active state 0) object: 00000000d8b0ce28 object type: timer_list hint: qsync_work_fn+0x0\u002F0x16c\n\nThis reports that there is an active delayed work w","2024-10-21T18:15:17.683+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49966",{"cveId":8011,"releaseId":31,"cycle":32,"description":8012,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8013,"url":8014},{"cveId":8011,"releaseId":25,"cycle":26,"description":8012,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8013,"url":8014},{"cveId":8018,"releaseId":17,"cycle":18,"description":8019,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8020,"url":8021},"CVE-2024-49965","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: remove unreasonable unlock in ocfs2_read_blocks\n\nPatch series \"Misc fixes for ocfs2_read_blocks\", v5.\n\nThis series contains 2 fixes for ocfs2_read_blocks().  The first patch fix\nthe issue reported by syzbot, which detects bad unlock balance in\nocfs2_read_blocks().  The second patch fixes an issue reported by Heming\nZhao when reviewing above fix.\n\n\nThis patch (of 2):\n\nThere was a lock release before exiting, so remove the","2024-10-21T18:15:17.593+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49965",{"cveId":8018,"releaseId":25,"cycle":26,"description":8019,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8020,"url":8021},{"cveId":8018,"releaseId":31,"cycle":32,"description":8019,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8020,"url":8021},{"cveId":8025,"releaseId":17,"cycle":18,"description":8026,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8027,"url":8028},"CVE-2024-49960","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix timer use-after-free on failed mount\n\nSyzbot has found an ODEBUG bug in ext4_fill_super\n\nThe del_timer_sync function cancels the s_err_report timer,\nwhich reminds about filesystem errors daily. We should\nguarantee the timer is no longer active before kfree(sbi).\n\nWhen filesystem mounting fails, the flow goes to failed_mount3,\nwhere an error occurs when ext4_stop_mmpd is called, causing\na read I\u002FO failure. This trigger","2024-10-21T18:15:17.187+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49960",{"cveId":8025,"releaseId":25,"cycle":26,"description":8026,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8027,"url":8028},{"cveId":8025,"releaseId":31,"cycle":32,"description":8026,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8027,"url":8028},{"cveId":8032,"releaseId":25,"cycle":26,"description":8033,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8034,"url":8035},"CVE-2024-49958","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reserve space for inline xattr before attaching reflink tree\n\nOne of our customers reported a crash and a corrupted ocfs2 filesystem. \nThe crash was due to the detection of corruption.  Upon troubleshooting,\nthe fsck -fn output showed the below corruption\n\n[EXTENT_LIST_FREE] Extent list in owner 33080590 claims 230 as the next free chain record,\nbut fsck believes the largest valid value is 227.  Clamp the next record val","2024-10-21T18:15:17.05+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49958",{"cveId":8032,"releaseId":31,"cycle":32,"description":8033,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8034,"url":8035},{"cveId":8032,"releaseId":17,"cycle":18,"description":8033,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8034,"url":8035},{"cveId":8039,"releaseId":17,"cycle":18,"description":8040,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8041,"url":8042},"CVE-2024-49952","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: prevent nf_skb_duplicated corruption\n\nsyzbot found that nf_dup_ipv4() or nf_dup_ipv6() could write\nper-cpu variable nf_skb_duplicated in an unsafe way [1].\n\nDisabling preemption as hinted by the splat is not enough,\nwe have to disable soft interrupts as well.\n\n[1]\nBUG: using __this_cpu_write() in preemptible [00000000] code: syz.4.282\u002F6316\n caller is nf_dup_ipv4+0x651\u002F0x8f0 net\u002Fipv4\u002Fnetfilter\u002Fnf_dup_ipv4.c","2024-10-21T18:15:16.59+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49952",{"cveId":8039,"releaseId":25,"cycle":26,"description":8040,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8041,"url":8042},{"cveId":8039,"releaseId":31,"cycle":32,"description":8040,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8041,"url":8042},{"cveId":8046,"releaseId":25,"cycle":26,"description":8047,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8048,"url":8049},"CVE-2024-49950","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix uaf in l2cap_connect\n\n[Syzbot reported]\nBUG: KASAN: slab-use-after-free in l2cap_connect.constprop.0+0x10d8\u002F0x1270 net\u002Fbluetooth\u002Fl2cap_core.c:3949\nRead of size 8 at addr ffff8880241e9800 by task kworker\u002Fu9:0\u002F54\n\nCPU: 0 UID: 0 PID: 54 Comm: kworker\u002Fu9:0 Not tainted 6.11.0-rc6-syzkaller-00268-g788220eee30d #0\nHardware name: Google Google Compute Engine\u002FGoogle Compute Engine, BIOS Google 08\u002F06\u002F2024\nWorkqueue:","2024-10-21T18:15:16.417+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49950",{"cveId":8046,"releaseId":17,"cycle":18,"description":8047,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8048,"url":8049},{"cveId":8046,"releaseId":31,"cycle":32,"description":8047,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8048,"url":8049},{"cveId":8053,"releaseId":25,"cycle":26,"description":8054,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8055,"url":8056},"CVE-2024-49940","In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: prevent possible tunnel refcount underflow\n\nWhen a session is created, it sets a backpointer to its tunnel. When\nthe session refcount drops to 0, l2tp_session_free drops the tunnel\nrefcount if session->tunnel is non-NULL. However, session->tunnel is\nset in l2tp_session_create, before the tunnel refcount is incremented\nby l2tp_session_register, which leaves a small window where\nsession->tunnel is non-NULL when the tunnel r","2024-10-21T18:15:15.703+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49940",{"cveId":8053,"releaseId":17,"cycle":18,"description":8054,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8055,"url":8056},{"cveId":8053,"releaseId":31,"cycle":32,"description":8054,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8055,"url":8056},{"cveId":8060,"releaseId":25,"cycle":26,"description":8061,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8062,"url":8063},"CVE-2024-49939","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: avoid to add interface to list twice when SER\n\nIf SER L2 occurs during the WoWLAN resume flow, the add interface flow\nis triggered by ieee80211_reconfig(). However, due to\nrtw89_wow_resume() return failure, it will cause the add interface flow\nto be executed again, resulting in a double add list and causing a kernel\npanic. Therefore, we have added a check to prevent double adding of the\nlist.\n\nlist_add double add: ","2024-10-21T18:15:15.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49939",{"cveId":8060,"releaseId":17,"cycle":18,"description":8061,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8062,"url":8063},{"cveId":8060,"releaseId":31,"cycle":32,"description":8061,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8062,"url":8063},{"cveId":8067,"releaseId":17,"cycle":18,"description":8068,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8069,"url":8070},"CVE-2024-49936","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fxen-netback: prevent UAF in xenvif_flush_hash()\n\nDuring the list_for_each_entry_rcu iteration call of xenvif_flush_hash,\nkfree_rcu does not exist inside the rcu read critical section, so if\nkfree_rcu is called when the rcu grace period ends during the iteration,\nUAF occurs when accessing head->next after the entry becomes free.\n\nTherefore, to solve this, you need to change it to list_for_each_entry_safe.","2024-10-21T18:15:15.413+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49936",{"cveId":8067,"releaseId":25,"cycle":26,"description":8068,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8069,"url":8070},{"cveId":8067,"releaseId":31,"cycle":32,"description":8068,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8069,"url":8070},{"cveId":8074,"releaseId":17,"cycle":18,"description":8075,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8076,"url":8077},"CVE-2024-49934","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Finode: Prevent dump_mapping() accessing invalid dentry.d_name.name\n\nIt's observed that a crash occurs during hot-remove a memory device,\nin which user is accessing the hugetlb. See calltrace as following:\n\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 14045 at arch\u002Fx86\u002Fmm\u002Ffault.c:1278 do_user_addr_fault+0x2a0\u002F0x790\nModules linked in: kmem device_dax cxl_mem cxl_pmem cxl_port cxl_pci dax_hmem dax_pmem nd_pmem cxl_","2024-10-21T18:15:15.273+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49934",{"cveId":8074,"releaseId":31,"cycle":32,"description":8075,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8076,"url":8077},{"cveId":8074,"releaseId":25,"cycle":26,"description":8075,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8076,"url":8077},{"cveId":8081,"releaseId":17,"cycle":18,"description":8082,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8083,"url":8084},"CVE-2024-49932","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't readahead the relocation inode on RST\n\nOn relocation we're doing readahead on the relocation inode, but if the\nfilesystem is backed by a RAID stripe tree we can get ENOENT (e.g. due to\npreallocated extents not being mapped in the RST) from the lookup.\n\nBut readahead doesn't handle the error and submits invalid reads to the\ndevice, causing an assertion in the scatter-gather list code:\n\n  BTRFS info (device nvme1n1):","2024-10-21T18:15:15.14+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49932",{"cveId":8081,"releaseId":31,"cycle":32,"description":8082,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8083,"url":8084},{"cveId":8081,"releaseId":25,"cycle":26,"description":8082,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8083,"url":8084},{"cveId":8088,"releaseId":25,"cycle":26,"description":8089,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8090,"url":8091},"CVE-2024-49930","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix array out-of-bound access in SoC stats\n\nCurrently, the ath11k_soc_dp_stats::hal_reo_error array is defined with a\nmaximum size of DP_REO_DST_RING_MAX. However, the ath11k_dp_process_rx()\nfunction access ath11k_soc_dp_stats::hal_reo_error using the REO\ndestination SRNG ring ID, which is incorrect. SRNG ring ID differ from\nnormal ring ID, and this usage leads to out-of-bounds array access. To fix\nthis issue, mod","2024-10-21T18:15:14.99+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49930",{"cveId":8088,"releaseId":17,"cycle":18,"description":8089,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8090,"url":8091},{"cveId":8088,"releaseId":31,"cycle":32,"description":8089,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8090,"url":8091},{"cveId":8095,"releaseId":17,"cycle":18,"description":8096,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8097,"url":8098},"CVE-2024-49925","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: efifb: Register sysfs groups through driver core\n\nThe driver core can register and cleanup sysfs groups already.\nMake use of that functionality to simplify the error handling and\ncleanup.\n\nAlso avoid a UAF race during unregistering where the sysctl attributes\nwere usable after the info struct was freed.","2024-10-21T18:15:14.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49925",{"cveId":8095,"releaseId":31,"cycle":32,"description":8096,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8097,"url":8098},{"cveId":8095,"releaseId":25,"cycle":26,"description":8096,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8097,"url":8098},{"cveId":8102,"releaseId":17,"cycle":18,"description":8103,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8104,"url":8105},"CVE-2024-49924","In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: pxafb: Fix possible use after free in pxafb_task()\n\nIn the pxafb_probe function, it calls the pxafb_init_fbinfo function,\nafter which &fbi->task is associated with pxafb_task. Moreover,\nwithin this pxafb_init_fbinfo function, the pxafb_blank function\nwithin the &pxafb_ops struct is capable of scheduling work.\n\nIf we remove the module which will call pxafb_remove to make cleanup,\nit will call unregister_framebuffer functi","2024-10-21T18:15:14.45+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49924",{"cveId":8102,"releaseId":31,"cycle":32,"description":8103,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8104,"url":8105},{"cveId":8102,"releaseId":25,"cycle":26,"description":8103,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8104,"url":8105},{"cveId":8109,"releaseId":17,"cycle":18,"description":8110,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8111,"url":8112},"CVE-2024-49902","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: check if leafidx greater than num leaves per dmap tree\n\nsyzbot report a out of bounds in dbSplit, it because dmt_leafidx greater\nthan num leaves per dmap tree, add a checking for dmt_leafidx in dbFindLeaf.\n\nShaggy:\nModified sanity check to apply to control pages as well as leaf pages.","2024-10-21T18:15:12.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49902",{"cveId":8109,"releaseId":25,"cycle":26,"description":8110,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8111,"url":8112},{"cveId":8109,"releaseId":31,"cycle":32,"description":8110,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8111,"url":8112},{"cveId":8116,"releaseId":17,"cycle":18,"description":8117,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8118,"url":8119},"CVE-2024-49894","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix index out of bounds in degamma hardware format translation\n\nFixes index out of bounds issue in\n`cm_helper_translate_curve_to_degamma_hw_format` function. The issue\ncould occur when the index 'i' exceeds the number of transfer function\npoints (TRANSFER_FUNC_POINTS).\n\nThe fix adds a check to ensure 'i' is within bounds before accessing the\ntransfer function points. If 'i' is out of bounds the function returns","2024-10-21T18:15:11.913+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49894",{"cveId":8121,"releaseId":31,"cycle":32,"description":8122,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8123,"url":8124},"CVE-2024-49889","In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid use-after-free in ext4_ext_show_leaf()\n\nIn ext4_find_extent(), path may be freed by error or be reallocated, so\nusing a previously saved *ppath may have been freed and thus may trigger\nuse-after-free, as follows:\n\next4_split_extent\n  path = *ppath;\n  ext4_split_extent_at(ppath)\n  path = ext4_find_extent(ppath)\n  ext4_split_extent_at(ppath)\n    \u002F\u002F ext4_find_extent fails to free path\n    \u002F\u002F but zeroout succeeds\n  ext4","2024-10-21T18:15:11.513+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49889",{"cveId":8121,"releaseId":25,"cycle":26,"description":8122,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8123,"url":8124},{"cveId":8121,"releaseId":17,"cycle":18,"description":8122,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8123,"url":8124},{"cveId":8128,"releaseId":17,"cycle":18,"description":8129,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8130,"url":8131},"CVE-2024-49884","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix slab-use-after-free in ext4_split_extent_at()\n\nWe hit the following use-after-free:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in ext4_split_extent_at+0xba8\u002F0xcc0\nRead of size 2 at addr ffff88810548ed08 by task kworker\u002Fu20:0\u002F40\nCPU: 0 PID: 40 Comm: kworker\u002Fu20:0 Not tainted 6.9.0-dirty #724\nCall Trace:\n \u003CTASK>\n kasan_report+0x93\u002F0xc0\n ext4_split_extent_at+0xba8\u002F","2024-10-21T18:15:11.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49884",{"cveId":8128,"releaseId":31,"cycle":32,"description":8129,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8130,"url":8131},{"cveId":8128,"releaseId":25,"cycle":26,"description":8129,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8130,"url":8131},{"cveId":8135,"releaseId":31,"cycle":32,"description":8136,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8137,"url":8138},"CVE-2024-49883","In the Linux kernel, the following vulnerability has been resolved:\n\next4: aovid use-after-free in ext4_ext_insert_extent()\n\nAs Ojaswin mentioned in Link, in ext4_ext_insert_extent(), if the path is\nreallocated in ext4_ext_create_new_leaf(), we'll use the stale path and\ncause UAF. Below is a sample trace with dummy values:\n\next4_ext_insert_extent\n  path = *ppath = 2000\n  ext4_ext_create_new_leaf(ppath)\n    ext4_find_extent(ppath)\n      path = *ppath = 2000\n      if (depth > path[0].p_maxdepth)\n ","2024-10-21T18:15:11.06+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49883",{"cveId":8135,"releaseId":25,"cycle":26,"description":8136,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8137,"url":8138},{"cveId":8135,"releaseId":17,"cycle":18,"description":8136,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8137,"url":8138},{"cveId":8142,"releaseId":17,"cycle":18,"description":8143,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8144,"url":8145},"CVE-2024-49882","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double brelse() the buffer of the extents path\n\nIn ext4_ext_try_to_merge_up(), set path[1].p_bh to NULL after it has been\nreleased, otherwise it may be released twice. An example of what triggers\nthis is as follows:\n\n  split2    map    split1\n|--------|-------|--------|\n\next4_ext_map_blocks\n ext4_ext_handle_unwritten_extents\n  ext4_split_convert_extents\n   \u002F\u002F path->p_depth == 0\n   ext4_split_extent\n     \u002F\u002F 1. do split","2024-10-21T18:15:10.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49882",{"cveId":8142,"releaseId":31,"cycle":32,"description":8143,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8144,"url":8145},{"cveId":8142,"releaseId":25,"cycle":26,"description":8143,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8144,"url":8145},{"cveId":8149,"releaseId":17,"cycle":18,"description":8150,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8151,"url":8152},"CVE-2024-49875","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: map the EBADMSG to nfserr_io to avoid warning\n\nExt4 will throw -EBADMSG through ext4_readdir when a checksum error\noccurs, resulting in the following WARNING.\n\nFix it by mapping EBADMSG to nfserr_io.\n\nnfsd_buffered_readdir\n iterate_dir \u002F\u002F -EBADMSG -74\n  ext4_readdir \u002F\u002F .iterate_shared\n   ext4_dx_readdir\n    ext4_htree_fill_tree\n     htree_dirblock_to_tree\n      ext4_read_dirblock\n       __ext4_read_dirblock\n        ext4_d","2024-10-21T18:15:09.183+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49875",{"cveId":8149,"releaseId":25,"cycle":26,"description":8150,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8151,"url":8152},{"cveId":8149,"releaseId":31,"cycle":32,"description":8150,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8151,"url":8152},{"cveId":8156,"releaseId":17,"cycle":18,"description":8157,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8158,"url":8159},"CVE-2024-49867","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: wait for fixup workers before stopping cleaner kthread during umount\n\nDuring unmount, at close_ctree(), we have the following steps in this order:\n\n1) Park the cleaner kthread - this doesn't destroy the kthread, it basically\n   halts its execution (wake ups against it work but do nothing);\n\n2) We stop the cleaner kthread - this results in freeing the respective\n   struct task_struct;\n\n3) We call btrfs_stop_all_workers() ","2024-10-21T18:15:06.403+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49867",{"cveId":8156,"releaseId":31,"cycle":32,"description":8157,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8158,"url":8159},{"cveId":8156,"releaseId":25,"cycle":26,"description":8157,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8158,"url":8159},{"cveId":8163,"releaseId":31,"cycle":32,"description":8164,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8165,"url":8166},"CVE-2024-49860","In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: sysfs: validate return type of _STR method\n\nOnly buffer objects are valid return values of _STR.\n\nIf something else is returned description_show() will access invalid\nmemory.","2024-10-21T13:15:06.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49860",{"cveId":8163,"releaseId":25,"cycle":26,"description":8164,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8165,"url":8166},{"cveId":8163,"releaseId":17,"cycle":18,"description":8164,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8165,"url":8166},{"cveId":8170,"releaseId":25,"cycle":26,"description":8171,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8172,"url":8173},"CVE-2024-49859","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to check atomic_file in f2fs ioctl interfaces\n\nSome f2fs ioctl interfaces like f2fs_ioc_set_pin_file(),\nf2fs_move_file_range(), and f2fs_defragment_range() missed to\ncheck atomic_write status, which may cause potential race issue,\nfix it.","2024-10-21T13:15:06.627+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49859",{"cveId":8170,"releaseId":17,"cycle":18,"description":8171,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8172,"url":8173},{"cveId":8170,"releaseId":31,"cycle":32,"description":8171,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8172,"url":8173},{"cveId":8177,"releaseId":31,"cycle":32,"description":8178,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8179,"url":8180},"CVE-2024-47749","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fcxgb4: Added NULL check for lookup_atid\n\nThe lookup_atid() function can return NULL if the ATID is\ninvalid or does not exist in the identifier table, which\ncould lead to dereferencing a null pointer without a\ncheck in the `act_establish()` and `act_open_rpl()` functions.\nAdd a NULL check to prevent null pointer dereferencing.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.","2024-10-21T13:15:04.95+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47749",{"cveId":8177,"releaseId":17,"cycle":18,"description":8178,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8179,"url":8180},{"cveId":8177,"releaseId":25,"cycle":26,"description":8178,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8179,"url":8180},{"cveId":8184,"releaseId":17,"cycle":18,"description":8185,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8186,"url":8187},"CVE-2024-47747","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition\n\nIn the ether3_probe function, a timer is initialized with a callback\nfunction ether3_ledoff, bound to &prev(dev)->timer. Once the timer is\nstarted, there is a risk of a race condition if the module or device\nis removed, triggering the ether3_remove function to perform cleanup.\nThe sequence of operations that may lead to a UAF bug is as follows:\n","2024-10-21T13:15:04.753+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47747",{"cveId":8189,"releaseId":31,"cycle":32,"description":8190,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8191,"url":8192},"CVE-2024-47745","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: call the security_mmap_file() LSM hook in remap_file_pages()\n\nThe remap_file_pages syscall handler calls do_mmap() directly, which\ndoesn't contain the LSM security check. And if the process has called\npersonality(READ_IMPLIES_EXEC) before and remap_file_pages() is called for\nRW pages, this will actually result in remapping the pages to RWX,\nbypassing a W^X policy enforced by SELinux.\n\nSo we should check prot by security_mma","2024-10-21T13:15:04.58+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47745",{"cveId":8189,"releaseId":17,"cycle":18,"description":8190,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8191,"url":8192},{"cveId":8189,"releaseId":25,"cycle":26,"description":8190,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8191,"url":8192},{"cveId":8196,"releaseId":31,"cycle":32,"description":8197,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8198,"url":8199},"CVE-2024-47742","In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: Block path traversal\n\nMost firmware names are hardcoded strings, or are constructed from fairly\nconstrained format strings where the dynamic parts are just some hex\nnumbers or such.\n\nHowever, there are a couple codepaths in the kernel where firmware file\nnames contain string components that are passed through from a device or\nsemi-privileged userspace; the ones I could find (not counting interfaces\nthat require","2024-10-21T13:15:04.297+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47742",{"cveId":8196,"releaseId":25,"cycle":26,"description":8197,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8198,"url":8199},{"cveId":8196,"releaseId":17,"cycle":18,"description":8197,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8198,"url":8199},{"cveId":8203,"releaseId":31,"cycle":32,"description":8204,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8205,"url":8206},"CVE-2024-47740","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: Require FMODE_WRITE for atomic write ioctls\n\nThe F2FS ioctls for starting and committing atomic writes check for\ninode_owner_or_capable(), but this does not give LSMs like SELinux or\nLandlock an opportunity to deny the write access - if the caller's FSUID\nmatches the inode's UID, inode_owner_or_capable() immediately returns true.\n\nThere are scenarios where LSMs want to deny a process the ability to write\nparticular files,","2024-10-21T13:15:04.103+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47740",{"cveId":8203,"releaseId":25,"cycle":26,"description":8204,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8205,"url":8206},{"cveId":8203,"releaseId":17,"cycle":18,"description":8204,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8205,"url":8206},{"cveId":8210,"releaseId":25,"cycle":26,"description":8211,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8212,"url":8213},"CVE-2024-47726","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to wait dio completion\n\nIt should wait all existing dio write IOs before block removal,\notherwise, previous direct write IO may overwrite data in the\nblock which may be reused by other inode.","2024-10-21T13:15:02.767+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47726",{"cveId":8210,"releaseId":17,"cycle":18,"description":8211,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8212,"url":8213},{"cveId":8210,"releaseId":31,"cycle":32,"description":8211,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8212,"url":8213},{"cveId":8217,"releaseId":25,"cycle":26,"description":8218,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8219,"url":8220},"CVE-2024-47723","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix out-of-bounds in dbNextAG() and diAlloc()\n\nIn dbNextAG() , there is no check for the case where bmp->db_numag is\ngreater or same than MAXAG due to a polluted image, which causes an\nout-of-bounds. Therefore, a bounds check should be added in dbMount().\n\nAnd in dbNextAG(), a check for the case where agpref is greater than\nbmp->db_numag should be added, so an out-of-bounds exception should be\nprevented.\n\nAdditionally, a c","2024-10-21T13:15:02.503+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47723",{"cveId":8217,"releaseId":17,"cycle":18,"description":8218,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8219,"url":8220},{"cveId":8217,"releaseId":31,"cycle":32,"description":8218,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8219,"url":8220},{"cveId":8224,"releaseId":25,"cycle":26,"description":8225,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8226,"url":8227},"CVE-2024-47706","In the Linux kernel, the following vulnerability has been resolved:\n\nblock, bfq: fix possible UAF for bfqq->bic with merge chain\n\n1) initial state, three tasks:\n\n\t\tProcess 1       Process 2\tProcess 3\n\t\t (BIC1)          (BIC2)\t\t (BIC3)\n\t\t  |  Λ            |  Λ\t\t  |  Λ\n\t\t  |  |            |  |\t\t  |  |\n\t\t  V  |            V  |\t\t  V  |\n\t\t  bfqq1           bfqq2\t\t  bfqq3\nprocess ref:\t   1\t\t    1\t\t    1\n\n2) bfqq1 merged to bfqq2:\n\n\t\tProcess 1       Process 2\tProcess 3\n\t\t (BIC1)          (BIC2)\t\t (BIC3","2024-10-21T12:15:07.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47706",{"cveId":8224,"releaseId":17,"cycle":18,"description":8225,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8226,"url":8227},{"cveId":8230,"releaseId":31,"cycle":32,"description":8231,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8232,"url":8233},"CVE-2024-47701","In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid OOB when system.data xattr changes underneath the filesystem\n\nWhen looking up for an entry in an inlined directory, if e_value_offs is\nchanged underneath the filesystem by some change in the block device, it\nwill lead to an out-of-bounds access that KASAN detects as an UAF.\n\nEXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r\u002Fw without journal. Quota mode: none.\nloop0: detected capacity change","2024-10-21T12:15:06.663+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47701",{"cveId":8230,"releaseId":25,"cycle":26,"description":8231,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8232,"url":8233},{"cveId":8230,"releaseId":17,"cycle":18,"description":8231,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8232,"url":8233},{"cveId":8237,"releaseId":31,"cycle":32,"description":8238,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8239,"url":8240},"CVE-2024-47698","In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: media: dvb-frontends\u002Frtl2832: fix an out-of-bounds write error\n\nEnsure index in rtl2832_pid_filter does not exceed 31 to prevent\nout-of-bounds access.\n\ndev->filters is a 32-bit value, so set_bit and clear_bit functions should\nonly operate on indices from 0 to 31. If index is 32, it will attempt to\naccess a non-existent 33rd bit, leading to out-of-bounds access.\nChange the boundary check from index > 32 to index >= 32 t","2024-10-21T12:15:06.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47698",{"cveId":8237,"releaseId":17,"cycle":18,"description":8238,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8239,"url":8240},{"cveId":8237,"releaseId":25,"cycle":26,"description":8238,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8239,"url":8240},{"cveId":8244,"releaseId":31,"cycle":32,"description":8245,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8246,"url":8247},"CVE-2024-47697","In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: media: dvb-frontends\u002Frtl2830: fix an out-of-bounds write error\n\nEnsure index in rtl2830_pid_filter does not exceed 31 to prevent\nout-of-bounds access.\n\ndev->filters is a 32-bit value, so set_bit and clear_bit functions should\nonly operate on indices from 0 to 31. If index is 32, it will attempt to\naccess a non-existent 33rd bit, leading to out-of-bounds access.\nChange the boundary check from index > 32 to index >= 32 t","2024-10-21T12:15:06.343+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47697",{"cveId":8244,"releaseId":25,"cycle":26,"description":8245,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8246,"url":8247},{"cveId":8244,"releaseId":17,"cycle":18,"description":8245,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8246,"url":8247},{"cveId":8251,"releaseId":17,"cycle":18,"description":8252,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8253,"url":8254},"CVE-2024-47696","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fiwcm: Fix WARNING:at_kernel\u002Fworkqueue.c:#check_flush_dependency\n\nIn the commit aee2424246f9 (\"RDMA\u002Fiwcm: Fix a use-after-free related to\ndestroying CM IDs\"), the function flush_workqueue is invoked to flush the\nwork queue iwcm_wq.\n\nBut at that time, the work queue iwcm_wq was created via the function\nalloc_ordered_workqueue without the flag WQ_MEM_RECLAIM.\n\nBecause the current process is trying to flush the whole iwcm_wq, ","2024-10-21T12:15:06.257+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47696",{"cveId":8256,"releaseId":31,"cycle":32,"description":8257,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8258,"url":8259},"CVE-2024-47690","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: get rid of online repaire on corrupted directory\n\nsyzbot reports a f2fs bug as below:\n\nkernel BUG at fs\u002Ff2fs\u002Finode.c:896!\nRIP: 0010:f2fs_evict_inode+0x1598\u002F0x15c0 fs\u002Ff2fs\u002Finode.c:896\nCall Trace:\n evict+0x532\u002F0x950 fs\u002Finode.c:704\n dispose_list fs\u002Finode.c:747 [inline]\n evict_inodes+0x5f9\u002F0x690 fs\u002Finode.c:797\n generic_shutdown_super+0x9d\u002F0x2d0 fs\u002Fsuper.c:627\n kill_block_super+0x44\u002F0x90 fs\u002Fsuper.c:1696\n kill_f2fs_super+0x344\u002F","2024-10-21T12:15:05.8+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47690",{"cveId":8256,"releaseId":17,"cycle":18,"description":8257,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8258,"url":8259},{"cveId":8256,"releaseId":25,"cycle":26,"description":8257,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8258,"url":8259},{"cveId":8263,"releaseId":31,"cycle":32,"description":8264,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8265,"url":8266},"CVE-2024-47679","In the Linux kernel, the following vulnerability has been resolved:\n\nvfs: fix race between evice_inodes() and find_inode()&iput()\n\nHi, all\n\nRecently I noticed a bug[1] in btrfs, after digged it into\nand I believe it'a race in vfs.\n\nLet's assume there's a inode (ie ino 261) with i_count 1 is\ncalled by iput(), and there's a concurrent thread calling\ngeneric_shutdown_super().\n\ncpu0:                              cpu1:\niput() \u002F\u002F i_count is 1\n  ->spin_lock(inode)\n  ->dec i_count to 0\n  ->iput_final() ","2024-10-21T12:15:04.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47679",{"cveId":8263,"releaseId":25,"cycle":26,"description":8264,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8265,"url":8266},{"cveId":8263,"releaseId":17,"cycle":18,"description":8264,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8265,"url":8266},{"cveId":8270,"releaseId":31,"cycle":32,"description":8271,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":8272,"url":8273},"CVE-2024-47678","In the Linux kernel, the following vulnerability has been resolved:\n\nicmp: change the order of rate limits\n\nICMP messages are ratelimited :\n\nAfter the blamed commits, the two rate limiters are applied in this order:\n\n1) host wide ratelimit (icmp_global_allow())\n\n2) Per destination ratelimit (inetpeer based)\n\nIn order to avoid side-channels attacks, we need to apply\nthe per destination check first.\n\nThis patch makes the following change :\n\n1) icmp_global_allow() checks if the host wide limit is r","2024-10-21T12:15:04.837+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47678",{"cveId":8270,"releaseId":25,"cycle":26,"description":8271,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":8272,"url":8273},{"cveId":8270,"releaseId":17,"cycle":18,"description":8271,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":8272,"url":8273},{"cveId":8277,"releaseId":31,"cycle":32,"description":8278,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8279,"url":8280},"CVE-2024-47674","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: avoid leaving partial pfn mappings around in error case\n\nAs Jann points out, PFN mappings are special, because unlike normal\nmemory mappings, there is no lifetime information associated with the\nmapping - it is just a raw mapping of PFNs with no reference counting of\na 'struct page'.\n\nThat's all very much intentional, but it does mean that it's easy to\nmess up the cleanup in case of errors.  Yes, a failed mmap() will always","2024-10-15T11:15:13.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47674",{"cveId":8277,"releaseId":25,"cycle":26,"description":8278,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8279,"url":8280},{"cveId":8277,"releaseId":17,"cycle":18,"description":8278,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8279,"url":8280},{"cveId":8284,"releaseId":31,"cycle":32,"description":8285,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8286,"url":8287},"CVE-2024-47670","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: add bounds checking to ocfs2_xattr_find_entry()\n\nAdd a paranoia check to make sure it doesn't stray beyond valid memory\nregion containing ocfs2 xattr entries when scanning for a match.  It will\nprevent out-of-bound access in case of crafted images.","2024-10-09T15:15:15.673+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47670",{"cveId":8284,"releaseId":25,"cycle":26,"description":8285,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8286,"url":8287},{"cveId":8284,"releaseId":17,"cycle":18,"description":8285,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8286,"url":8287},{"cveId":8291,"releaseId":25,"cycle":26,"description":8292,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8293,"url":8294},"CVE-2024-47669","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix state management in error path of log writing function\n\nAfter commit a694291a6211 (\"nilfs2: separate wait function from\nnilfs_segctor_write\") was applied, the log writing function\nnilfs_segctor_do_construct() was able to issue I\u002FO requests continuously\neven if user data blocks were split into multiple logs across segments,\nbut two potential flaws were introduced in its error handling.\n\nFirst, if nilfs_segctor_begin_","2024-10-09T15:15:15.59+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47669",{"cveId":8291,"releaseId":17,"cycle":18,"description":8292,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8293,"url":8294},{"cveId":8291,"releaseId":31,"cycle":32,"description":8292,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8293,"url":8294},{"cveId":8298,"releaseId":31,"cycle":32,"description":8299,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8300,"url":8301},"CVE-2024-47668","In the Linux kernel, the following vulnerability has been resolved:\n\nlib\u002Fgeneric-radix-tree.c: Fix rare race in __genradix_ptr_alloc()\n\nIf we need to increase the tree depth, allocate a new node, and then\nrace with another thread that increased the tree depth before us, we'll\nstill have a preallocated node that might be used later.\n\nIf we then use that node for a new non-root node, it'll still have a\npointer to the old root instead of being zeroed - fix this by zeroing it\nin the cmpxchg failure ","2024-10-09T15:15:15.513+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47668",{"cveId":8298,"releaseId":25,"cycle":26,"description":8299,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8300,"url":8301},{"cveId":8298,"releaseId":17,"cycle":18,"description":8299,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8300,"url":8301},{"cveId":8305,"releaseId":17,"cycle":18,"description":8306,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8307,"url":8308},"CVE-2024-47667","In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)\n\nErrata #i2037 in AM65x\u002FDRA80xM Processors Silicon Revision 1.0\n(SPRZ452D_July 2018_Revised December 2019 [1]) mentions when an\ninbound PCIe TLP spans more than two internal AXI 128-byte bursts,\nthe bus may corrupt the packet payload and the corrupt data may\ncause associated applications or the processor to hang.\n\nThe workaround for Errata #i2037 is to limit the max","2024-10-09T15:15:15.43+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47667",{"cveId":8305,"releaseId":31,"cycle":32,"description":8306,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8307,"url":8308},{"cveId":8305,"releaseId":25,"cycle":26,"description":8306,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8307,"url":8308},{"cveId":8312,"releaseId":31,"cycle":32,"description":8313,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":8314,"url":8315},"CVE-2024-47659","In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: tcp: ipv4, fix incorrect labeling\n\nCurrently, Smack mirrors the label of incoming tcp\u002Fipv4 connections:\nwhen a label 'foo' connects to a label 'bar' with tcp\u002Fipv4,\n'foo' always gets 'foo' in returned ipv4 packets. So,\n1) returned packets are incorrectly labeled ('foo' instead of 'bar')\n2) 'bar' can write to 'foo' without being authorized to write.\n\nHere is a scenario how to see this:\n\n* Take two machines, let's call them","2024-10-09T14:15:07.66+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47659",{"cveId":8312,"releaseId":17,"cycle":18,"description":8313,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":8314,"url":8315},{"cveId":8312,"releaseId":25,"cycle":26,"description":8313,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":8314,"url":8315},{"cveId":8319,"releaseId":31,"cycle":32,"description":8320,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8321,"url":8322},"CVE-2024-47658","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: stm32\u002Fcryp - call finalize with bh disabled\n\nThe finalize operation in interrupt mode produce a produces a spinlock\nrecursion warning. The reason is the fact that BH must be disabled\nduring this process.","2024-10-09T14:15:07.603+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47658",{"cveId":8319,"releaseId":25,"cycle":26,"description":8320,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8321,"url":8322},{"cveId":8319,"releaseId":17,"cycle":18,"description":8320,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8321,"url":8322},{"cveId":8326,"releaseId":31,"cycle":32,"description":8327,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8328,"url":8329},"CVE-2024-46863","In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: soc-acpi-intel-lnl-match: add missing empty item\n\nThere is no links_num in struct snd_soc_acpi_mach {}, and we test\n!link->num_adr as a condition to end the loop in hda_sdw_machine_select().\nSo an empty item in struct snd_soc_acpi_link_adr array is required.","2024-09-27T13:15:17.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46863",{"cveId":8326,"releaseId":25,"cycle":26,"description":8327,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8328,"url":8329},{"cveId":8326,"releaseId":17,"cycle":18,"description":8327,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8328,"url":8329},{"cveId":8333,"releaseId":25,"cycle":26,"description":8334,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8335,"url":8336},"CVE-2024-46859","In the Linux kernel, the following vulnerability has been resolved:\n\nplatform\u002Fx86: panasonic-laptop: Fix SINF array out of bounds accesses\n\nThe panasonic laptop code in various places uses the SINF array with index\nvalues of 0 - SINF_CUR_BRIGHT(0x0d) without checking that the SINF array\nis big enough.\n\nNot all panasonic laptops have this many SINF array entries, for example\nthe Toughbook CF-18 model only has 10 SINF array entries. So it only\nsupports the AC+DC brightness entries and mute.\n\nCheck","2024-09-27T13:15:17.43+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46859",{"cveId":8333,"releaseId":17,"cycle":18,"description":8334,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8335,"url":8336},{"cveId":8333,"releaseId":31,"cycle":32,"description":8334,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8335,"url":8336},{"cveId":8340,"releaseId":17,"cycle":18,"description":8341,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8342,"url":8343},"CVE-2024-46855","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_socket: fix sk refcount leaks\n\nWe must put 'sk' reference before returning.","2024-09-27T13:15:17.133+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46855",{"cveId":8345,"releaseId":25,"cycle":26,"description":8346,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8347,"url":8348},"CVE-2024-46844","In the Linux kernel, the following vulnerability has been resolved:\n\num: line: always fill *error_out in setup_one_line()\n\nThe pointer isn't initialized by callers, but I have\nencountered cases where it's still printed; initialize\nit in all possible cases in setup_one_line().","2024-09-27T13:15:16.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46844",{"cveId":8345,"releaseId":17,"cycle":18,"description":8346,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8347,"url":8348},{"cveId":8345,"releaseId":31,"cycle":32,"description":8346,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8347,"url":8348},{"cveId":8352,"releaseId":25,"cycle":26,"description":8353,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8354,"url":8355},"CVE-2024-46842","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info\n\nThe MBX_TIMEOUT return code is not handled in lpfc_get_sfp_info and the\nroutine unconditionally frees submitted mailbox commands regardless of\nreturn status.  The issue is that for MBX_TIMEOUT cases, when firmware\nreturns SFP information at a later time, that same mailbox memory region\nreferences previously freed memory in its cmpl routine.\n\nFix by adding checks for the ","2024-09-27T13:15:16.19+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46842",{"cveId":8352,"releaseId":17,"cycle":18,"description":8353,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8354,"url":8355},{"cveId":8352,"releaseId":31,"cycle":32,"description":8353,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8354,"url":8355},{"cveId":8359,"releaseId":25,"cycle":26,"description":8360,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8361,"url":8362},"CVE-2024-46834","In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: fail closed if we can't get max channel used in indirection tables\n\nCommit 0d1b7d6c9274 (\"bnxt: fix crashes when reducing ring count with\nactive RSS contexts\") proves that allowing indirection table to contain\nchannels with out of bounds IDs may lead to crashes. Currently the\nmax channel check in the core gets skipped if driver can't fetch\nthe indirection table or when we can't allocate memory.\n\nBoth of those condition","2024-09-27T13:15:15.66+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46834",{"cveId":8359,"releaseId":17,"cycle":18,"description":8360,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8361,"url":8362},{"cveId":8359,"releaseId":31,"cycle":32,"description":8360,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8361,"url":8362},{"cveId":8366,"releaseId":25,"cycle":26,"description":8367,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":8368,"url":8369},"CVE-2024-46823","In the Linux kernel, the following vulnerability has been resolved:\n\nkunit\u002Foverflow: Fix UB in overflow_allocation_test\n\nThe 'device_name' array doesn't exist out of the\n'overflow_allocation_test' function scope. However, it is being used as\na driver name when calling 'kunit_driver_create' from\n'kunit_device_register'. It produces the kernel panic with KASAN\nenabled.\n\nSince this variable is used in one place only, remove it and pass the\ndevice name into kunit_device_register directly as an ascii","2024-09-27T13:15:14.897+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46823",{"cveId":8366,"releaseId":17,"cycle":18,"description":8367,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":8368,"url":8369},{"cveId":8366,"releaseId":31,"cycle":32,"description":8367,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":8368,"url":8369},{"cveId":8373,"releaseId":31,"cycle":32,"description":8374,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8375,"url":8376},"CVE-2024-46818","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Check gpio_id before used as array index\n\n[WHY & HOW]\nGPIO_ID_UNKNOWN (-1) is not a valid value for array index and therefore\nshould be checked in advance.\n\nThis fixes 5 OVERRUN issues reported by Coverity.","2024-09-27T13:15:14.563+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46818",{"cveId":8373,"releaseId":17,"cycle":18,"description":8374,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8375,"url":8376},{"cveId":8373,"releaseId":25,"cycle":26,"description":8374,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8375,"url":8376},{"cveId":8380,"releaseId":31,"cycle":32,"description":8381,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8382,"url":8383},"CVE-2024-46815","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Check num_valid_sets before accessing reader_wm_sets[]\n\n[WHY & HOW]\nnum_valid_sets needs to be checked to avoid a negative index when\naccessing reader_wm_sets[num_valid_sets - 1].\n\nThis fixes an OVERRUN issue reported by Coverity.","2024-09-27T13:15:14.37+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46815",{"cveId":8380,"releaseId":25,"cycle":26,"description":8381,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8382,"url":8383},{"cveId":8380,"releaseId":17,"cycle":18,"description":8381,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8382,"url":8383},{"cveId":8387,"releaseId":31,"cycle":32,"description":8388,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8389,"url":8390},"CVE-2024-46813","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Check link_index before accessing dc->links[]\n\n[WHY & HOW]\ndc->links[] has max size of MAX_LINKS and NULL is return when trying to\naccess with out-of-bound index.\n\nThis fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.","2024-09-27T13:15:14.23+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46813",{"cveId":8387,"releaseId":17,"cycle":18,"description":8388,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8389,"url":8390},{"cveId":8387,"releaseId":25,"cycle":26,"description":8388,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8389,"url":8390},{"cveId":8394,"releaseId":25,"cycle":26,"description":8395,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8396,"url":8397},"CVE-2024-46812","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Skip inactive planes within ModeSupportAndSystemConfiguration\n\n[Why]\nCoverity reports Memory - illegal accesses.\n\n[How]\nSkip inactive planes.","2024-09-27T13:15:14.163+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46812",{"cveId":8394,"releaseId":17,"cycle":18,"description":8395,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8396,"url":8397},{"cveId":8394,"releaseId":31,"cycle":32,"description":8395,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8396,"url":8397},{"cveId":8401,"releaseId":31,"cycle":32,"description":8402,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8403,"url":8404},"CVE-2024-46811","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix index may exceed array range within fpu_update_bw_bounding_box\n\n[Why]\nCoverity reports OVERRUN warning. soc.num_states could\nbe 40. But array range of bw_params->clk_table.entries is 8.\n\n[How]\nAssert if soc.num_states greater than 8.","2024-09-27T13:15:14.107+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46811",{"cveId":8401,"releaseId":25,"cycle":26,"description":8402,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8403,"url":8404},{"cveId":8401,"releaseId":17,"cycle":18,"description":8402,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8403,"url":8404},{"cveId":8408,"releaseId":25,"cycle":26,"description":8409,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8410,"url":8411},"CVE-2024-46803","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdkfd: Check debug trap enable before write dbg_ev_file\n\nIn interrupt context, write dbg_ev_file will be run by work queue. It\nwill cause write dbg_ev_file execution after debug_trap_disable, which\nwill cause NULL pointer access.\nv2: cancel work \"debug_event_workarea\" before set dbg_ev_file as NULL.","2024-09-27T13:15:13.57+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46803",{"cveId":8408,"releaseId":17,"cycle":18,"description":8409,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8410,"url":8411},{"cveId":8408,"releaseId":31,"cycle":32,"description":8409,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8410,"url":8411},{"cveId":8415,"releaseId":17,"cycle":18,"description":8416,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8417,"url":8418},"CVE-2022-48945","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: fix compose size exceed boundary\n\nsyzkaller found a bug:\n\n BUG: unable to handle page fault for address: ffffc9000a3b1000\n #PF: supervisor write access in kernel mode\n #PF: error_code(0x0002) - not-present page\n PGD 100000067 P4D 100000067 PUD 10015f067 PMD 1121ca067 PTE 0\n Oops: 0002 [#1] PREEMPT SMP\n CPU: 0 PID: 23489 Comm: vivid-000-vid-c Not tainted 6.1.0-rc1+ #512\n Hardware name: QEMU Standard PC (i440FX + PI","2024-09-23T10:15:02.467+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48945",{"cveId":8415,"releaseId":25,"cycle":26,"description":8416,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8417,"url":8418},{"cveId":8415,"releaseId":31,"cycle":32,"description":8416,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8417,"url":8418},{"cveId":8422,"releaseId":17,"cycle":18,"description":8423,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8424,"url":8425},"CVE-2024-46800","In the Linux kernel, the following vulnerability has been resolved:\n\nsch\u002Fnetem: fix use after free in netem_dequeue\n\nIf netem_dequeue() enqueues packet to inner qdisc and that qdisc\nreturns __NET_XMIT_STOLEN. The packet is dropped but\nqdisc_tree_reduce_backlog() is not called to update the parent's\nq.qlen, leading to the similar use-after-free as Commit\ne04991a48dbaf382 (\"netem: fix return value if duplicate enqueue\nfails\")\n\nCommands to trigger KASAN UaF:\n\nip link add type dummy\nip link set lo u","2024-09-18T08:15:06.573+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46800",{"cveId":8422,"releaseId":25,"cycle":26,"description":8423,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8424,"url":8425},{"cveId":8422,"releaseId":31,"cycle":32,"description":8423,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8424,"url":8425},{"cveId":8429,"releaseId":25,"cycle":26,"description":8430,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8431,"url":8432},"CVE-2024-46787","In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: fix checks for huge PMDs\n\nPatch series \"userfaultfd: fix races around pmd_trans_huge() check\", v2.\n\nThe pmd_trans_huge() code in mfill_atomic() is wrong in three different\nways depending on kernel version:\n\n1. The pmd_trans_huge() check is racy and can lead to a BUG_ON() (if you hit\n   the right two race windows) - I've tested this in a kernel build with\n   some extra mdelay() calls. See the commit message for a de","2024-09-18T08:15:05.833+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46787",{"cveId":8429,"releaseId":17,"cycle":18,"description":8430,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8431,"url":8432},{"cveId":8429,"releaseId":31,"cycle":32,"description":8430,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8431,"url":8432},{"cveId":8436,"releaseId":25,"cycle":26,"description":8437,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8438,"url":8439},"CVE-2024-46781","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix missing cleanup on rollforward recovery error\n\nIn an error injection test of a routine for mount-time recovery, KASAN\nfound a use-after-free bug.\n\nIt turned out that if data recovery was performed using partial logs\ncreated by dsync writes, but an error occurred before starting the log\nwriter to create a recovered checkpoint, the inodes whose data had been\nrecovered were left in the ns_dirty_files list of the nilfs ","2024-09-18T08:15:05.527+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46781",{"cveId":8436,"releaseId":17,"cycle":18,"description":8437,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8438,"url":8439},{"cveId":8436,"releaseId":31,"cycle":32,"description":8437,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8438,"url":8439},{"cveId":8443,"releaseId":25,"cycle":26,"description":8444,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8445,"url":8446},"CVE-2024-46780","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: protect references to superblock parameters exposed in sysfs\n\nThe superblock buffers of nilfs2 can not only be overwritten at runtime\nfor modifications\u002Frepairs, but they are also regularly swapped, replaced\nduring resizing, and even abandoned when degrading to one side due to\nbacking device issues.  So, accessing them requires mutual exclusion using\nthe reader\u002Fwriter semaphore \"nilfs->ns_sem\".\n\nSome sysfs attribute show","2024-09-18T08:15:05.473+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46780",{"cveId":8443,"releaseId":17,"cycle":18,"description":8444,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8445,"url":8446},{"cveId":8443,"releaseId":31,"cycle":32,"description":8444,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8445,"url":8446},{"cveId":8450,"releaseId":25,"cycle":26,"description":8451,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8452,"url":8453},"CVE-2024-46777","In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Avoid excessive partition lengths\n\nAvoid mounting filesystems where the partition would overflow the\n32-bits used for block number. Also refuse to mount filesystems where\nthe partition length is so large we cannot safely index bits in a\nblock bitmap.","2024-09-18T08:15:05.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46777",{"cveId":8450,"releaseId":17,"cycle":18,"description":8451,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8452,"url":8453},{"cveId":8450,"releaseId":31,"cycle":32,"description":8451,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8452,"url":8453},{"cveId":8457,"releaseId":25,"cycle":26,"description":8458,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8459,"url":8460},"CVE-2024-46771","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: Remove proc entry when dev is unregistered.\n\nsyzkaller reported a warning in bcm_connect() below. [0]\n\nThe repro calls connect() to vxcan1, removes vxcan1, and calls\nconnect() with ifindex == 0.\n\nCalling connect() for a BCM socket allocates a proc entry.\nThen, bcm_sk(sk)->bound is set to 1 to prevent further connect().\n\nHowever, removing the bound device resets bcm_sk(sk)->bound to 0\nin bcm_notify().\n\nThe 2nd connect(","2024-09-18T08:15:05.01+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46771",{"cveId":8457,"releaseId":17,"cycle":18,"description":8458,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8459,"url":8460},{"cveId":8457,"releaseId":31,"cycle":32,"description":8458,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8459,"url":8460},{"cveId":8464,"releaseId":17,"cycle":18,"description":8465,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8466,"url":8467},"CVE-2024-46770","In the Linux kernel, the following vulnerability has been resolved:\n\nice: Add netif_device_attach\u002Fdetach into PF reset flow\n\nEthtool callbacks can be executed while reset is in progress and try to\naccess deleted resources, e.g. getting coalesce settings can result in a\nNULL pointer dereference seen below.\n\nReproduction steps:\nOnce the driver is fully initialized, trigger reset:\n\t# echo 1 > \u002Fsys\u002Fclass\u002Fnet\u002F\u003Cinterface>\u002Fdevice\u002Freset\nwhen reset is in progress try to get coalesce settings using ethtoo","2024-09-18T08:15:04.957+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46770",{"cveId":8469,"releaseId":25,"cycle":26,"description":8470,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8471,"url":8472},"CVE-2024-46763","In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Fix null-ptr-deref in GRO.\n\nWe observed a null-ptr-deref in fou_gro_receive() while shutting down\na host.  [0]\n\nThe NULL pointer is sk->sk_user_data, and the offset 8 is of protocol\nin struct fou.\n\nWhen fou_release() is called due to netns dismantle or explicit tunnel\nteardown, udp_tunnel_sock_release() sets NULL to sk->sk_user_data.\nThen, the tunnel socket is destroyed after a single RCU grace period.\n\nSo, in-flight udp4_","2024-09-18T08:15:04.613+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46763",{"cveId":8469,"releaseId":17,"cycle":18,"description":8470,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8471,"url":8472},{"cveId":8469,"releaseId":31,"cycle":32,"description":8470,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8471,"url":8472},{"cveId":8476,"releaseId":25,"cycle":26,"description":8477,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8478,"url":8479},"CVE-2024-46762","In the Linux kernel, the following vulnerability has been resolved:\n\nxen: privcmd: Fix possible access to a freed kirqfd instance\n\nNothing prevents simultaneous ioctl calls to privcmd_irqfd_assign() and\nprivcmd_irqfd_deassign(). If that happens, it is possible that a kirqfd\ncreated and added to the irqfds_list by privcmd_irqfd_assign() may get\nremoved by another thread executing privcmd_irqfd_deassign(), while the\nformer is still using it after dropping the locks.\n\nThis can lead to a situation w","2024-09-18T08:15:04.57+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46762",{"cveId":8476,"releaseId":17,"cycle":18,"description":8477,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8478,"url":8479},{"cveId":8476,"releaseId":31,"cycle":32,"description":8477,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8478,"url":8479},{"cveId":8483,"releaseId":31,"cycle":32,"description":8484,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8485,"url":8486},"CVE-2024-46755","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()\n\nmwifiex_get_priv_by_id() returns the priv pointer corresponding to\nthe bss_num and bss_type, but without checking if the priv is actually\ncurrently in use.\nUnused priv pointers do not have a wiphy attached to them which can\nlead to NULL pointer dereferences further down the callstack.  Fix\nthis by returning only used priv pointers which have priv->bss_mode\nse","2024-09-18T08:15:04.203+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46755",{"cveId":8483,"releaseId":25,"cycle":26,"description":8484,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8485,"url":8486},{"cveId":8483,"releaseId":17,"cycle":18,"description":8484,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8485,"url":8486},{"cveId":8490,"releaseId":17,"cycle":18,"description":8491,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8492,"url":8493},"CVE-2024-46754","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Remove tst_run from lwt_seg6local_prog_ops.\n\nThe syzbot reported that the lwt_seg6 related BPF ops can be invoked\nvia bpf_test_run() without without entering input_action_end_bpf()\nfirst.\n\nMartin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL\nprobably didn't work since it was introduced in commit 04d4b274e2a\n(\"ipv6: sr: Add seg6local action End.BPF\"). The reason is that the\nper-CPU variable seg6_bpf_srh_stat","2024-09-18T08:15:04.153+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46754",{"cveId":8495,"releaseId":31,"cycle":32,"description":8496,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8497,"url":8498},"CVE-2024-46751","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't BUG_ON() when 0 reference count at btrfs_lookup_extent_info()\n\nInstead of doing a BUG_ON() handle the error by returning -EUCLEAN,\naborting the transaction and logging an error message.","2024-09-18T08:15:04.01+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46751",{"cveId":8495,"releaseId":25,"cycle":26,"description":8496,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8497,"url":8498},{"cveId":8495,"releaseId":17,"cycle":18,"description":8496,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8497,"url":8498},{"cveId":8502,"releaseId":31,"cycle":32,"description":8503,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8504,"url":8505},"CVE-2024-46750","In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Add missing bridge lock to pci_bus_lock()\n\nOne of the true positives that the cfg_access_lock lockdep effort\nidentified is this sequence:\n\n  WARNING: CPU: 14 PID: 1 at drivers\u002Fpci\u002Fpci.c:4886 pci_bridge_secondary_bus_reset+0x5d\u002F0x70\n  RIP: 0010:pci_bridge_secondary_bus_reset+0x5d\u002F0x70\n  Call Trace:\n   \u003CTASK>\n   ? __warn+0x8c\u002F0x190\n   ? pci_bridge_secondary_bus_reset+0x5d\u002F0x70\n   ? report_bug+0x1f8\u002F0x200\n   ? handle_bug+0x3c","2024-09-18T08:15:03.947+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46750",{"cveId":8502,"releaseId":25,"cycle":26,"description":8503,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8504,"url":8505},{"cveId":8502,"releaseId":17,"cycle":18,"description":8503,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8504,"url":8505},{"cveId":8509,"releaseId":31,"cycle":32,"description":8510,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8511,"url":8512},"CVE-2024-46743","In the Linux kernel, the following vulnerability has been resolved:\n\nof\u002Firq: Prevent device address out-of-bounds read in interrupt map walk\n\nWhen of_irq_parse_raw() is invoked with a device address smaller than\nthe interrupt parent node (from #address-cells property), KASAN detects\nthe following out-of-bounds read when populating the initial match table\n(dyndbg=\"func of_irq_parse_* +p\"):\n\n  OF: of_irq_parse_one: dev=\u002Fsoc@0\u002Fpicasso\u002Fwatchdog, index=0\n  OF:  parent=\u002Fsoc@0\u002Fpci@878000000000\u002Fgpio0@17","2024-09-18T08:15:03.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46743",{"cveId":8509,"releaseId":17,"cycle":18,"description":8510,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8511,"url":8512},{"cveId":8509,"releaseId":25,"cycle":26,"description":8510,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":8511,"url":8512},{"cveId":8516,"releaseId":25,"cycle":26,"description":8517,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8518,"url":8519},"CVE-2024-46738","In the Linux kernel, the following vulnerability has been resolved:\n\nVMCI: Fix use-after-free when removing resource in vmci_resource_remove()\n\nWhen removing a resource from vmci_resource_table in\nvmci_resource_remove(), the search is performed using the resource\nhandle by comparing context and resource fields.\n\nIt is possible though to create two resources with different types\nbut same handle (same context and resource fields).\n\nWhen trying to remove one of the resources, vmci_resource_remove()","2024-09-18T08:15:03.233+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46738",{"cveId":8516,"releaseId":17,"cycle":18,"description":8517,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8518,"url":8519},{"cveId":8516,"releaseId":31,"cycle":32,"description":8517,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8518,"url":8519},{"cveId":8523,"releaseId":25,"cycle":26,"description":8524,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8525,"url":8526},"CVE-2024-46730","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Ensure array index tg_inst won't be -1\n\n[WHY & HOW]\ntg_inst will be a negative if timing_generator_count equals 0, which\nshould be checked before used.\n\nThis fixes 2 OVERRUN issues reported by Coverity.","2024-09-18T07:15:04.003+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46730",{"cveId":8523,"releaseId":17,"cycle":18,"description":8524,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8525,"url":8526},{"cveId":8523,"releaseId":31,"cycle":32,"description":8524,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8525,"url":8526},{"cveId":8530,"releaseId":25,"cycle":26,"description":8531,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8532,"url":8533},"CVE-2024-46717","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5e: SHAMPO, Fix incorrect page release\n\nUnder the following conditions:\n1) No skb created yet\n2) header_size == 0 (no SHAMPO header)\n3) header_index + 1 % MLX5E_SHAMPO_WQ_HEADER_PER_PAGE == 0 (this is the\n   last page fragment of a SHAMPO header page)\n\na new skb is formed with a page that is NOT a SHAMPO header page (it\nis a regular data page). Further down in the same function\n(mlx5e_handle_rx_cqe_mpwrq_shampo()), a SHA","2024-09-18T07:15:03.237+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46717",{"cveId":8530,"releaseId":17,"cycle":18,"description":8531,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8532,"url":8533},{"cveId":8530,"releaseId":31,"cycle":32,"description":8531,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8532,"url":8533},{"cveId":8537,"releaseId":31,"cycle":32,"description":8538,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8539,"url":8540},"CVE-2024-46716","In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor\n\nRemove list_del call in msgdma_chan_desc_cleanup, this should be the role\nof msgdma_free_descriptor. In consequence replace list_add_tail with\nlist_move_tail in msgdma_free_descriptor.\n\nThis fixes the path:\n   msgdma_free_chan_resources -> msgdma_free_descriptors ->\n   msgdma_free_desc_list -> msgdma_free_descriptor\n\nwhich does not correctly free the ","2024-09-18T07:15:03.183+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46716",{"cveId":8537,"releaseId":17,"cycle":18,"description":8538,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8539,"url":8540},{"cveId":8537,"releaseId":25,"cycle":26,"description":8538,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8539,"url":8540},{"cveId":8544,"releaseId":31,"cycle":32,"description":8545,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8546,"url":8547},"CVE-2024-46713","In the Linux kernel, the following vulnerability has been resolved:\n\nperf\u002Faux: Fix AUX buffer serialization\n\nOle reported that event->mmap_mutex is strictly insufficient to\nserialize the AUX buffer, add a per RB mutex to fully serialize it.\n\nNote that in the lock order comment the perf_event::mmap_mutex order\nwas already wrong, that is, it nesting under mmap_lock is not new with\nthis patch.","2024-09-13T15:15:15.01+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46713",{"cveId":8544,"releaseId":25,"cycle":26,"description":8545,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8546,"url":8547},{"cveId":8544,"releaseId":17,"cycle":18,"description":8545,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8546,"url":8547},{"cveId":8551,"releaseId":31,"cycle":32,"description":8552,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8553,"url":8554},"CVE-2024-46705","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fxe: reset mmio mappings with devm\n\nSet our various mmio mappings to NULL. This should make it easier to\ncatch something rogue trying to mess with mmio after device removal. For\nexample, we might unmap everything and then start hitting some mmio\naddress which has already been unmamped by us and then remapped by\nsomething else, causing all kinds of carnage.","2024-09-13T07:15:05.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46705",{"cveId":8551,"releaseId":25,"cycle":26,"description":8552,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8553,"url":8554},{"cveId":8551,"releaseId":17,"cycle":18,"description":8552,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8553,"url":8554},{"cveId":8558,"releaseId":31,"cycle":32,"description":8559,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8560,"url":8561},"CVE-2024-46695","In the Linux kernel, the following vulnerability has been resolved:\n\nselinux,smack: don't bypass permissions check in inode_setsecctx hook\n\nMarek Gresko reports that the root user on an NFS client is able to\nchange the security labels on files on an NFS filesystem that is\nexported with root squashing enabled.\n\nThe end of the kerneldoc comment for __vfs_setxattr_noperm() states:\n\n *  This function requires the caller to lock the inode's i_mutex before it\n *  is executed. It also assumes that the ","2024-09-13T06:15:14.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46695",{"cveId":8558,"releaseId":25,"cycle":26,"description":8559,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8560,"url":8561},{"cveId":8558,"releaseId":17,"cycle":18,"description":8559,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8560,"url":8561},{"cveId":8565,"releaseId":25,"cycle":26,"description":8566,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8567,"url":8568},"CVE-2024-46674","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: st: fix probed platform device ref count on probe error path\n\nThe probe function never performs any paltform device allocation, thus\nerror path \"undo_platform_dev_alloc\" is entirely bogus.  It drops the\nreference count from the platform device being probed.  If error path is\ntriggered, this will lead to unbalanced device reference counts and\npremature release of device resources, thus possible use-after-free when\nrel","2024-09-13T06:15:12.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46674",{"cveId":8565,"releaseId":17,"cycle":18,"description":8566,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8567,"url":8568},{"cveId":8565,"releaseId":31,"cycle":32,"description":8566,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8567,"url":8568},{"cveId":8572,"releaseId":17,"cycle":18,"description":8573,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8574,"url":8575},"CVE-2024-46673","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: aacraid: Fix double-free on probe failure\n\naac_probe_one() calls hardware-specific init functions through the\naac_driver_ident::init pointer, all of which eventually call down to\naac_init_adapter().\n\nIf aac_init_adapter() fails after allocating memory for aac_dev::queues,\nit frees the memory but does not clear that member.\n\nAfter the hardware-specific init function returns an error,\naac_probe_one() goes down an error path","2024-09-13T06:15:11.917+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-46673",{"cveId":8572,"releaseId":25,"cycle":26,"description":8573,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8574,"url":8575},{"cveId":8572,"releaseId":31,"cycle":32,"description":8573,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8574,"url":8575},{"cveId":8579,"releaseId":17,"cycle":18,"description":8580,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8581,"url":8582},"CVE-2024-45021","In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg_write_event_control(): fix a user-triggerable oops\n\nwe are *not* guaranteed that anything past the terminating NUL\nis mapped (let alone initialized with anything sane).","2024-09-11T16:15:07.103+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-45021",{"cveId":8579,"releaseId":25,"cycle":26,"description":8580,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8581,"url":8582},{"cveId":8579,"releaseId":31,"cycle":32,"description":8580,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8581,"url":8582},{"cveId":8586,"releaseId":31,"cycle":32,"description":8587,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8588,"url":8589},"CVE-2024-44998","In the Linux kernel, the following vulnerability has been resolved:\n\natm: idt77252: prevent use after free in dequeue_rx()\n\nWe can't dereference \"skb\" after calling vcc->push() because the skb\nis released.","2024-09-04T20:15:08.52+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44998",{"cveId":8586,"releaseId":25,"cycle":26,"description":8587,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8588,"url":8589},{"cveId":8586,"releaseId":17,"cycle":18,"description":8587,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8588,"url":8589},{"cveId":8593,"releaseId":17,"cycle":18,"description":8594,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8595,"url":8596},"CVE-2024-44995","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix a deadlock problem when config TC during resetting\n\nWhen config TC during the reset process, may cause a deadlock, the flow is\nas below:\n                             pf reset start\n                                 │\n                                 ▼\n                              ......\nsetup tc                         │\n    │                            ▼\n    ▼                      DOWN: napi_disable()\nnapi_disab","2024-09-04T20:15:08.353+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44995",{"cveId":8598,"releaseId":17,"cycle":18,"description":8599,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8600,"url":8601},"CVE-2024-44988","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Fix out-of-bound access\n\nIf an ATU violation was caused by a CPU Load operation, the SPID could\nbe larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array).","2024-09-04T20:15:07.96+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44988",{"cveId":8603,"releaseId":17,"cycle":18,"description":8604,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8605,"url":8606},"CVE-2024-44987","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent UAF in ip6_send_skb()\n\nsyzbot reported an UAF in ip6_send_skb() [1]\n\nAfter ip6_local_out() has returned, we no longer can safely\ndereference rt, unless we hold rcu_read_lock().\n\nA similar issue has been fixed in commit\na688caa34beb (\"ipv6: take rcu lock in rawv6_send_hdrinc()\")\n\nAnother potential issue in ip6_finish_output2() is handled in a\nseparate patch.\n\n[1]\n BUG: KASAN: slab-use-after-free in ip6_send_skb+0x1","2024-09-04T20:15:07.89+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44987",{"cveId":8603,"releaseId":25,"cycle":26,"description":8604,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8605,"url":8606},{"cveId":8603,"releaseId":31,"cycle":32,"description":8604,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8605,"url":8606},{"cveId":8610,"releaseId":17,"cycle":18,"description":8611,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8612,"url":8613},"CVE-2024-44970","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5e: SHAMPO, Fix invalid WQ linked list unlink\n\nWhen all the strides in a WQE have been consumed, the WQE is unlinked\nfrom the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible\nto receive CQEs with 0 consumed strides for the same WQE even after the\nWQE is fully consumed and unlinked. This triggers an additional unlink\nfor the same wqe which corrupts the linked list.\n\nFix this scenario by accepting 0 sized cons","2024-09-04T19:15:31.307+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44970",{"cveId":8610,"releaseId":31,"cycle":32,"description":8611,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8612,"url":8613},{"cveId":8610,"releaseId":25,"cycle":26,"description":8611,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8612,"url":8613},{"cveId":8617,"releaseId":25,"cycle":26,"description":8618,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8619,"url":8620},"CVE-2024-44954","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: line6: Fix racy access to midibuf\n\nThere can be concurrent accesses to line6 midibuf from both the URB\ncompletion callback and the rawmidi API access.  This could be a cause\nof KMSAN warning triggered by syzkaller below (so put as reported-by\nhere).\n\nThis patch protects the midibuf call of the former code path with a\nspinlock for avoiding the possible races.","2024-09-04T19:15:30.353+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44954",{"cveId":8617,"releaseId":17,"cycle":18,"description":8618,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8619,"url":8620},{"cveId":8617,"releaseId":31,"cycle":32,"description":8618,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8619,"url":8620},{"cveId":8624,"releaseId":25,"cycle":26,"description":8625,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8626,"url":8627},"CVE-2024-44950","In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix invalid FIFO access with special register set\n\nWhen enabling access to the special register set, Receiver time-out and\nRHR interrupts can happen. In this case, the IRQ handler will try to read\nfrom the FIFO thru the RHR register at address 0x00, but address 0x00 is\nmapped to DLL register, resulting in erroneous FIFO reading.\n\nCall graph example:\n    sc16is7xx_startup(): entry\n    sc16is7xx_ms_proc(): entr","2024-09-04T19:15:30.1+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44950",{"cveId":8624,"releaseId":31,"cycle":32,"description":8625,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8626,"url":8627},{"cveId":8624,"releaseId":17,"cycle":18,"description":8625,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8626,"url":8627},{"cveId":8631,"releaseId":25,"cycle":26,"description":8632,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8633,"url":8634},"CVE-2024-44949","In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: fix a possible DMA corruption\n\nARCH_DMA_MINALIGN was defined as 16 - this is too small - it may be\npossible that two unrelated 16-byte allocations share a cache line. If\none of these allocations is written using DMA and the other is written\nusing cached write, the value that was written with DMA may be\ncorrupted.\n\nThis commit changes ARCH_DMA_MINALIGN to be 128 on PA20 and 32 on PA1.1 -\nthat's the largest possible cache","2024-09-04T19:15:30.04+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44949",{"cveId":8631,"releaseId":17,"cycle":18,"description":8632,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8633,"url":8634},{"cveId":8631,"releaseId":31,"cycle":32,"description":8632,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8633,"url":8634},{"cveId":8638,"releaseId":25,"cycle":26,"description":8639,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8640,"url":8641},"CVE-2024-44946","In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: Serialise kcm_sendmsg() for the same socket.\n\nsyzkaller reported UAF in kcm_release(). [0]\n\nThe scenario is\n\n  1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb.\n\n  2. Thread A resumes building skb from kcm->seq_skb but is blocked\n     by sk_stream_wait_memory()\n\n  3. Thread B calls sendmsg() concurrently, finishes building kcm->seq_skb\n     and puts the skb to the write queue\n\n  4. Thread A faces an error and f","2024-08-31T14:15:04.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44946",{"cveId":8638,"releaseId":17,"cycle":18,"description":8639,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8640,"url":8641},{"cveId":8638,"releaseId":31,"cycle":32,"description":8639,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8640,"url":8641},{"cveId":8645,"releaseId":25,"cycle":26,"description":8646,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8647,"url":8648},"CVE-2024-44942","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs\u002Ff2fs\u002Finline.c:258!\nCPU: 1 PID: 34 Comm: kworker\u002Fu8:2 Not tainted 6.9.0-rc6-syzkaller-00012-g9e4bc4bcae01 #0\nRIP: 0010:f2fs_write_inline_data+0x781\u002F0x790 fs\u002Ff2fs\u002Finline.c:258\nCall Trace:\n f2fs_write_single_data_page+0xb65\u002F0x1d60 fs\u002Ff2fs\u002Fdata.c:2834\n f2fs_write_cache_","2024-08-26T12:15:06.157+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44942",{"cveId":8645,"releaseId":17,"cycle":18,"description":8646,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8647,"url":8648},{"cveId":8645,"releaseId":31,"cycle":32,"description":8646,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8647,"url":8648},{"cveId":8652,"releaseId":25,"cycle":26,"description":8653,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8654,"url":8655},"CVE-2024-44940","In the Linux kernel, the following vulnerability has been resolved:\n\nfou: remove warn in gue_gro_receive on unsupported protocol\n\nDrop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is\nnot known or does not have a GRO handler.\n\nSuch a packet is easily constructed. Syzbot generates them and sets\noff this warning.\n\nRemove the warning as it is expected and not actionable.\n\nThe warning was previously reduced from WARN_ON to WARN_ON_ONCE in\ncommit 270136613bf7 (\"fou: Do WARN_ON_ONCE in","2024-08-26T12:15:06.053+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44940",{"cveId":8652,"releaseId":17,"cycle":18,"description":8653,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8654,"url":8655},{"cveId":8652,"releaseId":31,"cycle":32,"description":8653,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8654,"url":8655},{"cveId":8659,"releaseId":25,"cycle":26,"description":8660,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8661,"url":8662},"CVE-2024-44939","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix null ptr deref in dtInsertEntry\n\n[syzbot reported]\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0\nHardware name: Google Google Compute Engine\u002FGoogle Compute Engine, BIOS Google 03\u002F27\u002F2024\nRIP: 00","2024-08-26T12:15:06.007+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-44939",{"cveId":8659,"releaseId":17,"cycle":18,"description":8660,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8661,"url":8662},{"cveId":8659,"releaseId":31,"cycle":32,"description":8660,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8661,"url":8662},{"cveId":8666,"releaseId":17,"cycle":18,"description":8667,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8668,"url":8669},"CVE-2024-43913","In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: apple: fix device reference counting\n\nDrivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl.\nSplit the allocation side out to make the error handling boundary easier\nto navigate. The apple driver had been doing this wrong, leaking the\ncontroller device memory on a tagset failure.","2024-08-26T11:15:05.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43913",{"cveId":8666,"releaseId":25,"cycle":26,"description":8667,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8668,"url":8669},{"cveId":8666,"releaseId":31,"cycle":32,"description":8667,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8668,"url":8669},{"cveId":8673,"releaseId":31,"cycle":32,"description":8674,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8675,"url":8676},"CVE-2024-43902","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Add null checker before passing variables\n\nChecks null pointer before passing variables to functions.\n\nThis fixes 3 NULL_RETURNS issues reported by Coverity.","2024-08-26T11:15:04.733+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43902",{"cveId":8673,"releaseId":17,"cycle":18,"description":8674,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8675,"url":8676},{"cveId":8673,"releaseId":25,"cycle":26,"description":8674,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":8675,"url":8676},{"cveId":8680,"releaseId":31,"cycle":32,"description":8681,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8682,"url":8683},"CVE-2024-43892","In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: protect concurrent access to mem_cgroup_idr\n\nCommit 73f576c04b94 (\"mm: memcontrol: fix cgroup creation failure after\nmany small jobs\") decoupled the memcg IDs from the CSS ID space to fix the\ncgroup creation failures.  It introduced IDR to maintain the memcg ID\nspace.  The IDR depends on external synchronization mechanisms for\nmodifications.  For the mem_cgroup_idr, the idr_alloc() and idr_replace()\nhappen within css cal","2024-08-26T11:15:04.157+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43892",{"cveId":8680,"releaseId":17,"cycle":18,"description":8681,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8682,"url":8683},{"cveId":8680,"releaseId":25,"cycle":26,"description":8681,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8682,"url":8683},{"cveId":8687,"releaseId":31,"cycle":32,"description":8688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8689,"url":8690},"CVE-2024-43883","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: vhci-hcd: Do not drop references before new references are gained\n\nAt a few places the driver carries stale pointers\nto references that can still be used. Make sure that does not happen.\nThis strictly speaking closes ZDI-CAN-22273, though there may be\nsimilar races in the driver.","2024-08-23T13:15:03.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43883",{"cveId":8687,"releaseId":17,"cycle":18,"description":8688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8689,"url":8690},{"cveId":8687,"releaseId":25,"cycle":26,"description":8688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8689,"url":8690},{"cveId":8694,"releaseId":31,"cycle":32,"description":8695,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8696,"url":8697},"CVE-2022-48943","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86\u002Fmmu: make apf token non-zero to fix bug\n\nIn current async pagefault logic, when a page is ready, KVM relies on\nkvm_arch_can_dequeue_async_page_present() to determine whether to deliver\na READY event to the Guest. This function test token value of struct\nkvm_vcpu_pv_apf_data, which must be reset to zero by Guest kernel when a\nREADY event is finished by Guest. If value is zero meaning that a READY\nevent is done, so the K","2024-08-22T04:15:19.027+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48943",{"cveId":8694,"releaseId":17,"cycle":18,"description":8695,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8696,"url":8697},{"cveId":8694,"releaseId":25,"cycle":26,"description":8695,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":8696,"url":8697},{"cveId":8701,"releaseId":31,"cycle":32,"description":8702,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8703,"url":8704},"CVE-2022-48941","In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix concurrent reset and removal of VFs\n\nCommit c503e63200c6 (\"ice: Stop processing VF messages during teardown\")\nintroduced a driver state flag, ICE_VF_DEINIT_IN_PROGRESS, which is\nintended to prevent some issues with concurrently handling messages from\nVFs while tearing down the VFs.\n\nThis change was motivated by crashes caused while tearing down and\nbringing up VFs in rapid succession.\n\nIt turns out that the fix actuall","2024-08-22T04:15:17.967+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48941",{"cveId":8701,"releaseId":25,"cycle":26,"description":8702,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8703,"url":8704},{"cveId":8701,"releaseId":17,"cycle":18,"description":8702,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8703,"url":8704},{"cveId":8708,"releaseId":25,"cycle":26,"description":8709,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8710,"url":8711},"CVE-2022-48935","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: unregister flowtable hooks on netns exit\n\nUnregister flowtable hooks before they are releases via\nnf_tables_flowtable_destroy() otherwise hook core reports UAF.\n\nBUG: KASAN: use-after-free in nf_hook_entries_grow+0x5a7\u002F0x700 net\u002Fnetfilter\u002Fcore.c:142 net\u002Fnetfilter\u002Fcore.c:142\nRead of size 4 at addr ffff8880736f7438 by task syz-executor579\u002F3666\n\nCPU: 0 PID: 3666 Comm: syz-executor579 Not tainted 5.16.0-rc5-sy","2024-08-22T04:15:16.877+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48935",{"cveId":8708,"releaseId":17,"cycle":18,"description":8709,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8710,"url":8711},{"cveId":8708,"releaseId":31,"cycle":32,"description":8709,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8710,"url":8711},{"cveId":8715,"releaseId":17,"cycle":18,"description":8716,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8717,"url":8718},"CVE-2022-48923","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: prevent copying too big compressed lzo segment\n\nCompressed length can be corrupted to be a lot larger than memory\nwe have allocated for buffer.\nThis will cause memcpy in copy_compressed_segment to write outside\nof allocated memory.\n\nThis mostly results in stuck read syscall but sometimes when using\nbtrfs send can get #GP\n\n  kernel: general protection fault, probably for non-canonical address 0x841551d5c1000: 0000 [#1] PR","2024-08-22T02:15:08.377+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48923",{"cveId":8715,"releaseId":25,"cycle":26,"description":8716,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8717,"url":8718},{"cveId":8715,"releaseId":31,"cycle":32,"description":8716,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8717,"url":8718},{"cveId":8722,"releaseId":25,"cycle":26,"description":8723,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8724,"url":8725},"CVE-2022-48919","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix double free race when mount fails in cifs_get_root()\n\nWhen cifs_get_root() fails during cifs_smb3_do_mount() we call\ndeactivate_locked_super() which eventually will call delayed_free() which\nwill free the context.\nIn this situation we should not proceed to enter the out: section in\ncifs_smb3_do_mount() and free the same resources a second time.\n\n[Thu Feb 10 12:59:06 2022] BUG: KASAN: use-after-free in rcu_cblist_deque","2024-08-22T02:15:05.987+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48919",{"cveId":8722,"releaseId":31,"cycle":32,"description":8723,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8724,"url":8725},{"cveId":8722,"releaseId":17,"cycle":18,"description":8723,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8724,"url":8725},{"cveId":8729,"releaseId":25,"cycle":26,"description":8730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8731,"url":8732},"CVE-2022-48912","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: fix use-after-free in __nf_register_net_hook()\n\nWe must not dereference @new_hooks after nf_hook_mutex has been released,\nbecause other threads might have freed our allocated hooks already.\n\nBUG: KASAN: use-after-free in nf_hook_entries_get_hook_ops include\u002Flinux\u002Fnetfilter.h:130 [inline]\nBUG: KASAN: use-after-free in hooks_validate net\u002Fnetfilter\u002Fcore.c:171 [inline]\nBUG: KASAN: use-after-free in __nf_register_net_hook","2024-08-22T02:15:05.55+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48912",{"cveId":8729,"releaseId":17,"cycle":18,"description":8730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8731,"url":8732},{"cveId":8735,"releaseId":31,"cycle":32,"description":8736,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8737,"url":8738},"CVE-2022-48911","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_queue: fix possible use-after-free\n\nEric Dumazet says:\n  The sock_hold() side seems suspect, because there is no guarantee\n  that sk_refcnt is not already 0.\n\nOn failure, we cannot queue the packet and need to indicate an\nerror.  The packet will be dropped by the caller.\n\nv2: split skb prefetch hunk into separate change","2024-08-22T02:15:05.483+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48911",{"cveId":8735,"releaseId":17,"cycle":18,"description":8736,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8737,"url":8738},{"cveId":8735,"releaseId":25,"cycle":26,"description":8736,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8737,"url":8738},{"cveId":8742,"releaseId":25,"cycle":26,"description":8743,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8744,"url":8745},"CVE-2023-52907","In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: Wait for out_urb's completion in pn533_usb_send_frame()\n\nFix a use-after-free that occurs in hcd when in_urb sent from\npn533_usb_send_frame() is completed earlier than out_urb. Its callback\nfrees the skb data in pn533_send_async_complete() that is used as a\ntransfer buffer of out_urb. Wait before sending in_urb until the\ncallback of out_urb is called. To modify the callback of out_urb alone,\nseparate the complete fu","2024-08-21T07:15:06.733+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52907",{"cveId":8742,"releaseId":31,"cycle":32,"description":8743,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8744,"url":8745},{"cveId":8742,"releaseId":17,"cycle":18,"description":8743,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8744,"url":8745},{"cveId":8749,"releaseId":25,"cycle":26,"description":8750,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8751,"url":8752},"CVE-2023-52903","In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: lock overflowing for IOPOLL\n\nsyzbot reports an issue with overflow filling for IOPOLL:\n\nWARNING: CPU: 0 PID: 28 at io_uring\u002Fio_uring.c:734 io_cqring_event_overflow+0x1c0\u002F0x230 io_uring\u002Fio_uring.c:734\nCPU: 0 PID: 28 Comm: kworker\u002Fu4:1 Not tainted 6.2.0-rc3-syzkaller-16369-g358a161a6a9e #0\nWorkqueue: events_unbound io_ring_exit_work\nCall trace:\n io_cqring_event_overflow+0x1c0\u002F0x230 io_uring\u002Fio_uring.c:734\n io_req_cqe_ov","2024-08-21T07:15:06.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52903",{"cveId":8749,"releaseId":17,"cycle":18,"description":8750,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8751,"url":8752},{"cveId":8749,"releaseId":31,"cycle":32,"description":8750,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8751,"url":8752},{"cveId":8756,"releaseId":25,"cycle":26,"description":8757,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8758,"url":8759},"CVE-2022-48899","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvirtio: Fix GEM handle creation UAF\n\nUserspace can guess the handle value and try to race GEM object creation\nwith handle close, resulting in a use-after-free if we dereference the\nobject after dropping the handle's reference.  For that reason, dropping\nthe handle's reference must be done *after* we are done dereferencing\nthe object.","2024-08-21T07:15:05.81+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48899",{"cveId":8756,"releaseId":31,"cycle":32,"description":8757,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8758,"url":8759},{"cveId":8756,"releaseId":17,"cycle":18,"description":8757,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8758,"url":8759},{"cveId":8763,"releaseId":17,"cycle":18,"description":8764,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8765,"url":8766},"CVE-2024-43882","In the Linux kernel, the following vulnerability has been resolved:\n\nexec: Fix ToCToU between perm check and set-uid\u002Fgid usage\n\nWhen opening a file for exec via do_filp_open(), permission checking is\ndone against the file's metadata at that moment, and on success, a file\npointer is passed back. Much later in the execve() code path, the file\nmetadata (specifically mode, uid, and gid) is used to determine if\u002Fhow\nto set the uid and gid. However, those values may have changed since the\npermissions c","2024-08-21T01:15:12.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43882",{"cveId":8763,"releaseId":25,"cycle":26,"description":8764,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8765,"url":8766},{"cveId":8763,"releaseId":31,"cycle":32,"description":8764,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8765,"url":8766},{"cveId":8770,"releaseId":17,"cycle":18,"description":8771,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8772,"url":8773},"CVE-2024-43872","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fhns: Fix soft lockup under heavy CEQE load\n\nCEQEs are handled in interrupt handler currently. This may cause the\nCPU core staying in interrupt context too long and lead to soft lockup\nunder heavy load.\n\nHandle CEQEs in BH workqueue and set an upper limit for the number of\nCEQE handled by a single call of work handler.","2024-08-21T01:15:11.74+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43872",{"cveId":8775,"releaseId":31,"cycle":32,"description":8776,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8777,"url":8778},"CVE-2024-43858","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix array-index-out-of-bounds in diFree","2024-08-17T10:15:10.75+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43858",{"cveId":8775,"releaseId":17,"cycle":18,"description":8776,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8777,"url":8778},{"cveId":8775,"releaseId":25,"cycle":26,"description":8776,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8777,"url":8778},{"cveId":8782,"releaseId":31,"cycle":32,"description":8783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8784,"url":8785},"CVE-2024-43856","In the Linux kernel, the following vulnerability has been resolved:\n\ndma: fix call order in dmam_free_coherent\n\ndmam_free_coherent() frees a DMA allocation, which makes the\nfreed vaddr available for reuse, then calls devres_destroy()\nto remove and free the data structure used to track the DMA\nallocation. Between the two calls, it is possible for a\nconcurrent task to make an allocation with the same vaddr\nand add it to the devres list.\n\nIf this happens, there will be two entries in the devres lis","2024-08-17T10:15:10.613+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43856",{"cveId":8782,"releaseId":17,"cycle":18,"description":8783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8784,"url":8785},{"cveId":8782,"releaseId":25,"cycle":26,"description":8783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8784,"url":8785},{"cveId":8789,"releaseId":25,"cycle":26,"description":8790,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8791,"url":8792},"CVE-2024-43853","In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup\u002Fcpuset: Prevent UAF in proc_cpuset_show()\n\nAn UAF can happen when \u002Fproc\u002Fcpuset is read as reported in [1].\n\nThis can be reproduced by the following methods:\n1.add an mdelay(1000) before acquiring the cgroup_lock In the\n cgroup_path_ns function.\n2.$cat \u002Fproc\u002F\u003Cpid>\u002Fcpuset   repeatly.\n3.$mount -t cgroup -o cpuset cpuset \u002Fsys\u002Ffs\u002Fcgroup\u002Fcpuset\u002F\n$umount \u002Fsys\u002Ffs\u002Fcgroup\u002Fcpuset\u002F   repeatly.\n\nThe race that cause this bug can be sh","2024-08-17T10:15:10.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43853",{"cveId":8789,"releaseId":17,"cycle":18,"description":8790,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8791,"url":8792},{"cveId":8789,"releaseId":31,"cycle":32,"description":8790,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8791,"url":8792},{"cveId":8796,"releaseId":17,"cycle":18,"description":8797,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8798,"url":8799},"CVE-2024-43830","In the Linux kernel, the following vulnerability has been resolved:\n\nleds: trigger: Unregister sysfs attributes before calling deactivate()\n\nTriggers which have trigger specific sysfs attributes typically store\nrelated data in trigger-data allocated by the activate() callback and\nfreed by the deactivate() callback.\n\nCalling device_remove_groups() after calling deactivate() leaves a window\nwhere the sysfs attributes show\u002Fstore functions could be called after\ndeactivation and then operate on the j","2024-08-17T10:15:08.857+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-43830",{"cveId":8801,"releaseId":17,"cycle":18,"description":8802,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8803,"url":8804},"CVE-2024-42313","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: fix use after free in vdec_close\n\nThere appears to be a possible use after free with vdec_close().\nThe firmware will add buffer release work to the work queue through\nHFI callbacks as a normal part of decoding. Randomly closing the\ndecoder device from userspace during normal decoding can incur\na read after free for inst.\n\nFix it by cancelling the work in vdec_close.","2024-08-17T09:15:11.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42313",{"cveId":8801,"releaseId":25,"cycle":26,"description":8802,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8803,"url":8804},{"cveId":8807,"releaseId":17,"cycle":18,"description":8808,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8809,"url":8810},"CVE-2024-42311","In the Linux kernel, the following vulnerability has been resolved:\n\nhfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()\n\nSyzbot reports uninitialized value access issue as below:\n\nloop0: detected capacity change from 0 to 64\n=====================================================\nBUG: KMSAN: uninit-value in hfs_revalidate_dentry+0x307\u002F0x3f0 fs\u002Fhfs\u002Fsysdep.c:30\n hfs_revalidate_dentry+0x307\u002F0x3f0 fs\u002Fhfs\u002Fsysdep.c:30\n d_revalidate fs\u002Fnamei.c:862 [inline]\n lookup_fast+0x89e\u002F0x8e0 fs","2024-08-17T09:15:11.147+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42311",{"cveId":8807,"releaseId":25,"cycle":26,"description":8808,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8809,"url":8810},{"cveId":8807,"releaseId":31,"cycle":32,"description":8808,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8809,"url":8810},{"cveId":8814,"releaseId":17,"cycle":18,"description":8815,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8816,"url":8817},"CVE-2024-42306","In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Avoid using corrupted block bitmap buffer\n\nWhen the filesystem block bitmap is corrupted, we detect the corruption\nwhile loading the bitmap and fail the allocation with error. However the\nnext allocation from the same bitmap will notice the bitmap buffer is\nalready loaded and tries to allocate from the bitmap with mixed results\n(depending on the exact nature of the bitmap corruption). Fix the\nproblem by using BH_verified b","2024-08-17T09:15:10.777+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42306",{"cveId":8814,"releaseId":25,"cycle":26,"description":8815,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8816,"url":8817},{"cveId":8820,"releaseId":25,"cycle":26,"description":8821,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8822,"url":8823},"CVE-2024-42304","In the Linux kernel, the following vulnerability has been resolved:\n\next4: make sure the first directory block is not a hole\n\nThe syzbot constructs a directory that has no dirblock but is non-inline,\ni.e. the first directory block is a hole. And no errors are reported when\ncreating files in this directory in the following flow.\n\n    ext4_mknod\n     ...\n      ext4_add_entry\n        \u002F\u002F Read block 0\n        ext4_read_dirblock(dir, block, DIRENT)\n          bh = ext4_bread(NULL, inode, block, 0)\n    ","2024-08-17T09:15:10.617+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42304",{"cveId":8820,"releaseId":31,"cycle":32,"description":8821,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8822,"url":8823},{"cveId":8820,"releaseId":17,"cycle":18,"description":8821,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8822,"url":8823},{"cveId":8827,"releaseId":17,"cycle":18,"description":8828,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8829,"url":8830},"CVE-2024-42301","In the Linux kernel, the following vulnerability has been resolved:\n\ndev\u002Fparport: fix the array out-of-bounds risk\n\nFixed array out-of-bounds issues caused by sprintf\nby replacing it with snprintf for safer data copying,\nensuring the destination buffer is not overflowed.\n\nBelow is the stack trace I encountered during the actual issue:\n\n[ 66.575408s] [pid:5118,cpu4,QThread,4]Kernel panic - not syncing: stack-protector:\nKernel stack is corrupted in: do_hardware_base_addr+0xcc\u002F0xd0 [parport]\n[ 66.5","2024-08-17T09:15:10.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42301",{"cveId":8827,"releaseId":31,"cycle":32,"description":8828,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8829,"url":8830},{"cveId":8827,"releaseId":25,"cycle":26,"description":8828,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8829,"url":8830},{"cveId":8834,"releaseId":17,"cycle":18,"description":8835,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8836,"url":8837},"CVE-2024-42297","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to don't dirty inode for readonly filesystem\n\nsyzbot reports f2fs bug as below:\n\nkernel BUG at fs\u002Ff2fs\u002Finode.c:933!\nRIP: 0010:f2fs_evict_inode+0x1576\u002F0x1590 fs\u002Ff2fs\u002Finode.c:933\nCall Trace:\n evict+0x2a4\u002F0x620 fs\u002Finode.c:664\n dispose_list fs\u002Finode.c:697 [inline]\n evict_inodes+0x5f8\u002F0x690 fs\u002Finode.c:747\n generic_shutdown_super+0x9d\u002F0x2c0 fs\u002Fsuper.c:675\n kill_block_super+0x44\u002F0x90 fs\u002Fsuper.c:1667\n kill_f2fs_super+0x303\u002F0x","2024-08-17T09:15:10.147+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42297",{"cveId":8834,"releaseId":31,"cycle":32,"description":8835,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8836,"url":8837},{"cveId":8834,"releaseId":25,"cycle":26,"description":8835,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8836,"url":8837},{"cveId":8841,"releaseId":17,"cycle":18,"description":8842,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8843,"url":8844},"CVE-2024-42296","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix return value of f2fs_convert_inline_inode()\n\nIf device is readonly, make f2fs_convert_inline_inode()\nreturn EROFS instead of zero, otherwise it may trigger\npanic during writeback of inline inode's dirty page as\nbelow:\n\n f2fs_write_single_data_page+0xbb6\u002F0x1e90 fs\u002Ff2fs\u002Fdata.c:2888\n f2fs_write_cache_pages fs\u002Ff2fs\u002Fdata.c:3187 [inline]\n __f2fs_write_data_pages fs\u002Ff2fs\u002Fdata.c:3342 [inline]\n f2fs_write_data_pages+0x1efe\u002F0x3","2024-08-17T09:15:10.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42296",{"cveId":8841,"releaseId":31,"cycle":32,"description":8842,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8843,"url":8844},{"cveId":8841,"releaseId":25,"cycle":26,"description":8842,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8843,"url":8844},{"cveId":8848,"releaseId":25,"cycle":26,"description":8849,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8850,"url":8851},"CVE-2024-42288","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix for possible memory corruption\n\nInit Control Block is dereferenced incorrectly.  Correctly dereference ICB","2024-08-17T09:15:09.523+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42288",{"cveId":8848,"releaseId":17,"cycle":18,"description":8849,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8850,"url":8851},{"cveId":8848,"releaseId":31,"cycle":32,"description":8849,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8850,"url":8851},{"cveId":8855,"releaseId":25,"cycle":26,"description":8856,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8857,"url":8858},"CVE-2024-42286","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: validate nvme_local_port correctly\n\nThe driver load failed with error message,\n\nqla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef\n\nand with a kernel crash,\n\n\tBUG: unable to handle kernel NULL pointer dereference at 0000000000000070\n\tWorkqueue: events_unbound qla_register_fcport_fn [qla2xxx]\n\tRIP: 0010:nvme_fc_register_remoteport+0x16\u002F0x430 [nvme_fc]\n\tRSP: 0018:ffffaaa040eb3d98 EFLAGS: 0001028","2024-08-17T09:15:09.38+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42286",{"cveId":8855,"releaseId":17,"cycle":18,"description":8856,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8857,"url":8858},{"cveId":8855,"releaseId":31,"cycle":32,"description":8856,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8857,"url":8858},{"cveId":8862,"releaseId":25,"cycle":26,"description":8863,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8864,"url":8865},"CVE-2024-42285","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fiwcm: Fix a use-after-free related to destroying CM IDs\n\niw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with\nan existing struct iw_cm_id (cm_id) as follows:\n\n        conn_id->cm_id.iw = cm_id;\n        cm_id->context = conn_id;\n        cm_id->cm_handler = cma_iw_handler;\n\nrdma_destroy_id() frees both the cm_id and the struct rdma_id_private. Make\nsure that cm_work_handler() does not trigger a use-af","2024-08-17T09:15:09.3+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42285",{"cveId":8862,"releaseId":17,"cycle":18,"description":8863,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8864,"url":8865},{"cveId":8862,"releaseId":31,"cycle":32,"description":8863,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8864,"url":8865},{"cveId":8869,"releaseId":17,"cycle":18,"description":8870,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":8871,"url":8872},"CVE-2024-42284","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Return non-zero value from tipc_udp_addr2str() on error\n\ntipc_udp_addr2str() should return non-zero value if the UDP media\naddress is invalid. Otherwise, a buffer overflow access can occur in\ntipc_media_addr_printf(). Fix this by returning 1 on an invalid UDP\nmedia address.","2024-08-17T09:15:09.233+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42284",{"cveId":8869,"releaseId":31,"cycle":32,"description":8870,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":8871,"url":8872},{"cveId":8869,"releaseId":25,"cycle":26,"description":8870,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":8871,"url":8872},{"cveId":8876,"releaseId":31,"cycle":32,"description":8877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8878,"url":8879},"CVE-2024-42280","In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: Fix a use after free in hfcmulti_tx()\n\nDon't dereference *sp after calling dev_kfree_skb(*sp).","2024-08-17T09:15:08.943+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42280",{"cveId":8876,"releaseId":17,"cycle":18,"description":8877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8878,"url":8879},{"cveId":8876,"releaseId":25,"cycle":26,"description":8877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8878,"url":8879},{"cveId":8883,"releaseId":25,"cycle":26,"description":8884,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8885,"url":8886},"CVE-2024-42271","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fiucv: fix use after free in iucv_sock_close()\n\niucv_sever_path() is called from process context and from bh context.\niucv->path is used as indicator whether somebody else is taking care of\nsevering the path (or it is already removed \u002F never existed).\nThis needs to be done with atomic compare and swap, otherwise there is a\nsmall window where iucv_sock_close() will try to work with a path that has\nalready been severed and fre","2024-08-17T09:15:08.307+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42271",{"cveId":8883,"releaseId":17,"cycle":18,"description":8884,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8885,"url":8886},{"cveId":8883,"releaseId":31,"cycle":32,"description":8884,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8885,"url":8886},{"cveId":8890,"releaseId":25,"cycle":26,"description":8891,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8892,"url":8893},"CVE-2024-42259","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fi915\u002Fgem: Fix Virtual Memory mapping boundaries calculation\n\nCalculating the size of the mapped area as the lesser value\nbetween the requested size and the actual size does not consider\nthe partial mapping offset. This can cause page fault access.\n\nFix the calculation of the starting and ending addresses, the\ntotal size is now deduced from the difference between the end and\nstart addresses.\n\nAdditionally, the calculations h","2024-08-14T15:15:31.673+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42259",{"cveId":8890,"releaseId":17,"cycle":18,"description":8891,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8892,"url":8893},{"cveId":8890,"releaseId":31,"cycle":32,"description":8891,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8892,"url":8893},{"cveId":8897,"releaseId":31,"cycle":32,"description":8898,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8899,"url":8900},"CVE-2024-42253","In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: pca953x: fix pca953x_irq_bus_sync_unlock race\n\nEnsure that `i2c_lock' is held when setting interrupt latch and mask in\npca953x_irq_bus_sync_unlock() in order to avoid races.\n\nThe other (non-probe) call site pca953x_gpio_set_multiple() ensures the\nlock is held before calling pca953x_write_regs().\n\nThe problem occurred when a request raced against irq_bus_sync_unlock()\napproximately once per thousand reboots on an i.MX8MP b","2024-08-08T09:15:08.22+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42253",{"cveId":8897,"releaseId":25,"cycle":26,"description":8898,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8899,"url":8900},{"cveId":8897,"releaseId":17,"cycle":18,"description":8898,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8899,"url":8900},{"cveId":8904,"releaseId":17,"cycle":18,"description":8905,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8906,"url":8907},"CVE-2024-42236","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: configfs: Prevent OOB read\u002Fwrite in usb_string_copy()\n\nUserspace provided string 's' could trivially have the length zero. Left\nunchecked this will firstly result in an OOB read in the form\n`if (str[0 - 1] == '\\n') followed closely by an OOB write in the form\n`str[0 - 1] = '\\0'`.\n\nThere is already a validating check to catch strings that are too long.\nLet's supply an additional check for invalid strings that are to","2024-08-07T16:15:46.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42236",{"cveId":8904,"releaseId":31,"cycle":32,"description":8905,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8906,"url":8907},{"cveId":8904,"releaseId":25,"cycle":26,"description":8905,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8906,"url":8907},{"cveId":8911,"releaseId":31,"cycle":32,"description":8912,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8913,"url":8914},"CVE-2024-42232","In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix race between delayed_work() and ceph_monc_stop()\n\nThe way the delayed work is handled in ceph_monc_stop() is prone to\nraces with mon_fault() and possibly also finish_hunting().  Both of\nthese can requeue the delayed work which wouldn't be canceled by any of\nthe following code in case that happens after cancel_delayed_work_sync()\nruns -- __close_session() doesn't mess with the delayed work in order\nto avoid interfer","2024-08-07T16:15:46.213+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42232",{"cveId":8911,"releaseId":25,"cycle":26,"description":8912,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8913,"url":8914},{"cveId":8911,"releaseId":17,"cycle":18,"description":8912,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":8913,"url":8914},{"cveId":8918,"releaseId":17,"cycle":18,"description":8919,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":8920,"url":8921},"CVE-2024-42225","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: replace skb_put with skb_put_zero\n\nAvoid potentially reusing uninitialized data","2024-07-30T08:15:07.747+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42225",{"cveId":8918,"releaseId":31,"cycle":32,"description":8919,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":8920,"url":8921},{"cveId":8918,"releaseId":25,"cycle":26,"description":8919,"severity":40,"cvssScore":1163,"epssScore":9,"inKev":42,"publishedAt":8920,"url":8921},{"cveId":8925,"releaseId":25,"cycle":26,"description":8926,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8927,"url":8928},"CVE-2024-42224","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: Correct check for empty list\n\nSince commit a3c53be55c95 (\"net: dsa: mv88e6xxx: Support multiple MDIO\nbusses\") mv88e6xxx_default_mdio_bus() has checked that the\nreturn value of list_first_entry() is non-NULL.\n\nThis appears to be intended to guard against the list chip->mdios being\nempty.  However, it is not the correct check as the implementation of\nlist_first_entry is not designed to return NULL for empty l","2024-07-30T08:15:07.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42224",{"cveId":8925,"releaseId":17,"cycle":18,"description":8926,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8927,"url":8928},{"cveId":8931,"releaseId":25,"cycle":26,"description":8932,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8933,"url":8934},"CVE-2024-42152","In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix a possible leak when destroy a ctrl during qp establishment\n\nIn nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we\nknow that a ctrl was allocated (in the admin connect request handler)\nand we need to release pending AERs, clear ctrl->sqs and sq->ctrl\n(for nvme-loop primarily), and drop the final reference on the ctrl.\n\nHowever, a small window is possible where nvmet_sq_destroy starts (as\na result of ","2024-07-30T08:15:06.763+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42152",{"cveId":8931,"releaseId":17,"cycle":18,"description":8932,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8933,"url":8934},{"cveId":8931,"releaseId":31,"cycle":32,"description":8932,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8933,"url":8934},{"cveId":8938,"releaseId":17,"cycle":18,"description":8939,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8940,"url":8941},"CVE-2024-42145","In the Linux kernel, the following vulnerability has been resolved:\n\nIB\u002Fcore: Implement a limit on UMAD receive List\n\nThe existing behavior of ib_umad, which maintains received MAD\npackets in an unbounded list, poses a risk of uncontrolled growth.\nAs user-space applications extract packets from this list, the rate\nof extraction may not match the rate of incoming packets, leading\nto potential list overflow.\n\nTo address this, we introduce a limit to the size of the list. After\nconsidering typical ","2024-07-30T08:15:06.227+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42145",{"cveId":8938,"releaseId":25,"cycle":26,"description":8939,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8940,"url":8941},{"cveId":8938,"releaseId":31,"cycle":32,"description":8939,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8940,"url":8941},{"cveId":8945,"releaseId":17,"cycle":18,"description":8946,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8947,"url":8948},"CVE-2024-42123","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: fix double free err_addr pointer warnings\n\nIn amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages\nwill be run many times so that double free err_addr in some special case.\nSo set the err_addr to NULL to avoid the warnings.","2024-07-30T08:15:04.5+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42123",{"cveId":8945,"releaseId":31,"cycle":32,"description":8946,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8947,"url":8948},{"cveId":8945,"releaseId":25,"cycle":26,"description":8946,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":8947,"url":8948},{"cveId":8952,"releaseId":17,"cycle":18,"description":8953,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8954,"url":8955},"CVE-2024-42120","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Check pipe offset before setting vblank\n\npipe_ctx has a size of MAX_PIPES so checking its index before accessing\nthe array.\n\nThis fixes an OVERRUN issue reported by Coverity.","2024-07-30T08:15:04.273+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42120",{"cveId":8957,"releaseId":25,"cycle":26,"description":8958,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8959,"url":8960},"CVE-2024-42115","In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: Fix potential illegal address access in jffs2_free_inode\n\nDuring the stress testing of the jffs2 file system,the following\nabnormal printouts were found:\n[ 2430.649000] Unable to handle kernel paging request at virtual address 0069696969696948\n[ 2430.649622] Mem abort info:\n[ 2430.649829]   ESR = 0x96000004\n[ 2430.650115]   EC = 0x25: DABT (current EL), IL = 32 bits\n[ 2430.650564]   SET = 0, FnV = 0\n[ 2430.650795]   EA =","2024-07-30T08:15:03.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42115",{"cveId":8957,"releaseId":17,"cycle":18,"description":8958,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8959,"url":8960},{"cveId":8957,"releaseId":31,"cycle":32,"description":8958,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8959,"url":8960},{"cveId":8964,"releaseId":17,"cycle":18,"description":8965,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8966,"url":8967},"CVE-2024-42110","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx()\n\nThe following is emitted when using idxd (DSA) dmanegine as the data\nmover for ntb_transport that ntb_netdev uses.\n\n[74412.546922] BUG: using smp_processor_id() in preemptible [00000000] code: irq\u002F52-idxd-por\u002F14526\n[74412.556784] caller is netif_rx_internal+0x42\u002F0x130\n[74412.562282] CPU: 6 PID: 14526 Comm: irq\u002F52-idxd-por Not tainted 6.9.5 #5\n[7","2024-07-30T08:15:03.487+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42110",{"cveId":8964,"releaseId":31,"cycle":32,"description":8965,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8966,"url":8967},{"cveId":8964,"releaseId":25,"cycle":26,"description":8965,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":8966,"url":8967},{"cveId":8971,"releaseId":17,"cycle":18,"description":8972,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8973,"url":8974},"CVE-2024-42105","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix inode number range checks\n\nPatch series \"nilfs2: fix potential issues related to reserved inodes\".\n\nThis series fixes one use-after-free issue reported by syzbot, caused by\nnilfs2's internal inode being exposed in the namespace on a corrupted\nfilesystem, and a couple of flaws that cause problems if the starting\nnumber of non-reserved inodes written in the on-disk super block is\nintentionally (or corruptly) changed f","2024-07-30T08:15:03+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42105",{"cveId":8971,"releaseId":25,"cycle":26,"description":8972,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8973,"url":8974},{"cveId":8971,"releaseId":31,"cycle":32,"description":8972,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8973,"url":8974},{"cveId":8978,"releaseId":31,"cycle":32,"description":8979,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8980,"url":8981},"CVE-2024-42104","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: add missing check for inode numbers on directory entries\n\nSyzbot reported that mounting and unmounting a specific pattern of\ncorrupted nilfs2 filesystem images causes a use-after-free of metadata\nfile inodes, which triggers a kernel bug in lru_add_fn().\n\nAs Jan Kara pointed out, this is because the link count of a metadata file\ngets corrupted to 0, and nilfs_evict_inode(), which is called from iput(),\ntries to delete th","2024-07-30T08:15:02.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42104",{"cveId":8978,"releaseId":25,"cycle":26,"description":8979,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8980,"url":8981},{"cveId":8978,"releaseId":17,"cycle":18,"description":8979,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8980,"url":8981},{"cveId":8985,"releaseId":25,"cycle":26,"description":8986,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8987,"url":8988},"CVE-2024-42097","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: emux: improve patch ioctl data validation\n\nIn load_data(), make the validation of and skipping over the main info\nblock match that in load_guspatch().\n\nIn load_guspatch(), add checking that the specified patch length matches\nthe actually supplied data, like load_data() already did.","2024-07-29T18:15:12.167+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42097",{"cveId":8985,"releaseId":31,"cycle":32,"description":8986,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8987,"url":8988},{"cveId":8985,"releaseId":17,"cycle":18,"description":8986,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":8987,"url":8988},{"cveId":8992,"releaseId":31,"cycle":32,"description":8993,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8994,"url":8995},"CVE-2024-42083","In the Linux kernel, the following vulnerability has been resolved:\n\nionic: fix kernel panic due to multi-buffer handling\n\nCurrently, the ionic_run_xdp() doesn't handle multi-buffer packets\nproperly for XDP_TX and XDP_REDIRECT.\nWhen a jumbo frame is received, the ionic_run_xdp() first makes xdp\nframe with all necessary pages in the rx descriptor.\nAnd if the action is either XDP_TX or XDP_REDIRECT, it should unmap\ndma-mapping and reset page pointer to NULL for all pages, not only the\nfirst page.\n","2024-07-29T16:15:07.44+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42083",{"cveId":8992,"releaseId":25,"cycle":26,"description":8993,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8994,"url":8995},{"cveId":8992,"releaseId":17,"cycle":18,"description":8993,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":8994,"url":8995},{"cveId":8999,"releaseId":25,"cycle":26,"description":9000,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9001,"url":9002},"CVE-2024-42079","In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Fix NULL pointer dereference in gfs2_log_flush\n\nIn gfs2_jindex_free(), set sdp->sd_jdesc to NULL under the log flush\nlock to provide exclusion against gfs2_log_flush().\n\nIn gfs2_log_flush(), check if sdp->sd_jdesc is non-NULL before\ndereferencing it.  Otherwise, we could run into a NULL pointer\ndereference when outstanding glock work races with an unmount\n(glock_work_func -> run_queue -> do_xmote -> inode_go_sync ->\ngfs2_","2024-07-29T16:15:07.18+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42079",{"cveId":8999,"releaseId":17,"cycle":18,"description":9000,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9001,"url":9002},{"cveId":8999,"releaseId":31,"cycle":32,"description":9000,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9001,"url":9002},{"cveId":9006,"releaseId":31,"cycle":32,"description":9007,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9008,"url":9009},"CVE-2024-42075","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix remap of arena.\n\nThe bpf arena logic didn't account for mremap operation. Add a refcnt for\nmultiple mmap events to prevent use-after-free in arena_vm_close.","2024-07-29T16:15:06.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42075",{"cveId":9006,"releaseId":17,"cycle":18,"description":9007,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9008,"url":9009},{"cveId":9006,"releaseId":25,"cycle":26,"description":9007,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9008,"url":9009},{"cveId":9013,"releaseId":17,"cycle":18,"description":9014,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9015,"url":9016},"CVE-2024-42071","In the Linux kernel, the following vulnerability has been resolved:\n\nionic: use dev_consume_skb_any outside of napi\n\nIf we're not in a NAPI softirq context, we need to be careful\nabout how we call napi_consume_skb(), specifically we need to\ncall it with budget==0 to signal to it that we're not in a\nsafe context.\n\nThis was found while running some configuration stress testing\nof traffic and a change queue config loop running, and this\ncurious note popped out:\n\n[ 4371.402645] BUG: using smp_proces","2024-07-29T16:15:06.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42071",{"cveId":9013,"releaseId":31,"cycle":32,"description":9014,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9015,"url":9016},{"cveId":9013,"releaseId":25,"cycle":26,"description":9014,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9015,"url":9016},{"cveId":9020,"releaseId":25,"cycle":26,"description":9021,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9022,"url":9023},"CVE-2024-42069","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix possible double free in error handling path\n\nWhen auxiliary_device_add() returns error and then calls\nauxiliary_device_uninit(), callback function adev_release\ncalls kfree(madev). We shouldn't call kfree(madev) again\nin the error handling path. Set 'madev' to NULL.","2024-07-29T16:15:06.467+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42069",{"cveId":9020,"releaseId":17,"cycle":18,"description":9021,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9022,"url":9023},{"cveId":9020,"releaseId":31,"cycle":32,"description":9021,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9022,"url":9023},{"cveId":9027,"releaseId":17,"cycle":18,"description":9028,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9029,"url":9030},"CVE-2024-42068","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro()\n\nset_memory_ro() can fail, leaving memory unprotected.\n\nCheck its return and take it into account as an error.","2024-07-29T16:15:06.387+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42068",{"cveId":9027,"releaseId":25,"cycle":26,"description":9028,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9029,"url":9030},{"cveId":9027,"releaseId":31,"cycle":32,"description":9028,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9029,"url":9030},{"cveId":9034,"releaseId":25,"cycle":26,"description":9035,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9036,"url":9037},"CVE-2024-42067","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()\n\nset_memory_rox() can fail, leaving memory unprotected.\n\nCheck return and bail out when bpf_jit_binary_lock_ro() returns\nan error.","2024-07-29T16:15:06.323+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42067",{"cveId":9034,"releaseId":17,"cycle":18,"description":9035,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9036,"url":9037},{"cveId":9034,"releaseId":31,"cycle":32,"description":9035,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9036,"url":9037},{"cveId":9041,"releaseId":25,"cycle":26,"description":9042,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9043,"url":9044},"CVE-2024-42066","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fxe: Fix potential integer overflow in page size calculation\n\nExplicitly cast tbo->page_alignment to u64 before bit-shifting to\nprevent overflow when assigning to min_page_size.","2024-07-29T16:15:06.257+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42066",{"cveId":9041,"releaseId":31,"cycle":32,"description":9042,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9043,"url":9044},{"cveId":9041,"releaseId":17,"cycle":18,"description":9042,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9043,"url":9044},{"cveId":9048,"releaseId":31,"cycle":32,"description":9049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9050,"url":9051},"CVE-2024-42064","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Skip pipe if the pipe idx not set properly\n\n[why]\nDriver crashes when pipe idx not set properly\n\n[how]\nAdd code to skip the pipe that idx not set properly","2024-07-29T16:15:06.133+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-42064",{"cveId":9048,"releaseId":25,"cycle":26,"description":9049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9050,"url":9051},{"cveId":9048,"releaseId":17,"cycle":18,"description":9049,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9050,"url":9051},{"cveId":9055,"releaseId":17,"cycle":18,"description":9056,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9057,"url":9058},"CVE-2024-41087","In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: Fix double free on error\n\nIf e.g. the ata_port_alloc() call in ata_host_alloc() fails, we will jump\nto the err_out label, which will call devres_release_group().\ndevres_release_group() will trigger a call to ata_host_release().\nata_host_release() calls kfree(host), so executing the kfree(host) in\nata_host_alloc() will lead to a double free:\n\nkernel BUG at mm\u002Fslub.c:553!\nOops: invalid opcode: 0000 [#1] PREEMPT ","2024-07-29T16:15:04.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41087",{"cveId":9060,"releaseId":25,"cycle":26,"description":9061,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9062,"url":9063},"CVE-2024-41081","In the Linux kernel, the following vulnerability has been resolved:\n\nila: block BH in ila_output()\n\nAs explained in commit 1378817486d6 (\"tipc: block BH\nbefore using dst_cache\"), net\u002Fcore\u002Fdst_cache.c\nhelpers need to be called with BH disabled.\n\nila_output() is called from lwtunnel_output()\npossibly from process context, and under rcu_read_lock().\n\nWe might be interrupted by a softirq, re-enter ila_output()\nand corrupt dst_cache data structures.\n\nFix the race by using local_bh_disable().","2024-07-29T15:15:15.593+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41081",{"cveId":9060,"releaseId":17,"cycle":18,"description":9061,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9062,"url":9063},{"cveId":9066,"releaseId":25,"cycle":26,"description":9067,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9068,"url":9069},"CVE-2024-41079","In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: always initialize cqe.result\n\nThe spec doesn't mandate that the first two double words (aka results)\nfor the command queue entry need to be set to 0 when they are not\nused (not specified). Though, the target implemention returns 0 for TCP\nand FC but not for RDMA.\n\nLet's make RDMA behave the same and thus explicitly initializing the\nresult field. This prevents leaking any data from the stack.","2024-07-29T15:15:15.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41079",{"cveId":9066,"releaseId":31,"cycle":32,"description":9067,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9068,"url":9069},{"cveId":9066,"releaseId":17,"cycle":18,"description":9067,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9068,"url":9069},{"cveId":9073,"releaseId":17,"cycle":18,"description":9074,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9075,"url":9076},"CVE-2024-41073","In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: avoid double free special payload\n\nIf a discard request needs to be retried, and that retry may fail before\na new special payload is added, a double free will result. Clear the\nRQF_SPECIAL_LOAD when the request is cleaned.","2024-07-29T15:15:15.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41073",{"cveId":9073,"releaseId":25,"cycle":26,"description":9074,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9075,"url":9076},{"cveId":9079,"releaseId":31,"cycle":32,"description":9080,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9081,"url":9082},"CVE-2024-41070","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()\n\nAl reported a possible use-after-free (UAF) in kvm_spapr_tce_attach_iommu_group().\n\nIt looks up `stt` from tablefd, but then continues to use it after doing\nfdput() on the returned fd. After the fdput() the tablefd is free to be\nclosed by another thread. The close calls kvm_spapr_tce_release() and\nthen release_spapr_tce_table() (via call_rcu()) which frees ","2024-07-29T15:15:14.787+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41070",{"cveId":9079,"releaseId":25,"cycle":26,"description":9080,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9081,"url":9082},{"cveId":9079,"releaseId":17,"cycle":18,"description":9080,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9081,"url":9082},{"cveId":9086,"releaseId":31,"cycle":32,"description":9087,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9088,"url":9089},"CVE-2024-41069","In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: topology: Fix references to freed memory\n\nMost users after parsing a topology file, release memory used by it, so\nhaving pointer references directly into topology file contents is wrong.\nUse devm_kmemdup(), to allocate memory as needed.","2024-07-29T15:15:14.713+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41069",{"cveId":9086,"releaseId":17,"cycle":18,"description":9087,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9088,"url":9089},{"cveId":9086,"releaseId":25,"cycle":26,"description":9087,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9088,"url":9089},{"cveId":9093,"releaseId":31,"cycle":32,"description":9094,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9095,"url":9096},"CVE-2024-41066","In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: Add tx check to prevent skb leak\n\nBelow is a summary of how the driver stores a reference to an skb during\ntransmit:\n    tx_buff[free_map[consumer_index]]->skb = new_skb;\n    free_map[consumer_index] = IBMVNIC_INVALID_MAP;\n    consumer_index ++;\nWhere variable data looks like this:\n    free_map == [4, IBMVNIC_INVALID_MAP, IBMVNIC_INVALID_MAP, 0, 3]\n                                               \tconsumer_index^\n    tx_","2024-07-29T15:15:14.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41066",{"cveId":9093,"releaseId":17,"cycle":18,"description":9094,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9095,"url":9096},{"cveId":9093,"releaseId":25,"cycle":26,"description":9094,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9095,"url":9096},{"cveId":9100,"releaseId":25,"cycle":26,"description":9101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9102,"url":9103},"CVE-2024-41064","In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc\u002Feeh: avoid possible crash when edev->pdev changes\n\nIf a PCI device is removed during eeh_pe_report_edev(), edev->pdev\nwill change and can cause a crash, hold the PCI rescan\u002Fremove lock\nwhile taking a copy of edev->pdev->bus.","2024-07-29T15:15:14.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41064",{"cveId":9100,"releaseId":31,"cycle":32,"description":9101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9102,"url":9103},{"cveId":9100,"releaseId":17,"cycle":18,"description":9101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9102,"url":9103},{"cveId":9107,"releaseId":17,"cycle":18,"description":9108,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9109,"url":9110},"CVE-2024-41062","In the Linux kernel, the following vulnerability has been resolved:\n\nbluetooth\u002Fl2cap: sync sock recv cb and release\n\nThe problem occurs between the system call to close the sock and hci_rx_work,\nwhere the former releases the sock and the latter accesses it without lock protection.\n\n           CPU0                       CPU1\n           ----                       ----\n           sock_close                 hci_rx_work\n\t   l2cap_sock_release         hci_acldata_packet\n\t   l2cap_sock_kill            ","2024-07-29T15:15:14.173+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41062",{"cveId":9107,"releaseId":31,"cycle":32,"description":9108,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9109,"url":9110},{"cveId":9107,"releaseId":25,"cycle":26,"description":9108,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9109,"url":9110},{"cveId":9114,"releaseId":25,"cycle":26,"description":9115,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9116,"url":9117},"CVE-2024-41060","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fradeon: check bo_va->bo is non-NULL before using it\n\nThe call to radeon_vm_clear_freed might clear bo_va->bo, so\nwe have to check it before dereferencing it.","2024-07-29T15:15:14.03+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41060",{"cveId":9114,"releaseId":31,"cycle":32,"description":9115,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9116,"url":9117},{"cveId":9114,"releaseId":17,"cycle":18,"description":9115,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9116,"url":9117},{"cveId":9121,"releaseId":25,"cycle":26,"description":9122,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9123,"url":9124},"CVE-2024-41059","In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: fix uninit-value in copy_name\n\n[syzbot reported]\nBUG: KMSAN: uninit-value in sized_strscpy+0xc4\u002F0x160\n sized_strscpy+0xc4\u002F0x160\n copy_name+0x2af\u002F0x320 fs\u002Fhfsplus\u002Fxattr.c:411\n hfsplus_listxattr+0x11e9\u002F0x1a50 fs\u002Fhfsplus\u002Fxattr.c:750\n vfs_listxattr fs\u002Fxattr.c:493 [inline]\n listxattr+0x1f3\u002F0x6b0 fs\u002Fxattr.c:840\n path_listxattr fs\u002Fxattr.c:864 [inline]\n __do_sys_listxattr fs\u002Fxattr.c:876 [inline]\n __se_sys_listxattr fs\u002Fxattr.c:","2024-07-29T15:15:13.927+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41059",{"cveId":9121,"releaseId":17,"cycle":18,"description":9122,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9123,"url":9124},{"cveId":9121,"releaseId":31,"cycle":32,"description":9122,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9123,"url":9124},{"cveId":9128,"releaseId":17,"cycle":18,"description":9129,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9130,"url":9131},"CVE-2024-41046","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: lantiq_etop: fix double free in detach\n\nThe number of the currently released descriptor is never incremented\nwhich results in the same skb being released multiple times.","2024-07-29T15:15:12.943+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41046",{"cveId":9128,"releaseId":25,"cycle":26,"description":9129,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9130,"url":9131},{"cveId":9128,"releaseId":31,"cycle":32,"description":9129,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9130,"url":9131},{"cveId":9135,"releaseId":17,"cycle":18,"description":9136,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9137,"url":9138},"CVE-2024-41034","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix kernel bug on rename operation of broken directory\n\nSyzbot reported that in rename directory operation on broken directory on\nnilfs2, __block_write_begin_int() called to prepare block write may fail\nBUG_ON check for access exceeding the folio\u002Fpage size.\n\nThis is because nilfs_dotdot(), which gets parent directory reference\nentry (\"..\") of the directory to be moved or renamed, does not check\nconsistency enough, and m","2024-07-29T15:15:11.99+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41034",{"cveId":9135,"releaseId":31,"cycle":32,"description":9136,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9137,"url":9138},{"cveId":9135,"releaseId":25,"cycle":26,"description":9136,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9137,"url":9138},{"cveId":9142,"releaseId":31,"cycle":32,"description":9143,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9144,"url":9145},"CVE-2024-41020","In the Linux kernel, the following vulnerability has been resolved:\n\nfilelock: Fix fcntl\u002Fclose race recovery compat path\n\nWhen I wrote commit 3cad1bc01041 (\"filelock: Remove locks reliably when\nfcntl\u002Fclose race is detected\"), I missed that there are two copies of the\ncode I was patching: The normal version, and the version for 64-bit offsets\non 32-bit kernels.\nThanks to Greg KH for stumbling over this while doing the stable\nbackport...\n\nApply exactly the same fix to the compat path for 32-bit ke","2024-07-29T14:15:03.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41020",{"cveId":9142,"releaseId":25,"cycle":26,"description":9143,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9144,"url":9145},{"cveId":9142,"releaseId":17,"cycle":18,"description":9143,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9144,"url":9145},{"cveId":9149,"releaseId":31,"cycle":32,"description":9150,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9151,"url":9152},"CVE-2024-41017","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: don't walk off the end of ealist\n\nAdd a check before visiting the members of ea to\nmake sure each ea stays within the ealist.","2024-07-29T07:15:06.523+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41017",{"cveId":9149,"releaseId":17,"cycle":18,"description":9150,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9151,"url":9152},{"cveId":9149,"releaseId":25,"cycle":26,"description":9150,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9151,"url":9152},{"cveId":9156,"releaseId":25,"cycle":26,"description":9157,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9158,"url":9159},"CVE-2024-41016","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()\n\nxattr in ocfs2 maybe 'non-indexed', which saved with additional space\nrequested.  It's better to check if the memory is out of bound before\nmemcmp, although this possibility mainly comes from crafted poisonous\nimages.","2024-07-29T07:15:06.293+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41016",{"cveId":9156,"releaseId":31,"cycle":32,"description":9157,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9158,"url":9159},{"cveId":9156,"releaseId":17,"cycle":18,"description":9157,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9158,"url":9159},{"cveId":9163,"releaseId":25,"cycle":26,"description":9164,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9165,"url":9166},"CVE-2024-41015","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: add bounds checking to ocfs2_check_dir_entry()\n\nThis adds sanity checks for ocfs2_dir_entry to make sure all members of\nocfs2_dir_entry don't stray beyond valid memory region.","2024-07-29T07:15:06.033+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41015",{"cveId":9163,"releaseId":17,"cycle":18,"description":9164,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9165,"url":9166},{"cveId":9163,"releaseId":31,"cycle":32,"description":9164,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9165,"url":9166},{"cveId":9170,"releaseId":17,"cycle":18,"description":9171,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9172,"url":9173},"CVE-2024-41014","In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: add bounds checking to xlog_recover_process_data\n\nThere is a lack of verification of the space occupied by fixed members\nof xlog_op_header in the xlog_recover_process_data.\n\nWe can create a crafted image to trigger an out of bounds read by\nfollowing these steps:\n    1) Mount an image of xfs, and do some file operations to leave records\n    2) Before umounting, copy the image for subsequent steps to simulate\n       abnormal","2024-07-29T07:15:05.81+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41014",{"cveId":9170,"releaseId":25,"cycle":26,"description":9171,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9172,"url":9173},{"cveId":9170,"releaseId":31,"cycle":32,"description":9171,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9172,"url":9173},{"cveId":9177,"releaseId":25,"cycle":26,"description":9178,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9179,"url":9180},"CVE-2024-41012","In the Linux kernel, the following vulnerability has been resolved:\n\nfilelock: Remove locks reliably when fcntl\u002Fclose race is detected\n\nWhen fcntl_setlk() races with close(), it removes the created lock with\ndo_lock_file_wait().\nHowever, LSMs can allow the first do_lock_file_wait() that created the lock\nwhile denying the second do_lock_file_wait() that tries to remove the lock.\nSeparately, posix_lock_file() could also fail to\nremove a lock due to GFP_KERNEL allocation failure (when splitting a r","2024-07-23T08:15:01.877+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41012",{"cveId":9177,"releaseId":17,"cycle":18,"description":9178,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9179,"url":9180},{"cveId":9177,"releaseId":31,"cycle":32,"description":9178,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9179,"url":9180},{"cveId":9184,"releaseId":25,"cycle":26,"description":9185,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":9186,"url":9187},"CVE-2022-48858","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5: Fix a race on command flush flow\n\nFix a refcount use after free warning due to a race on command entry.\nSuch race occurs when one of the commands releases its last refcount and\nfrees its index and entry while another process running command flush\nflow takes refcount to this command entry. The process which handles\ncommands flush may see this command as needed to be flushed if the other\nprocess released its refcount bu","2024-07-16T13:15:12.803+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48858",{"cveId":9184,"releaseId":17,"cycle":18,"description":9185,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":9186,"url":9187},{"cveId":9184,"releaseId":31,"cycle":32,"description":9185,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":9186,"url":9187},{"cveId":9191,"releaseId":17,"cycle":18,"description":9192,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9193,"url":9194},"CVE-2022-48851","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gdm724x: fix use after free in gdm_lte_rx()\n\nThe netif_rx_ni() function frees the skb so we can't dereference it to\nsave the skb->len.","2024-07-16T13:15:12.247+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48851",{"cveId":9191,"releaseId":25,"cycle":26,"description":9192,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9193,"url":9194},{"cveId":9191,"releaseId":31,"cycle":32,"description":9192,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9193,"url":9194},{"cveId":9198,"releaseId":17,"cycle":18,"description":9199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9200,"url":9201},"CVE-2022-48839","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fpacket: fix slab-out-of-bounds access in packet_recvmsg()\n\nsyzbot found that when an AF_PACKET socket is using PACKET_COPY_THRESH\nand mmap operations, tpacket_rcv() is queueing skbs with\ngarbage in skb->cb[], triggering a too big copy [1]\n\nPresumably, users of af_packet using mmap() already gets correct\nmetadata from the mapped buffer, we can simply make sure\nto clear 12 bytes that might be copied to user space later.\n\nBUG:","2024-07-16T13:15:11.353+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48839",{"cveId":9198,"releaseId":25,"cycle":26,"description":9199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9200,"url":9201},{"cveId":9198,"releaseId":31,"cycle":32,"description":9199,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9200,"url":9201},{"cveId":9205,"releaseId":25,"cycle":26,"description":9206,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9207,"url":9208},"CVE-2022-48829","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix NFSv3 SETATTR\u002FCREATE's handling of large file sizes\n\niattr::ia_size is a loff_t, so these NFSv3 procedures must be\ncareful to deal with incoming client size values that are larger\nthan s64_max without corrupting the value.\n\nSilently capping the value results in storing a different value\nthan the client passed in which is unexpected behavior, so remove\nthe min_t() check in decode_sattr3().\n\nNote that RFC 1813 permits o","2024-07-16T12:15:06.55+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48829",{"cveId":9205,"releaseId":17,"cycle":18,"description":9206,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9207,"url":9208},{"cveId":9205,"releaseId":31,"cycle":32,"description":9206,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9207,"url":9208},{"cveId":9212,"releaseId":25,"cycle":26,"description":9213,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9214,"url":9215},"CVE-2022-48828","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix ia_size underflow\n\niattr::ia_size is a loff_t, which is a signed 64-bit type. NFSv3 and\nNFSv4 both define file size as an unsigned 64-bit type. Thus there\nis a range of valid file size values an NFS client can send that is\nalready larger than Linux can handle.\n\nCurrently decode_fattr4() dumps a full u64 value into ia_size. If\nthat value happens to be larger than S64_MAX, then ia_size\nunderflows. I'm about to fix up th","2024-07-16T12:15:06.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48828",{"cveId":9212,"releaseId":17,"cycle":18,"description":9213,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9214,"url":9215},{"cveId":9212,"releaseId":31,"cycle":32,"description":9213,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9214,"url":9215},{"cveId":9219,"releaseId":31,"cycle":32,"description":9220,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9221,"url":9222},"CVE-2022-48827","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix the behavior of READ near OFFSET_MAX\n\nDan Aloni reports:\n> Due to commit 8cfb9015280d (\"NFS: Always provide aligned buffers to\n> the RPC read layers\") on the client, a read of 0xfff is aligned up\n> to server rsize of 0x1000.\n>\n> As a result, in a test where the server has a file of size\n> 0x7fffffffffffffff, and the client tries to read from the offset\n> 0x7ffffffffffff000, the read causes loff_t overflow in the serve","2024-07-16T12:15:06.42+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48827",{"cveId":9219,"releaseId":17,"cycle":18,"description":9220,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9221,"url":9222},{"cveId":9219,"releaseId":25,"cycle":26,"description":9220,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9221,"url":9222},{"cveId":9226,"releaseId":31,"cycle":32,"description":9227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9228,"url":9229},"CVE-2022-48822","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: f_fs: Fix use-after-free for epfile\n\nConsider a case where ffs_func_eps_disable is called from\nffs_func_disable as part of composition switch and at the\nsame time ffs_epfile_release get called from userspace.\nffs_epfile_release will free up the read buffer and call\nffs_data_closed which in turn destroys ffs->epfiles and\nmark it as NULL. While this was happening the driver has\nalready initialized the local epfile in ffs_fun","2024-07-16T12:15:06.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48822",{"cveId":9226,"releaseId":25,"cycle":26,"description":9227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9228,"url":9229},{"cveId":9226,"releaseId":17,"cycle":18,"description":9227,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9228,"url":9229},{"cveId":9233,"releaseId":25,"cycle":26,"description":9234,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9235,"url":9236},"CVE-2022-48792","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm8001: Fix use-after-free for aborted SSP\u002FSTP sas_task\n\nCurrently a use-after-free may occur if a sas_task is aborted by the upper\nlayer before we handle the I\u002FO completion in mpi_ssp_completion() or\nmpi_sata_completion().\n\nIn this case, the following are the two steps in handling those I\u002FO\ncompletions:\n\n - Call complete() to inform the upper layer handler of completion of\n   the I\u002FO.\n\n - Release driver resources associa","2024-07-16T12:15:03.983+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48792",{"cveId":9233,"releaseId":17,"cycle":18,"description":9234,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9235,"url":9236},{"cveId":9233,"releaseId":31,"cycle":32,"description":9234,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9235,"url":9236},{"cveId":9240,"releaseId":25,"cycle":26,"description":9241,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9242,"url":9243},"CVE-2022-48791","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm8001: Fix use-after-free for aborted TMF sas_task\n\nCurrently a use-after-free may occur if a TMF sas_task is aborted before we\nhandle the IO completion in mpi_ssp_completion(). The abort occurs due to\ntimeout.\n\nWhen the timeout occurs, the SAS_TASK_STATE_ABORTED flag is set and the\nsas_task is freed in pm8001_exec_internal_tmf_task().\n\nHowever, if the I\u002FO completion occurs later, the I\u002FO completion still\nthinks that the","2024-07-16T12:15:03.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48791",{"cveId":9240,"releaseId":17,"cycle":18,"description":9241,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9242,"url":9243},{"cveId":9240,"releaseId":31,"cycle":32,"description":9241,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9242,"url":9243},{"cveId":9247,"releaseId":31,"cycle":32,"description":9248,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9249,"url":9250},"CVE-2022-48790","In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: fix a possible use-after-free in controller reset during load\n\nUnlike .queue_rq, in .submit_async_event drivers may not check the ctrl\nreadiness for AER submission. This may lead to a use-after-free\ncondition that was observed with nvme-tcp.\n\nThe race condition may happen in the following scenario:\n1. driver executes its reset_ctrl_work\n2. -> nvme_stop_ctrl - flushes ctrl async_event_work\n3. ctrl sends AEN which is receiv","2024-07-16T12:15:03.843+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48790",{"cveId":9247,"releaseId":25,"cycle":26,"description":9248,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9249,"url":9250},{"cveId":9247,"releaseId":17,"cycle":18,"description":9248,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9249,"url":9250},{"cveId":9254,"releaseId":25,"cycle":26,"description":9255,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9256,"url":9257},"CVE-2022-48789","In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix possible use-after-free in transport error_recovery work\n\nWhile nvme_tcp_submit_async_event_work is checking the ctrl and queue\nstate before preparing the AER command and scheduling io_work, in order\nto fully prevent a race where this check is not reliable the error\nrecovery work must flush async_event_work before continuing to destroy\nthe admin queue after setting the ctrl state to RESETTING such that\nthere is no","2024-07-16T12:15:03.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48789",{"cveId":9254,"releaseId":31,"cycle":32,"description":9255,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9256,"url":9257},{"cveId":9254,"releaseId":17,"cycle":18,"description":9255,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9256,"url":9257},{"cveId":9261,"releaseId":31,"cycle":32,"description":9262,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9263,"url":9264},"CVE-2022-48788","In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-rdma: fix possible use-after-free in transport error_recovery work\n\nWhile nvme_rdma_submit_async_event_work is checking the ctrl and queue\nstate before preparing the AER command and scheduling io_work, in order\nto fully prevent a race where this check is not reliable the error\nrecovery work must flush async_event_work before continuing to destroy\nthe admin queue after setting the ctrl state to RESETTING such that\nthere is ","2024-07-16T12:15:03.703+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48788",{"cveId":9261,"releaseId":25,"cycle":26,"description":9262,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9263,"url":9264},{"cveId":9261,"releaseId":17,"cycle":18,"description":9262,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9263,"url":9264},{"cveId":9268,"releaseId":17,"cycle":18,"description":9269,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9270,"url":9271},"CVE-2022-48787","In the Linux kernel, the following vulnerability has been resolved:\n\niwlwifi: fix use-after-free\n\nIf no firmware was present at all (or, presumably, all of the\nfirmware files failed to parse), we end up unbinding by calling\ndevice_release_driver(), which calls remove(), which then in\niwlwifi calls iwl_drv_stop(), freeing the 'drv' struct. However\nthe new code I added will still erroneously access it after it\nwas freed.\n\nSet 'failure=false' in this case to avoid the access, all data\nwas already f","2024-07-16T12:15:03.633+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48787",{"cveId":9268,"releaseId":25,"cycle":26,"description":9269,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9270,"url":9271},{"cveId":9274,"releaseId":17,"cycle":18,"description":9275,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9276,"url":9277},"CVE-2022-48786","In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: remove vsock from connected table when connect is interrupted by a signal\n\nvsock_connect() expects that the socket could already be in the\nTCP_ESTABLISHED state when the connecting task wakes up with a signal\npending. If this happens the socket will be in the connected table, and\nit is not removed when the socket state is reset. In this situation it's\ncommon for the process to retry connect(), and if the connection is\nsu","2024-07-16T12:15:03.56+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48786",{"cveId":9274,"releaseId":31,"cycle":32,"description":9275,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9276,"url":9277},{"cveId":9274,"releaseId":25,"cycle":26,"description":9275,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9276,"url":9277},{"cveId":9281,"releaseId":25,"cycle":26,"description":9282,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9283,"url":9284},"CVE-2024-41008","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: change vm->task_info handling\n\nThis patch changes the handling and lifecycle of vm->task_info object.\nThe major changes are:\n- vm->task_info is a dynamically allocated ptr now, and its uasge is\n  reference counted.\n- introducing two new helper funcs for task_info lifecycle management\n    - amdgpu_vm_get_task_info: reference counts up task_info before\n      returning this info\n    - amdgpu_vm_put_task_info: reference","2024-07-16T08:15:02.24+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41008",{"cveId":9281,"releaseId":17,"cycle":18,"description":9282,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9283,"url":9284},{"cveId":9281,"releaseId":31,"cycle":32,"description":9282,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9283,"url":9284},{"cveId":9288,"releaseId":17,"cycle":18,"description":9289,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9290,"url":9291},"CVE-2024-41007","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: avoid too many retransmit packets\n\nIf a TCP socket is using TCP_USER_TIMEOUT, and the other peer\nretracted its window to zero, tcp_retransmit_timer() can\nretransmit a packet every two jiffies (2 ms for HZ=1000),\nfor about 4 minutes after TCP_USER_TIMEOUT has 'expired'.\n\nThe fix is to make sure tcp_rtx_probe0_timed_out() takes\nicsk->icsk_user_timeout into account.\n\nBefore blamed commit, the socket would not timeout after\nic","2024-07-15T09:15:02.803+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-41007",{"cveId":9293,"releaseId":17,"cycle":18,"description":9294,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9295,"url":9296},"CVE-2023-52885","In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Fix UAF in svc_tcp_listen_data_ready()\n\nAfter the listener svc_sock is freed, and before invoking svc_tcp_accept()\nfor the established child sock, there is a window that the newsock\nretaining a freed listener svc_sock in sk_user_data which cloning from\nparent. In the race window, if data is received on the newsock, we will\nobserve use-after-free report in svc_tcp_listen_data_ready().\n\nReproduce by two tasks:\n\n1. while :","2024-07-14T08:15:01.823+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52885",{"cveId":9293,"releaseId":25,"cycle":26,"description":9294,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9295,"url":9296},{"cveId":9293,"releaseId":31,"cycle":32,"description":9294,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9295,"url":9296},{"cveId":9300,"releaseId":25,"cycle":26,"description":9301,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9302,"url":9303},"CVE-2024-40999","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ena: Add validation for completion descriptors consistency\n\nValidate that `first` flag is set only for the first\ndescriptor in multi-buffer packets.\nIn case of an invalid descriptor, a reset will occur.\nA new reset reason for RX data corruption has been added.","2024-07-12T13:15:20.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40999",{"cveId":9300,"releaseId":31,"cycle":32,"description":9301,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9302,"url":9303},{"cveId":9300,"releaseId":17,"cycle":18,"description":9301,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9302,"url":9303},{"cveId":9307,"releaseId":25,"cycle":26,"description":9308,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9309,"url":9310},"CVE-2024-40990","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fmlx5: Add check for srq max_sge attribute\n\nmax_sge attribute is passed by the user, and is inserted and used\nunchecked, so verify that the value doesn't exceed maximum allowed value\nbefore using it.","2024-07-12T13:15:20.37+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40990",{"cveId":9307,"releaseId":31,"cycle":32,"description":9308,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9309,"url":9310},{"cveId":9307,"releaseId":17,"cycle":18,"description":9308,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9309,"url":9310},{"cveId":9314,"releaseId":25,"cycle":26,"description":9315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9316,"url":9317},"CVE-2024-40984","In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: Revert \"ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine.\"\n\nUndo the modifications made in commit d410ee5109a1 (\"ACPICA: avoid\n\"Info: mapping multiple BARs. Your kernel is fine.\"\"). The initial\npurpose of this commit was to stop memory mappings for operation\nregions from overlapping page boundaries, as it can trigger warnings\nif different page attributes are present.\n\nHowever, it was found that when this s","2024-07-12T13:15:19.977+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40984",{"cveId":9314,"releaseId":31,"cycle":32,"description":9315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9316,"url":9317},{"cveId":9314,"releaseId":17,"cycle":18,"description":9315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9316,"url":9317},{"cveId":9321,"releaseId":25,"cycle":26,"description":9322,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9323,"url":9324},"CVE-2024-40980","In the Linux kernel, the following vulnerability has been resolved:\n\ndrop_monitor: replace spin_lock by raw_spin_lock\n\ntrace_drop_common() is called with preemption disabled, and it acquires\na spin_lock. This is problematic for RT kernels because spin_locks are\nsleeping locks in this configuration, which causes the following splat:\n\nBUG: sleeping function called from invalid context at kernel\u002Flocking\u002Fspinlock_rt.c:48\nin_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 449, name: rcuc\u002F47\npreem","2024-07-12T13:15:19.55+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40980",{"cveId":9321,"releaseId":31,"cycle":32,"description":9322,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9323,"url":9324},{"cveId":9321,"releaseId":17,"cycle":18,"description":9322,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9323,"url":9324},{"cveId":9328,"releaseId":25,"cycle":26,"description":9329,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9330,"url":9331},"CVE-2024-40974","In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc\u002Fpseries: Enforce hcall result buffer validity and size\n\nplpar_hcall(), plpar_hcall9(), and related functions expect callers to\nprovide valid result buffers of certain minimum size. Currently this\nis communicated only through comments in the code and the compiler has\nno idea.\n\nFor example, if I write a bug like this:\n\n  long retbuf[PLPAR_HCALL_BUFSIZE]; \u002F\u002F should be PLPAR_HCALL9_BUFSIZE\n  plpar_hcall9(H_ALLOCATE_VAS_WIND","2024-07-12T13:15:18.943+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40974",{"cveId":9328,"releaseId":31,"cycle":32,"description":9329,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9330,"url":9331},{"cveId":9328,"releaseId":17,"cycle":18,"description":9329,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9330,"url":9331},{"cveId":9335,"releaseId":25,"cycle":26,"description":9336,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9337,"url":9338},"CVE-2024-40971","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: remove clear SB_INLINECRYPT flag in default_options\n\nIn f2fs_remount, SB_INLINECRYPT flag will be clear and re-set.\nIf create new file or open file during this gap, these files\nwill not use inlinecrypt. Worse case, it may lead to data\ncorruption if wrappedkey_v0 is enable.\n\nThread A:                               Thread B:\n\n-f2fs_remount\t\t\t\t-f2fs_file_open or f2fs_new_inode\n  -default_options\n\t\u003C- clear SB_INLINECRYPT flag","2024-07-12T13:15:18.75+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40971",{"cveId":9335,"releaseId":17,"cycle":18,"description":9336,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9337,"url":9338},{"cveId":9335,"releaseId":31,"cycle":32,"description":9336,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9337,"url":9338},{"cveId":9342,"releaseId":31,"cycle":32,"description":9343,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9344,"url":9345},"CVE-2024-40970","In the Linux kernel, the following vulnerability has been resolved:\n\nAvoid hw_desc array overrun in dw-axi-dmac\n\nI have a use case where nr_buffers = 3 and in which each descriptor is composed by 3\nsegments, resulting in the DMA channel descs_allocated to be 9. Since axi_desc_put()\nhandles the hw_desc considering the descs_allocated, this scenario would result in a\nkernel panic (hw_desc array will be overrun).\n\nTo fix this, the proposal is to add a new member to the axi_dma_desc structure,\nwhere","2024-07-12T13:15:18.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40970",{"cveId":9342,"releaseId":17,"cycle":18,"description":9343,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9344,"url":9345},{"cveId":9342,"releaseId":25,"cycle":26,"description":9343,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9344,"url":9345},{"cveId":9349,"releaseId":17,"cycle":18,"description":9350,"severity":40,"cvssScore":9351,"epssScore":9,"inKev":42,"publishedAt":9352,"url":9353},"CVE-2024-40953","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()\n\nUse {READ,WRITE}_ONCE() to access kvm->last_boosted_vcpu to ensure the\nloads and stores are atomic.  In the extremely unlikely scenario the\ncompiler tears the stores, it's theoretically possible for KVM to attempt\nto get a vCPU using an out-of-bounds index, e.g. if the write is split\ninto multiple 8-bit stores, and is paired with a 32-bit load on a VM with\n257 vCP",7.9,"2024-07-12T13:15:17.56+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40953",{"cveId":9349,"releaseId":25,"cycle":26,"description":9350,"severity":40,"cvssScore":9351,"epssScore":9,"inKev":42,"publishedAt":9352,"url":9353},{"cveId":9349,"releaseId":31,"cycle":32,"description":9350,"severity":40,"cvssScore":9351,"epssScore":9,"inKev":42,"publishedAt":9352,"url":9353},{"cveId":9357,"releaseId":25,"cycle":26,"description":9358,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9359,"url":9360},"CVE-2024-40943","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix races between hole punching and AIO+DIO\n\nAfter commit \"ocfs2: return real error code in ocfs2_dio_wr_get_block\",\nfstests\u002Fgeneric\u002F300 become from always failed to sometimes failed:\n\n========================================================================\n[  473.293420 ] run fstests generic\u002F300\n\n[  475.296983 ] JBD2: Ignoring recovery information on journal\n[  475.302473 ] ocfs2: Mounting device (253,1) on (node local,","2024-07-12T13:15:16.67+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40943",{"cveId":9357,"releaseId":17,"cycle":18,"description":9358,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9359,"url":9360},{"cveId":9357,"releaseId":31,"cycle":32,"description":9358,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9359,"url":9360},{"cveId":9364,"releaseId":17,"cycle":18,"description":9365,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9366,"url":9367},"CVE-2024-40941","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don't read past the mfuart notifcation\n\nIn case the firmware sends a notification that claims it has more data\nthan it has, we will read past that was allocated for the notification.\nRemove the print of the buffer, we won't see it by default. If needed,\nwe can see the content with tracing.\n\nThis was reported by KFENCE.","2024-07-12T13:15:16.44+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40941",{"cveId":9364,"releaseId":25,"cycle":26,"description":9365,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9366,"url":9367},{"cveId":9370,"releaseId":17,"cycle":18,"description":9371,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9372,"url":9373},"CVE-2024-40929","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: check n_ssids before accessing the ssids\n\nIn some versions of cfg80211, the ssids poinet might be a valid one even\nthough n_ssids is 0. Accessing the pointer in this case will cuase an\nout-of-bound access. Fix this by checking n_ssids first.","2024-07-12T13:15:15.61+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40929",{"cveId":9375,"releaseId":31,"cycle":32,"description":9376,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9377,"url":9378},"CVE-2024-40918","In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Try to fix random segmentation faults in package builds\n\nPA-RISC systems with PA8800 and PA8900 processors have had problems\nwith random segmentation faults for many years.  Systems with earlier\nprocessors are much more stable.\n\nSystems with PA8800 and PA8900 processors have a large L2 cache which\nneeds per page flushing for decent performance when a large range is\nflushed. The combined cache in these systems is also mo","2024-07-12T13:15:14.863+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40918",{"cveId":9375,"releaseId":17,"cycle":18,"description":9376,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9377,"url":9378},{"cveId":9375,"releaseId":25,"cycle":26,"description":9376,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9377,"url":9378},{"cveId":9382,"releaseId":17,"cycle":18,"description":9383,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9384,"url":9385},"CVE-2024-40911","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: Lock wiphy in cfg80211_get_station\n\nWiphy should be locked before calling rdev_get_station() (see lockdep\nassert in ieee80211_get_station()).\n\nThis fixes the following kernel NULL dereference:\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000050\n Mem abort info:\n   ESR = 0x0000000096000006\n   EC = 0x25: DABT (current EL), IL = 32 bits\n   SET = 0, FnV = 0\n   EA = 0, S1PTW = 0\n   ","2024-07-12T13:15:14.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40911",{"cveId":9382,"releaseId":25,"cycle":26,"description":9383,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9384,"url":9385},{"cveId":9382,"releaseId":31,"cycle":32,"description":9383,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9384,"url":9385},{"cveId":9389,"releaseId":25,"cycle":26,"description":9390,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9391,"url":9392},"CVE-2024-40901","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpt3sas: Avoid test\u002Fset_bit() operating in non-allocated memory\n\nThere is a potential out-of-bounds access when using test_bit() on a single\nword. The test_bit() and set_bit() functions operate on long values, and\nwhen testing or setting a single word, they can exceed the word\nboundary. KASAN detects this issue and produces a dump:\n\n\t BUG: KASAN: slab-out-of-bounds in _scsih_add_device.constprop.0 (.\u002Farch\u002Fx86\u002Finclude\u002Fasm\u002F","2024-07-12T13:15:13.5+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-40901",{"cveId":9389,"releaseId":17,"cycle":18,"description":9390,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9391,"url":9392},{"cveId":9395,"releaseId":25,"cycle":26,"description":9396,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9397,"url":9398},"CVE-2024-39494","In the Linux kernel, the following vulnerability has been resolved:\n\nima: Fix use-after-free on a dentry's dname.name\n\n->d_name.name can change on rename and the earlier value can be freed;\nthere are conditions sufficient to stabilize it (->d_lock on dentry,\n->d_lock on its parent, ->i_rwsem exclusive on the parent's inode,\nrename_lock), but none of those are met at any of the sites. Take a stable\nsnapshot of the name instead.","2024-07-12T13:15:12.113+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39494",{"cveId":9395,"releaseId":17,"cycle":18,"description":9396,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9397,"url":9398},{"cveId":9395,"releaseId":31,"cycle":32,"description":9396,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9397,"url":9398},{"cveId":9402,"releaseId":31,"cycle":32,"description":9403,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9404,"url":9405},"CVE-2024-39487","In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()\n\nIn function bond_option_arp_ip_targets_set(), if newval->string is an\nempty string, newval->string+1 will point to the byte after the\nstring, causing an out-of-bound read.\n\nBUG: KASAN: slab-out-of-bounds in strlen+0x7d\u002F0xa0 lib\u002Fstring.c:418\nRead of size 1 at addr ffff8881119c4781 by task syz-executor665\u002F8107\nCPU: 1 PID: 8107 Comm: syz-executor665 Not tainted 6","2024-07-09T10:15:04.597+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39487",{"cveId":9402,"releaseId":17,"cycle":18,"description":9403,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9404,"url":9405},{"cveId":9402,"releaseId":25,"cycle":26,"description":9403,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9404,"url":9405},{"cveId":9409,"releaseId":31,"cycle":32,"description":9410,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9411,"url":9412},"CVE-2024-39483","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked\n\nWhen requesting an NMI window, WARN on vNMI support being enabled if and\nonly if NMIs are actually masked, i.e. if the vCPU is already handling an\nNMI.  KVM's ABI for NMIs that arrive simultanesouly (from KVM's point of\nview) is to inject one NMI and pend the other.  When using vNMI, KVM pends\nthe second NMI simply by setting V_NMI_PENDING, and lets the CPU do th","2024-07-05T07:15:10.767+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39483",{"cveId":9409,"releaseId":25,"cycle":26,"description":9410,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9411,"url":9412},{"cveId":9409,"releaseId":17,"cycle":18,"description":9410,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9411,"url":9412},{"cveId":9416,"releaseId":17,"cycle":18,"description":9417,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":9418,"url":9419},"CVE-2024-39480","In the Linux kernel, the following vulnerability has been resolved:\n\nkdb: Fix buffer overflow during tab-complete\n\nCurrently, when the user attempts symbol completion with the Tab key, kdb\nwill use strncpy() to insert the completed symbol into the command buffer.\nUnfortunately it passes the size of the source buffer rather than the\ndestination to strncpy() with predictably horrible results. Most obviously\nif the command buffer is already full but cp, the cursor position, is in\nthe middle of the ","2024-07-05T07:15:10.59+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39480",{"cveId":9421,"releaseId":31,"cycle":32,"description":9422,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9423,"url":9424},"CVE-2024-39472","In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix log recovery buffer allocation for the legacy h_size fixup\n\nCommit a70f9fe52daa (\"xfs: detect and handle invalid iclog size set by\nmkfs\") added a fixup for incorrect h_size values used for the initial\numount record in old xfsprogs versions.  Later commit 0c771b99d6c9\n(\"xfs: clean up calculation of LR header blocks\") cleaned up the log\nreover buffer calculation, but stoped using the fixed up h_size value\nto size the log","2024-07-05T07:15:10.02+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39472",{"cveId":9421,"releaseId":25,"cycle":26,"description":9422,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9423,"url":9424},{"cveId":9421,"releaseId":17,"cycle":18,"description":9422,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9423,"url":9424},{"cveId":9428,"releaseId":25,"cycle":26,"description":9429,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9430,"url":9431},"CVE-2024-39471","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: add error handle to avoid out-of-bounds\n\nif the sdma_v4_0_irq_id_to_seq return -EINVAL, the process should\nbe stop to avoid out-of-bounds read, so directly return -EINVAL.","2024-06-25T15:15:15.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39471",{"cveId":9428,"releaseId":17,"cycle":18,"description":9429,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9430,"url":9431},{"cveId":9428,"releaseId":31,"cycle":32,"description":9429,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9430,"url":9431},{"cveId":9435,"releaseId":25,"cycle":26,"description":9436,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9437,"url":9438},"CVE-2024-39469","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix nilfs_empty_dir() misjudgment and long loop on I\u002FO errors\n\nThe error handling in nilfs_empty_dir() when a directory folio\u002Fpage read\nfails is incorrect, as in the old ext2 implementation, and if the\nfolio\u002Fpage cannot be read or nilfs_check_folio() fails, it will falsely\ndetermine the directory as empty and corrupt the file system.\n\nIn addition, since nilfs_empty_dir() does not immediately return on a\nfailed folio\u002Fpag","2024-06-25T15:15:15.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39469",{"cveId":9435,"releaseId":17,"cycle":18,"description":9436,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9437,"url":9438},{"cveId":9435,"releaseId":31,"cycle":32,"description":9436,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9437,"url":9438},{"cveId":9442,"releaseId":17,"cycle":18,"description":9443,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9444,"url":9445},"CVE-2024-39468","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix deadlock in smb2_find_smb_tcon()\n\nUnlock cifs_tcp_ses_lock before calling cifs_put_smb_ses() to avoid such\ndeadlock.","2024-06-25T15:15:15.27+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39468",{"cveId":9442,"releaseId":31,"cycle":32,"description":9443,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9444,"url":9445},{"cveId":9442,"releaseId":25,"cycle":26,"description":9443,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9444,"url":9445},{"cveId":9449,"releaseId":25,"cycle":26,"description":9450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9451,"url":9452},"CVE-2024-39467","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()\n\nsyzbot reports a kernel bug as below:\n\nF2FS-fs (loop0): Mounted with checkpoint version = 48b305e4\n==================================================================\nBUG: KASAN: slab-out-of-bounds in f2fs_test_bit fs\u002Ff2fs\u002Ff2fs.h:2933 [inline]\nBUG: KASAN: slab-out-of-bounds in current_nat_addr fs\u002Ff2fs\u002Fnode.h:213 [inline]\nBUG: KASAN: slab-out-of-bounds in f2fs_g","2024-06-25T15:15:15.19+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39467",{"cveId":9449,"releaseId":17,"cycle":18,"description":9450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9451,"url":9452},{"cveId":9449,"releaseId":31,"cycle":32,"description":9450,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9451,"url":9452},{"cveId":9456,"releaseId":25,"cycle":26,"description":9457,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9458,"url":9459},"CVE-2024-37354","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix crash on racing fsync and size-extending write into prealloc\n\nWe have been seeing crashes on duplicate keys in\nbtrfs_set_item_key_safe():\n\n  BTRFS critical (device vdb): slot 4 key (450 108 8192) new key (450 108 8192)\n  ------------[ cut here ]------------\n  kernel BUG at fs\u002Fbtrfs\u002Fctree.c:2620!\n  invalid opcode: 0000 [#1] PREEMPT SMP PTI\n  CPU: 0 PID: 3139 Comm: xfs_io Kdump: loaded Not tainted 6.9.0 #6\n  Hardware n","2024-06-25T15:15:13.177+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-37354",{"cveId":9456,"releaseId":31,"cycle":32,"description":9457,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9458,"url":9459},{"cveId":9456,"releaseId":17,"cycle":18,"description":9457,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9458,"url":9459},{"cveId":9463,"releaseId":17,"cycle":18,"description":9464,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9465,"url":9466},"CVE-2024-37078","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential kernel bug due to lack of writeback flag waiting\n\nDestructive writes to a block device on which nilfs2 is mounted can cause\na kernel bug in the folio\u002Fpage writeback start routine or writeback end\nroutine (__folio_start_writeback in the log below):\n\n kernel BUG at mm\u002Fpage-writeback.c:3070!\n Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI\n ...\n RIP: 0010:__folio_start_writeback+0xbaa\u002F0x10e0\n Code: 25 f","2024-06-25T15:15:12.287+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-37078",{"cveId":9463,"releaseId":31,"cycle":32,"description":9464,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9465,"url":9466},{"cveId":9463,"releaseId":25,"cycle":26,"description":9464,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9465,"url":9466},{"cveId":9470,"releaseId":17,"cycle":18,"description":9471,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9472,"url":9473},"CVE-2024-39292","In the Linux kernel, the following vulnerability has been resolved:\n\num: Add winch to winch_handlers before registering winch IRQ\n\nRegistering a winch IRQ is racy, an interrupt may occur before the winch is\nadded to the winch_handlers list.\n\nIf that happens, register_winch_irq() adds to that list a winch that is\nscheduled to be (or has already been) freed, causing a panic later in\nwinch_cleanup().\n\nAvoid the race by adding the winch to the winch_handlers list before\nregistering the IRQ, and roll","2024-06-24T14:15:12.943+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39292",{"cveId":9475,"releaseId":17,"cycle":18,"description":9476,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9477,"url":9478},"CVE-2024-36288","In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Fix loop termination condition in gss_free_in_token_pages()\n\nThe in_token->pages[] array is not NULL terminated. This results in\nthe following KASAN splat:\n\n  KASAN: maybe wild-memory-access in range [0x04a2013400000008-0x04a201340000000f]","2024-06-21T12:15:10.967+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36288",{"cveId":9475,"releaseId":31,"cycle":32,"description":9476,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9477,"url":9478},{"cveId":9475,"releaseId":25,"cycle":26,"description":9476,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9477,"url":9478},{"cveId":9482,"releaseId":25,"cycle":26,"description":9483,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9484,"url":9485},"CVE-2024-38659","In the Linux kernel, the following vulnerability has been resolved:\n\nenic: Validate length of nl attributes in enic_set_vf_port\n\nenic_set_vf_port assumes that the nl attribute IFLA_PORT_PROFILE\nis of length PORT_PROFILE_MAX and that the nl attributes\nIFLA_PORT_INSTANCE_UUID, IFLA_PORT_HOST_UUID are of length PORT_UUID_MAX.\nThese attributes are validated (in the function do_setlink in rtnetlink.c)\nusing the nla_policy ifla_port_policy. The policy defines IFLA_PORT_PROFILE\nas NLA_STRING, IFLA_PORT","2024-06-21T11:15:12.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38659",{"cveId":9482,"releaseId":17,"cycle":18,"description":9483,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9484,"url":9485},{"cveId":9482,"releaseId":31,"cycle":32,"description":9483,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9484,"url":9485},{"cveId":9489,"releaseId":17,"cycle":18,"description":9490,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9491,"url":9492},"CVE-2024-38635","In the Linux kernel, the following vulnerability has been resolved:\n\nsoundwire: cadence: fix invalid PDI offset\n\nFor some reason, we add an offset to the PDI, presumably to skip the\nPDI0 and PDI1 which are reserved for BPT.\n\nThis code is however completely wrong and leads to an out-of-bounds\naccess. We were just lucky so far since we used only a couple of PDIs\nand remained within the PDI array bounds.\n\nA Fixes: tag is not provided since there are no known platforms where\nthe out-of-bounds would ","2024-06-21T11:15:12.24+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38635",{"cveId":9489,"releaseId":25,"cycle":26,"description":9490,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9491,"url":9492},{"cveId":9489,"releaseId":31,"cycle":32,"description":9490,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9491,"url":9492},{"cveId":9496,"releaseId":17,"cycle":18,"description":9497,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9498,"url":9499},"CVE-2024-38381","In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: Fix uninit-value in nci_rx_work\n\nsyzbot reported the following uninit-value access issue [1]\n\nnci_rx_work() parses received packet from ndev->rx_q. It should be\nvalidated header size, payload size and total packet size before\nprocessing the packet. If an invalid packet is detected, it should be\nsilently discarded.","2024-06-21T11:15:10.757+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38381",{"cveId":9501,"releaseId":31,"cycle":32,"description":9502,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9503,"url":9504},"CVE-2024-36286","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()\n\nsyzbot reported that nf_reinject() could be called without rcu_read_lock() :\n\nWARNING: suspicious RCU usage\n6.9.0-rc7-syzkaller-02060-g5c1672705a1a #0 Not tainted\n\nnet\u002Fnetfilter\u002Fnfnetlink_queue.c:263 suspicious rcu_dereference_check() usage!\n\nother info that might help us debug this:\n\nrcu_scheduler_active = 2, debug_locks = 1\n2 locks held by syz-exec","2024-06-21T11:15:10.277+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36286",{"cveId":9501,"releaseId":17,"cycle":18,"description":9502,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9503,"url":9504},{"cveId":9501,"releaseId":25,"cycle":26,"description":9502,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9503,"url":9504},{"cveId":9508,"releaseId":25,"cycle":26,"description":9509,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9510,"url":9511},"CVE-2022-48771","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvmwgfx: Fix stale file descriptors on failed usercopy\n\nA failing usercopy of the fence_rep object will lead to a stale entry in\nthe file descriptor table as put_unused_fd() won't release it. This\nenables userland to refer to a dangling 'file' object through that still\nvalid file descriptor, leading to all kinds of use-after-free\nexploitation scenarios.\n\nFix this by deferring the call to fd_install() until after the usercopy","2024-06-20T12:15:15.043+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48771",{"cveId":9508,"releaseId":17,"cycle":18,"description":9509,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9510,"url":9511},{"cveId":9514,"releaseId":17,"cycle":18,"description":9515,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9516,"url":9517},"CVE-2022-48759","In the Linux kernel, the following vulnerability has been resolved:\n\nrpmsg: char: Fix race between the release of rpmsg_ctrldev and cdev\n\nstruct rpmsg_ctrldev contains a struct cdev. The current code frees\nthe rpmsg_ctrldev struct in rpmsg_ctrldev_release_device(), but the\ncdev is a managed object, therefore its release is not predictable\nand the rpmsg_ctrldev could be freed before the cdev is entirely\nreleased, as in the backtrace below.\n\n[   93.625603] ODEBUG: free active (active state 0) obje","2024-06-20T12:15:14.023+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48759",{"cveId":9514,"releaseId":25,"cycle":26,"description":9515,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9516,"url":9517},{"cveId":9520,"releaseId":17,"cycle":18,"description":9521,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9522,"url":9523},"CVE-2022-48754","In the Linux kernel, the following vulnerability has been resolved:\n\nphylib: fix potential use-after-free\n\nCommit bafbdd527d56 (\"phylib: Add device reset GPIO support\") added call\nto phy_device_reset(phydev) after the put_device() call in phy_detach().\n\nThe comment before the put_device() call says that the phydev might go\naway with put_device().\n\nFix potential use-after-free by calling phy_device_reset() before\nput_device().","2024-06-20T12:15:13.563+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48754",{"cveId":9525,"releaseId":17,"cycle":18,"description":9526,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9527,"url":9528},"CVE-2022-48751","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: Transitional solution for clcsock race issue\n\nWe encountered a crash in smc_setsockopt() and it is caused by\naccessing smc->clcsock after clcsock was released.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000020\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 PID: 50309 Comm: nginx Kdump: loaded Tainted: G E     ","2024-06-20T12:15:13.31+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48751",{"cveId":9530,"releaseId":31,"cycle":32,"description":9531,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9532,"url":9533},"CVE-2022-48744","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5e: Avoid field-overflowing memcpy()\n\nIn preparation for FORTIFY_SOURCE performing compile-time and run-time\nfield bounds checking for memcpy(), memmove(), and memset(), avoid\nintentionally writing across neighboring fields.\n\nUse flexible arrays instead of zero-element arrays (which look like they\nare always overflowing) and split the cross-field memcpy() into two halves\nthat can be appropriately bounds-checked by the co","2024-06-20T12:15:12.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48744",{"cveId":9530,"releaseId":25,"cycle":26,"description":9531,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9532,"url":9533},{"cveId":9530,"releaseId":17,"cycle":18,"description":9531,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9532,"url":9533},{"cveId":9537,"releaseId":31,"cycle":32,"description":9538,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9539,"url":9540},"CVE-2022-48743","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: amd-xgbe: Fix skb data length underflow\n\nThere will be BUG_ON() triggered in include\u002Flinux\u002Fskbuff.h leading to\nintermittent kernel panic, when the skb length underflow is detected.\n\nFix this by dropping the packet if such length underflows are seen\nbecause of inconsistencies in the hardware descriptors.","2024-06-20T12:15:12.61+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48743",{"cveId":9537,"releaseId":25,"cycle":26,"description":9538,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9539,"url":9540},{"cveId":9537,"releaseId":17,"cycle":18,"description":9538,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9539,"url":9540},{"cveId":9544,"releaseId":31,"cycle":32,"description":9545,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9546,"url":9547},"CVE-2022-48742","In the Linux kernel, the following vulnerability has been resolved:\n\nrtnetlink: make sure to refresh master_dev\u002Fm_ops in __rtnl_newlink()\n\nWhile looking at one unrelated syzbot bug, I found the replay logic\nin __rtnl_newlink() to potentially trigger use-after-free.\n\nIt is better to clear master_dev and m_ops inside the loop,\nin case we have to replay it.","2024-06-20T12:15:12.517+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48742",{"cveId":9544,"releaseId":17,"cycle":18,"description":9545,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9546,"url":9547},{"cveId":9544,"releaseId":25,"cycle":26,"description":9545,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9546,"url":9547},{"cveId":9551,"releaseId":31,"cycle":32,"description":9552,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9553,"url":9554},"CVE-2022-48739","In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: hdmi-codec: Fix OOB memory accesses\n\nCorrect size of iec_status array by changing it to the size of status\narray of the struct snd_aes_iec958. This fixes out-of-bounds slab\nread accesses made by memcpy() of the hdmi-codec driver. This problem\nis reported by KASAN.","2024-06-20T12:15:12.243+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48739",{"cveId":9551,"releaseId":17,"cycle":18,"description":9552,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9553,"url":9554},{"cveId":9551,"releaseId":25,"cycle":26,"description":9552,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9553,"url":9554},{"cveId":9558,"releaseId":31,"cycle":32,"description":9559,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9560,"url":9561},"CVE-2022-48733","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free after failure to create a snapshot\n\nAt ioctl.c:create_snapshot(), we allocate a pending snapshot structure and\nthen attach it to the transaction's list of pending snapshots. After that\nwe call btrfs_commit_transaction(), and if that returns an error we jump\nto 'fail' label, where we kfree() the pending snapshot structure. This can\nresult in a later use-after-free of the pending snapshot:\n\n1) We allocat","2024-06-20T12:15:11.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48733",{"cveId":9558,"releaseId":25,"cycle":26,"description":9559,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9560,"url":9561},{"cveId":9558,"releaseId":17,"cycle":18,"description":9559,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9560,"url":9561},{"cveId":9565,"releaseId":17,"cycle":18,"description":9566,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9567,"url":9568},"CVE-2022-48717","In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: max9759: fix underflow in speaker_gain_control_put()\n\nCheck for negative values of \"priv->gain\" to prevent an out of bounds\naccess.  The concern is that these might come from the user via:\n  -> snd_ctl_elem_write_user()\n    -> snd_ctl_elem_write()\n      -> kctl->put()","2024-06-20T11:15:55.287+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48717",{"cveId":9570,"releaseId":17,"cycle":18,"description":9571,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9572,"url":9573},"CVE-2022-48711","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: improve size validations for received domain records\n\nThe function tipc_mon_rcv() allows a node to receive and process\ndomain_record structs from peer nodes to track their views of the\nnetwork topology.\n\nThis patch verifies that the number of members in a received domain\nrecord does not exceed the limit defined by MAX_MON_DOMAIN, something\nthat may otherwise lead to a stack overflow.\n\ntipc_mon_rcv() is called from the fun","2024-06-20T11:15:54.793+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48711",{"cveId":9570,"releaseId":25,"cycle":26,"description":9571,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9572,"url":9573},{"cveId":9570,"releaseId":31,"cycle":32,"description":9571,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9572,"url":9573},{"cveId":9577,"releaseId":31,"cycle":32,"description":9578,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9579,"url":9580},"CVE-2021-47620","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: refactor malicious adv data check\n\nCheck for out-of-bound read was being performed at the end of while\nnum_reports loop, and would fill journal with false positives. Added\ncheck to beginning of loop processing so that it doesn't get checked\nafter ptr has been advanced.","2024-06-20T11:15:54.653+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47620",{"cveId":9577,"releaseId":25,"cycle":26,"description":9578,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9579,"url":9580},{"cveId":9577,"releaseId":17,"cycle":18,"description":9578,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9579,"url":9580},{"cveId":9584,"releaseId":17,"cycle":18,"description":9585,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9586,"url":9587},"CVE-2024-38620","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HCI: Remove HCI_AMP support\n\nSince BT_HS has been remove HCI_AMP controllers no longer has any use so\nremove it along with the capability of creating AMP controllers.\n\nSince we no longer need to differentiate between AMP and Primary\ncontrollers, as only HCI_PRIMARY is left, this also remove\nhdev->dev_type altogether.","2024-06-20T08:15:38.377+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38620",{"cveId":9584,"releaseId":25,"cycle":26,"description":9585,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9586,"url":9587},{"cveId":9584,"releaseId":31,"cycle":32,"description":9585,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9586,"url":9587},{"cveId":9591,"releaseId":17,"cycle":18,"description":9592,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":9593,"url":9594},"CVE-2021-47611","In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: validate extended element ID is present\n\nBefore attempting to parse an extended element, verify that\nthe extended element ID is present.","2024-06-19T15:15:55.65+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47611",{"cveId":9596,"releaseId":31,"cycle":32,"description":9597,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9598,"url":9599},"CVE-2021-47600","In the Linux kernel, the following vulnerability has been resolved:\n\ndm btree remove: fix use after free in rebalance_children()\n\nMove dm_tm_unlock() after dm_tm_dec().","2024-06-19T15:15:54.567+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47600",{"cveId":9596,"releaseId":25,"cycle":26,"description":9597,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9598,"url":9599},{"cveId":9596,"releaseId":17,"cycle":18,"description":9597,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9598,"url":9599},{"cveId":9603,"releaseId":17,"cycle":18,"description":9604,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9605,"url":9606},"CVE-2021-47598","In the Linux kernel, the following vulnerability has been resolved:\n\nsch_cake: do not call cake_destroy() from cake_init()\n\nqdiscs are not supposed to call their own destroy() method\nfrom init(), because core stack already does that.\n\nsyzbot was able to trigger use after free:\n\nDEBUG_LOCKS_WARN_ON(lock->magic != lock)\nWARNING: CPU: 0 PID: 21902 at kernel\u002Flocking\u002Fmutex.c:586 __mutex_lock_common kernel\u002Flocking\u002Fmutex.c:586 [inline]\nWARNING: CPU: 0 PID: 21902 at kernel\u002Flocking\u002Fmutex.c:586 __mutex_lo","2024-06-19T15:15:54.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47598",{"cveId":9608,"releaseId":25,"cycle":26,"description":9609,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9610,"url":9611},"CVE-2021-47588","In the Linux kernel, the following vulnerability has been resolved:\n\nsit: do not call ipip6_dev_free() from sit_init_net()\n\nipip6_dev_free is sit dev->priv_destructor, already called\nby register_netdevice() if something goes wrong.\n\nAlternative would be to make ipip6_dev_free() robust against\nmultiple invocations, but other drivers do not implement this\nstrategy.\n\nsyzbot reported:\n\ndst_release underflow\nWARNING: CPU: 0 PID: 5059 at net\u002Fcore\u002Fdst.c:173 dst_release+0xd8\u002F0xe0 net\u002Fcore\u002Fdst.c:173\nModu","2024-06-19T15:15:53.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47588",{"cveId":9608,"releaseId":17,"cycle":18,"description":9609,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9610,"url":9611},{"cveId":9614,"releaseId":31,"cycle":32,"description":9615,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9616,"url":9617},"CVE-2021-47587","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: systemport: Add global locking for descriptor lifecycle\n\nThe descriptor list is a shared resource across all of the transmit queues, and\nthe locking mechanism used today only protects concurrency across a given\ntransmit queue between the transmit and reclaiming. This creates an opportunity\nfor the SYSTEMPORT hardware to work on corrupted descriptors if we have\nmultiple producers at once which is the case when using multipl","2024-06-19T15:15:53.26+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47587",{"cveId":9614,"releaseId":17,"cycle":18,"description":9615,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9616,"url":9617},{"cveId":9614,"releaseId":25,"cycle":26,"description":9615,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9616,"url":9617},{"cveId":9621,"releaseId":25,"cycle":26,"description":9622,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9623,"url":9624},"CVE-2021-47580","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix type in min_t to avoid stack OOB\n\nChange min_t() to use type \"u32\" instead of type \"int\" to avoid stack out\nof bounds. With min_t() type \"int\" the values get sign extended and the\nlarger value gets used causing stack out of bounds.\n\nBUG: KASAN: stack-out-of-bounds in memcpy include\u002Flinux\u002Ffortify-string.h:191 [inline]\nBUG: KASAN: stack-out-of-bounds in sg_copy_buffer+0x1de\u002F0x240 lib\u002Fscatterlist.c:976\nRead o","2024-06-19T15:15:52.537+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47580",{"cveId":9621,"releaseId":17,"cycle":18,"description":9622,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9623,"url":9624},{"cveId":9621,"releaseId":31,"cycle":32,"description":9622,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9623,"url":9624},{"cveId":9628,"releaseId":17,"cycle":18,"description":9629,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9630,"url":9631},"CVE-2021-47577","In the Linux kernel, the following vulnerability has been resolved:\n\nio-wq: check for wq exit after adding new worker task_work\n\nWe check IO_WQ_BIT_EXIT before attempting to create a new worker, and\nwq exit cancels pending work if we have any. But it's possible to have\na race between the two, where creation checks exit finding it not set,\nbut we're in the process of exiting. The exit side will cancel pending\ncreation task_work, but there's a gap where we add task_work after we've\ncanceled existi","2024-06-19T15:15:52.223+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47577",{"cveId":9628,"releaseId":25,"cycle":26,"description":9629,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9630,"url":9631},{"cveId":9628,"releaseId":31,"cycle":32,"description":9629,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9630,"url":9631},{"cveId":9635,"releaseId":25,"cycle":26,"description":9636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9637,"url":9638},"CVE-2021-47576","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Sanity check block descriptor length in resp_mode_select()\n\nIn resp_mode_select() sanity check the block descriptor len to avoid UAF.\n\nBUG: KASAN: use-after-free in resp_mode_select+0xa4c\u002F0xb40 drivers\u002Fscsi\u002Fscsi_debug.c:2509\nRead of size 1 at addr ffff888026670f50 by task scsicmd\u002F15032\n\nCPU: 1 PID: 15032 Comm: scsicmd Not tainted 5.15.0-01d0625 #15\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\nCa","2024-06-19T15:15:52.117+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47576",{"cveId":9635,"releaseId":31,"cycle":32,"description":9636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9637,"url":9638},{"cveId":9635,"releaseId":17,"cycle":18,"description":9636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9637,"url":9638},{"cveId":9642,"releaseId":25,"cycle":26,"description":9643,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":9644,"url":9645},"CVE-2024-38612","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: fix invalid unregister error path\n\nThe error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL\nis not defined. In that case if seg6_hmac_init() fails, the\ngenl_unregister_family() isn't called.\n\nThis issue exist since commit 46738b1317e1 (\"ipv6: sr: add option to control\nlwtunnel support\"), and commit 5559cea2d5aa (\"ipv6: sr: fix possible\nuse-after-free and null-ptr-deref\") replaced unregister_pernet_subs","2024-06-19T14:15:21.06+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38612",{"cveId":9642,"releaseId":17,"cycle":18,"description":9643,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":9644,"url":9645},{"cveId":9648,"releaseId":25,"cycle":26,"description":9649,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9650,"url":9651},"CVE-2024-38611","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: et8ek8: Don't strip remove function when driver is builtin\n\nUsing __exit for the remove function results in the remove callback\nbeing discarded with CONFIG_VIDEO_ET8EK8=y. When such a device gets\nunbound (e.g. using sysfs or hotplug), the driver is just removed\nwithout the cleanup being performed. This results in resource leaks. Fix\nit by compiling in the remove callback unconditionally.\n\nThis also fixes a W=1 modpo","2024-06-19T14:15:20.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38611",{"cveId":9648,"releaseId":17,"cycle":18,"description":9649,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9650,"url":9651},{"cveId":9654,"releaseId":31,"cycle":32,"description":9655,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9656,"url":9657},"CVE-2024-38599","In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: prevent xattr node from overflowing the eraseblock\n\nAdd a check to make sure that the requested xattr node size is no larger\nthan the eraseblock minus the cleanmarker.\n\nUnlike the usual inode nodes, the xattr nodes aren't split into parts\nand spread across multiple eraseblocks, which means that a xattr node\nmust not occupy more than one eraseblock. If the requested xattr value is\ntoo large, the xattr node can spill onto ","2024-06-19T14:15:19.903+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38599",{"cveId":9654,"releaseId":25,"cycle":26,"description":9655,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9656,"url":9657},{"cveId":9654,"releaseId":17,"cycle":18,"description":9655,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9656,"url":9657},{"cveId":9661,"releaseId":17,"cycle":18,"description":9662,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9663,"url":9664},"CVE-2024-38587","In the Linux kernel, the following vulnerability has been resolved:\n\nspeakup: Fix sizeof() vs ARRAY_SIZE() bug\n\nThe \"buf\" pointer is an array of u16 values.  This code should be\nusing ARRAY_SIZE() (which is 256) instead of sizeof() (which is 512),\notherwise it can the still got out of bounds.","2024-06-19T14:15:18.8+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38587",{"cveId":9666,"releaseId":31,"cycle":32,"description":9667,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9668,"url":9669},"CVE-2024-38583","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix use-after-free of timer for log writer thread\n\nPatch series \"nilfs2: fix log writer related issues\".\n\nThis bug fix series covers three nilfs2 log writer-related issues,\nincluding a timer use-after-free issue and potential deadlock issue on\nunmount, and a potential freeze issue in event synchronization found\nduring their analysis.  Details are described in each commit log.\n\n\nThis patch (of 3):\n\nA use-after-free issue","2024-06-19T14:15:18.397+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38583",{"cveId":9666,"releaseId":17,"cycle":18,"description":9667,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9668,"url":9669},{"cveId":9666,"releaseId":25,"cycle":26,"description":9667,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9668,"url":9669},{"cveId":9673,"releaseId":31,"cycle":32,"description":9674,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9675,"url":9676},"CVE-2024-38580","In the Linux kernel, the following vulnerability has been resolved:\n\nepoll: be better about file lifetimes\n\nepoll can call out to vfs_poll() with a file pointer that may race with\nthe last 'fput()'. That would make f_count go down to zero, and while\nthe ep->mtx locking means that the resulting file pointer tear-down will\nbe blocked until the poll returns, it means that f_count is already\ndead, and any use of it won't actually get a reference to the file any\nmore: it's dead regardless.\n\nMake sure","2024-06-19T14:15:18.057+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38580",{"cveId":9673,"releaseId":25,"cycle":26,"description":9674,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9675,"url":9676},{"cveId":9673,"releaseId":17,"cycle":18,"description":9674,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9675,"url":9676},{"cveId":9680,"releaseId":25,"cycle":26,"description":9681,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9682,"url":9683},"CVE-2024-38578","In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: Fix buffer size for tag 66 packet\n\nThe 'TAG 66 Packet Format' description is missing the cipher code and\nchecksum fields that are packed into the message packet. As a result,\nthe buffer allocated for the packet is 3 bytes too small and\nwrite_tag_66_packet() will write up to 3 bytes past the end of the\nbuffer.\n\nFix this by increasing the size of the allocation so the whole packet\nwill always fit in the buffer.\n\nThis fi","2024-06-19T14:15:17.87+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38578",{"cveId":9680,"releaseId":31,"cycle":32,"description":9681,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9682,"url":9683},{"cveId":9680,"releaseId":17,"cycle":18,"description":9681,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9682,"url":9683},{"cveId":9687,"releaseId":17,"cycle":18,"description":9688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9689,"url":9690},"CVE-2024-38570","In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Fix potential glock use-after-free on unmount\n\nWhen a DLM lockspace is released and there ares still locks in that\nlockspace, DLM will unlock those locks automatically.  Commit\nfb6791d100d1b started exploiting this behavior to speed up filesystem\nunmount: gfs2 would simply free glocks it didn't want to unlock and then\nrelease the lockspace.  This didn't take the bast callbacks for\nasynchronous lock contention notification","2024-06-19T14:15:17.153+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38570",{"cveId":9687,"releaseId":25,"cycle":26,"description":9688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9689,"url":9690},{"cveId":9687,"releaseId":31,"cycle":32,"description":9688,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9689,"url":9690},{"cveId":9694,"releaseId":25,"cycle":26,"description":9695,"severity":101,"cvssScore":6301,"epssScore":9,"inKev":42,"publishedAt":9696,"url":9697},"CVE-2024-38558","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix overwriting ct original tuple for ICMPv6\n\nOVS_PACKET_CMD_EXECUTE has 3 main attributes:\n - OVS_PACKET_ATTR_KEY - Packet metadata in a netlink format.\n - OVS_PACKET_ATTR_PACKET - Binary packet content.\n - OVS_PACKET_ATTR_ACTIONS - Actions to execute on the packet.\n\nOVS_PACKET_ATTR_KEY is parsed first to populate sw_flow_key structure\nwith the metadata like conntrack state, input port, recirculation id,\netc.","2024-06-19T14:15:15.983+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38558",{"cveId":9694,"releaseId":17,"cycle":18,"description":9695,"severity":101,"cvssScore":6301,"epssScore":9,"inKev":42,"publishedAt":9696,"url":9697},{"cveId":9700,"releaseId":17,"cycle":18,"description":9701,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9702,"url":9703},"CVE-2024-38552","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix potential index out of bounds in color transformation function\n\nFixes index out of bounds issue in the color transformation function.\nThe issue could occur when the index 'i' exceeds the number of transfer\nfunction points (TRANSFER_FUNC_POINTS).\n\nThe fix adds a check to ensure 'i' is within bounds before accessing the\ntransfer function points. If 'i' is out of bounds, an error message is\nlogged and the func","2024-06-19T14:15:15.45+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38552",{"cveId":9705,"releaseId":31,"cycle":32,"description":9706,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9707,"url":9708},"CVE-2024-38545","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fhns: Fix UAF for cq async event\n\nThe refcount of CQ is not protected by locks. When CQ asynchronous\nevents and CQ destruction are concurrent, CQ may have been released,\nwhich will cause UAF.\n\nUse the xa_lock() to protect the CQ refcount.","2024-06-19T14:15:14.787+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38545",{"cveId":9705,"releaseId":17,"cycle":18,"description":9706,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9707,"url":9708},{"cveId":9705,"releaseId":25,"cycle":26,"description":9706,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9707,"url":9708},{"cveId":9712,"releaseId":25,"cycle":26,"description":9713,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9714,"url":9715},"CVE-2024-38544","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Frxe: Fix seg fault in rxe_comp_queue_pkt\n\nIn rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the\nresp_pkts queue and then a decision is made whether to run the completer\ntask inline or schedule it. Finally the skb is dereferenced to bump a 'hw'\nperformance counter. This is wrong because if the completer task is\nalready running in a separate thread it may have already processed the skb\nand freed it which","2024-06-19T14:15:14.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38544",{"cveId":9712,"releaseId":17,"cycle":18,"description":9713,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9714,"url":9715},{"cveId":9718,"releaseId":17,"cycle":18,"description":9719,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9720,"url":9721},"CVE-2024-38541","In the Linux kernel, the following vulnerability has been resolved:\n\nof: module: add buffer overflow check in of_modalias()\n\nIn of_modalias(), if the buffer happens to be too small even for the 1st\nsnprintf() call, the len parameter will become negative and str parameter\n(if not NULL initially) will point beyond the buffer's end. Add the buffer\noverflow check after the 1st snprintf() call and fix such check after the\nstrlen() call (accounting for the terminating NUL char).","2024-06-19T14:15:14.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38541",{"cveId":9718,"releaseId":25,"cycle":26,"description":9719,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9720,"url":9721},{"cveId":9724,"releaseId":17,"cycle":18,"description":9725,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9726,"url":9727},"CVE-2024-38538","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: xmit: make sure we have at least eth header len bytes\n\nsyzbot triggered an uninit value[1] error in bridge device's xmit path\nby sending a short (less than ETH_HLEN bytes) skb. To fix it check if\nwe can actually pull that amount instead of assuming.\n\nTested with dropwatch:\n drop at: br_dev_xmit+0xb93\u002F0x12d0 [bridge] (0xffffffffc06739b3)\n origin: software\n timestamp: Mon May 13 11:31:53 2024 778214037 nsec\n protocol","2024-06-19T14:15:14.107+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-38538",{"cveId":9724,"releaseId":25,"cycle":26,"description":9725,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9726,"url":9727},{"cveId":9724,"releaseId":31,"cycle":32,"description":9725,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":9726,"url":9727},{"cveId":9731,"releaseId":31,"cycle":32,"description":9732,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":9733,"url":9734},"CVE-2024-36968","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init()\n\nl2cap_le_flowctl_init() can cause both div-by-zero and an integer\noverflow since hdev->le_mtu may not fall in the valid range.\n\nMove MTU from hci_dev to hci_conn to validate MTU and stop the connection\nprocess earlier if MTU is invalid.\nAlso, add a missing validation in read_buffer_size() and make it return\nan error value if the validation fails.\nNow hci_conn_add() r","2024-06-08T13:15:58.093+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36968",{"cveId":9731,"releaseId":25,"cycle":26,"description":9732,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":9733,"url":9734},{"cveId":9731,"releaseId":17,"cycle":18,"description":9732,"severity":40,"cvssScore":7165,"epssScore":9,"inKev":42,"publishedAt":9733,"url":9734},{"cveId":9738,"releaseId":17,"cycle":18,"description":9739,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9740,"url":9741},"CVE-2024-36964","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002F9p: only translate RWX permissions for plain 9P2000\n\nGarbage in plain 9P2000's perm bits is allowed through, which causes it\nto be able to set (among others) the suid bit. This was presumably not\nthe intent since the unix extended bits are handled explicitly and\nconditionally on .u.","2024-06-03T08:15:09.903+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36964",{"cveId":9738,"releaseId":25,"cycle":26,"description":9739,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9740,"url":9741},{"cveId":9738,"releaseId":31,"cycle":32,"description":9739,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9740,"url":9741},{"cveId":9745,"releaseId":25,"cycle":26,"description":9746,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9747,"url":9748},"CVE-2024-36960","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvmwgfx: Fix invalid reads in fence signaled events\n\nCorrectly set the length of the drm_event to the size of the structure\nthat's actually used.\n\nThe length of the drm_event was set to the parent structure instead of\nto the drm_vmw_event_fence which is supposed to be read. drm_read\nuses the length parameter to copy the event to the user space thus\nresuling in oob reads.","2024-06-03T08:15:09.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36960",{"cveId":9745,"releaseId":17,"cycle":18,"description":9746,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9747,"url":9748},{"cveId":9745,"releaseId":31,"cycle":32,"description":9746,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9747,"url":9748},{"cveId":9752,"releaseId":17,"cycle":18,"description":9753,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9754,"url":9755},"CVE-2024-36940","In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: core: delete incorrect free in pinctrl_enable()\n\nThe \"pctldev\" struct is allocated in devm_pinctrl_register_and_init().\nIt's a devm_ managed pointer that is freed by devm_pinctrl_dev_release(),\nso freeing it in pinctrl_enable() will lead to a double free.\n\nThe devm_pinctrl_dev_release() function frees the pindescs and destroys\nthe mutex as well.","2024-05-30T16:15:17.063+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36940",{"cveId":9752,"releaseId":25,"cycle":26,"description":9753,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9754,"url":9755},{"cveId":9758,"releaseId":25,"cycle":26,"description":9759,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9760,"url":9761},"CVE-2024-36933","In the Linux kernel, the following vulnerability has been resolved:\n\nnsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().\n\nsyzbot triggered various splats (see [0] and links) by a crafted GSO\npacket of VIRTIO_NET_HDR_GSO_UDP layering the following protocols:\n\n  ETH_P_8021AD + ETH_P_NSH + ETH_P_IPV6 + IPPROTO_UDP\n\nNSH can encapsulate IPv4, IPv6, Ethernet, NSH, and MPLS.  As the inner\nprotocol can be Ethernet, NSH GSO handler, nsh_gso_segment(), calls\nskb_mac_gso_seg","2024-05-30T16:15:16.463+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36933",{"cveId":9758,"releaseId":17,"cycle":18,"description":9759,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9760,"url":9761},{"cveId":9764,"releaseId":17,"cycle":18,"description":9765,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":9766,"url":9767},"CVE-2024-36927","In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Fix uninit-value access in __ip_make_skb()\n\nKMSAN reported uninit-value access in __ip_make_skb() [1].  __ip_make_skb()\ntests HDRINCL to know if the skb has icmphdr. However, HDRINCL can cause a\nrace condition. If calling setsockopt(2) with IP_HDRINCL changes HDRINCL\nwhile __ip_make_skb() is running, the function will access icmphdr in the\nskb even if it is not included. This causes the issue reported by KMSAN.\n\nCheck FLO","2024-05-30T16:15:15.957+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36927",{"cveId":9764,"releaseId":25,"cycle":26,"description":9765,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":9766,"url":9767},{"cveId":9770,"releaseId":17,"cycle":18,"description":9771,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9772,"url":9773},"CVE-2024-36922","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: read txq->read_ptr under lock\n\nIf we read txq->read_ptr without lock, we can read the same\nvalue twice, then obtain the lock, and reclaim from there\nto two different places, but crucially reclaim the same\nentry twice, resulting in the WARN_ONCE() a little later.\nFix that by reading txq->read_ptr under lock.","2024-05-30T16:15:15.47+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36922",{"cveId":9770,"releaseId":25,"cycle":26,"description":9771,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9772,"url":9773},{"cveId":9770,"releaseId":31,"cycle":32,"description":9771,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9772,"url":9773},{"cveId":9777,"releaseId":31,"cycle":32,"description":9778,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9779,"url":9780},"CVE-2024-36921","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: guard against invalid STA ID on removal\n\nGuard against invalid station IDs in iwl_mvm_mld_rm_sta_id as that would\nresult in out-of-bounds array accesses. This prevents issues should the\ndriver get into a bad state during error handling.","2024-05-30T16:15:15.397+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36921",{"cveId":9777,"releaseId":17,"cycle":18,"description":9778,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9779,"url":9780},{"cveId":9777,"releaseId":25,"cycle":26,"description":9778,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9779,"url":9780},{"cveId":9784,"releaseId":31,"cycle":32,"description":9785,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9786,"url":9787},"CVE-2024-36915","In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: fix nfc_llcp_setsockopt() unsafe copies\n\nsyzbot reported unsafe calls to copy_from_sockptr() [1]\n\nUse copy_safe_from_sockptr() instead.\n\n[1]\n\nBUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include\u002Flinux\u002Fsockptr.h:49 [inline]\n BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include\u002Flinux\u002Fsockptr.h:55 [inline]\n BUG: KASAN: slab-out-of-bounds in nfc_llcp_setsockopt+0x6c2\u002F0x850 net\u002Fnfc\u002Fllcp_sock.c:255\nRea","2024-05-30T16:15:14.887+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36915",{"cveId":9784,"releaseId":25,"cycle":26,"description":9785,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9786,"url":9787},{"cveId":9784,"releaseId":17,"cycle":18,"description":9785,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9786,"url":9787},{"cveId":9791,"releaseId":17,"cycle":18,"description":9792,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9793,"url":9794},"CVE-2024-36914","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Skip on writeback when it's not applicable\n\n[WHY]\ndynamic memory safety error detector (KASAN) catches and generates error\nmessages \"BUG: KASAN: slab-out-of-bounds\" as writeback connector does not\nsupport certain features which are not initialized.\n\n[HOW]\nSkip them when connector type is DRM_MODE_CONNECTOR_WRITEBACK.","2024-05-30T16:15:14.79+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36914",{"cveId":9796,"releaseId":17,"cycle":18,"description":9797,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9798,"url":9799},"CVE-2024-36911","In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: Don't free decrypted memory\n\nIn CoCo VMs it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nThe netvsc driver could free decrypted\u002F","2024-05-30T16:15:14.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36911",{"cveId":9796,"releaseId":25,"cycle":26,"description":9797,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9798,"url":9799},{"cveId":9796,"releaseId":31,"cycle":32,"description":9797,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9798,"url":9799},{"cveId":9803,"releaseId":25,"cycle":26,"description":9804,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":9805,"url":9806},"CVE-2024-36910","In the Linux kernel, the following vulnerability has been resolved:\n\nuio_hv_generic: Don't free decrypted memory\n\nIn CoCo VMs it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nThe VMBus device UIO driver could ","2024-05-30T16:15:14.457+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36910",{"cveId":9803,"releaseId":17,"cycle":18,"description":9804,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":9805,"url":9806},{"cveId":9803,"releaseId":31,"cycle":32,"description":9804,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":9805,"url":9806},{"cveId":9810,"releaseId":25,"cycle":26,"description":9811,"severity":101,"cvssScore":9812,"epssScore":9,"inKev":42,"publishedAt":9813,"url":9814},"CVE-2024-36909","In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted\n\nIn CoCo VMs it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nThe ",9.3,"2024-05-30T16:15:14.38+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36909",{"cveId":9810,"releaseId":17,"cycle":18,"description":9811,"severity":101,"cvssScore":9812,"epssScore":9,"inKev":42,"publishedAt":9813,"url":9814},{"cveId":9810,"releaseId":31,"cycle":32,"description":9811,"severity":101,"cvssScore":9812,"epssScore":9,"inKev":42,"publishedAt":9813,"url":9814},{"cveId":9818,"releaseId":17,"cycle":18,"description":9819,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9820,"url":9821},"CVE-2024-36904","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Use refcount_inc_not_zero() in tcp_twsk_unique().\n\nAnderson Nascimento reported a use-after-free splat in tcp_twsk_unique()\nwith nice analysis.\n\nSince commit ec94c2696f0b (\"tcp\u002Fdccp: avoid one atomic operation for\ntimewait hashdance\"), inet_twsk_hashdance() sets TIME-WAIT socket's\nsk_refcnt after putting it into ehash and releasing the bucket lock.\n\nThus, there is a small race window where other threads could try to\nreuse ","2024-05-30T16:15:13.947+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36904",{"cveId":9823,"releaseId":25,"cycle":26,"description":9824,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9825,"url":9826},"CVE-2024-36903","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: Fix potential uninit-value access in __ip6_make_skb()\n\nAs it was done in commit fc1092f51567 (\"ipv4: Fix uninit-value access in\n__ip_make_skb()\") for IPv4, check FLOWI_FLAG_KNOWN_NH on fl6->flowi6_flags\ninstead of testing HDRINCL on the socket to avoid a race condition which\ncauses uninit-value access.","2024-05-30T16:15:13.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36903",{"cveId":9823,"releaseId":17,"cycle":18,"description":9824,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":9825,"url":9826},{"cveId":9829,"releaseId":17,"cycle":18,"description":9830,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9831,"url":9832},"CVE-2024-36894","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete\n\nFFS based applications can utilize the aio_cancel() callback to dequeue\npending USB requests submitted to the UDC.  There is a scenario where the\nFFS application issues an AIO cancel call, while the UDC is handling a\nsoft disconnect.  For a DWC3 based implementation, the callstack looks\nlike the following:\n\n    DWC3 Gadget                               F","2024-05-30T16:15:12.857+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36894",{"cveId":9829,"releaseId":25,"cycle":26,"description":9830,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9831,"url":9832},{"cveId":9829,"releaseId":31,"cycle":32,"description":9830,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9831,"url":9832},{"cveId":9836,"releaseId":31,"cycle":32,"description":9837,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9838,"url":9839},"CVE-2024-36886","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix UAF in error path\n\nSam Page (sam4k) working with Trend Micro Zero Day Initiative reported\na UAF in the tipc_buf_append() error path:\n\nBUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e\u002F0x4c0\nlinux\u002Fnet\u002Fcore\u002Fskbuff.c:1183\nRead of size 8 at addr ffff88804d2a7c80 by task poc\u002F8034\n\nCPU: 1 PID: 8034 Comm: poc Not tainted 6.8.2 #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.0-debian-1.16.0-5 ","2024-05-30T16:15:12.15+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36886",{"cveId":9836,"releaseId":25,"cycle":26,"description":9837,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9838,"url":9839},{"cveId":9836,"releaseId":17,"cycle":18,"description":9837,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9838,"url":9839},{"cveId":9843,"releaseId":17,"cycle":18,"description":9844,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9845,"url":9846},"CVE-2024-36883","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix out-of-bounds access in ops_init\n\nnet_alloc_generic is called by net_alloc, which is called without any\nlocking. It reads max_gen_ptrs, which is changed under pernet_ops_rwsem. It\nis read twice, first to allocate an array, then to set s.len, which is\nlater used to limit the bounds of the array access.\n\nIt is possible that the array is allocated and another thread is\nregistering a new pernet ops, increments max_gen_ptrs","2024-05-30T16:15:11.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36883",{"cveId":9843,"releaseId":25,"cycle":26,"description":9844,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9845,"url":9846},{"cveId":9843,"releaseId":31,"cycle":32,"description":9844,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9845,"url":9846},{"cveId":9850,"releaseId":25,"cycle":26,"description":9851,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9852,"url":9853},"CVE-2024-36880","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: add missing firmware sanity checks\n\nAdd the missing sanity checks when parsing the firmware files before\ndownloading them to avoid accessing and corrupting memory beyond the\nvmalloced buffer.","2024-05-30T16:15:11.64+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36880",{"cveId":9850,"releaseId":17,"cycle":18,"description":9851,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9852,"url":9853},{"cveId":9850,"releaseId":31,"cycle":32,"description":9851,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9852,"url":9853},{"cveId":9857,"releaseId":17,"cycle":18,"description":9858,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9859,"url":9860},"CVE-2024-36020","In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: fix vf may be used uninitialized in this function warning\n\nTo fix the regression introduced by commit 52424f974bc5, which causes\nservers hang in very hard to reproduce conditions with resets races.\nUsing two sources for the information is the root cause.\nIn this function before the fix bumping v didn't mean bumping vf\npointer. But the code used this variables interchangeably, so stale vf\ncould point to different\u002Fnot inten","2024-05-30T15:15:49.107+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36020",{"cveId":9862,"releaseId":31,"cycle":32,"description":9863,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9864,"url":9865},"CVE-2024-36016","In the Linux kernel, the following vulnerability has been resolved:\n\ntty: n_gsm: fix possible out-of-bounds in gsm0_receive()\n\nAssuming the following:\n- side A configures the n_gsm in basic option mode\n- side B sends the header of a basic option mode frame with data length 1\n- side A switches to advanced option mode\n- side B sends 2 data bytes which exceeds gsm->len\n  Reason: gsm->len is not used in advanced option mode.\n- side A switches to basic option mode\n- side B keeps sending until gsm0_re","2024-05-29T19:15:48.297+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36016",{"cveId":9862,"releaseId":25,"cycle":26,"description":9863,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9864,"url":9865},{"cveId":9862,"releaseId":17,"cycle":18,"description":9863,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9864,"url":9865},{"cveId":9869,"releaseId":17,"cycle":18,"description":9870,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9871,"url":9872},"CVE-2023-52881","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: do not accept ACK of bytes we never sent\n\nThis patch is based on a detailed report and ideas from Yepeng Pan\nand Christian Rossow.\n\nACK seq validation is currently following RFC 5961 5.2 guidelines:\n\n   The ACK value is considered acceptable only if\n   it is in the range of ((SND.UNA - MAX.SND.WND) \u003C= SEG.ACK \u003C=\n   SND.NXT).  All incoming segments whose ACK value doesn't satisfy the\n   above condition MUST be discarded and","2024-05-29T11:16:02.11+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52881",{"cveId":9869,"releaseId":25,"cycle":26,"description":9870,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9871,"url":9872},{"cveId":9869,"releaseId":31,"cycle":32,"description":9870,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9871,"url":9872},{"cveId":9876,"releaseId":17,"cycle":18,"description":9877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9878,"url":9879},"CVE-2023-52880","In the Linux kernel, the following vulnerability has been resolved:\n\ntty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc\n\nAny unprivileged user can attach N_GSM0710 ldisc, but it requires\nCAP_NET_ADMIN to create a GSM network anyway.\n\nRequire initial namespace CAP_NET_ADMIN to do that.","2024-05-24T16:15:10.033+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52880",{"cveId":9876,"releaseId":25,"cycle":26,"description":9877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9878,"url":9879},{"cveId":9876,"releaseId":31,"cycle":32,"description":9877,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9878,"url":9879},{"cveId":9883,"releaseId":17,"cycle":18,"description":9884,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9885,"url":9886},"CVE-2021-47559","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: Fix NULL pointer dereferencing in smc_vlan_by_tcpsk()\n\nCoverity reports a possible NULL dereferencing problem:\n\nin smc_vlan_by_tcpsk():\n6. returned_null: netdev_lower_get_next returns NULL (checked 29 out of 30 times).\n7. var_assigned: Assigning: ndev = NULL return value from netdev_lower_get_next.\n1623                ndev = (struct net_device *)netdev_lower_get_next(ndev, &lower);\nCID 1468509 (#1 of 1): Dereference nu","2024-05-24T15:15:20.537+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47559",{"cveId":9888,"releaseId":17,"cycle":18,"description":9889,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9890,"url":9891},"CVE-2021-47552","In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: cancel blk-mq dispatch work in both blk_cleanup_queue and disk_release()\n\nFor avoiding to slow down queue destroy, we don't call\nblk_mq_quiesce_queue() in blk_cleanup_queue(), instead of delaying to\ncancel dispatch work in blk_release_queue().\n\nHowever, this way has caused kernel oops[1], reported by Changhui. The log\nshows that scsi_device can be freed before running blk_release_queue(),\nwhich is expected too since scs","2024-05-24T15:15:20+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47552",{"cveId":9888,"releaseId":25,"cycle":26,"description":9889,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9890,"url":9891},{"cveId":9888,"releaseId":31,"cycle":32,"description":9889,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9890,"url":9891},{"cveId":9895,"releaseId":25,"cycle":26,"description":9896,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9897,"url":9898},"CVE-2021-47551","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Famdkfd: Fix kernel panic when reset failed and been triggered again\n\nIn SRIOV configuration, the reset may failed to bring asic back to normal but stop cpsch\nalready been called, the start_cpsch will not be called since there is no resume in this\ncase.  When reset been triggered again, driver should avoid to do uninitialization again.","2024-05-24T15:15:19.927+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47551",{"cveId":9895,"releaseId":17,"cycle":18,"description":9896,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9897,"url":9898},{"cveId":9895,"releaseId":31,"cycle":32,"description":9896,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9897,"url":9898},{"cveId":9902,"releaseId":25,"cycle":26,"description":9903,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9904,"url":9905},"CVE-2021-47544","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix page frag corruption on page fault\n\nSteffen reported a TCP stream corruption for HTTP requests\nserved by the apache web-server using a cifs mount-point\nand memory mapping the relevant file.\n\nThe root cause is quite similar to the one addressed by\ncommit 20eb4f29b602 (\"net: fix sk_page_frag() recursion from\nmemory reclaim\"). Here the nested access to the task page frag\nis caused by a page fault on the (mmapped) user-spa","2024-05-24T15:15:18.983+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47544",{"cveId":9902,"releaseId":17,"cycle":18,"description":9903,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9904,"url":9905},{"cveId":9902,"releaseId":31,"cycle":32,"description":9903,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9904,"url":9905},{"cveId":9909,"releaseId":17,"cycle":18,"description":9910,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9911,"url":9912},"CVE-2021-47541","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx4_en: Fix an use-after-free bug in mlx4_en_try_alloc_resources()\n\nIn mlx4_en_try_alloc_resources(), mlx4_en_copy_priv() is called and\ntmp->tx_cq will be freed on the error path of mlx4_en_copy_priv().\nAfter that mlx4_en_alloc_resources() is called and there is a dereference\nof &tmp->tx_cq[t][i] in mlx4_en_alloc_resources(), which could lead to\na use after free problem on failure of mlx4_en_copy_priv().\n\nFix this bug by a","2024-05-24T15:15:18.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47541",{"cveId":9909,"releaseId":25,"cycle":26,"description":9910,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9911,"url":9912},{"cveId":9909,"releaseId":31,"cycle":32,"description":9910,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9911,"url":9912},{"cveId":9916,"releaseId":17,"cycle":18,"description":9917,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9918,"url":9919},"CVE-2021-47520","In the Linux kernel, the following vulnerability has been resolved:\n\ncan: pch_can: pch_can_rx_normal: fix use after free\n\nAfter calling netif_receive_skb(skb), dereferencing skb is unsafe.\nEspecially, the can_frame cf which aliases skb memory is dereferenced\njust after the call netif_receive_skb(skb).\n\nReordering the lines solves the issue.","2024-05-24T15:15:14.003+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47520",{"cveId":9916,"releaseId":25,"cycle":26,"description":9917,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9918,"url":9919},{"cveId":9916,"releaseId":31,"cycle":32,"description":9917,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":9918,"url":9919},{"cveId":9923,"releaseId":17,"cycle":18,"description":9924,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9925,"url":9926},"CVE-2021-47515","In the Linux kernel, the following vulnerability has been resolved:\n\nseg6: fix the iif in the IPv6 socket control block\n\nWhen an IPv4 packet is received, the ip_rcv_core(...) sets the receiving\ninterface index into the IPv4 socket control block (v5.16-rc4,\nnet\u002Fipv4\u002Fip_input.c line 510):\n\n    IPCB(skb)->iif = skb->skb_iif;\n\nIf that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH\nheader, the seg6_do_srh_encap(...) performs the required encapsulation.\nIn this case, the seg6_do_srh_enca","2024-05-24T15:15:12.937+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47515",{"cveId":9923,"releaseId":25,"cycle":26,"description":9924,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":9925,"url":9926},{"cveId":9929,"releaseId":25,"cycle":26,"description":9930,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9931,"url":9932},"CVE-2021-47506","In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix use-after-free due to delegation race\n\nA delegation break could arrive as soon as we've called vfs_setlease.  A\ndelegation break runs a callback which immediately (in\nnfsd4_cb_recall_prepare) adds the delegation to del_recall_lru.  If we\nthen exit nfs4_set_delegation without hashing the delegation, it will be\nfreed as soon as the callback is done with it, without ever being\nremoved from del_recall_lru.\n\nSymptoms show ","2024-05-24T15:15:11.197+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47506",{"cveId":9929,"releaseId":31,"cycle":32,"description":9930,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9931,"url":9932},{"cveId":9929,"releaseId":17,"cycle":18,"description":9930,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9931,"url":9932},{"cveId":9936,"releaseId":17,"cycle":18,"description":9937,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9938,"url":9939},"CVE-2021-47505","In the Linux kernel, the following vulnerability has been resolved:\n\naio: fix use-after-free due to missing POLLFREE handling\n\nsignalfd_poll() and binder_poll() are special in that they use a\nwaitqueue whose lifetime is the current task, rather than the struct\nfile as is normally the case.  This is okay for blocking polls, since a\nblocking poll occurs within one task; however, non-blocking polls\nrequire another solution.  This solution is for the queue to be cleared\nbefore it is freed, by sendin","2024-05-24T15:15:11+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47505",{"cveId":9941,"releaseId":25,"cycle":26,"description":9942,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9943,"url":9944},"CVE-2021-47500","In the Linux kernel, the following vulnerability has been resolved:\n\niio: mma8452: Fix trigger reference couting\n\nThe mma8452 driver directly assigns a trigger to the struct iio_dev. The\nIIO core when done using this trigger will call `iio_trigger_put()` to drop\nthe reference count by 1.\n\nWithout the matching `iio_trigger_get()` in the driver the reference count\ncan reach 0 too early, the trigger gets freed while still in use and a\nuse-after-free occurs.\n\nFix this by getting a reference to the t","2024-05-24T15:15:09.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47500",{"cveId":9941,"releaseId":17,"cycle":18,"description":9942,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9943,"url":9944},{"cveId":9941,"releaseId":31,"cycle":32,"description":9942,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9943,"url":9944},{"cveId":9948,"releaseId":17,"cycle":18,"description":9949,"severity":58,"cvssScore":543,"epssScore":9,"inKev":42,"publishedAt":9950,"url":9951},"CVE-2024-36013","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()\n\nExtend a critical section to prevent chan from early freeing.\nAlso make the l2cap_connect() return type void. Nothing is using the\nreturned value but it is ugly to return a potentially freed pointer.\nMaking it void will help with backports because earlier kernels did use\nthe return value. Now the compile will break for kernels where this\npatch is not a complete fix.\n","2024-05-23T07:15:08.987+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36013",{"cveId":9948,"releaseId":25,"cycle":26,"description":9949,"severity":58,"cvssScore":543,"epssScore":9,"inKev":42,"publishedAt":9950,"url":9951},{"cveId":9948,"releaseId":31,"cycle":32,"description":9949,"severity":58,"cvssScore":543,"epssScore":9,"inKev":42,"publishedAt":9950,"url":9951},{"cveId":9955,"releaseId":17,"cycle":18,"description":9956,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":9957,"url":9958},"CVE-2021-47496","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Ftls: Fix flipped sign in tls_err_abort() calls\n\nsk->sk_err appears to expect a positive value, a convention that ktls\ndoesn't always follow and that leads to memory corruption in other code.\nFor instance,\n\n    [kworker]\n    tls_encrypt_done(..., err=\u003Cnegative error from crypto request>)\n      tls_err_abort(.., err)\n        sk->sk_err = err;\n\n    [task]\n    splice_from_pipe_feed\n      ...\n        tls_sw_do_sendpage\n         ","2024-05-22T09:15:11.447+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47496",{"cveId":9960,"releaseId":25,"cycle":26,"description":9961,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9962,"url":9963},"CVE-2021-47493","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix race between searching chunks and release journal_head from buffer_head\n\nEncountered a race between ocfs2_test_bg_bit_allocatable() and\njbd2_journal_put_journal_head() resulting in the below vmcore.\n\n  PID: 106879  TASK: ffff880244ba9c00  CPU: 2   COMMAND: \"loop3\"\n  Call trace:\n    panic\n    oops_end\n    no_context\n    __bad_area_nosemaphore\n    bad_area_nosemaphore\n    __do_page_fault\n    do_page_fault\n    page_faul","2024-05-22T09:15:11.1+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47493",{"cveId":9960,"releaseId":31,"cycle":32,"description":9961,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9962,"url":9963},{"cveId":9960,"releaseId":17,"cycle":18,"description":9961,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9962,"url":9963},{"cveId":9967,"releaseId":25,"cycle":26,"description":9968,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9969,"url":9970},"CVE-2021-47485","In the Linux kernel, the following vulnerability has been resolved:\n\nIB\u002Fqib: Protect from buffer overflow in struct qib_user_sdma_pkt fields\n\nOverflowing either addrlimit or bytes_togo can allow userspace to trigger\na buffer overflow of kernel memory. Check for overflows in all the places\ndoing math on user controlled buffers.","2024-05-22T09:15:10.503+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47485",{"cveId":9967,"releaseId":17,"cycle":18,"description":9968,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9969,"url":9970},{"cveId":9967,"releaseId":31,"cycle":32,"description":9968,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9969,"url":9970},{"cveId":9974,"releaseId":31,"cycle":32,"description":9975,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9976,"url":9977},"CVE-2021-47483","In the Linux kernel, the following vulnerability has been resolved:\n\nregmap: Fix possible double-free in regcache_rbtree_exit()\n\nIn regcache_rbtree_insert_to_block(), when 'present' realloc failed,\nthe 'blk' which is supposed to assign to 'rbnode->block' will be freed,\nso 'rbnode->block' points a freed memory, in the error handling path of\nregcache_rbtree_init(), 'rbnode->block' will be freed again in\nregcache_rbtree_exit(), KASAN will report double-free as follows:\n\nBUG: KASAN: double-free or i","2024-05-22T09:15:10.227+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47483",{"cveId":9974,"releaseId":25,"cycle":26,"description":9975,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9976,"url":9977},{"cveId":9974,"releaseId":17,"cycle":18,"description":9975,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":9976,"url":9977},{"cveId":9981,"releaseId":31,"cycle":32,"description":9982,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9983,"url":9984},"CVE-2021-47478","In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: Fix out of bound access for corrupted isofs image\n\nWhen isofs image is suitably corrupted isofs_read_inode() can read data\nbeyond the end of buffer. Sanity-check the directory entry length before\nusing it.","2024-05-22T09:15:09.747+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47478",{"cveId":9981,"releaseId":17,"cycle":18,"description":9982,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9983,"url":9984},{"cveId":9981,"releaseId":25,"cycle":26,"description":9982,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":9983,"url":9984},{"cveId":9988,"releaseId":25,"cycle":26,"description":9989,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9990,"url":9991},"CVE-2021-47458","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: mount fails with buffer overflow in strlen\n\nStarting with kernel 5.11 built with CONFIG_FORTIFY_SOURCE mouting an\nocfs2 filesystem with either o2cb or pcmk cluster stack fails with the\ntrace below.  Problem seems to be that strings for cluster stack and\ncluster name are not guaranteed to be null terminated in the disk\nrepresentation, while strlcpy assumes that the source string is always\nnull terminated.  This causes a r","2024-05-22T07:15:10.78+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47458",{"cveId":9988,"releaseId":17,"cycle":18,"description":9989,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9990,"url":9991},{"cveId":9988,"releaseId":31,"cycle":32,"description":9989,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9990,"url":9991},{"cveId":9995,"releaseId":25,"cycle":26,"description":9996,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9997,"url":9998},"CVE-2021-47438","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5e: Fix memory leak in mlx5_core_destroy_cq() error path\n\nPrior to this patch in case mlx5_core_destroy_cq() failed it returns\nwithout completing all destroy operations and that leads to memory leak.\nInstead, complete the destroy flow before return error.\n\nAlso move mlx5_debug_cq_remove() to the beginning of mlx5_core_destroy_cq()\nto be symmetrical with mlx5_core_create_cq().\n\nkmemleak complains on:\n\nunreferenced object ","2024-05-22T07:15:09.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47438",{"cveId":9995,"releaseId":31,"cycle":32,"description":9996,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9997,"url":9998},{"cveId":9995,"releaseId":17,"cycle":18,"description":9996,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":9997,"url":9998},{"cveId":10002,"releaseId":31,"cycle":32,"description":10003,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":10004,"url":10005},"CVE-2021-47433","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix abort logic in btrfs_replace_file_extents\n\nError injection testing uncovered a case where we'd end up with a\ncorrupt file system with a missing extent in the middle of a file.  This\noccurs because the if statement to decide if we should abort is wrong.\n\nThe only way we would abort in this case is if we got a ret !=\n-EOPNOTSUPP and we called from the file clone code.  However the\nprealloc code uses this path too.  Ins","2024-05-22T07:15:08.347+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47433",{"cveId":10002,"releaseId":17,"cycle":18,"description":10003,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":10004,"url":10005},{"cveId":10002,"releaseId":25,"cycle":26,"description":10003,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":10004,"url":10005},{"cveId":10009,"releaseId":17,"cycle":18,"description":10010,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10011,"url":10012},"CVE-2023-52871","In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: llcc: Handle a second device without data corruption\n\nUsually there is only one llcc device. But if there were a second, even\na failed probe call would modify the global drv_data pointer. So check\nif drv_data is valid before overwriting it.","2024-05-21T16:15:23.907+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52871",{"cveId":10014,"releaseId":17,"cycle":18,"description":10015,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10016,"url":10017},"CVE-2023-52867","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fradeon: possible buffer overflow\n\nBuffer 'afmt_status' of size 6 could overflow, since index 'afmt_idx' is\nchecked after access.","2024-05-21T16:15:23.597+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52867",{"cveId":10014,"releaseId":25,"cycle":26,"description":10015,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10016,"url":10017},{"cveId":10020,"releaseId":17,"cycle":18,"description":10021,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":10022,"url":10023},"CVE-2023-52864","In the Linux kernel, the following vulnerability has been resolved:\n\nplatform\u002Fx86: wmi: Fix opening of char device\n\nSince commit fa1f68db6ca7 (\"drivers: misc: pass miscdevice pointer via\nfile private data\"), the miscdevice stores a pointer to itself inside\nfilp->private_data, which means that private_data will not be NULL when\nwmi_char_open() is called. This might cause memory corruption should\nwmi_char_open() be unable to find its driver, something which can\nhappen when the associated WMI devic","2024-05-21T16:15:23.317+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52864",{"cveId":10025,"releaseId":17,"cycle":18,"description":10026,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10027,"url":10028},"CVE-2023-52847","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: bttv: fix use after free error due to btv->timeout timer\n\nThere may be some a race condition between timer function\nbttv_irq_timeout and bttv_remove. The timer is setup in\nprobe and there is no timer_delete operation in remove\nfunction. When it hit kfree btv, the function might still be\ninvoked, which will cause use after free bug.\n\nThis bug is found by static analysis, it may be false positive.\n\nFix it by adding del_tim","2024-05-21T16:15:21.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52847",{"cveId":10030,"releaseId":25,"cycle":26,"description":10031,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10032,"url":10033},"CVE-2023-52845","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Change nla_policy for bearer-related names to NLA_NUL_STRING\n\nsyzbot reported the following uninit-value access issue [1]:\n\n=====================================================\nBUG: KMSAN: uninit-value in strlen lib\u002Fstring.c:418 [inline]\nBUG: KMSAN: uninit-value in strstr+0xb8\u002F0x2f0 lib\u002Fstring.c:756\n strlen lib\u002Fstring.c:418 [inline]\n strstr+0xb8\u002F0x2f0 lib\u002Fstring.c:756\n tipc_nl_node_reset_link_stats+0x3ea\u002F0xb50 net\u002Ftipc\u002Fn","2024-05-21T16:15:21.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52845",{"cveId":10030,"releaseId":31,"cycle":32,"description":10031,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10032,"url":10033},{"cveId":10030,"releaseId":17,"cycle":18,"description":10031,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10032,"url":10033},{"cveId":10037,"releaseId":25,"cycle":26,"description":10038,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10039,"url":10040},"CVE-2023-52834","In the Linux kernel, the following vulnerability has been resolved:\n\natl1c: Work around the DMA RX overflow issue\n\nThis is based on alx driver commit 881d0327db37 (\"net: alx: Work around\nthe DMA RX overflow issue\").\n\nThe alx and atl1c drivers had RX overflow error which was why a custom\nallocator was created to avoid certain addresses. The simpler workaround\nthen created for alx driver, but not for atl1c due to lack of tester.\n\nInstead of using a custom allocator, check the allocated skb address","2024-05-21T16:15:20.95+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52834",{"cveId":10037,"releaseId":31,"cycle":32,"description":10038,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10039,"url":10040},{"cveId":10037,"releaseId":17,"cycle":18,"description":10038,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10039,"url":10040},{"cveId":10044,"releaseId":17,"cycle":18,"description":10045,"severity":40,"cvssScore":10046,"epssScore":9,"inKev":42,"publishedAt":10047,"url":10048},"CVE-2023-52827","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix possible out-of-bound read in ath12k_htt_pull_ppdu_stats()\n\nlen is extracted from HTT message and could be an unexpected value in\ncase errors happen, so add validation before using to avoid possible\nout-of-bound read in the following message iteration and parsing.\n\nThe same issue also applies to ppdu_info->ppdu_stats.common.num_users,\nso validate it before using too.\n\nThese are found during code review.\n\nCompi",7.7,"2024-05-21T16:15:20.463+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52827",{"cveId":10044,"releaseId":31,"cycle":32,"description":10045,"severity":40,"cvssScore":10046,"epssScore":9,"inKev":42,"publishedAt":10047,"url":10048},{"cveId":10044,"releaseId":25,"cycle":26,"description":10045,"severity":40,"cvssScore":10046,"epssScore":9,"inKev":42,"publishedAt":10047,"url":10048},{"cveId":10052,"releaseId":25,"cycle":26,"description":10053,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10054,"url":10055},"CVE-2023-52825","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdkfd: Fix a race condition of vram buffer unref in svm code\n\nprange->svm_bo unref can happen in both mmu callback and a callback after\nmigrate to system ram. Both are async call in different tasks. Sync svm_bo\nunref operation to avoid random \"use-after-free\".","2024-05-21T16:15:20.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52825",{"cveId":10052,"releaseId":17,"cycle":18,"description":10053,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10054,"url":10055},{"cveId":10052,"releaseId":31,"cycle":32,"description":10053,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10054,"url":10055},{"cveId":10059,"releaseId":31,"cycle":32,"description":10060,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10061,"url":10062},"CVE-2023-52810","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Fjfs: Add check for negative db_l2nbperpage\n\nl2nbperpage is log2(number of blks per page), and the minimum legal\nvalue should be 0, not negative.\n\nIn the case of l2nbperpage being negative, an error will occur\nwhen subsequently used as shift exponent.\n\nSyzbot reported this bug:\n\nUBSAN: shift-out-of-bounds in fs\u002Fjfs\u002Fjfs_dmap.c:799:12\nshift exponent -16777216 is negative","2024-05-21T16:15:19.27+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52810",{"cveId":10059,"releaseId":17,"cycle":18,"description":10060,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10061,"url":10062},{"cveId":10059,"releaseId":25,"cycle":26,"description":10060,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10061,"url":10062},{"cveId":10066,"releaseId":31,"cycle":32,"description":10067,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10068,"url":10069},"CVE-2023-52804","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Fjfs: Add validity check for db_maxag and db_agpref\n\nBoth db_maxag and db_agpref are used as the index of the\ndb_agfree array, but there is currently no validity check for\ndb_maxag and db_agpref, which can lead to errors.\n\nThe following is related bug reported by Syzbot:\n\nUBSAN: array-index-out-of-bounds in fs\u002Fjfs\u002Fjfs_dmap.c:639:20\nindex 7936 is out of range for type 'atomic_t[128]'\n\nAdd checking that the values of db_maxag a","2024-05-21T16:15:18.82+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52804",{"cveId":10066,"releaseId":25,"cycle":26,"description":10067,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10068,"url":10069},{"cveId":10066,"releaseId":17,"cycle":18,"description":10067,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10068,"url":10069},{"cveId":10073,"releaseId":17,"cycle":18,"description":10074,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10075,"url":10076},"CVE-2023-52799","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in dbFindLeaf\n\nCurrently while searching for dmtree_t for sufficient free blocks there\nis an array out of bounds while getting element in tp->dm_stree. To add\nthe required check for out of bound we first need to determine the type\nof dmtree. Thus added an extra parameter to dbFindLeaf so that the type\nof tree can be determined and the required check can be applied.","2024-05-21T16:15:18.443+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52799",{"cveId":10073,"releaseId":31,"cycle":32,"description":10074,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10075,"url":10076},{"cveId":10073,"releaseId":25,"cycle":26,"description":10074,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10075,"url":10076},{"cveId":10080,"releaseId":25,"cycle":26,"description":10081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10082,"url":10083},"CVE-2023-52766","In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Fix out of bounds access in hci_dma_irq_handler\n\nDo not loop over ring headers in hci_dma_irq_handler() that are not\nallocated and enabled in hci_dma_init(). Otherwise out of bounds access\nwill occur from rings->headers[i] access when i >= number of allocated\nring headers.","2024-05-21T16:15:15.847+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52766",{"cveId":10080,"releaseId":31,"cycle":32,"description":10081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10082,"url":10083},{"cveId":10080,"releaseId":17,"cycle":18,"description":10081,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10082,"url":10083},{"cveId":10087,"releaseId":17,"cycle":18,"description":10088,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10089,"url":10090},"CVE-2023-52761","In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: VMAP_STACK overflow detection thread-safe\n\ncommit 31da94c25aea (\"riscv: add VMAP_STACK overflow detection\") added\nsupport for CONFIG_VMAP_STACK. If overflow is detected, CPU switches to\n`shadow_stack` temporarily before switching finally to per-cpu\n`overflow_stack`.\n\nIf two CPUs\u002Fharts are racing and end up in over flowing kernel stack, one\nor both will end up corrupting each other state because `shadow_stack` is\nnot per-","2024-05-21T16:15:15.487+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52761",{"cveId":10092,"releaseId":25,"cycle":26,"description":10093,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10094,"url":10095},"CVE-2023-52760","In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Fix slab-use-after-free in gfs2_qd_dealloc\n\nIn gfs2_put_super(), whether withdrawn or not, the quota should\nbe cleaned up by gfs2_quota_cleanup().\n\nOtherwise, struct gfs2_sbd will be freed before gfs2_qd_dealloc (rcu\ncallback) has run for all gfs2_quota_data objects, resulting in\nuse-after-free.\n\nAlso, gfs2_destroy_threads() and gfs2_quota_cleanup() is already called\nby gfs2_make_fs_ro(), so in gfs2_put_super(), after cal","2024-05-21T16:15:15.41+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52760",{"cveId":10092,"releaseId":17,"cycle":18,"description":10093,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10094,"url":10095},{"cveId":10092,"releaseId":31,"cycle":32,"description":10093,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10094,"url":10095},{"cveId":10099,"releaseId":17,"cycle":18,"description":10100,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10101,"url":10102},"CVE-2023-52751","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in smb2_query_info_compound()\n\nThe following UAF was triggered when running fstests generic\u002F072 with\nKASAN enabled against Windows Server 2022 and mount options\n'multichannel,max_channels=2,vers=3.1.1,mfsymlinks,noperm'\n\n  BUG: KASAN: slab-use-after-free in smb2_query_info_compound+0x423\u002F0x6d0 [cifs]\n  Read of size 8 at addr ffff888014941048 by task xfs_io\u002F27534\n\n  CPU: 0 PID: 27534 Comm: xfs_io ","2024-05-21T16:15:14.763+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52751",{"cveId":10099,"releaseId":31,"cycle":32,"description":10100,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10101,"url":10102},{"cveId":10099,"releaseId":25,"cycle":26,"description":10100,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10101,"url":10102},{"cveId":10106,"releaseId":31,"cycle":32,"description":10107,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10108,"url":10109},"CVE-2023-52745","In the Linux kernel, the following vulnerability has been resolved:\n\nIB\u002FIPoIB: Fix legacy IPoIB due to wrong number of queues\n\nThe cited commit creates child PKEY interfaces over netlink will\nmultiple tx and rx queues, but some devices doesn't support more than 1\ntx and 1 rx queues. This causes to a crash when traffic is sent over the\nPKEY interface due to the parent having a single queue but the child\nhaving multiple queues.\n\nThis patch fixes the number of queues to 1 for legacy IPoIB at the\nea","2024-05-21T16:15:14.303+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52745",{"cveId":10106,"releaseId":17,"cycle":18,"description":10107,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10108,"url":10109},{"cveId":10106,"releaseId":25,"cycle":26,"description":10107,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10108,"url":10109},{"cveId":10113,"releaseId":31,"cycle":32,"description":10114,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10115,"url":10116},"CVE-2023-52741","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix use-after-free in rdata->read_into_pages()\n\nWhen the network status is unstable, use-after-free may occur when\nread data from the server.\n\n  BUG: KASAN: use-after-free in readpages_fill_pages+0x14c\u002F0x7e0\n\n  Call Trace:\n   \u003CTASK>\n   dump_stack_lvl+0x38\u002F0x4c\n   print_report+0x16f\u002F0x4a6\n   kasan_report+0xb7\u002F0x130\n   readpages_fill_pages+0x14c\u002F0x7e0\n   cifs_readv_receive+0x46d\u002F0xa40\n   cifs_demultiplex_thread+0x121c\u002F0x149","2024-05-21T16:15:14+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52741",{"cveId":10113,"releaseId":17,"cycle":18,"description":10114,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10115,"url":10116},{"cveId":10113,"releaseId":25,"cycle":26,"description":10114,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10115,"url":10116},{"cveId":10120,"releaseId":31,"cycle":32,"description":10121,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10122,"url":10123},"CVE-2023-52737","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: lock the inode in shared mode before starting fiemap\n\nCurrently fiemap does not take the inode's lock (VFS lock), it only locks\na file range in the inode's io tree. This however can lead to a deadlock\nif we have a concurrent fsync on the file and fiemap code triggers a fault\nwhen accessing the user space buffer with fiemap_fill_next_extent(). The\ndeadlock happens on the inode's i_mmap_lock semaphore, which is taken both\n","2024-05-21T16:15:13.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52737",{"cveId":10120,"releaseId":17,"cycle":18,"description":10121,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10122,"url":10123},{"cveId":10120,"releaseId":25,"cycle":26,"description":10121,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10122,"url":10123},{"cveId":10127,"releaseId":25,"cycle":26,"description":10128,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10129,"url":10130},"CVE-2023-52732","In the Linux kernel, the following vulnerability has been resolved:\n\nceph: blocklist the kclient when receiving corrupted snap trace\n\nWhen received corrupted snap trace we don't know what exactly has\nhappened in MDS side. And we shouldn't continue IOs and metadatas\naccess to MDS, which may corrupt or get incorrect contents.\n\nThis patch will just block all the further IO\u002FMDS requests\nimmediately and then evict the kclient itself.\n\nThe reason why we still need to evict the kclient just after\nblock","2024-05-21T16:15:13.303+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52732",{"cveId":10127,"releaseId":17,"cycle":18,"description":10128,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10129,"url":10130},{"cveId":10127,"releaseId":31,"cycle":32,"description":10128,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10129,"url":10130},{"cveId":10134,"releaseId":31,"cycle":32,"description":10135,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10136,"url":10137},"CVE-2021-47412","In the Linux kernel, the following vulnerability has been resolved:\n\nblock: don't call rq_qos_ops->done_bio if the bio isn't tracked\n\nrq_qos framework is only applied on request based driver, so:\n\n1) rq_qos_done_bio() needn't to be called for bio based driver\n\n2) rq_qos_done_bio() needn't to be called for bio which isn't tracked,\nsuch as bios ended from error handling code.\n\nEspecially in bio_endio():\n\n1) request queue is referred via bio->bi_bdev->bd_disk->queue, which\nmay be gone since request","2024-05-21T15:15:26.7+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47412",{"cveId":10134,"releaseId":25,"cycle":26,"description":10135,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10136,"url":10137},{"cveId":10134,"releaseId":17,"cycle":18,"description":10135,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10136,"url":10137},{"cveId":10141,"releaseId":31,"cycle":32,"description":10142,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10143,"url":10144},"CVE-2021-47401","In the Linux kernel, the following vulnerability has been resolved:\n\nipack: ipoctal: fix stack information leak\n\nThe tty driver name is used also after registering the driver and must\nspecifically not be allocated on the stack to avoid leaking information\nto user space (or triggering an oops).\n\nDrivers should not try to encode topology information in the tty device\nname but this one snuck in through staging without anyone noticing and\nanother driver has since copied this malpractice.\n\nFixing the","2024-05-21T15:15:25.563+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47401",{"cveId":10141,"releaseId":25,"cycle":26,"description":10142,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10143,"url":10144},{"cveId":10141,"releaseId":17,"cycle":18,"description":10142,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10143,"url":10144},{"cveId":10148,"releaseId":31,"cycle":32,"description":10149,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10150,"url":10151},"CVE-2021-47397","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb\n\nWe should always check if skb_header_pointer's return is NULL before\nusing it, otherwise it may cause null-ptr-deref, as syzbot reported:\n\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  RIP: 0010:sctp_rcv_ootb net\u002Fsctp\u002Finput.c:705 [inline]\n  RIP: 0010:sctp_rcv+0x1d84\u002F0x3220 net\u002Fsctp\u002Finput.c:196\n  Call Trace:\n  \u003CIRQ>\n   sctp6_rcv+0x3","2024-05-21T15:15:25.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47397",{"cveId":10148,"releaseId":25,"cycle":26,"description":10149,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10150,"url":10151},{"cveId":10148,"releaseId":17,"cycle":18,"description":10149,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10150,"url":10151},{"cveId":10155,"releaseId":25,"cycle":26,"description":10156,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10157,"url":10158},"CVE-2021-47391","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fcma: Ensure rdma_addr_cancel() happens before issuing more requests\n\nThe FSM can run in a circle allowing rdma_resolve_ip() to be called twice\non the same id_priv. While this cannot happen without going through the\nwork, it violates the invariant that the same address resolution\nbackground request cannot be active twice.\n\n       CPU 1                                  CPU 2\n\nrdma_resolve_addr():\n  RDMA_CM_IDLE -> RDMA_CM_AD","2024-05-21T15:15:24.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47391",{"cveId":10155,"releaseId":31,"cycle":32,"description":10156,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10157,"url":10158},{"cveId":10155,"releaseId":17,"cycle":18,"description":10156,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10157,"url":10158},{"cveId":10162,"releaseId":17,"cycle":18,"description":10163,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10164,"url":10165},"CVE-2021-47388","In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: fix use-after-free in CCMP\u002FGCMP RX\n\nWhen PN checking is done in mac80211, for fragmentation we need\nto copy the PN to the RX struct so we can later use it to do a\ncomparison, since commit bf30ca922a0c (\"mac80211: check defrag\nPN against current frame\").\n\nUnfortunately, in that commit I used the 'hdr' variable without\nit being necessarily valid, so use-after-free could occur if it\nwas necessary to reallocate (parts of)","2024-05-21T15:15:24.257+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47388",{"cveId":10162,"releaseId":25,"cycle":26,"description":10163,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10164,"url":10165},{"cveId":10162,"releaseId":31,"cycle":32,"description":10163,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10164,"url":10165},{"cveId":10169,"releaseId":25,"cycle":26,"description":10170,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10171,"url":10172},"CVE-2021-47383","In the Linux kernel, the following vulnerability has been resolved:\n\ntty: Fix out-of-bound vmalloc access in imageblit\n\nThis issue happens when a userspace program does an ioctl\nFBIOPUT_VSCREENINFO passing the fb_var_screeninfo struct\ncontaining only the fields xres, yres, and bits_per_pixel\nwith values.\n\nIf this struct is the same as the previous ioctl, the\nvc_resize() detects it and doesn't call the resize_screen(),\nleaving the fb_var_screeninfo incomplete. And this leads to\nthe updatescrollmo","2024-05-21T15:15:23.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47383",{"cveId":10169,"releaseId":31,"cycle":32,"description":10170,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10171,"url":10172},{"cveId":10169,"releaseId":17,"cycle":18,"description":10170,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10171,"url":10172},{"cveId":10176,"releaseId":31,"cycle":32,"description":10177,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10178,"url":10179},"CVE-2021-47380","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: amd_sfh: Fix potential NULL pointer dereference\n\ndevm_add_action_or_reset() can suddenly invoke amd_mp2_pci_remove() at\nregistration that will cause NULL pointer dereference since\ncorresponding data is not initialized yet. The patch moves\ninitialization of data before devm_add_action_or_reset().\n\nFound by Linux Driver Verification project (linuxtesting.org).\n\n[jkosina@suse.cz: rebase]","2024-05-21T15:15:23.663+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47380",{"cveId":10176,"releaseId":17,"cycle":18,"description":10177,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10178,"url":10179},{"cveId":10176,"releaseId":25,"cycle":26,"description":10177,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10178,"url":10179},{"cveId":10183,"releaseId":31,"cycle":32,"description":10184,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10185,"url":10186},"CVE-2021-47374","In the Linux kernel, the following vulnerability has been resolved:\n\ndma-debug: prevent an error message from causing runtime problems\n\nFor some drivers, that use the DMA API. This error message can be reached\nseveral millions of times per second, causing spam to the kernel's printk\nbuffer and bringing the CPU usage up to 100% (so, it should be rate\nlimited). However, since there is at least one driver that is in the\nmainline and suffers from the error condition, it is more useful to\nerr_printk(","2024-05-21T15:15:23.223+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47374",{"cveId":10183,"releaseId":17,"cycle":18,"description":10184,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10185,"url":10186},{"cveId":10183,"releaseId":25,"cycle":26,"description":10184,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10185,"url":10186},{"cveId":10190,"releaseId":25,"cycle":26,"description":10191,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10192,"url":10193},"CVE-2021-47366","In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix corruption in reads at fpos 2G-4G from an OpenAFS server\n\nAFS-3 has two data fetch RPC variants, FS.FetchData and FS.FetchData64, and\nLinux's afs client switches between them when talking to a non-YFS server\nif the read size, the file position or the sum of the two have the upper 32\nbits set of the 64-bit value.\n\nThis is a problem, however, since the file position and length fields of\nFS.FetchData are *signed* 32-bit v","2024-05-21T15:15:22.633+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47366",{"cveId":10190,"releaseId":17,"cycle":18,"description":10191,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10192,"url":10193},{"cveId":10190,"releaseId":31,"cycle":32,"description":10191,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10192,"url":10193},{"cveId":10197,"releaseId":17,"cycle":18,"description":10198,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10199,"url":10200},"CVE-2021-47358","In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: greybus: uart: fix tty use after free\n\nUser space can hold a tty open indefinitely and tty drivers must not\nrelease the underlying structures until the last user is gone.\n\nSwitch to using the tty-port reference counter to manage the life time\nof the greybus tty state to avoid use after free after a disconnect.","2024-05-21T15:15:22.073+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47358",{"cveId":10197,"releaseId":31,"cycle":32,"description":10198,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10199,"url":10200},{"cveId":10197,"releaseId":25,"cycle":26,"description":10198,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10199,"url":10200},{"cveId":10204,"releaseId":25,"cycle":26,"description":10205,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10206,"url":10207},"CVE-2021-47354","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fsched: Avoid data corruptions\n\nWait for all dependencies of a job  to complete before\nkilling it to avoid data corruptions.","2024-05-21T15:15:21.767+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47354",{"cveId":10204,"releaseId":31,"cycle":32,"description":10205,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10206,"url":10207},{"cveId":10204,"releaseId":17,"cycle":18,"description":10205,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10206,"url":10207},{"cveId":10211,"releaseId":17,"cycle":18,"description":10212,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10213,"url":10214},"CVE-2021-47352","In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-net: Add validation for used length\n\nThis adds validation for used length (might come\nfrom an untrusted device) to avoid data corruption\nor loss.","2024-05-21T15:15:21.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47352",{"cveId":10211,"releaseId":25,"cycle":26,"description":10212,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10213,"url":10214},{"cveId":10211,"releaseId":31,"cycle":32,"description":10212,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10213,"url":10214},{"cveId":10218,"releaseId":25,"cycle":26,"description":10219,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10220,"url":10221},"CVE-2021-47351","In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: Fix races between xattr_{set|get} and listxattr operations\n\nUBIFS may occur some problems with concurrent xattr_{set|get} and\nlistxattr operations, such as assertion failure, memory corruption,\nstale xattr value[1].\n\nFix it by importing a new rw-lock in @ubifs_inode to serilize write\noperations on xattr, concurrent read operations are still effective,\njust like ext4.\n\n[1] https:\u002F\u002Flore.kernel.org\u002Flinux-mtd\u002F20200630130438.","2024-05-21T15:15:21.553+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47351",{"cveId":10218,"releaseId":31,"cycle":32,"description":10219,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10220,"url":10221},{"cveId":10218,"releaseId":17,"cycle":18,"description":10219,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10220,"url":10221},{"cveId":10225,"releaseId":31,"cycle":32,"description":10226,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10227,"url":10228},"CVE-2021-47347","In the Linux kernel, the following vulnerability has been resolved:\n\nwl1251: Fix possible buffer overflow in wl1251_cmd_scan\n\nFunction wl1251_cmd_scan calls memcpy without checking the length.\nHarden by checking the length is within the maximum allowed size.","2024-05-21T15:15:21.287+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47347",{"cveId":10225,"releaseId":17,"cycle":18,"description":10226,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10227,"url":10228},{"cveId":10225,"releaseId":25,"cycle":26,"description":10226,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10227,"url":10228},{"cveId":10232,"releaseId":17,"cycle":18,"description":10233,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10234,"url":10235},"CVE-2021-47346","In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: tmc-etf: Fix global-out-of-bounds in tmc_update_etf_buffer()\n\ncommit 6f755e85c332 (\"coresight: Add helper for inserting synchronization\npackets\") removed trailing '\\0' from barrier_pkt array and updated the\ncall sites like etb_update_buffer() to have proper checks for barrier_pkt\nsize before read but missed updating tmc_update_etf_buffer() which still\nreads barrier_pkt past the array size resulting in KASAN out-of-bo","2024-05-21T15:15:21.217+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47346",{"cveId":10232,"releaseId":25,"cycle":26,"description":10233,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10234,"url":10235},{"cveId":10238,"releaseId":17,"cycle":18,"description":10239,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10240,"url":10241},"CVE-2021-47343","In the Linux kernel, the following vulnerability has been resolved:\n\ndm btree remove: assign new_root only when removal succeeds\n\nremove_raw() in dm_btree_remove() may fail due to IO read error\n(e.g. read the content of origin block fails during shadowing),\nand the value of shadow_spine::root is uninitialized, but\nthe uninitialized value is still assign to new_root in the\nend of dm_btree_remove().\n\nFor dm-thin, the value of pmd->details_root or pmd->root will become\nan uninitialized value, so if","2024-05-21T15:15:20.993+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47343",{"cveId":10238,"releaseId":25,"cycle":26,"description":10239,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10240,"url":10241},{"cveId":10238,"releaseId":31,"cycle":32,"description":10239,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10240,"url":10241},{"cveId":10245,"releaseId":31,"cycle":32,"description":10246,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10247,"url":10248},"CVE-2021-47328","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: iscsi: Fix conn use after free during resets\n\nIf we haven't done a unbind target call we can race where\niscsi_conn_teardown wakes up the EH thread and then frees the conn while\nthose threads are still accessing the conn ehwait.\n\nWe can only do one TMF per session so this just moves the TMF fields from\nthe conn to the session. We can then rely on the\niscsi_session_teardown->iscsi_remove_session->__iscsi_unbind_session call","2024-05-21T15:15:19.823+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47328",{"cveId":10245,"releaseId":17,"cycle":18,"description":10246,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10247,"url":10248},{"cveId":10245,"releaseId":25,"cycle":26,"description":10246,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10247,"url":10248},{"cveId":10252,"releaseId":17,"cycle":18,"description":10253,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10254,"url":10255},"CVE-2021-47309","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: validate lwtstate->data before returning from skb_tunnel_info()\n\nskb_tunnel_info() returns pointer of lwtstate->data as ip_tunnel_info\ntype without validation. lwtstate->data can have various types such as\nmpls_iptunnel_encap, etc and these are not compatible.\nSo skb_tunnel_info() should validate before returning that pointer.\n\nSplat looks like:\nBUG: KASAN: slab-out-of-bounds in vxlan_get_route+0x418\u002F0x4b0 [vxlan]\nRead of ","2024-05-21T15:15:18.453+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47309",{"cveId":10252,"releaseId":25,"cycle":26,"description":10253,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10254,"url":10255},{"cveId":10252,"releaseId":31,"cycle":32,"description":10253,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10254,"url":10255},{"cveId":10259,"releaseId":31,"cycle":32,"description":10260,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10261,"url":10262},"CVE-2021-47308","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libfc: Fix array index out of bound exception\n\nFix array index out of bound exception in fc_rport_prli_resp().","2024-05-21T15:15:18.383+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47308",{"cveId":10259,"releaseId":17,"cycle":18,"description":10260,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10261,"url":10262},{"cveId":10259,"releaseId":25,"cycle":26,"description":10260,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10261,"url":10262},{"cveId":10266,"releaseId":31,"cycle":32,"description":10267,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10268,"url":10269},"CVE-2021-47307","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: prevent NULL deref in cifs_compose_mount_options()\n\nThe optional @ref parameter might contain an NULL node_name, so\nprevent dereferencing it in cifs_compose_mount_options().\n\nAddresses-Coverity: 1476408 (\"Explicit null dereferenced\")","2024-05-21T15:15:18.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47307",{"cveId":10266,"releaseId":17,"cycle":18,"description":10267,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10268,"url":10269},{"cveId":10266,"releaseId":25,"cycle":26,"description":10267,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10268,"url":10269},{"cveId":10273,"releaseId":17,"cycle":18,"description":10274,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10275,"url":10276},"CVE-2021-47296","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Fix kvm_arch_vcpu_ioctl vcpu_load leak\n\nvcpu_put is not called if the user copy fails. This can result in preempt\nnotifier corruption and crashes, among other issues.","2024-05-21T15:15:17.477+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47296",{"cveId":10278,"releaseId":25,"cycle":26,"description":10279,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10280,"url":10281},"CVE-2021-47281","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix race of snd_seq_timer_open()\n\nThe timer instance per queue is exclusive, and snd_seq_timer_open()\nshould have managed the concurrent accesses.  It looks as if it's\nchecking the already existing timer instance at the beginning, but\nit's not right, because there is no protection, hence any later\nconcurrent call of snd_seq_timer_open() may override the timer\ninstance easily.  This may result in UAF, as the leftover ","2024-05-21T15:15:16.353+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47281",{"cveId":10278,"releaseId":17,"cycle":18,"description":10279,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10280,"url":10281},{"cveId":10278,"releaseId":31,"cycle":32,"description":10279,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10280,"url":10281},{"cveId":10285,"releaseId":17,"cycle":18,"description":10286,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10287,"url":10288},"CVE-2021-47274","In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Correct the length check which causes memory corruption\n\nWe've suffered from severe kernel crashes due to memory corruption on\nour production environment, like,\n\nCall Trace:\n[1640542.554277] general protection fault: 0000 [#1] SMP PTI\n[1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G\n[1640542.556629] RIP: 0010:kmem_cache_alloc+0x90\u002F0x190\n[1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 0001028","2024-05-21T15:15:15.83+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47274",{"cveId":10285,"releaseId":31,"cycle":32,"description":10286,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10287,"url":10288},{"cveId":10285,"releaseId":25,"cycle":26,"description":10286,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10287,"url":10288},{"cveId":10292,"releaseId":17,"cycle":18,"description":10293,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10294,"url":10295},"CVE-2021-47261","In the Linux kernel, the following vulnerability has been resolved:\n\nIB\u002Fmlx5: Fix initializing CQ fragments buffer\n\nThe function init_cq_frag_buf() can be called to initialize the current CQ\nfragments buffer cq->buf, or the temporary cq->resize_buf that is filled\nduring CQ resize operation.\n\nHowever, the offending commit started to use function get_cqe() for\ngetting the CQEs, the issue with this change is that get_cqe() always\nreturns CQEs from cq->buf, which leads us to initialize the wrong buf","2024-05-21T15:15:14.77+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47261",{"cveId":10297,"releaseId":17,"cycle":18,"description":10298,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10299,"url":10300},"CVE-2021-47259","In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix use-after-free in nfs4_init_client()\n\nKASAN reports a use-after-free when attempting to mount two different\nexports through two different NICs that belong to the same server.\n\nOlga was able to hit this with kernels starting somewhere between 5.7\nand 5.10, but I traced the patch that introduced the clear_bit() call to\n4.13. So something must have changed in the refcounting of the clp\npointer to make this call to nfs_put","2024-05-21T15:15:14.61+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47259",{"cveId":10297,"releaseId":25,"cycle":26,"description":10298,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10299,"url":10300},{"cveId":10303,"releaseId":17,"cycle":18,"description":10304,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10305,"url":10306},"CVE-2021-47254","In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Fix use-after-free in gfs2_glock_shrink_scan\n\nThe GLF_LRU flag is checked under lru_lock in gfs2_glock_remove_from_lru() to\nremove the glock from the lru list in __gfs2_glock_put().\n\nOn the shrink scan path, the same flag is cleared under lru_lock but because\nof cond_resched_lock(&lru_lock) in gfs2_dispose_glock_lru(), progress on the\nput side can be made without deleting the glock from the lru list.\n\nKeep GLF_LRU across ","2024-05-21T15:15:14.233+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47254",{"cveId":10303,"releaseId":31,"cycle":32,"description":10304,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10305,"url":10306},{"cveId":10303,"releaseId":25,"cycle":26,"description":10304,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10305,"url":10306},{"cveId":10310,"releaseId":25,"cycle":26,"description":10311,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10312,"url":10313},"CVE-2021-47248","In the Linux kernel, the following vulnerability has been resolved:\n\nudp: fix race between close() and udp_abort()\n\nKaustubh reported and diagnosed a panic in udp_lib_lookup().\nThe root cause is udp_abort() racing with close(). Both\nracing functions acquire the socket lock, but udp{v6}_destroy_sock()\nrelease it before performing destructive actions.\n\nWe can't easily extend the socket lock scope to avoid the race,\ninstead use the SOCK_DEAD flag to prevent udp_abort from doing\nany action when the ","2024-05-21T15:15:13.78+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47248",{"cveId":10310,"releaseId":17,"cycle":18,"description":10311,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10312,"url":10313},{"cveId":10310,"releaseId":31,"cycle":32,"description":10311,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10312,"url":10313},{"cveId":10317,"releaseId":25,"cycle":26,"description":10318,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10319,"url":10320},"CVE-2021-47247","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5e: Fix use-after-free of encap entry in neigh update handler\n\nFunction mlx5e_rep_neigh_update() wasn't updated to accommodate rtnl lock\nremoval from TC filter update path and properly handle concurrent encap\nentry insertion\u002Fdeletion which can lead to following use-after-free:\n\n [23827.464923] ==================================================================\n [23827.469446] BUG: KASAN: use-after-free in mlx5e_encap_take","2024-05-21T15:15:13.703+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47247",{"cveId":10317,"releaseId":17,"cycle":18,"description":10318,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10319,"url":10320},{"cveId":10317,"releaseId":31,"cycle":32,"description":10318,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10319,"url":10320},{"cveId":10324,"releaseId":25,"cycle":26,"description":10325,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":10326,"url":10327},"CVE-2021-47245","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: Fix out of bounds when parsing TCP options\n\nThe TCP option parser in synproxy (synproxy_parse_options) could read\none byte out of bounds. When the length is 1, the execution flow gets\ninto the loop, reads one byte of the opcode, and if the opcode is\nneither TCPOPT_EOL nor TCPOPT_NOP, it reads one more byte, which exceeds\nthe length of 1.\n\nThis fix is inspired by commit 9609dad263f8 (\"ipv4: tcp_input: fix st","2024-05-21T15:15:13.55+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47245",{"cveId":10324,"releaseId":31,"cycle":32,"description":10325,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":10326,"url":10327},{"cveId":10324,"releaseId":17,"cycle":18,"description":10325,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":10326,"url":10327},{"cveId":10331,"releaseId":17,"cycle":18,"description":10332,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10333,"url":10334},"CVE-2021-47243","In the Linux kernel, the following vulnerability has been resolved:\n\nsch_cake: Fix out of bounds when parsing TCP options and header\n\nThe TCP option parser in cake qdisc (cake_get_tcpopt and\ncake_tcph_may_drop) could read one byte out of bounds. When the length\nis 1, the execution flow gets into the loop, reads one byte of the\nopcode, and if the opcode is neither TCPOPT_EOL nor TCPOPT_NOP, it reads\none more byte, which exceeds the length of 1.\n\nThis fix is inspired by commit 9609dad263f8 (\"ipv4:","2024-05-21T15:15:13.403+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47243",{"cveId":10336,"releaseId":17,"cycle":18,"description":10337,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10338,"url":10339},"CVE-2021-47240","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: fix OOB Read in qrtr_endpoint_post\n\nSyzbot reported slab-out-of-bounds Read in\nqrtr_endpoint_post. The problem was in wrong\n_size_ type:\n\n\tif (len != ALIGN(size, 4) + hdrlen)\n\t\tgoto err;\n\nIf size from qrtr_hdr is 4294967293 (0xfffffffd), the result of\nALIGN(size, 4) will be 0. In case of len == hdrlen and size == 4294967293\nin header this check won't fail and\n\n\tskb_put_data(skb, data + hdrlen, size);\n\nwill read out o","2024-05-21T15:15:13.177+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47240",{"cveId":10341,"releaseId":31,"cycle":32,"description":10342,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10343,"url":10344},"CVE-2021-47224","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ll_temac: Make sure to free skb when it is completely used\n\nWith the skb pointer piggy-backed on the TX BD, we have a simple and\nefficient way to free the skb buffer when the frame has been transmitted.\nBut in order to avoid freeing the skb while there are still fragments from\nthe skb in use, we need to piggy-back on the TX BD of the skb, not the\nfirst.\n\nWithout this, we are doing use-after-free on the DMA side, when the f","2024-05-21T15:15:11.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47224",{"cveId":10341,"releaseId":25,"cycle":26,"description":10342,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10343,"url":10344},{"cveId":10341,"releaseId":17,"cycle":18,"description":10342,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10343,"url":10344},{"cveId":10348,"releaseId":17,"cycle":18,"description":10349,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10350,"url":10351},"CVE-2021-47222","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: fix vlan tunnel dst refcnt when egressing\n\nThe egress tunnel code uses dst_clone() and directly sets the result\nwhich is wrong because the entry might have 0 refcnt or be already deleted,\ncausing number of problems. It also triggers the WARN_ON() in dst_hold()[1]\nwhen a refcnt couldn't be taken. Fix it by using dst_hold_safe() and\nchecking if a reference was actually taken before setting the dst.\n\n[1] dmesg WARN_ON","2024-05-21T15:15:11.453+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47222",{"cveId":10348,"releaseId":25,"cycle":26,"description":10349,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10350,"url":10351},{"cveId":10354,"releaseId":25,"cycle":26,"description":10355,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10356,"url":10357},"CVE-2024-36009","In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Fix netdev refcount issue\n\nThe dev_tracker is added to ax25_cb in ax25_bind(). When the\nax25 device is detaching, the dev_tracker of ax25_cb should be\ndeallocated in ax25_kill_by_device() instead of the dev_tracker\nof ax25_dev. The log reported by ref_tracker is shown below:\n\n[   80.884935] ref_tracker: reference already released.\n[   80.885150] ref_tracker: allocated in:\n[   80.885349]  ax25_dev_device_up+0x105\u002F0x540\n[  ","2024-05-20T10:15:14.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-36009",{"cveId":10354,"releaseId":17,"cycle":18,"description":10355,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10356,"url":10357},{"cveId":10360,"releaseId":31,"cycle":32,"description":10361,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10362,"url":10363},"CVE-2024-35999","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb3: missing lock when picking channel\n\nCoverity spotted a place where we should have been holding the\nchannel lock when accessing the ses channel index.\n\nAddresses-Coverity: 1582039 (\"Data race condition (MISSING_LOCK)\")","2024-05-20T10:15:14.1+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35999",{"cveId":10360,"releaseId":25,"cycle":26,"description":10361,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10362,"url":10363},{"cveId":10360,"releaseId":17,"cycle":18,"description":10361,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10362,"url":10363},{"cveId":10367,"releaseId":31,"cycle":32,"description":10368,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10369,"url":10370},"CVE-2024-35998","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb3: fix lock ordering potential deadlock in cifs_sync_mid_result\n\nCoverity spotted that the cifs_sync_mid_result function could deadlock\n\n\"Thread deadlock (ORDER_REVERSAL) lock_order: Calling spin_lock acquires\nlock TCP_Server_Info.srv_lock while holding lock TCP_Server_Info.mid_lock\"\n\nAddresses-Coverity: 1590401 (\"Thread deadlock (ORDER_REVERSAL)\")","2024-05-20T10:15:14.03+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35998",{"cveId":10367,"releaseId":17,"cycle":18,"description":10368,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10369,"url":10370},{"cveId":10367,"releaseId":25,"cycle":26,"description":10368,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10369,"url":10370},{"cveId":10374,"releaseId":17,"cycle":18,"description":10375,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10376,"url":10377},"CVE-2024-35976","In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING\n\nsyzbot reported an illegal copy in xsk_setsockopt() [1]\n\nMake sure to validate setsockopt() @optlen parameter.\n\n[1]\n\n BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include\u002Flinux\u002Fsockptr.h:49 [inline]\n BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include\u002Flinux\u002Fsockptr.h:55 [inline]\n BUG: KASAN: slab-out-of-bounds in xsk_setsockopt+0x909\u002F0xa40 net\u002Fx","2024-05-20T10:15:12.273+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35976",{"cveId":10379,"releaseId":17,"cycle":18,"description":10380,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10381,"url":10382},"CVE-2024-35969","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr\n\nAlthough ipv6_get_ifaddr walks inet6_addr_lst under the RCU lock, it\nstill means hlist_for_each_entry_rcu can return an item that got removed\nfrom the list. The memory itself of such item is not freed thanks to RCU\nbut nothing guarantees the actual content of the memory is sane.\n\nIn particular, the reference count can be zero. This can happen if\nipv6_del_addr i","2024-05-20T10:15:11.78+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35969",{"cveId":10379,"releaseId":25,"cycle":26,"description":10380,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10381,"url":10382},{"cveId":10379,"releaseId":31,"cycle":32,"description":10380,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10381,"url":10382},{"cveId":10386,"releaseId":17,"cycle":18,"description":10387,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10388,"url":10389},"CVE-2024-35967","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: Fix not validating setsockopt user input\n\nsyzbot reported sco_sock_setsockopt() is copying data without\nchecking user input length.\n\nBUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset\ninclude\u002Flinux\u002Fsockptr.h:49 [inline]\nBUG: KASAN: slab-out-of-bounds in copy_from_sockptr\ninclude\u002Flinux\u002Fsockptr.h:55 [inline]\nBUG: KASAN: slab-out-of-bounds in sco_sock_setsockopt+0xc0b\u002F0xf90\nnet\u002Fbluetooth\u002Fsco.c:893\nRead of s","2024-05-20T10:15:11.647+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35967",{"cveId":10386,"releaseId":31,"cycle":32,"description":10387,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10388,"url":10389},{"cveId":10386,"releaseId":25,"cycle":26,"description":10387,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10388,"url":10389},{"cveId":10393,"releaseId":17,"cycle":18,"description":10394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10395,"url":10396},"CVE-2024-35950","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fclient: Fully protect modes[] with dev->mode_config.mutex\n\nThe modes[] array contains pointers to modes on the connectors'\nmode lists, which are protected by dev->mode_config.mutex.\nThus we need to extend modes[] the same protection or by the\ntime we use it the elements may already be pointing to\nfreed\u002Freused memory.","2024-05-20T10:15:10.49+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35950",{"cveId":10393,"releaseId":31,"cycle":32,"description":10394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10395,"url":10396},{"cveId":10393,"releaseId":25,"cycle":26,"description":10394,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10395,"url":10396},{"cveId":10400,"releaseId":17,"cycle":18,"description":10401,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10402,"url":10403},"CVE-2024-35949","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: make sure that WRITTEN is set on all metadata blocks\n\nWe previously would call btrfs_check_leaf() if we had the check\nintegrity code enabled, which meant that we could only run the extended\nleaf checks if we had WRITTEN set on the header flags.\n\nThis leaves a gap in our checking, because we could end up with\ncorruption on disk where WRITTEN isn't set on the leaf, and then the\nextended leaf checks don't get run which we r","2024-05-20T10:15:10.413+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35949",{"cveId":10400,"releaseId":31,"cycle":32,"description":10401,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10402,"url":10403},{"cveId":10400,"releaseId":25,"cycle":26,"description":10401,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10402,"url":10403},{"cveId":10407,"releaseId":25,"cycle":26,"description":10408,"severity":101,"cvssScore":9812,"epssScore":9,"inKev":42,"publishedAt":10409,"url":10410},"CVE-2024-35939","In the Linux kernel, the following vulnerability has been resolved:\n\ndma-direct: Leak pages on dma_set_decrypted() failure\n\nOn TDX it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nDMA could free decrypted\u002Fshar","2024-05-19T11:15:49.69+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35939",{"cveId":10407,"releaseId":17,"cycle":18,"description":10408,"severity":101,"cvssScore":9812,"epssScore":9,"inKev":42,"publishedAt":10409,"url":10410},{"cveId":10407,"releaseId":31,"cycle":32,"description":10408,"severity":101,"cvssScore":9812,"epssScore":9,"inKev":42,"publishedAt":10409,"url":10410},{"cveId":10414,"releaseId":31,"cycle":32,"description":10415,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":10416,"url":10417},"CVE-2024-35937","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: check A-MSDU format more carefully\n\nIf it looks like there's another subframe in the A-MSDU\nbut the header isn't fully there, we can end up reading\ndata out of bounds, only to discard later. Make this a\nbit more careful and check if the subframe header can\neven be present.","2024-05-19T11:15:49.553+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35937",{"cveId":10414,"releaseId":25,"cycle":26,"description":10415,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":10416,"url":10417},{"cveId":10414,"releaseId":17,"cycle":18,"description":10415,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":10416,"url":10417},{"cveId":10421,"releaseId":17,"cycle":18,"description":10422,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10423,"url":10424},"CVE-2024-35932","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fvc4: don't check if plane->state->fb == state->fb\n\nCurrently, when using non-blocking commits, we can see the following\nkernel warning:\n\n[  110.908514] ------------[ cut here ]------------\n[  110.908529] refcount_t: underflow; use-after-free.\n[  110.908620] WARNING: CPU: 0 PID: 1866 at lib\u002Frefcount.c:87 refcount_dec_not_one+0xb8\u002F0xc0\n[  110.908664] Modules linked in: rfcomm snd_seq_dummy snd_hrtimer snd_seq snd_seq_device c","2024-05-19T11:15:49.203+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35932",{"cveId":10421,"releaseId":31,"cycle":32,"description":10422,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10423,"url":10424},{"cveId":10421,"releaseId":25,"cycle":26,"description":10422,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10423,"url":10424},{"cveId":10428,"releaseId":17,"cycle":18,"description":10429,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10430,"url":10431},"CVE-2024-35931","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: Skip do PCI error slot reset during RAS recovery\n\nWhy:\n    The PCI error slot reset maybe triggered after inject ue to UMC multi times, this\n    caused system hang.\n    [  557.371857] amdgpu 0000:af:00.0: amdgpu: GPU reset succeeded, trying to resume\n    [  557.373718] [drm] PCIE GART of 512M enabled.\n    [  557.373722] [drm] PTB located at 0x0000031FED700000\n    [  557.373788] [drm] VRAM is lost due to GPU reset!\n ","2024-05-19T11:15:49.133+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35931",{"cveId":10428,"releaseId":25,"cycle":26,"description":10429,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10430,"url":10431},{"cveId":10428,"releaseId":31,"cycle":32,"description":10429,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10430,"url":10431},{"cveId":10435,"releaseId":31,"cycle":32,"description":10436,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10437,"url":10438},"CVE-2024-35915","In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet\n\nsyzbot reported the following uninit-value access issue [1][2]:\n\nnci_rx_work() parses and processes received packet. When the payload\nlength is zero, each message type handler reads uninitialized payload\nand KMSAN detects this issue. The receipt of a packet with a zero-size\npayload is considered unexpected, and therefore, such packets should be\nsilently discarded.\n\nTh","2024-05-19T09:15:11.987+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35915",{"cveId":10435,"releaseId":17,"cycle":18,"description":10436,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10437,"url":10438},{"cveId":10435,"releaseId":25,"cycle":26,"description":10436,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10437,"url":10438},{"cveId":10442,"releaseId":25,"cycle":26,"description":10443,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10444,"url":10445},"CVE-2024-35910","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: properly terminate timers for kernel sockets\n\nWe had various syzbot reports about tcp timers firing after\nthe corresponding netns has been dismantled.\n\nFortunately Josef Bacik could trigger the issue more often,\nand could test a patch I wrote two years ago.\n\nWhen TCP sockets are closed, we call inet_csk_clear_xmit_timers()\nto 'stop' the timers.\n\ninet_csk_clear_xmit_timers() can be called from any context,\nincluding when so","2024-05-19T09:15:11.617+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35910",{"cveId":10442,"releaseId":31,"cycle":32,"description":10443,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10444,"url":10445},{"cveId":10442,"releaseId":17,"cycle":18,"description":10443,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10444,"url":10445},{"cveId":10449,"releaseId":17,"cycle":18,"description":10450,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":10451,"url":10452},"CVE-2024-35898","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get()\n\nnft_unregister_flowtable_type() within nf_flow_inet_module_exit() can\nconcurrent with __nft_flowtable_type_get() within nf_tables_newflowtable().\nAnd thhere is not any protection when iterate over nf_tables_flowtables\nlist in __nft_flowtable_type_get(). Therefore, there is pertential\ndata-race of nf_tables_flowtables list entry.\n\nUse list_for_each_entr","2024-05-19T09:15:10.723+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35898",{"cveId":10454,"releaseId":25,"cycle":26,"description":10455,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10456,"url":10457},"CVE-2024-35896","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: validate user input for expected length\n\nI got multiple syzbot reports showing old bugs exposed\nby BPF after commit 20f2505fb436 (\"bpf: Try to avoid kzalloc\nin cgroup\u002F{s,g}etsockopt\")\n\nsetsockopt() @optlen argument should be taken into account\nbefore copying data.\n\n BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include\u002Flinux\u002Fsockptr.h:49 [inline]\n BUG: KASAN: slab-out-of-bounds in copy_from_sockptr inclu","2024-05-19T09:15:10.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35896",{"cveId":10454,"releaseId":17,"cycle":18,"description":10455,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10456,"url":10457},{"cveId":10454,"releaseId":31,"cycle":32,"description":10455,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10456,"url":10457},{"cveId":10461,"releaseId":17,"cycle":18,"description":10462,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10463,"url":10464},"CVE-2024-35888","In the Linux kernel, the following vulnerability has been resolved:\n\nerspan: make sure erspan_base_hdr is present in skb->head\n\nsyzbot reported a problem in ip6erspan_rcv() [1]\n\nIssue is that ip6erspan_rcv() (and erspan_rcv()) no longer make\nsure erspan_base_hdr is present in skb linear part (skb->head)\nbefore getting @ver field from it.\n\nAdd the missing pskb_may_pull() calls.\n\nv2: Reload iph pointer in erspan_rcv() after pskb_may_pull()\n    because skb->head might have changed.\n\n[1]\n\n BUG: KMSA","2024-05-19T09:15:09.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35888",{"cveId":10466,"releaseId":25,"cycle":26,"description":10467,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10468,"url":10469},"CVE-2024-35887","In the Linux kernel, the following vulnerability has been resolved:\n\nax25: fix use-after-free bugs caused by ax25_ds_del_timer\n\nWhen the ax25 device is detaching, the ax25_dev_device_down()\ncalls ax25_ds_del_timer() to cleanup the slave_timer. When\nthe timer handler is running, the ax25_ds_del_timer() that\ncalls del_timer() in it will return directly. As a result,\nthe use-after-free bugs could happen, one of the scenarios\nis shown below:\n\n      (Thread 1)          |      (Thread 2)\n             ","2024-05-19T09:15:09.837+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35887",{"cveId":10466,"releaseId":31,"cycle":32,"description":10467,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10468,"url":10469},{"cveId":10466,"releaseId":17,"cycle":18,"description":10467,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10468,"url":10469},{"cveId":10473,"releaseId":17,"cycle":18,"description":10474,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10475,"url":10476},"CVE-2024-35875","In the Linux kernel, the following vulnerability has been resolved:\n\nx86\u002Fcoco: Require seeding RNG with RDRAND on CoCo systems\n\nThere are few uses of CoCo that don't rely on working cryptography and\nhence a working RNG. Unfortunately, the CoCo threat model means that the\nVM host cannot be trusted and may actively work against guests to\nextract secrets or manipulate computation. Since a malicious host can\nmodify or observe nearly all inputs to guests, the only remaining source\nof entropy for CoCo","2024-05-19T09:15:08.833+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35875",{"cveId":10473,"releaseId":25,"cycle":26,"description":10474,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10475,"url":10476},{"cveId":10473,"releaseId":31,"cycle":32,"description":10474,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10475,"url":10476},{"cveId":10480,"releaseId":17,"cycle":18,"description":10481,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10482,"url":10483},"CVE-2024-35870","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix UAF in smb2_reconnect_server()\n\nThe UAF bug is due to smb2_reconnect_server() accessing a session that\nis already being teared down by another thread that is executing\n__cifs_put_smb_ses().  This can happen when (a) the client has\nconnection to the server but no session or (b) another thread ends up\nsetting @ses->ses_status again to something different than\nSES_EXITING.\n\nTo fix this, we need to make sure to unc","2024-05-19T09:15:08.427+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35870",{"cveId":10480,"releaseId":31,"cycle":32,"description":10481,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10482,"url":10483},{"cveId":10480,"releaseId":25,"cycle":26,"description":10481,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10482,"url":10483},{"cveId":10487,"releaseId":17,"cycle":18,"description":10488,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10489,"url":10490},"CVE-2024-35865","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential UAF in smb2_is_valid_oplock_break()\n\nSkip sessions that are being teared down (status == SES_EXITING) to\navoid UAF.","2024-05-19T09:15:08.033+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35865",{"cveId":10487,"releaseId":25,"cycle":26,"description":10488,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10489,"url":10490},{"cveId":10487,"releaseId":31,"cycle":32,"description":10488,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10489,"url":10490},{"cveId":10494,"releaseId":31,"cycle":32,"description":10495,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10496,"url":10497},"CVE-2024-35864","In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential UAF in smb2_is_valid_lease_break()\n\nSkip sessions that are being teared down (status == SES_EXITING) to\navoid UAF.","2024-05-19T09:15:07.957+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35864",{"cveId":10494,"releaseId":25,"cycle":26,"description":10495,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10496,"url":10497},{"cveId":10494,"releaseId":17,"cycle":18,"description":10495,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10496,"url":10497},{"cveId":10501,"releaseId":25,"cycle":26,"description":10502,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10503,"url":10504},"CVE-2024-35847","In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip\u002Fgic-v3-its: Prevent double free on error\n\nThe error handling path in its_vpe_irq_domain_alloc() causes a double free\nwhen its_vpe_init() fails after successfully allocating at least one\ninterrupt. This happens because its_vpe_irq_domain_free() frees the\ninterrupts along with the area bitmap and the vprop_page and\nits_vpe_irq_domain_alloc() subsequently frees the area bitmap and the\nvprop_page again.\n\nFix this by uncondi","2024-05-17T15:15:21.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35847",{"cveId":10501,"releaseId":17,"cycle":18,"description":10502,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10503,"url":10504},{"cveId":10507,"releaseId":17,"cycle":18,"description":10508,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10509,"url":10510},"CVE-2024-35843","In the Linux kernel, the following vulnerability has been resolved:\n\niommu\u002Fvt-d: Use device rbtree in iopf reporting path\n\nThe existing I\u002FO page fault handler currently locates the PCI device by\ncalling pci_get_domain_bus_and_slot(). This function searches the list\nof all PCI devices until the desired device is found. To improve lookup\nefficiency, replace it with device_rbtree_find() to search the device\nwithin the probed device rbtree.\n\nThe I\u002FO page fault is initiated by the device, which does ","2024-05-17T15:15:21.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35843",{"cveId":10507,"releaseId":25,"cycle":26,"description":10508,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10509,"url":10510},{"cveId":10507,"releaseId":31,"cycle":32,"description":10508,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10509,"url":10510},{"cveId":10514,"releaseId":17,"cycle":18,"description":10515,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10516,"url":10517},"CVE-2024-35839","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: replace physindev with physinif in nf_bridge_info\n\nAn skb can be added to a neigh->arp_queue while waiting for an arp\nreply. Where original skb's skb->dev can be different to neigh's\nneigh->dev. For instance in case of bridging dnated skb from one veth to\nanother, the skb would be added to a neigh->arp_queue of the bridge.\n\nAs skb->dev can be reset back to nf_bridge->physindev and used, and as\nthere is no exp","2024-05-17T15:15:21.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35839",{"cveId":10514,"releaseId":25,"cycle":26,"description":10515,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10516,"url":10517},{"cveId":10514,"releaseId":31,"cycle":32,"description":10515,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10516,"url":10517},{"cveId":10521,"releaseId":17,"cycle":18,"description":10522,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10523,"url":10524},"CVE-2023-52691","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fpm: fix a double-free in si_dpm_init\n\nWhen the allocation of\nadev->pm.dpm.dyn_state.vddc_dependency_on_dispclk.entries fails,\namdgpu_free_extended_power_table is called to free some fields of adev.\nHowever, when the control flow returns to si_dpm_sw_init, it goes to\nlabel dpm_failed and calls si_dpm_fini, which calls\namdgpu_free_extended_power_table again and free those fields again. Thus\na double-free is triggered.","2024-05-17T15:15:20.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52691",{"cveId":10521,"releaseId":25,"cycle":26,"description":10522,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10523,"url":10524},{"cveId":10521,"releaseId":31,"cycle":32,"description":10522,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10523,"url":10524},{"cveId":10528,"releaseId":17,"cycle":18,"description":10529,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10530,"url":10531},"CVE-2023-52679","In the Linux kernel, the following vulnerability has been resolved:\n\nof: Fix double free in of_parse_phandle_with_args_map\n\nIn of_parse_phandle_with_args_map() the inner loop that\niterates through the map entries calls of_node_put(new)\nto free the reference acquired by the previous iteration\nof the inner loop. This assumes that the value of \"new\" is\nNULL on the first iteration of the inner loop.\n\nMake sure that this is true in all iterations of the outer\nloop by setting \"new\" to NULL after its v","2024-05-17T15:15:19.207+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52679",{"cveId":10533,"releaseId":25,"cycle":26,"description":10534,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10535,"url":10536},"CVE-2024-35835","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fmlx5e: fix a double-free in arfs_create_groups\n\nWhen `in` allocated by kvzalloc fails, arfs_create_groups will free\nft->g and return an error. However, arfs_create_table, the only caller of\narfs_create_groups, will hold this error and call to\nmlx5e_destroy_flow_table, in which the ft->g will be freed again.","2024-05-17T14:15:20.387+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35835",{"cveId":10533,"releaseId":31,"cycle":32,"description":10534,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10535,"url":10536},{"cveId":10533,"releaseId":17,"cycle":18,"description":10534,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10535,"url":10536},{"cveId":10540,"releaseId":17,"cycle":18,"description":10541,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10542,"url":10543},"CVE-2024-35830","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: tc358743: register v4l2 async device only after successful setup\n\nEnsure the device has been setup correctly before registering the v4l2\nasync device, thus allowing userspace to access.","2024-05-17T14:15:19.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35830",{"cveId":10540,"releaseId":25,"cycle":26,"description":10541,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10542,"url":10543},{"cveId":10540,"releaseId":31,"cycle":32,"description":10541,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10542,"url":10543},{"cveId":10547,"releaseId":25,"cycle":26,"description":10548,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10549,"url":10550},"CVE-2024-35811","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach\n\nThis is the candidate patch of CVE-2023-47233 :\nhttps:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-47233\n\nIn brcm80211 driver,it starts with the following invoking chain\nto start init a timeout worker:\n\n->brcmf_usb_probe\n  ->brcmf_usb_probe_cb\n    ->brcmf_attach\n      ->brcmf_bus_started\n        ->brcmf_cfg80211_attach\n          ->wl_init_priv\n            ->brcmf_init_esca","2024-05-17T14:15:15.177+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35811",{"cveId":10547,"releaseId":17,"cycle":18,"description":10548,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10549,"url":10550},{"cveId":10547,"releaseId":31,"cycle":32,"description":10548,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10549,"url":10550},{"cveId":10554,"releaseId":31,"cycle":32,"description":10555,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10556,"url":10557},"CVE-2024-35808","In the Linux kernel, the following vulnerability has been resolved:\n\nmd\u002Fdm-raid: don't call md_reap_sync_thread() directly\n\nCurrently md_reap_sync_thread() is called from raid_message() directly\nwithout holding 'reconfig_mutex', this is definitely unsafe because\nmd_reap_sync_thread() can change many fields that is protected by\n'reconfig_mutex'.\n\nHowever, hold 'reconfig_mutex' here is still problematic because this\nwill cause deadlock, for example, commit 130443d60b1b (\"md: refactor\nidle\u002Ffrozen_s","2024-05-17T14:15:14.503+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35808",{"cveId":10554,"releaseId":25,"cycle":26,"description":10555,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10556,"url":10557},{"cveId":10554,"releaseId":17,"cycle":18,"description":10555,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10556,"url":10557},{"cveId":10561,"releaseId":31,"cycle":32,"description":10562,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":10563,"url":10564},"CVE-2023-52669","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: s390\u002Faes - Fix buffer overread in CTR mode\n\nWhen processing the last block, the s390 ctr code will always read\na whole block, even if there isn't a whole block of data left.  Fix\nthis by using the actual length left and copy it into a buffer first\nfor processing.","2024-05-17T14:15:09.827+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52669",{"cveId":10561,"releaseId":17,"cycle":18,"description":10562,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":10563,"url":10564},{"cveId":10561,"releaseId":25,"cycle":26,"description":10562,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":10563,"url":10564},{"cveId":10568,"releaseId":17,"cycle":18,"description":10569,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10570,"url":10571},"CVE-2023-52664","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: eliminate double free in error handling logic\n\nDriver has a logic leak in ring data allocation\u002Ffree,\nwhere aq_ring_free could be called multiple times on same ring,\nif system is under stress and got memory allocation error.\n\nRing pointer was used as an indicator of failure, but this is\nnot correct since only ring data is allocated\u002Fdeallocated.\nRing itself is an array member.\n\nChanging ring allocation functions to","2024-05-17T14:15:08.807+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52664",{"cveId":10568,"releaseId":31,"cycle":32,"description":10569,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10570,"url":10571},{"cveId":10568,"releaseId":25,"cycle":26,"description":10569,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10570,"url":10571},{"cveId":10575,"releaseId":17,"cycle":18,"description":10576,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10577,"url":10578},"CVE-2024-35791","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region()\n\nDo the cache flush of converted pages in svm_register_enc_region() before\ndropping kvm->lock to fix use-after-free issues where region and\u002For its\narray of pages could be freed by a different task, e.g. if userspace has\n__unregister_enc_region_locked() already queued up for the region.\n\nNote, the \"obvious\" alternative of using local variables doesn't ","2024-05-17T13:15:58.873+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35791",{"cveId":10580,"releaseId":17,"cycle":18,"description":10581,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":10582,"url":10583},"CVE-2024-35789","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: check\u002Fclear fast rx for non-4addr sta VLAN changes\n\nWhen moving a station out of a VLAN and deleting the VLAN afterwards, the\nfast_rx entry still holds a pointer to the VLAN's netdev, which can cause\nuse-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx\nafter the VLAN change.","2024-05-17T13:15:58.717+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35789",{"cveId":10580,"releaseId":25,"cycle":26,"description":10581,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":10582,"url":10583},{"cveId":10586,"releaseId":25,"cycle":26,"description":10587,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10588,"url":10589},"CVE-2024-27416","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST\n\nIf we received HCI_EV_IO_CAPA_REQUEST while\nHCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote\ndoes support SSP since otherwise this event shouldn't be generated.","2024-05-17T12:15:13.07+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27416",{"cveId":10586,"releaseId":17,"cycle":18,"description":10587,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10588,"url":10589},{"cveId":10592,"releaseId":25,"cycle":26,"description":10593,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10594,"url":10595},"CVE-2024-27415","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: confirm multicast packets before passing them up the stack\n\nconntrack nf_confirm logic cannot handle cloned skbs referencing\nthe same nf_conn entry, which will happen for multicast (broadcast)\nframes on bridges.\n\n Example:\n    macvlan0\n       |\n      br0\n     \u002F  \\\n  ethX    ethY\n\n ethX (or Y) receives a L2 multicast or broadcast packet containing\n an IP packet, flow is not yet in conntrack table.\n\n 1. skb pas","2024-05-17T12:15:12.867+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27415",{"cveId":10592,"releaseId":31,"cycle":32,"description":10593,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10594,"url":10595},{"cveId":10592,"releaseId":17,"cycle":18,"description":10593,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10594,"url":10595},{"cveId":10599,"releaseId":17,"cycle":18,"description":10600,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10601,"url":10602},"CVE-2024-27403","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_flow_offload: reset dst in route object after setting up flow\n\ndst is transferred to the flow object, route object does not own it\nanymore.  Reset dst in route object, otherwise if flow_offload_add()\nfails, error path releases dst twice, leading to a refcount underflow.","2024-05-17T12:15:10.03+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27403",{"cveId":10604,"releaseId":17,"cycle":18,"description":10605,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10606,"url":10607},"CVE-2024-27401","In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: nosy: ensure user_length is taken into account when fetching packet contents\n\nEnsure that packet_buffer_get respects the user_length provided. If\nthe length of the head packet exceeds the user_length, packet_buffer_get\nwill now return 0 to signify to the user that no data were read\nand a larger buffer size is required. Helps prevent user space overflows.","2024-05-14T15:12:29.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27401",{"cveId":10604,"releaseId":31,"cycle":32,"description":10605,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10606,"url":10607},{"cveId":10604,"releaseId":25,"cycle":26,"description":10605,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10606,"url":10607},{"cveId":10611,"releaseId":17,"cycle":18,"description":10612,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":10613,"url":10614},"CVE-2024-27398","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix use-after-free bugs caused by sco_sock_timeout\n\nWhen the sco connection is established and then, the sco socket\nis releasing, timeout_work will be scheduled to judge whether\nthe sco disconnection is timeout. The sock will be deallocated\nlater, but it is dereferenced again in sco_sock_timeout. As a\nresult, the use-after-free bugs will happen. The root cause is\nshown below:\n\n    Cleanup Thread               |      ","2024-05-14T15:12:28.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27398",{"cveId":10611,"releaseId":25,"cycle":26,"description":10612,"severity":40,"cvssScore":376,"epssScore":9,"inKev":42,"publishedAt":10613,"url":10614},{"cveId":10617,"releaseId":31,"cycle":32,"description":10618,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10619,"url":10620},"CVE-2024-27397","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: use timestamp to check for set element timeout\n\nAdd a timestamp field at the beginning of the transaction, store it\nin the nftables per-netns area.\n\nUpdate set backend .insert, .deactivate and sync gc path to use the\ntimestamp, this avoids that an element expires while control plane\ntransaction is still unfinished.\n\n.lookup and .update, which are used from packet path, still use the\ncurrent time to check i","2024-05-14T15:12:28.24+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27397",{"cveId":10617,"releaseId":25,"cycle":26,"description":10618,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10619,"url":10620},{"cveId":10617,"releaseId":17,"cycle":18,"description":10618,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10619,"url":10620},{"cveId":10624,"releaseId":25,"cycle":26,"description":10625,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10626,"url":10627},"CVE-2024-27396","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gtp: Fix Use-After-Free in gtp_dellink\n\nSince call_rcu, which is called in the hlist_for_each_entry_rcu traversal\nof gtp_dellink, is not part of the RCU read critical section, it\nis possible that the RCU grace period will pass during the traversal and\nthe key will be free.\n\nTo prevent this, it should be changed to hlist_for_each_entry_safe.","2024-05-14T15:12:27.983+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27396",{"cveId":10624,"releaseId":17,"cycle":18,"description":10625,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10626,"url":10627},{"cveId":10630,"releaseId":17,"cycle":18,"description":10631,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10632,"url":10633},"CVE-2024-27395","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: Fix Use-After-Free in ovs_ct_exit\n\nSince kfree_rcu, which is called in the hlist_for_each_entry_rcu traversal\nof ovs_ct_limit_exit, is not part of the RCU read critical section, it\nis possible that the RCU grace period will pass during the traversal and\nthe key will be free.\n\nTo prevent this, it should be changed to hlist_for_each_entry_safe.","2024-05-14T15:12:27.683+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27395",{"cveId":10635,"releaseId":31,"cycle":32,"description":10636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10637,"url":10638},"CVE-2022-48695","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpt3sas: Fix use-after-free warning\n\nFix the following use-after-free warning which is observed during\ncontroller reset:\n\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 23 PID: 5399 at lib\u002Frefcount.c:28 refcount_warn_saturate+0xa6\u002F0xf0","2024-05-03T18:15:08.247+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48695",{"cveId":10635,"releaseId":25,"cycle":26,"description":10636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10637,"url":10638},{"cveId":10635,"releaseId":17,"cycle":18,"description":10636,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10637,"url":10638},{"cveId":10642,"releaseId":25,"cycle":26,"description":10643,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10644,"url":10645},"CVE-2022-48703","In the Linux kernel, the following vulnerability has been resolved:\n\nthermal\u002Fint340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR\n\nIn some case, the GDDV returns a package with a buffer which has\nzero length. It causes that kmemdup() returns ZERO_SIZE_PTR (0x10).\n\nThen the data_vault_read() got NULL point dereference problem when\naccessing the 0x10 value in data_vault.\n\n[   71.024560] BUG: kernel NULL pointer dereference, address:\n0000000000000010\n\nThis patch uses ZERO_OR_NULL_PTR(","2024-05-03T16:15:08.65+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48703",{"cveId":10642,"releaseId":31,"cycle":32,"description":10643,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10644,"url":10645},{"cveId":10642,"releaseId":17,"cycle":18,"description":10643,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10644,"url":10645},{"cveId":10649,"releaseId":31,"cycle":32,"description":10650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10651,"url":10652},"CVE-2022-48702","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc()\n\nThe voice allocator sometimes begins allocating from near the end of the\narray and then wraps around, however snd_emu10k1_pcm_channel_alloc()\naccesses the newly allocated voices as if it never wrapped around.\n\nThis results in out of bounds access if the first voice has a high enough\nindex so that first_voice + requested_voice_count > NUM_G (64).\nThe mor","2024-05-03T16:15:08.593+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48702",{"cveId":10649,"releaseId":17,"cycle":18,"description":10650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10651,"url":10652},{"cveId":10649,"releaseId":25,"cycle":26,"description":10650,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10651,"url":10652},{"cveId":10656,"releaseId":17,"cycle":18,"description":10657,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10658,"url":10659},"CVE-2022-48697","In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix a use-after-free\n\nFix the following use-after-free complaint triggered by blktests nvme\u002F004:\n\nBUG: KASAN: user-memory-access in blk_mq_complete_request_remote+0xac\u002F0x350\nRead of size 4 at addr 0000607bd1835943 by task kworker\u002F13:1\u002F460\nWorkqueue: nvmet-wq nvme_loop_execute_work [nvme_loop]\nCall Trace:\n show_stack+0x52\u002F0x58\n dump_stack_lvl+0x49\u002F0x5e\n print_report.cold+0x36\u002F0x1e2\n kasan_report+0xb9\u002F0xf0\n __asan_load4+0x","2024-05-03T16:15:08.363+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48697",{"cveId":10656,"releaseId":25,"cycle":26,"description":10657,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10658,"url":10659},{"cveId":10656,"releaseId":31,"cycle":32,"description":10657,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10658,"url":10659},{"cveId":10663,"releaseId":17,"cycle":18,"description":10664,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10665,"url":10666},"CVE-2022-48674","In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix pcluster use-after-free on UP platforms\n\nDuring stress testing with CONFIG_SMP disabled, KASAN reports as below:\n\n==================================================================\nBUG: KASAN: use-after-free in __mutex_lock+0xe5\u002F0xc30\nRead of size 8 at addr ffff8881094223f8 by task stress\u002F7789\n\nCPU: 0 PID: 7789 Comm: stress Not tainted 6.0.0-rc1-00002-g0d53d2e882f9 #3\nHardware name: Red Hat KVM, BIOS 0.5.1 01\u002F01\u002F2011","2024-05-03T15:15:07.58+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48674",{"cveId":10668,"releaseId":25,"cycle":26,"description":10669,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10670,"url":10671},"CVE-2022-48673","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: Fix possible access to freed memory in link clear\n\nAfter modifying the QP to the Error state, all RX WR would be completed\nwith WC in IB_WC_WR_FLUSH_ERR status. Current implementation does not\nwait for it is done, but destroy the QP and free the link group directly.\nSo there is a risk that accessing the freed memory in tasklet context.\n\nHere is a crash example:\n\n BUG: unable to handle page fault for address: ffffffff8f","2024-05-03T15:15:07.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48673",{"cveId":10668,"releaseId":17,"cycle":18,"description":10669,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10670,"url":10671},{"cveId":10674,"releaseId":17,"cycle":18,"description":10675,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10676,"url":10677},"CVE-2024-27388","In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix some memleaks in gssx_dec_option_array\n\nThe creds and oa->data need to be freed in the error-handling paths after\ntheir allocation. So this patch add these deallocations in the\ncorresponding paths.","2024-05-01T13:15:51.55+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27388",{"cveId":10674,"releaseId":31,"cycle":32,"description":10675,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10676,"url":10677},{"cveId":10674,"releaseId":25,"cycle":26,"description":10675,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10676,"url":10677},{"cveId":10681,"releaseId":31,"cycle":32,"description":10682,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10683,"url":10684},"CVE-2024-27073","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ttpci: fix two memleaks in budget_av_attach\n\nWhen saa7146_register_device and saa7146_vv_init fails, budget_av_attach\nshould free the resources it allocates, like the error-handling of\nttpci_budget_init does. Besides, there are two fixme comment refers to\nsuch deallocations.","2024-05-01T13:15:51.167+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27073",{"cveId":10681,"releaseId":17,"cycle":18,"description":10682,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10683,"url":10684},{"cveId":10681,"releaseId":25,"cycle":26,"description":10682,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10683,"url":10684},{"cveId":10688,"releaseId":31,"cycle":32,"description":10689,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10690,"url":10691},"CVE-2024-27062","In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau: lock the client object tree.\n\nIt appears the client object tree has no locking unless I've missed\nsomething else. Fix races around adding\u002Fremoving client objects,\nmostly vram bar mappings.\n\n 4562.099306] general protection fault, probably for non-canonical address 0x6677ed422bceb80c: 0000 [#1] PREEMPT SMP PTI\n[ 4562.099314] CPU: 2 PID: 23171 Comm: deqp-vk Not tainted 6.8.0-rc6+ #27\n[ 4562.099324] Hardware name: Gigabyt","2024-05-01T13:15:50.66+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27062",{"cveId":10688,"releaseId":25,"cycle":26,"description":10689,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10690,"url":10691},{"cveId":10688,"releaseId":17,"cycle":18,"description":10689,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10690,"url":10691},{"cveId":10695,"releaseId":31,"cycle":32,"description":10696,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10697,"url":10698},"CVE-2024-27056","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: ensure offloading TID queue exists\n\nThe resume code path assumes that the TX queue for the offloading TID\nhas been configured. At resume time it then tries to sync the write\npointer as it may have been updated by the firmware.\n\nIn the unusual event that no packets have been send on TID 0, the queue\nwill not have been allocated and this causes a crash. Fix this by\nensuring the queue exist at suspend time.","2024-05-01T13:15:50.36+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27056",{"cveId":10695,"releaseId":17,"cycle":18,"description":10696,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10697,"url":10698},{"cveId":10695,"releaseId":25,"cycle":26,"description":10696,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10697,"url":10698},{"cveId":10702,"releaseId":17,"cycle":18,"description":10703,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10704,"url":10705},"CVE-2024-27043","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: edia: dvbdev: fix a use-after-free\n\nIn dvb_register_device, *pdvbdev is set equal to dvbdev, which is freed\nin several error-handling paths. However, *pdvbdev is not set to NULL\nafter dvbdev's deallocation, causing use-after-frees in many places,\nfor example, in the following call chain:\n\nbudget_register\n  |-> dvb_dmxdev_init\n        |-> dvb_register_device\n  |-> dvb_dmxdev_release\n        |-> dvb_unregister_device\n     ","2024-05-01T13:15:49.74+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27043",{"cveId":10702,"releaseId":25,"cycle":26,"description":10703,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10704,"url":10705},{"cveId":10702,"releaseId":31,"cycle":32,"description":10703,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10704,"url":10705},{"cveId":10709,"releaseId":25,"cycle":26,"description":10710,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10711,"url":10712},"CVE-2024-27020","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: Fix potential data-race in __nft_expr_type_get()\n\nnft_unregister_expr() can concurrent with __nft_expr_type_get(),\nand there is not any protection when iterate over nf_tables_expressions\nlist in __nft_expr_type_get(). Therefore, there is potential data-race\nof nf_tables_expressions list entry.\n\nUse list_for_each_entry_rcu() to iterate over nf_tables_expressions\nlist in __nft_expr_type_get(), and use rcu_re","2024-05-01T06:15:20.84+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27020",{"cveId":10709,"releaseId":17,"cycle":18,"description":10710,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10711,"url":10712},{"cveId":10709,"releaseId":31,"cycle":32,"description":10710,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10711,"url":10712},{"cveId":10716,"releaseId":17,"cycle":18,"description":10717,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10718,"url":10719},"CVE-2024-27019","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: Fix potential data-race in __nft_obj_type_get()\n\nnft_unregister_obj() can concurrent with __nft_obj_type_get(),\nand there is not any protection when iterate over nf_tables_objects\nlist in __nft_obj_type_get(). Therefore, there is potential data-race\nof nf_tables_objects list entry.\n\nUse list_for_each_entry_rcu() to iterate over nf_tables_objects\nlist in __nft_obj_type_get(), and use rcu_read_lock() in the ","2024-05-01T06:15:20.743+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-27019",{"cveId":10716,"releaseId":25,"cycle":26,"description":10717,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10718,"url":10719},{"cveId":10722,"releaseId":25,"cycle":26,"description":10723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10724,"url":10725},"CVE-2024-26996","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: Fix UAF ncm object at re-bind after usb ep transport error\n\nWhen ncm function is working and then stop usb0 interface for link down,\neth_stop() is called. At this piont, accidentally if usb transport error\nshould happen in usb_ep_enable(), 'in_ep' and\u002For 'out_ep' may not be enabled.\n\nAfter that, ncm_disable() is called to disable for ncm unbind\nbut gether_disconnect() is never called since 'in_ep' is not ena","2024-05-01T06:15:17.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26996",{"cveId":10722,"releaseId":17,"cycle":18,"description":10723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10724,"url":10725},{"cveId":10722,"releaseId":31,"cycle":32,"description":10723,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10724,"url":10725},{"cveId":10729,"releaseId":17,"cycle":18,"description":10730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10731,"url":10732},"CVE-2024-26994","In the Linux kernel, the following vulnerability has been resolved:\n\nspeakup: Avoid crash on very long word\n\nIn case a console is set up really large and contains a really long word\n(> 256 characters), we have to stop before the length of the word buffer.","2024-05-01T06:15:17.207+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26994",{"cveId":10729,"releaseId":25,"cycle":26,"description":10730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10731,"url":10732},{"cveId":10729,"releaseId":31,"cycle":32,"description":10730,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10731,"url":10732},{"cveId":10736,"releaseId":17,"cycle":18,"description":10737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10738,"url":10739},"CVE-2024-26976","In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Always flush async #PF workqueue when vCPU is being destroyed\n\nAlways flush the per-vCPU async #PF workqueue when a vCPU is clearing its\ncompletion queue, e.g. when a VM and all its vCPUs is being destroyed.\nKVM must ensure that none of its workqueue callbacks is running when the\nlast reference to the KVM _module_ is put.  Gifting a reference to the\nassociated VM prevents the workqueue callback from dereferencing freed\nvCP","2024-05-01T06:15:14.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26976",{"cveId":10736,"releaseId":25,"cycle":26,"description":10737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10738,"url":10739},{"cveId":10736,"releaseId":31,"cycle":32,"description":10737,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10738,"url":10739},{"cveId":10743,"releaseId":17,"cycle":18,"description":10744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10745,"url":10746},"CVE-2024-26974","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - resolve race condition during AER recovery\n\nDuring the PCI AER system's error recovery process, the kernel driver\nmay encounter a race condition with freeing the reset_data structure's\nmemory. If the device restart will take more than 10 seconds the function\nscheduling that restart will exit due to a timeout, and the reset_data\nstructure will be freed. However, this data structure is used for\ncompletion notificati","2024-05-01T06:15:14.313+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26974",{"cveId":10743,"releaseId":31,"cycle":32,"description":10744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10745,"url":10746},{"cveId":10743,"releaseId":25,"cycle":26,"description":10744,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10745,"url":10746},{"cveId":10750,"releaseId":17,"cycle":18,"description":10751,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10752,"url":10753},"CVE-2024-26969","In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: gcc-ipq8074: fix terminating of frequency table arrays\n\nThe frequency table arrays are supposed to be terminated with an\nempty element. Add such entry to the end of the arrays where it\nis missing in order to avoid possible out-of-bound access when\nthe table is traversed by functions like qcom_find_freq() or\nqcom_find_freq_floor().\n\nOnly compile tested.","2024-05-01T06:15:13.22+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26969",{"cveId":10755,"releaseId":17,"cycle":18,"description":10756,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10757,"url":10758},"CVE-2024-26966","In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: mmcc-apq8084: fix terminating of frequency table arrays\n\nThe frequency table arrays are supposed to be terminated with an\nempty element. Add such entry to the end of the arrays where it\nis missing in order to avoid possible out-of-bound access when\nthe table is traversed by functions like qcom_find_freq() or\nqcom_find_freq_floor().\n\nOnly compile tested.","2024-05-01T06:15:12.913+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26966",{"cveId":10755,"releaseId":31,"cycle":32,"description":10756,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10757,"url":10758},{"cveId":10755,"releaseId":25,"cycle":26,"description":10756,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10757,"url":10758},{"cveId":10762,"releaseId":17,"cycle":18,"description":10763,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10764,"url":10765},"CVE-2024-26965","In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: mmcc-msm8974: fix terminating of frequency table arrays\n\nThe frequency table arrays are supposed to be terminated with an\nempty element. Add such entry to the end of the arrays where it\nis missing in order to avoid possible out-of-bound access when\nthe table is traversed by functions like qcom_find_freq() or\nqcom_find_freq_floor().\n\nOnly compile tested.","2024-05-01T06:15:12.783+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26965",{"cveId":10762,"releaseId":31,"cycle":32,"description":10763,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10764,"url":10765},{"cveId":10762,"releaseId":25,"cycle":26,"description":10763,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10764,"url":10765},{"cveId":10769,"releaseId":17,"cycle":18,"description":10770,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":10771,"url":10772},"CVE-2024-26961","In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: fix llsec key resources release in mac802154_llsec_key_del\n\nmac802154_llsec_key_del() can free resources of a key directly without\nfollowing the RCU rules for waiting before the end of a grace period. This\nmay lead to use-after-free in case llsec_lookup_key() is traversing the\nlist of keys in parallel with a key deletion:\n\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 4 PID: 16000 at lib\u002Frefcount.c:25 refc","2024-05-01T06:15:12.437+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26961",{"cveId":10769,"releaseId":31,"cycle":32,"description":10770,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":10771,"url":10772},{"cveId":10769,"releaseId":25,"cycle":26,"description":10770,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":10771,"url":10772},{"cveId":10776,"releaseId":25,"cycle":26,"description":10777,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":10778,"url":10779},"CVE-2024-26960","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: swap: fix race between free_swap_and_cache() and swapoff()\n\nThere was previously a theoretical window where swapoff() could run and\nteardown a swap_info_struct while a call to free_swap_and_cache() was\nrunning in another thread.  This could cause, amongst other bad\npossibilities, swap_page_trans_huge_swapped() (called by\nfree_swap_and_cache()) to access the freed memory for swap_map.\n\nThis is a theoretical problem and I hav","2024-05-01T06:15:12.323+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26960",{"cveId":10776,"releaseId":17,"cycle":18,"description":10777,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":10778,"url":10779},{"cveId":10782,"releaseId":31,"cycle":32,"description":10783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10784,"url":10785},"CVE-2024-26958","In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: fix UAF in direct writes\n\nIn production we have been hitting the following warning consistently\n\n------------[ cut here ]------------\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 17 PID: 1800359 at lib\u002Frefcount.c:28 refcount_warn_saturate+0x9c\u002F0xe0\nWorkqueue: nfsiod nfs_direct_write_schedule_work [nfs]\nRIP: 0010:refcount_warn_saturate+0x9c\u002F0xe0\nPKRU: 55555554\nCall Trace:\n \u003CTASK>\n ? __warn+0x9f\u002F0x130\n ? refcount_war","2024-05-01T06:15:12.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26958",{"cveId":10782,"releaseId":25,"cycle":26,"description":10783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10784,"url":10785},{"cveId":10782,"releaseId":17,"cycle":18,"description":10783,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10784,"url":10785},{"cveId":10789,"releaseId":25,"cycle":26,"description":10790,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10791,"url":10792},"CVE-2024-26957","In the Linux kernel, the following vulnerability has been resolved:\n\ns390\u002Fzcrypt: fix reference counting on zcrypt card objects\n\nTests with hot-plugging crytpo cards on KVM guests with debug\nkernel build revealed an use after free for the load field of\nthe struct zcrypt_card. The reason was an incorrect reference\nhandling of the zcrypt card object which could lead to a free\nof the zcrypt card object while it was still in use.\n\nThis is an example of the slab message:\n\n    kernel: 0x00000000885a75","2024-05-01T06:15:11.953+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26957",{"cveId":10789,"releaseId":17,"cycle":18,"description":10790,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10791,"url":10792},{"cveId":10789,"releaseId":31,"cycle":32,"description":10790,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10791,"url":10792},{"cveId":10796,"releaseId":17,"cycle":18,"description":10797,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10798,"url":10799},"CVE-2024-26931","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix command flush on cable pull\n\nSystem crash due to command failed to flush back to SCSI layer.\n\n BUG: unable to handle kernel NULL pointer dereference at 0000000000000000\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP NOPTI\n CPU: 27 PID: 793455 Comm: kworker\u002Fu130:6 Kdump: loaded Tainted: G           OE    --------- -  - 4.18.0-372.9.1.el8.x86_64 #1\n Hardware name: HPE ProLiant DL360 Gen10\u002FProLiant DL360 Gen10, BIOS U32 09\u002F0","2024-05-01T06:15:07.673+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26931",{"cveId":10796,"releaseId":31,"cycle":32,"description":10797,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10798,"url":10799},{"cveId":10796,"releaseId":25,"cycle":26,"description":10797,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10798,"url":10799},{"cveId":10803,"releaseId":17,"cycle":18,"description":10804,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10805,"url":10806},"CVE-2022-48636","In the Linux kernel, the following vulnerability has been resolved:\n\ns390\u002Fdasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroup\n\nFix Oops in dasd_alias_get_start_dev() function caused by the pavgroup\npointer being NULL.\n\nThe pavgroup pointer is checked on the entrance of the function but\nwithout the lcu->lock being held. Therefore there is a race window\nbetween dasd_alias_get_start_dev() and _lcu_update() which sets\npavgroup to NULL with the lcu->lock held.\n\nFix by checking the pavg","2024-04-28T13:15:06.71+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48636",{"cveId":10803,"releaseId":25,"cycle":26,"description":10804,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10805,"url":10806},{"cveId":10803,"releaseId":31,"cycle":32,"description":10804,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10805,"url":10806},{"cveId":10810,"releaseId":17,"cycle":18,"description":10811,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10812,"url":10813},"CVE-2024-26925","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: release mutex after nft_gc_seq_end from abort path\n\nThe commit mutex should not be released during the critical section\nbetween nft_gc_seq_begin() and nft_gc_seq_end(), otherwise, async GC\nworker could collect expired objects and get the released commit lock\nwithin the same GC sequence.\n\nnf_tables_module_autoload() temporarily releases the mutex to load\nmodule dependencies, then it goes back to replay the ","2024-04-25T06:15:57.59+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26925",{"cveId":10815,"releaseId":25,"cycle":26,"description":10816,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10817,"url":10818},"CVE-2024-26923","In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Fix garbage collector racing against connect()\n\nGarbage collector does not take into account the risk of embryo getting\nenqueued during the garbage collection. If such embryo has a peer that\ncarries SCM_RIGHTS, two consecutive passes of scan_children() may see a\ndifferent set of children. Leading to an incorrectly elevated inflight\ncount, and then a dangling pointer within the gc_inflight_list.\n\nsockets are AF_UNIX\u002FSOC","2024-04-25T06:15:57.16+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26923",{"cveId":10815,"releaseId":17,"cycle":18,"description":10816,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10817,"url":10818},{"cveId":10815,"releaseId":31,"cycle":32,"description":10816,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10817,"url":10818},{"cveId":10822,"releaseId":25,"cycle":26,"description":10823,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10824,"url":10825},"CVE-2024-26922","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: validate the parameters of bo mapping operations more clearly\n\nVerify the parameters of\namdgpu_vm_bo_(map\u002Freplace_map\u002Fclearing_mappings) in one common place.","2024-04-23T13:15:46.643+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26922",{"cveId":10822,"releaseId":17,"cycle":18,"description":10823,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10824,"url":10825},{"cveId":10828,"releaseId":25,"cycle":26,"description":10829,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10830,"url":10831},"CVE-2024-26921","In the Linux kernel, the following vulnerability has been resolved:\n\ninet: inet_defrag: prevent sk release while still in use\n\nip_local_out() and other functions can pass skb->sk as function argument.\n\nIf the skb is a fragment and reassembly happens before such function call\nreturns, the sk must not be released.\n\nThis affects skb fragments reassembled via netfilter or similar\nmodules, e.g. openvswitch or ct_act.c, when run as part of tx pipeline.\n\nEric Dumazet made an initial analysis of this bu","2024-04-18T10:15:07.74+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26921",{"cveId":10828,"releaseId":31,"cycle":32,"description":10829,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10830,"url":10831},{"cveId":10828,"releaseId":17,"cycle":18,"description":10829,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10830,"url":10831},{"cveId":10835,"releaseId":31,"cycle":32,"description":10836,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10837,"url":10838},"CVE-2024-26898","In the Linux kernel, the following vulnerability has been resolved:\n\naoe: fix the potential use-after-free problem in aoecmd_cfg_pkts\n\nThis patch is against CVE-2023-6270. The description of cve is:\n\n  A flaw was found in the ATA over Ethernet (AoE) driver in the Linux\n  kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on\n  `struct net_device`, and a use-after-free can be triggered by racing\n  between the free on the struct and the access through the `skbtxq`\n  global queue. ","2024-04-17T11:15:10.82+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26898",{"cveId":10835,"releaseId":25,"cycle":26,"description":10836,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10837,"url":10838},{"cveId":10835,"releaseId":17,"cycle":18,"description":10836,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10837,"url":10838},{"cveId":10842,"releaseId":31,"cycle":32,"description":10843,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10844,"url":10845},"CVE-2024-26883","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix stackmap overflow check on 32-bit arches\n\nThe stackmap code relies on roundup_pow_of_two() to compute the number\nof hash buckets, and contains an overflow check by checking if the\nresulting value is 0. However, on 32-bit arches, the roundup code itself\ncan overflow by doing a 32-bit left-shift of an unsigned long value,\nwhich is undefined behaviour, so it is not guaranteed to truncate\nneatly. This was triggered by syzb","2024-04-17T11:15:10.113+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26883",{"cveId":10842,"releaseId":17,"cycle":18,"description":10843,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10844,"url":10845},{"cveId":10842,"releaseId":25,"cycle":26,"description":10843,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10844,"url":10845},{"cveId":10849,"releaseId":25,"cycle":26,"description":10850,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10851,"url":10852},"CVE-2024-26882","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv()\n\nApply the same fix than ones found in :\n\n8d975c15c0cd (\"ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()\")\n1ca1ba465e55 (\"geneve: make sure to pull inner header in geneve_rx()\")\n\nWe have to save skb->network_header in a temporary variable\nin order to be able to recompute the network_header pointer\nafter a pskb_inet_may_pull() call.\n\npskb_inet_may_pu","2024-04-17T11:15:10.06+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26882",{"cveId":10849,"releaseId":17,"cycle":18,"description":10850,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10851,"url":10852},{"cveId":10849,"releaseId":31,"cycle":32,"description":10850,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10851,"url":10852},{"cveId":10856,"releaseId":17,"cycle":18,"description":10857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10858,"url":10859},"CVE-2024-26880","In the Linux kernel, the following vulnerability has been resolved:\n\ndm: call the resume method on internal suspend\n\nThere is this reported crash when experimenting with the lvm2 testsuite.\nThe list corruption is caused by the fact that the postsuspend and resume\nmethods were not paired correctly; there were two consecutive calls to the\norigin_postsuspend function. The second call attempts to remove the\n\"hash_list\" entry from a list, while it was already removed by the first\ncall.\n\nFix __dm_inte","2024-04-17T11:15:09.963+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26880",{"cveId":10856,"releaseId":31,"cycle":32,"description":10857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10858,"url":10859},{"cveId":10856,"releaseId":25,"cycle":26,"description":10857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10858,"url":10859},{"cveId":10863,"releaseId":17,"cycle":18,"description":10864,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10865,"url":10866},"CVE-2024-26872","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fsrpt: Do not register event handler until srpt device is fully setup\n\nUpon rare occasions, KASAN reports a use-after-free Write\nin srpt_refresh_port().\n\nThis seems to be because an event handler is registered before the\nsrpt device is fully setup and a race condition upon error may leave a\npartially setup event handler in place.\n\nInstead, only register the event handler after srpt device initialization\nis complete.","2024-04-17T11:15:09.56+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26872",{"cveId":10863,"releaseId":25,"cycle":26,"description":10864,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10865,"url":10866},{"cveId":10863,"releaseId":31,"cycle":32,"description":10864,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10865,"url":10866},{"cveId":10870,"releaseId":17,"cycle":18,"description":10871,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10872,"url":10873},"CVE-2024-26869","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to truncate meta inode pages forcely\n\nBelow race case can cause data corruption:\n\nThread A\t\t\t\tGC thread\n\t\t\t\t\t- gc_data_segment\n\t\t\t\t\t - ra_data_block\n\t\t\t\t\t  - locked meta_inode page\n- f2fs_inplace_write_data\n - invalidate_mapping_pages\n : fail to invalidate meta_inode page\n   due to lock failure or dirty|writeback\n   status\n - f2fs_submit_page_bio\n : write last dirty data to old blkaddr\n\t\t\t\t\t - move_data_block\n\t\t\t\t\t  -","2024-04-17T11:15:09.413+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26869",{"cveId":10875,"releaseId":25,"cycle":26,"description":10876,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10877,"url":10878},"CVE-2024-26865","In the Linux kernel, the following vulnerability has been resolved:\n\nrds: tcp: Fix use-after-free of net in reqsk_timer_handler().\n\nsyzkaller reported a warning of netns tracker [0] followed by KASAN\nsplat [1] and another ref tracker warning [1].\n\nsyzkaller could not find a repro, but in the log, the only suspicious\nsequence was as follows:\n\n  18:26:22 executing program 1:\n  r0 = socket$inet6_mptcp(0xa, 0x1, 0x106)\n  ...\n  connect$inet6(r0, &(0x7f0000000080)={0xa, 0x4001, 0x0, @loopback}, 0x1c) ","2024-04-17T11:15:09.207+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26865",{"cveId":10875,"releaseId":31,"cycle":32,"description":10876,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10877,"url":10878},{"cveId":10875,"releaseId":17,"cycle":18,"description":10876,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10877,"url":10878},{"cveId":10882,"releaseId":31,"cycle":32,"description":10883,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10884,"url":10885},"CVE-2024-26857","In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: make sure to pull inner header in geneve_rx()\n\nsyzbot triggered a bug in geneve_rx() [1]\n\nIssue is similar to the one I fixed in commit 8d975c15c0cd\n(\"ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()\")\n\nWe have to save skb->network_header in a temporary variable\nin order to be able to recompute the network_header pointer\nafter a pskb_inet_may_pull() call.\n\npskb_inet_may_pull() makes sure the needed headers ","2024-04-17T11:15:08.787+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26857",{"cveId":10882,"releaseId":25,"cycle":26,"description":10883,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10884,"url":10885},{"cveId":10882,"releaseId":17,"cycle":18,"description":10883,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":10884,"url":10885},{"cveId":10889,"releaseId":31,"cycle":32,"description":10890,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10891,"url":10892},"CVE-2024-26851","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_h323: Add protection for bmp length out of range\n\nUBSAN load reports an exception of BRK#5515 SHIFT_ISSUE:Bitwise shifts\nthat are out of bounds for their data type.\n\nvmlinux   get_bitmap(b=75) + 712\n\u003Cnet\u002Fnetfilter\u002Fnf_conntrack_h323_asn1.c:0>\nvmlinux   decode_seq(bs=0xFFFFFFD008037000, f=0xFFFFFFD008037018, level=134443100) + 1956\n\u003Cnet\u002Fnetfilter\u002Fnf_conntrack_h323_asn1.c:592>\nvmlinux   decode_choice(base=0","2024-04-17T11:15:08.473+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26851",{"cveId":10889,"releaseId":25,"cycle":26,"description":10890,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10891,"url":10892},{"cveId":10889,"releaseId":17,"cycle":18,"description":10890,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10891,"url":10892},{"cveId":10896,"releaseId":25,"cycle":26,"description":10897,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10898,"url":10899},"CVE-2024-26845","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Add TMF to tmr_list handling\n\nAn abort that is responded to by iSCSI itself is added to tmr_list but does\nnot go to target core. A LUN_RESET that goes through tmr_list takes a\nrefcounter on the abort and waits for completion. However, the abort will\nbe never complete because it was not started in target core.\n\n Unable to locate ITT: 0x05000000 on CID: 0\n Unable to locate RefTaskTag: 0x05000000 on CID: 0.\n wa","2024-04-17T10:15:10.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26845",{"cveId":10896,"releaseId":17,"cycle":18,"description":10897,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10898,"url":10899},{"cveId":10896,"releaseId":31,"cycle":32,"description":10897,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":10898,"url":10899},{"cveId":10903,"releaseId":31,"cycle":32,"description":10904,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10905,"url":10906},"CVE-2024-26830","In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Do not allow untrusted VF to remove administratively set MAC\n\nCurrently when PF administratively sets VF's MAC address and the VF\nis put down (VF tries to delete all MACs) then the MAC is removed\nfrom MAC filters and primary VF MAC is zeroed.\n\nDo not allow untrusted VF to remove primary MAC when it was set\nadministratively by PF.\n\nReproducer:\n1) Create VF\n2) Set VF interface up\n3) Administratively set the VF's MAC\n4) Put ","2024-04-17T10:15:09.4+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26830",{"cveId":10903,"releaseId":25,"cycle":26,"description":10904,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10905,"url":10906},{"cveId":10903,"releaseId":17,"cycle":18,"description":10904,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":10905,"url":10906},{"cveId":10910,"releaseId":17,"cycle":18,"description":10911,"severity":101,"cvssScore":657,"epssScore":9,"inKev":42,"publishedAt":10912,"url":10913},"CVE-2024-26828","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix underflow in parse_server_interfaces()\n\nIn this loop, we step through the buffer and after each item we check\nif the size_left is greater than the minimum size we need.  However,\nthe problem is that \"bytes_left\" is type ssize_t while sizeof() is type\nsize_t.  That means that because of type promotion, the comparison is\ndone as an unsigned and if we have negative bytes left the loop\ncontinues instead of ending.","2024-04-17T10:15:09.3+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26828",{"cveId":10915,"releaseId":25,"cycle":26,"description":10916,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10917,"url":10918},"CVE-2021-47219","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix out-of-bound read in resp_report_tgtpgs()\n\nThe following issue was observed running syzkaller:\n\nBUG: KASAN: slab-out-of-bounds in memcpy include\u002Flinux\u002Fstring.h:377 [inline]\nBUG: KASAN: slab-out-of-bounds in sg_copy_buffer+0x150\u002F0x1c0 lib\u002Fscatterlist.c:831\nRead of size 2132 at addr ffff8880aea95dc8 by task syz-executor.0\u002F9815\n\nCPU: 0 PID: 9815 Comm: syz-executor.0 Not tainted 4.19.202-00874-gfc0fe04215a9 #2","2024-04-10T19:15:48.903+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47219",{"cveId":10915,"releaseId":17,"cycle":18,"description":10916,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10917,"url":10918},{"cveId":10915,"releaseId":31,"cycle":32,"description":10916,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10917,"url":10918},{"cveId":10922,"releaseId":25,"cycle":26,"description":10923,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10924,"url":10925},"CVE-2021-47203","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix list_add() corruption in lpfc_drain_txq()\n\nWhen parsing the txq list in lpfc_drain_txq(), the driver attempts to pass\nthe requests to the adapter. If such an attempt fails, a local \"fail_msg\"\nstring is set and a log message output.  The job is then added to a\ncompletions list for cancellation.\n\nProcessing of any further jobs from the txq list continues, but since\n\"fail_msg\" remains set, jobs are added to the com","2024-04-10T19:15:48.217+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47203",{"cveId":10922,"releaseId":31,"cycle":32,"description":10923,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10924,"url":10925},{"cveId":10922,"releaseId":17,"cycle":18,"description":10923,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10924,"url":10925},{"cveId":10929,"releaseId":17,"cycle":18,"description":10930,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10931,"url":10932},"CVE-2021-47201","In the Linux kernel, the following vulnerability has been resolved:\n\niavf: free q_vectors before queues in iavf_disable_vf\n\niavf_free_queues() clears adapter->num_active_queues, which\niavf_free_q_vectors() relies on, so swap the order of these two function\ncalls in iavf_disable_vf(). This resolves a panic encountered when the\ninterface is disabled and then later brought up again after PF\ncommunication is restored.","2024-04-10T19:15:48.123+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47201",{"cveId":10929,"releaseId":25,"cycle":26,"description":10930,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10931,"url":10932},{"cveId":10935,"releaseId":25,"cycle":26,"description":10936,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10937,"url":10938},"CVE-2021-47194","In the Linux kernel, the following vulnerability has been resolved:\n\ncfg80211: call cfg80211_stop_ap when switch from P2P_GO type\n\nIf the userspace tools switch from NL80211_IFTYPE_P2P_GO to\nNL80211_IFTYPE_ADHOC via send_msg(NL80211_CMD_SET_INTERFACE), it\ndoes not call the cleanup cfg80211_stop_ap(), this leads to the\ninitialization of in-use data. For example, this path re-init the\nsdata->assigned_chanctx_list while it is still an element of\nassigned_vifs list, and makes that linked list corrup","2024-04-10T19:15:47.807+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47194",{"cveId":10935,"releaseId":17,"cycle":18,"description":10936,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10937,"url":10938},{"cveId":10935,"releaseId":31,"cycle":32,"description":10936,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10937,"url":10938},{"cveId":10942,"releaseId":25,"cycle":26,"description":10943,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10944,"url":10945},"CVE-2021-47191","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix out-of-bound read in resp_readcap16()\n\nThe following warning was observed running syzkaller:\n\n[ 3813.830724] sg_write: data in\u002Fout 65466\u002F242 bytes for SCSI command 0x9e-- guessing data in;\n[ 3813.830724]    program syz-executor not setting count and\u002For reply_len properly\n[ 3813.836956] ==================================================================\n[ 3813.839465] BUG: KASAN: stack-out-of-bounds in sg_co","2024-04-10T19:15:47.663+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47191",{"cveId":10942,"releaseId":17,"cycle":18,"description":10943,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10944,"url":10945},{"cveId":10942,"releaseId":31,"cycle":32,"description":10943,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":10944,"url":10945},{"cveId":10949,"releaseId":31,"cycle":32,"description":10950,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10951,"url":10952},"CVE-2021-47189","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix memory ordering between normal and ordered work functions\n\nOrdered work functions aren't guaranteed to be handled by the same thread\nwhich executed the normal work functions. The only way execution between\nnormal\u002Fordered functions is synchronized is via the WORK_DONE_BIT,\nunfortunately the used bitops don't guarantee any ordering whatsoever.\n\nThis manifested as seemingly inexplicable crashes on ARM64, where\nasync_chu","2024-04-10T19:15:47.57+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47189",{"cveId":10949,"releaseId":17,"cycle":18,"description":10950,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10951,"url":10952},{"cveId":10949,"releaseId":25,"cycle":26,"description":10950,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10951,"url":10952},{"cveId":10956,"releaseId":25,"cycle":26,"description":10957,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10958,"url":10959},"CVE-2021-47188","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Improve SCSI abort handling\n\nThe following has been observed on a test setup:\n\nWARNING: CPU: 4 PID: 250 at drivers\u002Fscsi\u002Fufs\u002Fufshcd.c:2737 ufshcd_queuecommand+0x468\u002F0x65c\nCall trace:\n ufshcd_queuecommand+0x468\u002F0x65c\n scsi_send_eh_cmnd+0x224\u002F0x6a0\n scsi_eh_test_devices+0x248\u002F0x418\n scsi_eh_ready_devs+0xc34\u002F0xe58\n scsi_error_handler+0x204\u002F0x80c\n kthread+0x150\u002F0x1b4\n ret_from_fork+0x10\u002F0x30\n\nThat warning is trigger","2024-04-10T19:15:47.527+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47188",{"cveId":10956,"releaseId":31,"cycle":32,"description":10957,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10958,"url":10959},{"cveId":10956,"releaseId":17,"cycle":18,"description":10957,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":10958,"url":10959},{"cveId":10963,"releaseId":31,"cycle":32,"description":10964,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10965,"url":10966},"CVE-2021-47184","In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix NULL ptr dereference on VSI filter sync\n\nRemove the reason of null pointer dereference in sync VSI filters.\nAdded new I40E_VSI_RELEASING flag to signalize deleting and releasing\nof VSI resources to sync this thread with sync filters subtask.\nWithout this patch it is possible to start update the VSI filter list\nafter VSI is removed, that's causing a kernel oops.","2024-04-10T19:15:47.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47184",{"cveId":10963,"releaseId":17,"cycle":18,"description":10964,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10965,"url":10966},{"cveId":10963,"releaseId":25,"cycle":26,"description":10964,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10965,"url":10966},{"cveId":10970,"releaseId":17,"cycle":18,"description":10971,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10972,"url":10973},"CVE-2021-47183","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix link down processing to address NULL pointer dereference\n\nIf an FC link down transition while PLOGIs are outstanding to fabric well\nknown addresses, outstanding ABTS requests may result in a NULL pointer\ndereference. Driver unload requests may hang with repeated \"2878\" log\nmessages.\n\nThe Link down processing results in ABTS requests for outstanding ELS\nrequests. The Abort WQEs are sent for the ELSs before the dr","2024-04-10T19:15:47.287+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47183",{"cveId":10970,"releaseId":25,"cycle":26,"description":10971,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10972,"url":10973},{"cveId":10970,"releaseId":31,"cycle":32,"description":10971,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":10972,"url":10973},{"cveId":10977,"releaseId":17,"cycle":18,"description":10978,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10979,"url":10980},"CVE-2024-26811","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate payload size in ipc response\n\nIf installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc\nresponse to ksmbd kernel server. ksmbd should validate payload size of\nipc response from ksmbd.mountd to avoid memory overrun or\nslab-out-of-bounds. This patch validate 3 ipc response that has payload.","2024-04-08T10:15:08.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26811",{"cveId":10977,"releaseId":31,"cycle":32,"description":10978,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10979,"url":10980},{"cveId":10977,"releaseId":25,"cycle":26,"description":10978,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":10979,"url":10980},{"cveId":10984,"releaseId":17,"cycle":18,"description":10985,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10986,"url":10987},"CVE-2024-26812","In the Linux kernel, the following vulnerability has been resolved:\n\nvfio\u002Fpci: Create persistent INTx handler\n\nA vulnerability exists where the eventfd for INTx signaling can be\ndeconfigured, which unregisters the IRQ handler but still allows\neventfds to be signaled with a NULL context through the SET_IRQS ioctl\nor through unmask irqfd if the device interrupt is pending.\n\nIdeally this could be solved with some additional locking; the igate\nmutex serializes the ioctl and config space accesses, an","2024-04-05T09:15:09.283+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26812",{"cveId":10984,"releaseId":31,"cycle":32,"description":10985,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10986,"url":10987},{"cveId":10984,"releaseId":25,"cycle":26,"description":10985,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10986,"url":10987},{"cveId":10991,"releaseId":17,"cycle":18,"description":10992,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10993,"url":10994},"CVE-2024-26810","In the Linux kernel, the following vulnerability has been resolved:\n\nvfio\u002Fpci: Lock external INTx masking ops\n\nMask operations through config space changes to DisINTx may race INTx\nconfiguration changes via ioctl.  Create wrappers that add locking for\npaths outside of the core interrupt code.\n\nIn particular, irq_type is updated holding igate, therefore testing\nis_intx() requires holding igate.  For example clearing DisINTx from\nconfig space can otherwise race changes of the interrupt configurati","2024-04-05T09:15:09.23+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26810",{"cveId":10991,"releaseId":31,"cycle":32,"description":10992,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10993,"url":10994},{"cveId":10991,"releaseId":25,"cycle":26,"description":10992,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":10993,"url":10994},{"cveId":10998,"releaseId":17,"cycle":18,"description":10999,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11000,"url":11001},"CVE-2024-26807","In the Linux kernel, the following vulnerability has been resolved:\n\nBoth cadence-quadspi ->runtime_suspend() and ->runtime_resume()\nimplementations start with:\n\n\tstruct cqspi_st *cqspi = dev_get_drvdata(dev);\n\tstruct spi_controller *host = dev_get_drvdata(dev);\n\nThis obviously cannot be correct, unless \"struct cqspi_st\" is the\nfirst member of \" struct spi_controller\", or the other way around, but\nit is not the case. \"struct spi_controller\" is allocated by\ndevm_spi_alloc_host(), which allocates ","2024-04-04T09:15:09.38+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26807",{"cveId":11003,"releaseId":17,"cycle":18,"description":11004,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11005,"url":11006},"CVE-2024-26804","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: prevent perpetual headroom growth\n\nsyzkaller triggered following kasan splat:\nBUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1\u002F0x7a50 net\u002Fcore\u002Fflow_dissector.c:1170\nRead of size 1 at addr ffff88812fb4000e by task syz-executor183\u002F5191\n[..]\n kasan_report+0xda\u002F0x110 mm\u002Fkasan\u002Freport.c:588\n __skb_flow_dissect+0x19d1\u002F0x7a50 net\u002Fcore\u002Fflow_dissector.c:1170\n skb_flow_dissect_flow_keys include\u002Flinux\u002Fskbuff.h:1514 [","2024-04-04T09:15:09.217+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26804",{"cveId":11003,"releaseId":25,"cycle":26,"description":11004,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11005,"url":11006},{"cveId":11003,"releaseId":31,"cycle":32,"description":11004,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11005,"url":11006},{"cveId":11010,"releaseId":31,"cycle":32,"description":11011,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11012,"url":11013},"CVE-2024-26801","In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Avoid potential use-after-free in hci_error_reset\n\nWhile handling the HCI_EV_HARDWARE_ERROR event, if the underlying\nBT controller is not responding, the GPIO reset mechanism would\nfree the hci_dev and lead to a use-after-free in hci_error_reset.\n\nHere's the call trace observed on a ChromeOS device with Intel AX201:\n   queue_work_on+0x3e\u002F0x6c\n   __hci_cmd_sync_sk+0x2ee\u002F0x4c0 [bluetooth \u003CHASH:3b4a6>]\n   ? init_wait_en","2024-04-04T09:15:09.05+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26801",{"cveId":11010,"releaseId":17,"cycle":18,"description":11011,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11012,"url":11013},{"cveId":11010,"releaseId":25,"cycle":26,"description":11011,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11012,"url":11013},{"cveId":11017,"releaseId":31,"cycle":32,"description":11018,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11019,"url":11020},"CVE-2024-26793","In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: fix use-after-free and null-ptr-deref in gtp_newlink()\n\nThe gtp_link_ops operations structure for the subsystem must be\nregistered after registering the gtp_net_ops pernet operations structure.\n\nSyzkaller hit 'general protection fault in gtp_genl_dump_pdp' bug:\n\n[ 1010.702740] gtp: GTP module unloaded\n[ 1010.715877] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n[","2024-04-04T09:15:08.62+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26793",{"cveId":11017,"releaseId":25,"cycle":26,"description":11018,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11019,"url":11020},{"cveId":11017,"releaseId":17,"cycle":18,"description":11018,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11019,"url":11020},{"cveId":11024,"releaseId":31,"cycle":32,"description":11025,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11026,"url":11027},"CVE-2024-26779","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix race condition on enabling fast-xmit\n\nfast-xmit must only be enabled after the sta has been uploaded to the driver,\notherwise it could end up passing the not-yet-uploaded sta via drv_tx calls\nto the driver, leading to potential crashes because of uninitialized drv_priv\ndata.\nAdd a missing sta->uploaded check and re-check fast xmit after inserting a sta.","2024-04-03T17:15:53.423+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26779",{"cveId":11024,"releaseId":25,"cycle":26,"description":11025,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11026,"url":11027},{"cveId":11024,"releaseId":17,"cycle":18,"description":11025,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11026,"url":11027},{"cveId":11031,"releaseId":31,"cycle":32,"description":11032,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11033,"url":11034},"CVE-2024-26773","In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found()\n\nDetermine if the group block bitmap is corrupted before using ac_b_ex in\next4_mb_try_best_found() to avoid allocating blocks from a group with a\ncorrupted block bitmap in the following concurrency and making the\nsituation worse.\n\next4_mb_regular_allocator\n  ext4_lock_group(sb, group)\n  ext4_mb_good_group\n   \u002F\u002F check if the group bbitmap is corrupted","2024-04-03T17:15:53.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26773",{"cveId":11031,"releaseId":17,"cycle":18,"description":11032,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11033,"url":11034},{"cveId":11031,"releaseId":25,"cycle":26,"description":11032,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11033,"url":11034},{"cveId":11038,"releaseId":17,"cycle":18,"description":11039,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11040,"url":11041},"CVE-2024-26772","In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal()\n\nPlaces the logic for checking if the group's block bitmap is corrupt under\nthe protection of the group lock to avoid allocating blocks from the group\nwith a corrupted block bitmap.","2024-04-03T17:15:53.023+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26772",{"cveId":11038,"releaseId":31,"cycle":32,"description":11039,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11040,"url":11041},{"cveId":11038,"releaseId":25,"cycle":26,"description":11039,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11040,"url":11041},{"cveId":11045,"releaseId":31,"cycle":32,"description":11046,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11047,"url":11048},"CVE-2024-26769","In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-fc: avoid deadlock on delete association path\n\nWhen deleting an association the shutdown path is deadlocking because we\ntry to flush the nvmet_wq nested. Avoid this by deadlock by deferring\nthe put work into its own work item.","2024-04-03T17:15:52.853+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26769",{"cveId":11045,"releaseId":25,"cycle":26,"description":11046,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11047,"url":11048},{"cveId":11045,"releaseId":17,"cycle":18,"description":11046,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11047,"url":11048},{"cveId":11052,"releaseId":17,"cycle":18,"description":11053,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11054,"url":11055},"CVE-2024-26766","In the Linux kernel, the following vulnerability has been resolved:\n\nIB\u002Fhfi1: Fix sdma.h tx->num_descs off-by-one error\n\nUnfortunately the commit `fd8958efe877` introduced another error\ncausing the `descs` array to overflow. This reults in further crashes\neasily reproducible by `sendmsg` system call.\n\n[ 1080.836473] general protection fault, probably for non-canonical address 0x400300015528b00a: 0000 [#1] PREEMPT SMP PTI\n[ 1080.869326] RIP: 0010:hfi1_ipoib_build_ib_tx_headers.constprop.0+0xe1\u002F0x","2024-04-03T17:15:52.683+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26766",{"cveId":11057,"releaseId":17,"cycle":18,"description":11058,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11059,"url":11060},"CVE-2024-26763","In the Linux kernel, the following vulnerability has been resolved:\n\ndm-crypt: don't modify the data when using authenticated encryption\n\nIt was said that authenticated encryption could produce invalid tag when\nthe data that is being encrypted is modified [1]. So, fix this problem by\ncopying the data into the clone bio first and then encrypt them inside the\nclone bio.\n\nThis may reduce performance, but it is needed to prevent the user from\ncorrupting the device by writing data with O_DIRECT and m","2024-04-03T17:15:52.52+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26763",{"cveId":11057,"releaseId":25,"cycle":26,"description":11058,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11059,"url":11060},{"cveId":11057,"releaseId":31,"cycle":32,"description":11058,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11059,"url":11060},{"cveId":11064,"releaseId":17,"cycle":18,"description":11065,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11066,"url":11067},"CVE-2024-26759","In the Linux kernel, the following vulnerability has been resolved:\n\nmm\u002Fswap: fix race when skipping swapcache\n\nWhen skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads\nswapin the same entry at the same time, they get different pages (A, B). \nBefore one thread (T0) finishes the swapin and installs page (A) to the\nPTE, another thread (T1) could finish swapin of page (B), swap_free the\nentry, then swap out the possibly modified page reusing the same entry. \nIt breaks the pte_same che","2024-04-03T17:15:52.32+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26759",{"cveId":11069,"releaseId":17,"cycle":18,"description":11070,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11071,"url":11072},"CVE-2024-26739","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsched: act_mirred: don't override retval if we already lost the skb\n\nIf we're redirecting the skb, and haven't called tcf_mirred_forward(),\nyet, we need to tell the core to drop the skb by setting the retcode\nto SHOT. If we have called tcf_mirred_forward(), however, the skb\nis out of our hands and returning SHOT will lead to UaF.\n\nMove the retval override to the error path which actually need it.","2024-04-03T17:15:51.367+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26739",{"cveId":11074,"releaseId":17,"cycle":18,"description":11075,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":11076,"url":11077},"CVE-2024-26736","In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Increase buffer size in afs_update_volume_status()\n\nThe max length of volume->vid value is 20 characters.\nSo increase idbuf[] size up to 24 to avoid overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[DH: Actually, it's 20 + NUL, so increase it to 24 and use snprintf()]","2024-04-03T17:15:51.197+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26736",{"cveId":11079,"releaseId":17,"cycle":18,"description":11080,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11081,"url":11082},"CVE-2023-52640","In the Linux kernel, the following vulnerability has been resolved:\n\nfs\u002Fntfs3: Fix oob in ntfs_listxattr\n\nThe length of name cannot exceed the space occupied by ea.","2024-04-03T17:15:47.41+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52640",{"cveId":11079,"releaseId":31,"cycle":32,"description":11080,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11081,"url":11082},{"cveId":11079,"releaseId":25,"cycle":26,"description":11080,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11081,"url":11082},{"cveId":11086,"releaseId":31,"cycle":32,"description":11087,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11088,"url":11089},"CVE-2024-26706","In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Fix random data corruption from exception handler\n\nThe current exception handler implementation, which assists when accessing\nuser space memory, may exhibit random data corruption if the compiler decides\nto use a different register than the specified register %r29 (defined in\nASM_EXCEPTIONTABLE_REG) for the error code. If the compiler choose another\nregister, the fault handler will nevertheless store -EFAULT into %r29 a","2024-04-03T15:15:53.293+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26706",{"cveId":11086,"releaseId":17,"cycle":18,"description":11087,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11088,"url":11089},{"cveId":11086,"releaseId":25,"cycle":26,"description":11087,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11088,"url":11089},{"cveId":11093,"releaseId":17,"cycle":18,"description":11094,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11095,"url":11096},"CVE-2024-26704","In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double-free of blocks due to wrong extents moved_len\n\nIn ext4_move_extents(), moved_len is only updated when all moves are\nsuccessfully executed, and only discards orig_inode and donor_inode\npreallocations when moved_len is not zero. When the loop fails to exit\nafter successfully moving some extents, moved_len is not updated and\nremains at 0, so it does not discard the preallocations.\n\nIf the moved extents overlap wit","2024-04-03T15:15:53.193+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26704",{"cveId":11093,"releaseId":25,"cycle":26,"description":11094,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11095,"url":11096},{"cveId":11093,"releaseId":31,"cycle":32,"description":11094,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11095,"url":11096},{"cveId":11100,"releaseId":31,"cycle":32,"description":11101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11102,"url":11103},"CVE-2024-26699","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famd\u002Fdisplay: Fix array-index-out-of-bounds in dcn35_clkmgr\n\n[Why]\nThere is a potential memory access violation while\niterating through array of dcn35 clks.\n\n[How]\nLimit iteration per array size.","2024-04-03T15:15:52.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26699",{"cveId":11100,"releaseId":25,"cycle":26,"description":11101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11102,"url":11103},{"cveId":11100,"releaseId":17,"cycle":18,"description":11101,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11102,"url":11103},{"cveId":11107,"releaseId":31,"cycle":32,"description":11108,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11109,"url":11110},"CVE-2024-26697","In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix data corruption in dsync block recovery for small block sizes\n\nThe helper function nilfs_recovery_copy_block() of\nnilfs_recovery_dsync_blocks(), which recovers data from logs created by\ndata sync writes during a mount after an unclean shutdown, incorrectly\ncalculates the on-page offset when copying repair data to the file's page\ncache.  In environments where the block size is smaller than the page\nsize, this flaw ca","2024-04-03T15:15:52.88+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26697",{"cveId":11107,"releaseId":17,"cycle":18,"description":11108,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11109,"url":11110},{"cveId":11107,"releaseId":25,"cycle":26,"description":11108,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11109,"url":11110},{"cveId":11114,"releaseId":25,"cycle":26,"description":11115,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11116,"url":11117},"CVE-2024-26689","In the Linux kernel, the following vulnerability has been resolved:\n\nceph: prevent use-after-free in encode_cap_msg()\n\nIn fs\u002Fceph\u002Fcaps.c, in encode_cap_msg(), \"use after free\" error was\ncaught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This\nimplies before the refcount could be increment here, it was freed.\n\nIn same file, in \"handle_cap_grant()\" refcount is decremented by this\nline - 'ceph_buffer_put(ci->i_xattrs.blob);'. It appears that a race\noccurred and resource was freed by ","2024-04-03T15:15:52.427+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26689",{"cveId":11114,"releaseId":17,"cycle":18,"description":11115,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11116,"url":11117},{"cveId":11114,"releaseId":31,"cycle":32,"description":11115,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11116,"url":11117},{"cveId":11121,"releaseId":17,"cycle":18,"description":11122,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11123,"url":11124},"CVE-2024-26664","In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (coretemp) Fix out-of-bounds memory access\n\nFix a bug that pdata->cpu_map[] is set before out-of-bounds check.\nThe problem might be triggered on systems with more than 128 cores per\npackage.","2024-04-02T07:15:43.36+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26664",{"cveId":11126,"releaseId":25,"cycle":26,"description":11127,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11128,"url":11129},"CVE-2024-26663","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Check the bearer type before calling tipc_udp_nl_bearer_add()\n\nsyzbot reported the following general protection fault [1]:\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000010: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000080-0x0000000000000087]\n...\nRIP: 0010:tipc_udp_is_known_peer+0x9c\u002F0x250 net\u002Ftipc\u002Fudp_media.c:291\n...\nCall Trace:\n \u003CTASK>\n tipc_udp_nl_bearer_add+","2024-04-02T07:15:43.287+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26663",{"cveId":11126,"releaseId":31,"cycle":32,"description":11127,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11128,"url":11129},{"cveId":11126,"releaseId":17,"cycle":18,"description":11127,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11128,"url":11129},{"cveId":11133,"releaseId":17,"cycle":18,"description":11134,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11135,"url":11136},"CVE-2024-26659","In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: handle isoc Babble and Buffer Overrun events properly\n\nxHCI 4.9 explicitly forbids assuming that the xHC has released its\nownership of a multi-TRB TD when it reports an error on one of the\nearly TRBs. Yet the driver makes such assumption and releases the TD,\nallowing the remaining TRBs to be freed or overwritten by new TDs.\n\nThe xHC should also report completion of the final TRB due to its IOC\nflag being set by us, regard","2024-04-02T07:15:42.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26659",{"cveId":11133,"releaseId":25,"cycle":26,"description":11134,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11135,"url":11136},{"cveId":11133,"releaseId":31,"cycle":32,"description":11134,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11135,"url":11136},{"cveId":11140,"releaseId":17,"cycle":18,"description":11141,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11142,"url":11143},"CVE-2024-26656","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: fix use-after-free bug\n\nThe bug can be triggered by sending a single amdgpu_gem_userptr_ioctl\nto the AMDGPU DRM driver on any ASICs with an invalid address and size.\nThe bug was reported by Joonkyo Jung \u003Cjoonkyoj@yonsei.ac.kr>.\nFor example the following code:\n\nstatic void Syzkaller1(int fd)\n{\n\tstruct drm_amdgpu_gem_userptr arg;\n\tint ret;\n\n\targ.addr = 0xffffffffffff0000;\n\targ.size = 0x80000000; \u002F*2 Gb*\u002F\n\targ.flags = ","2024-04-02T07:15:42.76+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26656",{"cveId":11140,"releaseId":25,"cycle":26,"description":11141,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11142,"url":11143},{"cveId":11140,"releaseId":31,"cycle":32,"description":11141,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11142,"url":11143},{"cveId":11147,"releaseId":31,"cycle":32,"description":11148,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11149,"url":11150},"CVE-2024-26654","In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: sh: aica: reorder cleanup operations to avoid UAF bugs\n\nThe dreamcastcard->timer could schedule the spu_dma_work and the\nspu_dma_work could also arm the dreamcastcard->timer.\n\nWhen the snd_pcm_substream is closing, the aica_channel will be\ndeallocated. But it could still be dereferenced in the worker\nthread. The reason is that del_timer() will return directly\nregardless of whether the timer handler is running or not and\nt","2024-04-01T09:15:51.063+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26654",{"cveId":11147,"releaseId":25,"cycle":26,"description":11148,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11149,"url":11150},{"cveId":11147,"releaseId":17,"cycle":18,"description":11148,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11149,"url":11150},{"cveId":11154,"releaseId":31,"cycle":32,"description":11155,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11156,"url":11157},"CVE-2023-52628","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nftables: exthdr: fix 4-byte stack OOB write\n\nIf priv->len is a multiple of 4, then dst[len \u002F 4] can write past\nthe destination array which leads to stack corruption.\n\nThis construct is necessary to clean the remainder of the register\nin case ->len is NOT a multiple of the register size, so make it\nconditional just like nft_payload.c does.\n\nThe bug was added in 4.1 cycle and then copied\u002Finherited when\ntcp\u002Fsctp and ip","2024-03-28T08:15:25.98+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52628",{"cveId":11154,"releaseId":17,"cycle":18,"description":11155,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11156,"url":11157},{"cveId":11154,"releaseId":25,"cycle":26,"description":11155,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11156,"url":11157},{"cveId":11161,"releaseId":17,"cycle":18,"description":11162,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11163,"url":11164},"CVE-2024-26646","In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: intel: hfi: Add syscore callbacks for system-wide PM\n\nThe kernel allocates a memory buffer and provides its location to the\nhardware, which uses it to update the HFI table. This allocation occurs\nduring boot and remains constant throughout runtime.\n\nWhen resuming from hibernation, the restore kernel allocates a second\nmemory buffer and reprograms the HFI hardware with the new location as\npart of a normal boot. The loca","2024-03-26T18:15:09.91+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26646",{"cveId":11161,"releaseId":31,"cycle":32,"description":11162,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11163,"url":11164},{"cveId":11161,"releaseId":25,"cycle":26,"description":11162,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11163,"url":11164},{"cveId":11168,"releaseId":17,"cycle":18,"description":11169,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11170,"url":11171},"CVE-2023-52623","In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Fix a suspicious RCU usage warning\n\nI received the following warning while running cthon against an ontap\nserver running pNFS:\n\n[   57.202521] =============================\n[   57.202522] WARNING: suspicious RCU usage\n[   57.202523] 6.7.0-rc3-g2cc14f52aeb7 #41492 Not tainted\n[   57.202525] -----------------------------\n[   57.202525] net\u002Fsunrpc\u002Fxprtmultipath.c:349 RCU-list traversed in non-reader section!!\n[   57.202527","2024-03-26T18:15:08.93+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52623",{"cveId":11168,"releaseId":25,"cycle":26,"description":11169,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11170,"url":11171},{"cveId":11168,"releaseId":31,"cycle":32,"description":11169,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11170,"url":11171},{"cveId":11175,"releaseId":17,"cycle":18,"description":11176,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11177,"url":11178},"CVE-2021-47179","In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return()\n\nCommit de144ff4234f changes _pnfs_return_layout() to call\npnfs_mark_matching_lsegs_return() passing NULL as the struct\npnfs_layout_range argument. Unfortunately,\npnfs_mark_matching_lsegs_return() doesn't check if we have a value here\nbefore dereferencing it, causing an oops.\n\nI'm able to hit this crash consistently when running connectathon basic\ntests ","2024-03-25T10:15:09.317+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47179",{"cveId":11175,"releaseId":31,"cycle":32,"description":11176,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11177,"url":11178},{"cveId":11175,"releaseId":25,"cycle":26,"description":11176,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11177,"url":11178},{"cveId":11182,"releaseId":25,"cycle":26,"description":11183,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11184,"url":11185},"CVE-2021-47168","In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix an incorrect limit in filelayout_decode_layout()\n\nThe \"sizeof(struct nfs_fh)\" is two bytes too large and could lead to\nmemory corruption.  It should be NFS_MAXFHSIZE because that's the size\nof the ->data[] buffer.\n\nI reversed the size of the arguments to put the variable on the left.","2024-03-25T10:15:08.773+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47168",{"cveId":11182,"releaseId":17,"cycle":18,"description":11183,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11184,"url":11185},{"cveId":11182,"releaseId":31,"cycle":32,"description":11183,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11184,"url":11185},{"cveId":11189,"releaseId":31,"cycle":32,"description":11190,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11191,"url":11192},"CVE-2021-47163","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: wait and exit until all work queues are done\n\nOn some host, a crash could be triggered simply by repeating these\ncommands several times:\n\n  # modprobe tipc\n  # tipc bearer enable media udp name UDP1 localip 127.0.0.1\n  # rmmod tipc\n\n  [] BUG: unable to handle kernel paging request at ffffffffc096bb00\n  [] Workqueue: events 0xffffffffc096bb00\n  [] Call Trace:\n  []  ? process_one_work+0x1a7\u002F0x360\n  []  ? worker_thread+0x30\u002F","2024-03-25T10:15:08.53+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47163",{"cveId":11189,"releaseId":17,"cycle":18,"description":11190,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11191,"url":11192},{"cveId":11189,"releaseId":25,"cycle":26,"description":11190,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11191,"url":11192},{"cveId":11196,"releaseId":31,"cycle":32,"description":11197,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11198,"url":11199},"CVE-2021-47162","In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: skb_linearize the head skb when reassembling msgs\n\nIt's not a good idea to append the frag skb to a skb's frag_list if\nthe frag_list already has skbs from elsewhere, such as this skb was\ncreated by pskb_copy() where the frag_list was cloned (all the skbs\nin it were skb_get'ed) and shared by multiple skbs.\n\nHowever, the new appended frag skb should have been only seen by the\ncurrent skb. Otherwise, it will cause use after ","2024-03-25T10:15:08.48+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47162",{"cveId":11196,"releaseId":17,"cycle":18,"description":11197,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11198,"url":11199},{"cveId":11196,"releaseId":25,"cycle":26,"description":11197,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11198,"url":11199},{"cveId":11203,"releaseId":17,"cycle":18,"description":11204,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":11205,"url":11206},"CVE-2021-47160","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mt7530: fix VLAN traffic leaks\n\nPCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but\nwas not reset when it is disabled, which may cause traffic leaks:\n\n\tip link add br0 type bridge vlan_filtering 1\n\tip link add br1 type bridge vlan_filtering 1\n\tip link set swp0 master br0\n\tip link set swp1 master br1\n\tip link set br0 type bridge vlan_filtering 0\n\tip link set br1 type bridge vlan_filtering 0\n\t# traff","2024-03-25T10:15:08.377+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47160",{"cveId":11208,"releaseId":31,"cycle":32,"description":11209,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11210,"url":11211},"CVE-2021-47159","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: fix a crash if ->get_sset_count() fails\n\nIf ds->ops->get_sset_count() fails then it \"count\" is a negative error\ncode such as -EOPNOTSUPP.  Because \"i\" is an unsigned int, the negative\nerror code is type promoted to a very high value and the loop will\ncorrupt memory until the system crashes.\n\nFix this by checking for error codes and changing the type of \"i\" to\njust int.","2024-03-25T10:15:08.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47159",{"cveId":11208,"releaseId":17,"cycle":18,"description":11209,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11210,"url":11211},{"cveId":11208,"releaseId":25,"cycle":26,"description":11209,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11210,"url":11211},{"cveId":11215,"releaseId":31,"cycle":32,"description":11216,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11217,"url":11218},"CVE-2021-47153","In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: i801: Don't generate an interrupt on bus reset\n\nNow that the i2c-i801 driver supports interrupts, setting the KILL bit\nin a attempt to recover from a timed out transaction triggers an\ninterrupt. Unfortunately, the interrupt handler (i801_isr) is not\nprepared for this situation and will try to process the interrupt as\nif it was signaling the end of a successful transaction. In the case\nof a block transaction, this can resul","2024-03-25T09:15:09.407+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47153",{"cveId":11215,"releaseId":17,"cycle":18,"description":11216,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11217,"url":11218},{"cveId":11215,"releaseId":25,"cycle":26,"description":11216,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11217,"url":11218},{"cveId":11222,"releaseId":31,"cycle":32,"description":11223,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11224,"url":11225},"CVE-2021-47142","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Famdgpu: Fix a use-after-free\n\nlooks like we forget to set ttm->sg to NULL.\nHit panic below\n\n[ 1235.844104] general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b7b4b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI\n[ 1235.989074] Call Trace:\n[ 1235.991751]  sg_free_table+0x17\u002F0x20\n[ 1235.995667]  amdgpu_ttm_backend_unbind.cold+0x4d\u002F0xf7 [amdgpu]\n[ 1236.002288]  amdgpu_ttm_backend_destroy+0x29\u002F0x130 [amdgpu]\n[ 1236.","2024-03-25T09:15:08.843+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47142",{"cveId":11222,"releaseId":17,"cycle":18,"description":11223,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11224,"url":11225},{"cveId":11222,"releaseId":25,"cycle":26,"description":11223,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11224,"url":11225},{"cveId":11229,"releaseId":31,"cycle":32,"description":11230,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11231,"url":11232},"CVE-2024-26643","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout\n\nWhile the rhashtable set gc runs asynchronously, a race allows it to\ncollect elements from anonymous sets with timeouts while it is being\nreleased from the commit path.\n\nMingi Cho originally reported this issue in a different path in 6.1.x\nwith a pipapo set with low timeouts which is not possible upstream since\n7395dfacfff6 (\"netfilter: nf_tables:","2024-03-21T11:15:28.34+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26643",{"cveId":11229,"releaseId":25,"cycle":26,"description":11230,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11231,"url":11232},{"cveId":11229,"releaseId":17,"cycle":18,"description":11230,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11231,"url":11232},{"cveId":11236,"releaseId":31,"cycle":32,"description":11237,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11238,"url":11239},"CVE-2024-26642","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: disallow anonymous set with timeout flag\n\nAnonymous sets are never used with timeout from userspace, reject this.\nException to this rule is NFT_SET_EVAL to ensure legacy meters still work.","2024-03-21T11:15:28.293+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26642",{"cveId":11236,"releaseId":25,"cycle":26,"description":11237,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11238,"url":11239},{"cveId":11236,"releaseId":17,"cycle":18,"description":11237,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11238,"url":11239},{"cveId":11243,"releaseId":31,"cycle":32,"description":11244,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11245,"url":11246},"CVE-2023-52620","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: disallow timeout for anonymous sets\n\nNever used from userspace, disallow these parameters.","2024-03-21T11:15:28.23+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52620",{"cveId":11243,"releaseId":17,"cycle":18,"description":11244,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11245,"url":11246},{"cveId":11243,"releaseId":25,"cycle":26,"description":11244,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11245,"url":11246},{"cveId":11250,"releaseId":25,"cycle":26,"description":11251,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":11252,"url":11253},"CVE-2024-26641","In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()\n\nsyzbot found __ip6_tnl_rcv() could access unitiliazed data [1].\n\nCall pskb_inet_may_pull() to fix this, and initialize ipv6h\nvariable after this call as it can change skb->head.\n\n[1]\n BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include\u002Fnet\u002Finet_ecn.h:253 [inline]\n BUG: KMSAN: uninit-value in INET_ECN_decapsulate include\u002Fnet\u002Finet_ecn.h:275 [inline]\n BUG: KMSAN","2024-03-18T11:15:11.193+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26641",{"cveId":11250,"releaseId":17,"cycle":18,"description":11251,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":11252,"url":11253},{"cveId":11250,"releaseId":31,"cycle":32,"description":11251,"severity":40,"cvssScore":1337,"epssScore":9,"inKev":42,"publishedAt":11252,"url":11253},{"cveId":11257,"releaseId":17,"cycle":18,"description":11258,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11259,"url":11260},"CVE-2024-26640","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: add sanity checks to rx zerocopy\n\nTCP rx zerocopy intent is to map pages initially allocated\nfrom NIC drivers, not pages owned by a fs.\n\nThis patch adds to can_map_frag() these additional checks:\n\n- Page must not be a compound one.\n- page->mapping must be NULL.\n\nThis fixes the panic reported by ZhangPeng.\n\nsyzbot was able to loopback packets built with sendfile(),\nmapping pages owned by an ext4 file to TCP rx zerocopy.\n\nr3","2024-03-18T11:15:11.043+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26640",{"cveId":11262,"releaseId":31,"cycle":32,"description":11263,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11264,"url":11265},"CVE-2023-52614","In the Linux kernel, the following vulnerability has been resolved:\n\nPM \u002F devfreq: Fix buffer overflow in trans_stat_show\n\nFix buffer overflow in trans_stat_show().\n\nConvert simple snprintf to the more secure scnprintf with size of\nPAGE_SIZE.\n\nAdd condition checking if we are exceeding PAGE_SIZE and exit early from\nloop. Also add at the end a warning that we exceeded PAGE_SIZE and that\nstats is disabled.\n\nReturn -EFBIG in the case where we don't have enough space to write the\nfull transition tab","2024-03-18T11:15:08.64+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52614",{"cveId":11262,"releaseId":17,"cycle":18,"description":11263,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11264,"url":11265},{"cveId":11262,"releaseId":25,"cycle":26,"description":11263,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11264,"url":11265},{"cveId":11269,"releaseId":25,"cycle":26,"description":11270,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11271,"url":11272},"CVE-2023-52612","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: scomp - fix req->dst buffer overflow\n\nThe req->dst buffer size should be checked before copying from the\nscomp_scratch->dst to avoid req->dst buffer overflow problem.","2024-03-18T11:15:08.317+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52612",{"cveId":11269,"releaseId":17,"cycle":18,"description":11270,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11271,"url":11272},{"cveId":11275,"releaseId":17,"cycle":18,"description":11276,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":11277,"url":11278},"CVE-2021-47131","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Ftls: Fix use-after-free after the TLS device goes down and up\n\nWhen a netdev with active TLS offload goes down, tls_device_down is\ncalled to stop the offload and tear down the TLS context. However, the\nsocket stays alive, and it still points to the TLS context, which is now\ndeallocated. If a netdev goes up, while the connection is still active,\nand the data flow resumes after a number of TCP retransmissions, it will\nlead to","2024-03-15T21:15:07.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47131",{"cveId":11280,"releaseId":25,"cycle":26,"description":11281,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11282,"url":11283},"CVE-2021-47113","In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: abort in rename_exchange if we fail to insert the second ref\n\nError injection stress uncovered a problem where we'd leave a dangling\ninode ref if we failed during a rename_exchange.  This happens because\nwe insert the inode ref for one side of the rename, and then for the\nother side.  If this second inode ref insert fails we'll leave the first\none dangling and leave a corrupt file system behind.  Fix this by\naborting if ","2024-03-15T21:15:06.673+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47113",{"cveId":11280,"releaseId":31,"cycle":32,"description":11281,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11282,"url":11283},{"cveId":11280,"releaseId":17,"cycle":18,"description":11281,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11282,"url":11283},{"cveId":11287,"releaseId":31,"cycle":32,"description":11288,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11289,"url":11290},"CVE-2021-47112","In the Linux kernel, the following vulnerability has been resolved:\n\nx86\u002Fkvm: Teardown PV features on boot CPU as well\n\nVarious PV features (Async PF, PV EOI, steal time) work through memory\nshared with hypervisor and when we restore from hibernation we must\nproperly teardown all these features to make sure hypervisor doesn't\nwrite to stale locations after we jump to the previously hibernated kernel\n(which can try to place anything there). For secondary CPUs the job is\nalready done by kvm_cpu_do","2024-03-15T21:15:06.627+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47112",{"cveId":11287,"releaseId":17,"cycle":18,"description":11288,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11289,"url":11290},{"cveId":11287,"releaseId":25,"cycle":26,"description":11288,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11289,"url":11290},{"cveId":11294,"releaseId":25,"cycle":26,"description":11295,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11296,"url":11297},"CVE-2024-26614","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: make sure init the accept_queue's spinlocks once\n\nWhen I run syz's reproduction C program locally, it causes the following\nissue:\npvqspinlock: lock 0xffff9d181cd5c660 has corrupted value 0x0!\nWARNING: CPU: 19 PID: 21160 at __pv_queued_spin_unlock_slowpath (kernel\u002Flocking\u002Fqspinlock_paravirt.h:508)\nHardware name: Red Hat KVM, BIOS 0.5.1 01\u002F01\u002F2011\nRIP: 0010:__pv_queued_spin_unlock_slowpath (kernel\u002Flocking\u002Fqspinlock_paravirt.","2024-03-11T18:15:19.28+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26614",{"cveId":11294,"releaseId":17,"cycle":18,"description":11295,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11296,"url":11297},{"cveId":11294,"releaseId":31,"cycle":32,"description":11295,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11296,"url":11297},{"cveId":11301,"releaseId":25,"cycle":26,"description":11302,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11303,"url":11304},"CVE-2023-52491","In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_run\n\nIn mtk_jpeg_probe, &jpeg->job_timeout_work is bound with\nmtk_jpeg_job_timeout_work.\n\nIn mtk_jpeg_dec_device_run, if error happens in\nmtk_jpeg_set_dec_dst, it will finally start the worker while\nmark the job as finished by invoking v4l2_m2m_job_finish.\n\nThere are two methods to trigger the bug. If we remove the\nmodule, it which will ca","2024-03-11T18:15:16.807+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52491",{"cveId":11301,"releaseId":17,"cycle":18,"description":11302,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11303,"url":11304},{"cveId":11307,"releaseId":17,"cycle":18,"description":11308,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11309,"url":11310},"CVE-2023-52486","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: Don't unref the same fb many times by mistake due to deadlock handling\n\nIf we get a deadlock after the fb lookup in drm_mode_page_flip_ioctl()\nwe proceed to unref the fb and then retry the whole thing from the top.\nBut we forget to reset the fb pointer back to NULL, and so if we then\nget another error during the retry, before the fb lookup, we proceed\nthe unref the same fb again without having gotten another reference.\nThe","2024-03-11T18:15:16.427+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52486",{"cveId":11307,"releaseId":31,"cycle":32,"description":11308,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11309,"url":11310},{"cveId":11307,"releaseId":25,"cycle":26,"description":11308,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11309,"url":11310},{"cveId":11314,"releaseId":31,"cycle":32,"description":11315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11316,"url":11317},"CVE-2024-26625","In the Linux kernel, the following vulnerability has been resolved:\n\nllc: call sock_orphan() at release time\n\nsyzbot reported an interesting trace [1] caused by a stale sk->sk_wq\npointer in a closed llc socket.\n\nIn commit ff7b11aa481f (\"net: socket: set sock->sk to NULL after\ncalling proto_ops::release()\") Eric Biggers hinted that some protocols\nare missing a sock_orphan(), we need to perform a full audit.\n\nIn net-next, I plan to clear sock->sk from sock_orphan() and\namend Eric patch to add a wa","2024-03-06T07:15:12.587+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26625",{"cveId":11314,"releaseId":17,"cycle":18,"description":11315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11316,"url":11317},{"cveId":11314,"releaseId":25,"cycle":26,"description":11315,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11316,"url":11317},{"cveId":11321,"releaseId":25,"cycle":26,"description":11322,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11323,"url":11324},"CVE-2023-52606","In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc\u002Flib: Validate size for vector operations\n\nSome of the fp\u002Fvmx code in sstep.c assume a certain maximum size for the\ninstructions being emulated. The size of those operations however is\ndetermined separately in analyse_instr().\n\nAdd a check to validate the assumption on the maximum size of the\noperations, so as to prevent any unintended kernel stack corruption.","2024-03-06T07:15:11.75+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52606",{"cveId":11321,"releaseId":17,"cycle":18,"description":11322,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11323,"url":11324},{"cveId":11321,"releaseId":31,"cycle":32,"description":11322,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11323,"url":11324},{"cveId":11328,"releaseId":25,"cycle":26,"description":11329,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11330,"url":11331},"CVE-2023-52604","In the Linux kernel, the following vulnerability has been resolved:\n\nFS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree\n\nSyzkaller reported the following issue:\n\nUBSAN: array-index-out-of-bounds in fs\u002Fjfs\u002Fjfs_dmap.c:2867:6\nindex 196694 is out of range for type 's8[1365]' (aka 'signed char[1365]')\nCPU: 1 PID: 109 Comm: jfsCommit Not tainted 6.6.0-rc3-syzkaller #0\nHardware name: Google Google Compute Engine\u002FGoogle Compute Engine, BIOS Google 08\u002F04\u002F2023\nCall Trace:\n \u003CTASK>\n __dump_stack lib\u002Fdump_s","2024-03-06T07:15:11.347+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52604",{"cveId":11328,"releaseId":31,"cycle":32,"description":11329,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11330,"url":11331},{"cveId":11328,"releaseId":17,"cycle":18,"description":11329,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11330,"url":11331},{"cveId":11335,"releaseId":31,"cycle":32,"description":11336,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11337,"url":11338},"CVE-2023-52603","In the Linux kernel, the following vulnerability has been resolved:\n\nUBSAN: array-index-out-of-bounds in dtSplitRoot\n\nSyzkaller reported the following issue:\n\noop0: detected capacity change from 0 to 32768\n\nUBSAN: array-index-out-of-bounds in fs\u002Fjfs\u002Fjfs_dtree.c:1971:9\nindex -2 is out of range for type 'struct dtslot [128]'\nCPU: 0 PID: 3613 Comm: syz-executor270 Not tainted 6.0.0-syzkaller-09423-g493ffd6605b2 #0\nHardware name: Google Google Compute Engine\u002FGoogle Compute Engine, BIOS Google 09\u002F22\u002F","2024-03-06T07:15:11.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52603",{"cveId":11335,"releaseId":17,"cycle":18,"description":11336,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11337,"url":11338},{"cveId":11335,"releaseId":25,"cycle":26,"description":11336,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11337,"url":11338},{"cveId":11342,"releaseId":25,"cycle":26,"description":11343,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11344,"url":11345},"CVE-2023-52600","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix uaf in jfs_evict_inode\n\nWhen the execution of diMount(ipimap) fails, the object ipimap that has been\nreleased may be accessed in diFreeSpecial(). Asynchronous ipimap release occurs\nwhen rcu_core() calls jfs_free_node().\n\nTherefore, when diMount(ipimap) fails, sbi->ipimap should not be initialized as\nipimap.","2024-03-06T07:15:10.497+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52600",{"cveId":11342,"releaseId":17,"cycle":18,"description":11343,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11344,"url":11345},{"cveId":11342,"releaseId":31,"cycle":32,"description":11343,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11344,"url":11345},{"cveId":11349,"releaseId":31,"cycle":32,"description":11350,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11351,"url":11352},"CVE-2023-52599","In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in diNewExt\n\n[Syz report]\nUBSAN: array-index-out-of-bounds in fs\u002Fjfs\u002Fjfs_imap.c:2360:2\nindex -878706688 is out of range for type 'struct iagctl[128]'\nCPU: 1 PID: 5065 Comm: syz-executor282 Not tainted 6.7.0-rc4-syzkaller-00009-gbee0e7762ad2 #0\nHardware name: Google Google Compute Engine\u002FGoogle Compute Engine, BIOS Google 11\u002F10\u002F2023\nCall Trace:\n \u003CTASK>\n __dump_stack lib\u002Fdump_stack.c:88 [inline]","2024-03-06T07:15:10.21+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52599",{"cveId":11349,"releaseId":17,"cycle":18,"description":11350,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11351,"url":11352},{"cveId":11349,"releaseId":25,"cycle":26,"description":11350,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11351,"url":11352},{"cveId":11356,"releaseId":31,"cycle":32,"description":11357,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11358,"url":11359},"CVE-2023-52590","In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: Avoid touching renamed directory if parent does not change\n\nThe VFS will not be locking moved directory if its parent does not\nchange. Change ocfs2 rename code to avoid touching renamed directory if\nits parent does not change as without locking that can corrupt the\nfilesystem.","2024-03-06T07:15:08.297+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52590",{"cveId":11356,"releaseId":25,"cycle":26,"description":11357,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11358,"url":11359},{"cveId":11356,"releaseId":17,"cycle":18,"description":11357,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11358,"url":11359},{"cveId":11363,"releaseId":25,"cycle":26,"description":11364,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":11365,"url":11366},"CVE-2023-52588","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to tag gcing flag on page during block migration\n\nIt needs to add missing gcing flag on page during block migration,\nin order to garantee migrated data be persisted during checkpoint,\notherwise out-of-order persistency between data and node may cause\ndata corruption after SPOR.\n\nSimilar issue was fixed by commit 2d1fe8a86bf5 (\"f2fs: fix to tag\ngcing flag on page during file defragment\").","2024-03-06T07:15:07.82+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52588",{"cveId":11363,"releaseId":17,"cycle":18,"description":11364,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":11365,"url":11366},{"cveId":11363,"releaseId":31,"cycle":32,"description":11364,"severity":40,"cvssScore":1246,"epssScore":9,"inKev":42,"publishedAt":11365,"url":11366},{"cveId":11370,"releaseId":31,"cycle":32,"description":11371,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11372,"url":11373},"CVE-2023-52586","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm\u002Fmsm\u002Fdpu: Add mutex lock in control vblank irq\n\nAdd a mutex lock to control vblank irq to synchronize vblank\nenable\u002Fdisable operations happening from different threads to prevent\nrace conditions while registering\u002Funregistering the vblank irq callback.\n\nv4: -Removed vblank_ctl_lock from dpu_encoder_virt, so it is only a\n    parameter of dpu_encoder_phys.\n    -Switch from atomic refcnt to a simple int counter as mutex has\n    ","2024-03-06T07:15:07.443+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52586",{"cveId":11370,"releaseId":25,"cycle":26,"description":11371,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11372,"url":11373},{"cveId":11370,"releaseId":17,"cycle":18,"description":11371,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11372,"url":11373},{"cveId":11377,"releaseId":17,"cycle":18,"description":11378,"severity":40,"cvssScore":391,"epssScore":9,"inKev":42,"publishedAt":11379,"url":11380},"CVE-2022-48629","In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qcom-rng - ensure buffer for generate is completely filled\n\nThe generate function in struct rng_alg expects that the destination\nbuffer is completely filled if the function returns 0. qcom_rng_read()\ncan run into a situation where the buffer is partially filled with\nrandomness and the remaining part of the buffer is zeroed since\nqcom_rng_generate() doesn't check the return value. This issue can\nbe reproduced by running ","2024-03-05T12:15:45.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-48629",{"cveId":11382,"releaseId":31,"cycle":32,"description":11383,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11384,"url":11385},"CVE-2021-47103","In the Linux kernel, the following vulnerability has been resolved:\n\ninet: fully convert sk->sk_rx_dst to RCU rules\n\nsyzbot reported various issues around early demux,\none being included in this changelog [1]\n\nsk->sk_rx_dst is using RCU protection without clearly\ndocumenting it.\n\nAnd following sequences in tcp_v4_do_rcv()\u002Ftcp_v6_do_rcv()\nare not following standard RCU rules.\n\n[a]    dst_release(dst);\n[b]    sk->sk_rx_dst = NULL;\n\nThey look wrong because a delete operation of RCU protected\npointe","2024-03-04T18:15:08.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47103",{"cveId":11382,"releaseId":25,"cycle":26,"description":11383,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11384,"url":11385},{"cveId":11382,"releaseId":17,"cycle":18,"description":11383,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11384,"url":11385},{"cveId":11389,"releaseId":31,"cycle":32,"description":11390,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11391,"url":11392},"CVE-2021-47083","In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: mediatek: fix global-out-of-bounds issue\n\nWhen eint virtual eint number is greater than gpio number,\nit maybe produce 'desc[eint_n]' size globle-out-of-bounds issue.","2024-03-04T18:15:07.193+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47083",{"cveId":11389,"releaseId":25,"cycle":26,"description":11390,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11391,"url":11392},{"cveId":11389,"releaseId":17,"cycle":18,"description":11390,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11391,"url":11392},{"cveId":11396,"releaseId":31,"cycle":32,"description":11397,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11398,"url":11399},"CVE-2021-47082","In the Linux kernel, the following vulnerability has been resolved:\n\ntun: avoid double free in tun_free_netdev\n\nAvoid double free in tun_free_netdev() by moving the\ndev->tstats and tun->security allocs to a new ndo_init routine\n(tun_net_init()) that will be called by register_netdevice().\nndo_init is paired with the desctructor (tun_free_netdev()),\nso if there's an error in register_netdevice() the destructor\nwill handle the frees.\n\nBUG: KASAN: double-free or invalid-free in selinux_tun_dev_free","2024-03-04T18:15:07.12+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47082",{"cveId":11396,"releaseId":25,"cycle":26,"description":11397,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11398,"url":11399},{"cveId":11396,"releaseId":17,"cycle":18,"description":11397,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11398,"url":11399},{"cveId":11403,"releaseId":31,"cycle":32,"description":11404,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11405,"url":11406},"CVE-2023-52574","In the Linux kernel, the following vulnerability has been resolved:\n\nteam: fix null-ptr-deref when team device type is changed\n\nGet a null-ptr-deref bug as follows with reproducer [1].\n\nBUG: kernel NULL pointer dereference, address: 0000000000000228\n...\nRIP: 0010:vlan_dev_hard_header+0x35\u002F0x140 [8021q]\n...\nCall Trace:\n \u003CTASK>\n ? __die+0x24\u002F0x70\n ? page_fault_oops+0x82\u002F0x150\n ? exc_page_fault+0x69\u002F0x150\n ? asm_exc_page_fault+0x26\u002F0x30\n ? vlan_dev_hard_header+0x35\u002F0x140 [8021q]\n ? vlan_dev_hard_he","2024-03-02T22:15:49.393+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52574",{"cveId":11403,"releaseId":17,"cycle":18,"description":11404,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11405,"url":11406},{"cveId":11403,"releaseId":25,"cycle":26,"description":11404,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11405,"url":11406},{"cveId":11410,"releaseId":31,"cycle":32,"description":11411,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11412,"url":11413},"CVE-2023-52572","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix UAF in cifs_demultiplex_thread()\n\nThere is a UAF when xfstests on cifs:\n\n  BUG: KASAN: use-after-free in smb2_is_network_name_deleted+0x27\u002F0x160\n  Read of size 4 at addr ffff88810103fc08 by task cifsd\u002F923\n\n  CPU: 1 PID: 923 Comm: cifsd Not tainted 6.1.0-rc4+ #45\n  ...\n  Call Trace:\n   \u003CTASK>\n   dump_stack_lvl+0x34\u002F0x44\n   print_report+0x171\u002F0x472\n   kasan_report+0xad\u002F0x130\n   kasan_check_range+0x145\u002F0x1a0\n   smb2_is_n","2024-03-02T22:15:49.3+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52572",{"cveId":11410,"releaseId":25,"cycle":26,"description":11411,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11412,"url":11413},{"cveId":11410,"releaseId":17,"cycle":18,"description":11411,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11412,"url":11413},{"cveId":11417,"releaseId":17,"cycle":18,"description":11418,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11419,"url":11420},"CVE-2023-52530","In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix potential key use-after-free\n\nWhen ieee80211_key_link() is called by ieee80211_gtk_rekey_add()\nbut returns 0 due to KRACK protection (identical key reinstall),\nieee80211_gtk_rekey_add() will still return a pointer into the\nkey, in a potential use-after-free. This normally doesn't happen\nsince it's only called by iwlwifi in case of WoWLAN rekey offload\nwhich has its own KRACK protection, but still better to f","2024-03-02T22:15:48.567+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52530",{"cveId":11417,"releaseId":25,"cycle":26,"description":11418,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11419,"url":11420},{"cveId":11423,"releaseId":31,"cycle":32,"description":11424,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11425,"url":11426},"CVE-2023-52522","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix possible store tearing in neigh_periodic_work()\n\nWhile looking at a related syzbot report involving neigh_periodic_work(),\nI found that I forgot to add an annotation when deleting an\nRCU protected item from a list.\n\nReaders use rcu_deference(*np), we need to use either\nrcu_assign_pointer() or WRITE_ONCE() on writer side\nto prevent store tearing.\n\nI use rcu_assign_pointer() to have lockdep support,\nthis was the choice m","2024-03-02T22:15:48.17+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52522",{"cveId":11423,"releaseId":25,"cycle":26,"description":11424,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11425,"url":11426},{"cveId":11423,"releaseId":17,"cycle":18,"description":11424,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11425,"url":11426},{"cveId":11430,"releaseId":31,"cycle":32,"description":11431,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11432,"url":11433},"CVE-2023-52517","In the Linux kernel, the following vulnerability has been resolved:\n\nspi: sun6i: fix race between DMA RX transfer completion and RX FIFO drain\n\nPreviously the transfer complete IRQ immediately drained to RX FIFO to\nread any data remaining in FIFO to the RX buffer. This behaviour is\ncorrect when dealing with SPI in interrupt mode. However in DMA mode the\ntransfer complete interrupt still fires as soon as all bytes to be\ntransferred have been stored in the FIFO. At that point data in the FIFO\nstil","2024-03-02T22:15:47.923+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52517",{"cveId":11430,"releaseId":17,"cycle":18,"description":11431,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11432,"url":11433},{"cveId":11430,"releaseId":25,"cycle":26,"description":11431,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11432,"url":11433},{"cveId":11437,"releaseId":31,"cycle":32,"description":11438,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11439,"url":11440},"CVE-2023-52515","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Fsrp: Do not call scsi_done() from srp_abort()\n\nAfter scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler\ncallback, it performs one of the following actions:\n* Call scsi_queue_insert().\n* Call scsi_finish_command().\n* Call scsi_eh_scmd_add().\nHence, SCSI abort handlers must not call scsi_done(). Otherwise all\nthe above actions would trigger a use-after-free. Hence remove the\nscsi_done() call from srp_abort(). K","2024-03-02T22:15:47.823+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52515",{"cveId":11437,"releaseId":25,"cycle":26,"description":11438,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11439,"url":11440},{"cveId":11437,"releaseId":17,"cycle":18,"description":11438,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11439,"url":11440},{"cveId":11444,"releaseId":31,"cycle":32,"description":11445,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11446,"url":11447},"CVE-2023-52509","In the Linux kernel, the following vulnerability has been resolved:\n\nravb: Fix use-after-free issue in ravb_tx_timeout_work()\n\nThe ravb_stop() should call cancel_work_sync(). Otherwise,\nravb_tx_timeout_work() is possible to use the freed priv after\nravb_remove() was called like below:\n\nCPU0\t\t\tCPU1\n\t\t\travb_tx_timeout()\nravb_remove()\nunregister_netdev()\nfree_netdev(ndev)\n\u002F\u002F free priv\n\t\t\travb_tx_timeout_work()\n\t\t\t\u002F\u002F use priv\n\nunregister_netdev() will call .ndo_stop() so that ravb_stop() is\ncalled. ","2024-03-02T22:15:47.54+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52509",{"cveId":11444,"releaseId":25,"cycle":26,"description":11445,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11446,"url":11447},{"cveId":11444,"releaseId":17,"cycle":18,"description":11445,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11446,"url":11447},{"cveId":11451,"releaseId":31,"cycle":32,"description":11452,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11453,"url":11454},"CVE-2023-52502","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn()\n\nSili Luo reported a race in nfc_llcp_sock_get(), leading to UAF.\n\nGetting a reference on the socket found in a lookup while\nholding a lock should happen before releasing the lock.\n\nnfc_llcp_sock_get_sn() has a similar problem.\n\nFinally nfc_llcp_recv_snl() needs to make sure the socket\nfound by nfc_llcp_sock_from_sn() does not disappear.","2024-03-02T22:15:47.203+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52502",{"cveId":11451,"releaseId":25,"cycle":26,"description":11452,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11453,"url":11454},{"cveId":11451,"releaseId":17,"cycle":18,"description":11452,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11453,"url":11454},{"cveId":11458,"releaseId":17,"cycle":18,"description":11459,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11460,"url":11461},"CVE-2021-47078","In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA\u002Frxe: Clear all QP fields if creation failed\n\nrxe_qp_do_cleanup() relies on valid pointer values in QP for the properly\ncreated ones, but in case rxe_qp_from_init() failed it was filled with\ngarbage and caused tot the following error.\n\n  refcount_t: underflow; use-after-free.\n  WARNING: CPU: 1 PID: 12560 at lib\u002Frefcount.c:28 refcount_warn_saturate+0x1d1\u002F0x1e0 lib\u002Frefcount.c:28\n  Modules linked in:\n  CPU: 1 PID: 12560 Comm: ","2024-03-01T22:15:47.333+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47078",{"cveId":11458,"releaseId":25,"cycle":26,"description":11459,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11460,"url":11461},{"cveId":11458,"releaseId":31,"cycle":32,"description":11459,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11460,"url":11461},{"cveId":11465,"releaseId":25,"cycle":26,"description":11466,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11467,"url":11468},"CVE-2021-47055","In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: require write permissions for locking and badblock ioctls\n\nMEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus require\nwrite permission. Depending on the hardware MEMLOCK might even be\nwrite-once, e.g. for SPI-NOR flashes with their WP# tied to GND. OTPLOCK\nis always write-once.\n\nMEMSETBADBLOCK modifies the bad block table.","2024-02-29T23:15:07.473+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47055",{"cveId":11465,"releaseId":17,"cycle":18,"description":11466,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11467,"url":11468},{"cveId":11465,"releaseId":31,"cycle":32,"description":11466,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11467,"url":11468},{"cveId":11472,"releaseId":31,"cycle":32,"description":11473,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11474,"url":11475},"CVE-2023-52479","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix uaf in smb20_oplock_break_ack\n\ndrop reference after use opinfo.","2024-02-29T06:15:45.973+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52479",{"cveId":11472,"releaseId":25,"cycle":26,"description":11473,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11474,"url":11475},{"cveId":11472,"releaseId":17,"cycle":18,"description":11473,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11474,"url":11475},{"cveId":11479,"releaseId":25,"cycle":26,"description":11480,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11481,"url":11482},"CVE-2023-52478","In the Linux kernel, the following vulnerability has been resolved:\n\nHID: logitech-hidpp: Fix kernel crash on receiver USB disconnect\n\nhidpp_connect_event() has *four* time-of-check vs time-of-use (TOCTOU)\nraces when it races with itself.\n\nhidpp_connect_event() primarily runs from a workqueue but it also runs\non probe() and if a \"device-connected\" packet is received by the hw\nwhen the thread running hidpp_connect_event() from probe() is waiting on\nthe hw, then a second thread running hidpp_conne","2024-02-29T06:15:45.92+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52478",{"cveId":11479,"releaseId":17,"cycle":18,"description":11480,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11481,"url":11482},{"cveId":11479,"releaseId":31,"cycle":32,"description":11480,"severity":40,"cvssScore":67,"epssScore":9,"inKev":42,"publishedAt":11481,"url":11482},{"cveId":11486,"releaseId":17,"cycle":18,"description":11487,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":11488,"url":11489},"CVE-2021-47049","In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: Use after free in __vmbus_open()\n\nThe \"open_info\" variable is added to the &vmbus_connection.chn_msg_list,\nbut the error handling frees \"open_info\" without removing it from the\nlist.  This will result in a use after free.  First remove it from the\nlist, and then free it.","2024-02-28T09:15:40.417+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47049",{"cveId":11486,"releaseId":25,"cycle":26,"description":11487,"severity":40,"cvssScore":164,"epssScore":9,"inKev":42,"publishedAt":11488,"url":11489},{"cveId":11492,"releaseId":31,"cycle":32,"description":11493,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11494,"url":11495},"CVE-2021-47013","In the Linux kernel, the following vulnerability has been resolved:\n\nnet:emac\u002Femac-mac: Fix a use after free in emac_mac_tx_buf_send\n\nIn emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..).\nIf some error happens in emac_tx_fill_tpd(), the skb will be freed via\ndev_kfree_skb(skb) in error branch of emac_tx_fill_tpd().\nBut the freed skb is still used via skb->len by netdev_sent_queue(,skb->len).\n\nAs i observed that emac_tx_fill_tpd() haven't modified the value of skb->len,\nthus my patch ass","2024-02-28T09:15:38.8+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-47013",{"cveId":11492,"releaseId":17,"cycle":18,"description":11493,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11494,"url":11495},{"cveId":11492,"releaseId":25,"cycle":26,"description":11493,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11494,"url":11495},{"cveId":11499,"releaseId":17,"cycle":18,"description":11500,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11501,"url":11502},"CVE-2021-46999","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: do asoc update earlier in sctp_sf_do_dupcook_a\n\nThere's a panic that occurs in a few of envs, the call trace is as below:\n\n  [] general protection fault, ... 0x29acd70f1000a: 0000 [#1] SMP PTI\n  [] RIP: 0010:sctp_ulpevent_notify_peer_addr_change+0x4b\u002F0x1fa [sctp]\n  []  sctp_assoc_control_transport+0x1b9\u002F0x210 [sctp]\n  []  sctp_do_8_2_transport_strike.isra.16+0x15c\u002F0x220 [sctp]\n  []  sctp_cmd_interpreter.isra.21+0x1231\u002F0x1","2024-02-28T09:15:38.13+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46999",{"cveId":11504,"releaseId":17,"cycle":18,"description":11505,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11506,"url":11507},"CVE-2021-46998","In the Linux kernel, the following vulnerability has been resolved:\n\nethernet:enic: Fix a use after free bug in enic_hard_start_xmit\n\nIn enic_hard_start_xmit, it calls enic_queue_wq_skb(). Inside\nenic_queue_wq_skb, if some error happens, the skb will be freed\nby dev_kfree_skb(skb). But the freed skb is still used in\nskb_tx_timestamp(skb).\n\nMy patch makes enic_queue_wq_skb() return error and goto spin_unlock()\nincase of error. The solution is provided by Govind.\nSee https:\u002F\u002Flkml.org\u002Flkml\u002F2021\u002F4\u002F3","2024-02-28T09:15:38.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46998",{"cveId":11509,"releaseId":25,"cycle":26,"description":11510,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11511,"url":11512},"CVE-2021-46992","In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nftables: avoid overflows in nft_hash_buckets()\n\nNumber of buckets being stored in 32bit variables, we have to\nensure that no overflows occur in nft_hash_buckets()\n\nsyzbot injected a size == 0x40000000 and reported:\n\nUBSAN: shift-out-of-bounds in .\u002Finclude\u002Flinux\u002Flog2.h:57:13\nshift exponent 64 is too large for 64-bit type 'long unsigned int'\nCPU: 1 PID: 29539 Comm: syz-executor.4 Not tainted 5.12.0-rc7-syzkaller #0\nHa","2024-02-28T09:15:37.833+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46992",{"cveId":11509,"releaseId":31,"cycle":32,"description":11510,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11511,"url":11512},{"cveId":11509,"releaseId":17,"cycle":18,"description":11510,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11511,"url":11512},{"cveId":11516,"releaseId":17,"cycle":18,"description":11517,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11518,"url":11519},"CVE-2021-46989","In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: prevent corruption in shrinking truncate\n\nI believe there are some issues introduced by commit 31651c607151\n(\"hfsplus: avoid deadlock on file truncation\")\n\nHFS+ has extent records which always contains 8 extents.  In case the\nfirst extent record in catalog file gets full, new ones are allocated from\nextents overflow file.\n\nIn case shrinking truncate happens to middle of an extent record which\nlocates in extents overflo","2024-02-28T09:15:37.687+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46989",{"cveId":11521,"releaseId":17,"cycle":18,"description":11522,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11523,"url":11524},"CVE-2021-46984","In the Linux kernel, the following vulnerability has been resolved:\n\nkyber: fix out of bounds access when preempted\n\n__blk_mq_sched_bio_merge() gets the ctx and hctx for the current CPU and\npasses the hctx to ->bio_merge(). kyber_bio_merge() then gets the ctx\nfor the current CPU again and uses that to get the corresponding Kyber\ncontext in the passed hctx. However, the thread may be preempted between\nthe two calls to blk_mq_get_ctx(), and the ctx returned the second time\nmay no longer correspond","2024-02-28T09:15:37.45+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46984",{"cveId":11526,"releaseId":17,"cycle":18,"description":11527,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11528,"url":11529},"CVE-2021-46974","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix masking negation logic upon negative dst register\n\nThe negation logic for the case where the off_reg is sitting in the\ndst register is not correct given then we cannot just invert the add\nto a sub or vice versa. As a fix, perform the final bitwise and-op\nunconditionally into AX from the off_reg, then move the pointer from\nthe src to dst and finally use AX as the source for the original\npointer arithmetic operation such","2024-02-27T19:04:07.5+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46974",{"cveId":11526,"releaseId":25,"cycle":26,"description":11527,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11528,"url":11529},{"cveId":11532,"releaseId":17,"cycle":18,"description":11533,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11534,"url":11535},"CVE-2021-46963","In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()\n\n    RIP: 0010:kmem_cache_free+0xfa\u002F0x1b0\n    Call Trace:\n       qla2xxx_mqueuecommand+0x2b5\u002F0x2c0 [qla2xxx]\n       scsi_queue_rq+0x5e2\u002F0xa40\n       __blk_mq_try_issue_directly+0x128\u002F0x1d0\n       blk_mq_request_issue_directly+0x4e\u002F0xb0\n\nFix incorrect call to free srb in qla2xxx_mqueuecommand(), as srb is now\nallocated by upper layers. This fixes smatch warning of srb unintende","2024-02-27T19:04:07+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46963",{"cveId":11537,"releaseId":25,"cycle":26,"description":11538,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11539,"url":11540},"CVE-2021-46960","In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Return correct error code from smb2_get_enc_key\n\nAvoid a warning if the error percolates back up:\n\n[440700.376476] CIFS VFS: \\\\otters.example.com crypt_message: Could not get encryption key\n[440700.386947] ------------[ cut here ]------------\n[440700.386948] err = 1\n[440700.386977] WARNING: CPU: 11 PID: 2733 at \u002Fbuild\u002Flinux-hwe-5.4-p6lk6L\u002Flinux-hwe-5.4-5.4.0\u002Flib\u002Ferrseq.c:74 errseq_set+0x5c\u002F0x70\n...\n[440700.397304] CPU: 11","2024-02-27T19:04:06.86+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46960",{"cveId":11537,"releaseId":17,"cycle":18,"description":11538,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11539,"url":11540},{"cveId":11543,"releaseId":25,"cycle":26,"description":11544,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":11545,"url":11546},"CVE-2021-46955","In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: fix stack OOB read while fragmenting IPv4 packets\n\nrunning openvswitch on kernels built with KASAN, it's possible to see the\nfollowing splat while testing fragmentation of IPv4 packets:\n\n BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03\u002F0x1f60\n Read of size 1 at addr ffff888112fc713c by task handler2\u002F1367\n\n CPU: 0 PID: 1367 Comm: handler2 Not tainted 5.12.0-rc6+ #418\n Hardware name: Red Hat KVM, BIOS 1.11.1","2024-02-27T19:04:06.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46955",{"cveId":11543,"releaseId":17,"cycle":18,"description":11544,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":11545,"url":11546},{"cveId":11543,"releaseId":31,"cycle":32,"description":11544,"severity":40,"cvssScore":341,"epssScore":9,"inKev":42,"publishedAt":11545,"url":11546},{"cveId":11550,"releaseId":31,"cycle":32,"description":11551,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11552,"url":11553},"CVE-2021-46936","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix use-after-free in tw_timer_handler\n\nA real world panic issue was found as follow in Linux 5.4.\n\n    BUG: unable to handle page fault for address: ffffde49a863de28\n    PGD 7e6fe62067 P4D 7e6fe62067 PUD 7e6fe63067 PMD f51e064067 PTE 0\n    RIP: 0010:tw_timer_handler+0x20\u002F0x40\n    Call Trace:\n     \u003CIRQ>\n     call_timer_fn+0x2b\u002F0x120\n     run_timer_softirq+0x1ef\u002F0x450\n     __do_softirq+0x10d\u002F0x2b8\n     irq_exit+0xc7\u002F0xd0\n  ","2024-02-27T10:15:08.017+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46936",{"cveId":11550,"releaseId":17,"cycle":18,"description":11551,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11552,"url":11553},{"cveId":11550,"releaseId":25,"cycle":26,"description":11551,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11552,"url":11553},{"cveId":11557,"releaseId":25,"cycle":26,"description":11558,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11559,"url":11560},"CVE-2021-46933","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear.\n\nffs_data_clear is indirectly called from both ffs_fs_kill_sb and\nffs_ep0_release, so it ends up being called twice when userland closes ep0\nand then unmounts f_fs.\nIf userland provided an eventfd along with function's USB descriptors, it\nends up calling eventfd_ctx_put as many times, causing a refcount\nunderflow.\nNULL-ify ffs_eventfd to prevent these extraneous eventfd_ct","2024-02-27T10:15:07.807+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46933",{"cveId":11557,"releaseId":31,"cycle":32,"description":11558,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11559,"url":11560},{"cveId":11557,"releaseId":17,"cycle":18,"description":11558,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11559,"url":11560},{"cveId":11564,"releaseId":17,"cycle":18,"description":11565,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11566,"url":11567},"CVE-2021-46929","In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: use call_rcu to free endpoint\n\nThis patch is to delay the endpoint free by calling call_rcu() to fix\nanother use-after-free issue in sctp_sock_dump():\n\n  BUG: KASAN: use-after-free in __lock_acquire+0x36d9\u002F0x4c20\n  Call Trace:\n    __lock_acquire+0x36d9\u002F0x4c20 kernel\u002Flocking\u002Flockdep.c:3218\n    lock_acquire+0x1ed\u002F0x520 kernel\u002Flocking\u002Flockdep.c:3844\n    __raw_spin_lock_bh include\u002Flinux\u002Fspinlock_api_smp.h:135 [inline]\n    _ra","2024-02-27T10:15:07.573+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46929",{"cveId":11564,"releaseId":25,"cycle":26,"description":11565,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11566,"url":11567},{"cveId":11570,"releaseId":25,"cycle":26,"description":11571,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11572,"url":11573},"CVE-2021-46925","In the Linux kernel, the following vulnerability has been resolved:\n\nnet\u002Fsmc: fix kernel panic caused by race of smc_sock\n\nA crash occurs when smc_cdc_tx_handler() tries to access smc_sock\nbut smc_release() has already freed it.\n\n[ 4570.695099] BUG: unable to handle page fault for address: 000000002eae9e88\n[ 4570.696048] #PF: supervisor write access in kernel mode\n[ 4570.696728] #PF: error_code(0x0002) - not-present page\n[ 4570.697401] PGD 0 P4D 0\n[ 4570.697716] Oops: 0002 [#1] PREEMPT SMP NOPTI","2024-02-27T10:15:07.237+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46925",{"cveId":11570,"releaseId":17,"cycle":18,"description":11571,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11572,"url":11573},{"cveId":11576,"releaseId":17,"cycle":18,"description":11577,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11578,"url":11579},"CVE-2021-46921","In the Linux kernel, the following vulnerability has been resolved:\n\nlocking\u002Fqrwlock: Fix ordering in queued_write_lock_slowpath()\n\nWhile this code is executed with the wait_lock held, a reader can\nacquire the lock without holding wait_lock.  The writer side loops\nchecking the value with the atomic_cond_read_acquire(), but only truly\nacquires the lock when the compare-and-exchange is completed\nsuccessfully which isn’t ordered. This exposes the window between the\nacquire and the cmpxchg to an A-B","2024-02-27T10:15:06.99+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-46921",{"cveId":11581,"releaseId":25,"cycle":26,"description":11582,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11583,"url":11584},"CVE-2023-52474","In the Linux kernel, the following vulnerability has been resolved:\n\nIB\u002Fhfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests\n\nhfi1 user SDMA request processing has two bugs that can cause data\ncorruption for user SDMA requests that have multiple payload iovecs\nwhere an iovec other than the tail iovec does not run up to the page\nboundary for the buffer pointed to by that iovec.a\n\nHere are the specific bugs:\n1. user_sdma_txadd() does not use struct user_sdma_iovec->iov.iov_len.\n   ","2024-02-26T18:15:07.237+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52474",{"cveId":11581,"releaseId":17,"cycle":18,"description":11582,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11583,"url":11584},{"cveId":11581,"releaseId":31,"cycle":32,"description":11582,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11583,"url":11584},{"cveId":11588,"releaseId":25,"cycle":26,"description":11589,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11590,"url":11591},"CVE-2019-25162","In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: Fix a potential use after free\n\nFree the adap structure only after we are done using it.\nThis patch just moves the put_device() down a bit to avoid the\nuse after free.\n\n[wsa: added comment to the code, added Fixes tag]","2024-02-26T18:15:07.043+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2019-25162",{"cveId":11588,"releaseId":17,"cycle":18,"description":11589,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11590,"url":11591},{"cveId":11588,"releaseId":31,"cycle":32,"description":11589,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11590,"url":11591},{"cveId":11595,"releaseId":17,"cycle":18,"description":11596,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":11597,"url":11598},"CVE-2019-25160","In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: fix out-of-bounds memory accesses\n\nThere are two array out-of-bounds memory accesses, one in\ncipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk().  Both\nerrors are embarassingly simple, and the fixes are straightforward.\n\nAs a FYI for anyone backporting this patch to kernels prior to v4.8,\nyou'll want to apply the netlbl_bitmap_walk() patch to\ncipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before\n","2024-02-26T18:15:06.93+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2019-25160",{"cveId":11595,"releaseId":31,"cycle":32,"description":11596,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":11597,"url":11598},{"cveId":11595,"releaseId":25,"cycle":26,"description":11596,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":11597,"url":11598},{"cveId":11602,"releaseId":17,"cycle":18,"description":11603,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11604,"url":11605},"CVE-2024-26601","In the Linux kernel, the following vulnerability has been resolved:\n\next4: regenerate buddy after block freeing failed if under fc replay\n\nThis mostly reverts commit 6bd97bf273bd (\"ext4: remove redundant\nmb_regenerate_buddy()\") and reintroduces mb_regenerate_buddy(). Based on\ncode in mb_free_blocks(), fast commit replay can end up marking as free\nblocks that are already marked as such. This causes corruption of the\nbuddy bitmap so we need to regenerate it in that case.","2024-02-26T16:27:59.987+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26601",{"cveId":11602,"releaseId":31,"cycle":32,"description":11603,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11604,"url":11605},{"cveId":11602,"releaseId":25,"cycle":26,"description":11603,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11604,"url":11605},{"cveId":11609,"releaseId":25,"cycle":26,"description":11610,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11611,"url":11612},"CVE-2023-52469","In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers\u002Famd\u002Fpm: fix a use-after-free in kv_parse_power_table\n\nWhen ps allocated by kzalloc equals to NULL, kv_parse_power_table\nfrees adev->pm.dpm.ps that allocated before. However, after the control\nflow goes through the following call chains:\n\nkv_parse_power_table\n  |-> kv_dpm_init\n        |-> kv_dpm_sw_init\n\t      |-> kv_dpm_fini\n\nThe adev->pm.dpm.ps is used in the for loop of kv_dpm_fini after its\nfirst free in kv_parse_pow","2024-02-26T16:27:48.767+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52469",{"cveId":11609,"releaseId":17,"cycle":18,"description":11610,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11611,"url":11612},{"cveId":11609,"releaseId":31,"cycle":32,"description":11610,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11611,"url":11612},{"cveId":11616,"releaseId":17,"cycle":18,"description":11617,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11618,"url":11619},"CVE-2024-26597","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qualcomm: rmnet: fix global oob in rmnet_policy\n\nThe variable rmnet_link_ops assign a *bigger* maxtype which leads to a\nglobal out-of-bounds read when parsing the netlink attributes. See bug\ntrace below:\n\n==================================================================\nBUG: KASAN: global-out-of-bounds in validate_nla lib\u002Fnlattr.c:386 [inline]\nBUG: KASAN: global-out-of-bounds in __nla_validate_parse+0x24af\u002F0x2750 lib\u002Fnlat","2024-02-23T15:15:09.557+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26597",{"cveId":11621,"releaseId":25,"cycle":26,"description":11622,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":11623,"url":11624},"CVE-2024-26594","In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate mech token in session setup\n\nIf client send invalid mech token in session setup request, ksmbd\nvalidate and make the error if it is invalid.","2024-02-23T14:15:45.15+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26594",{"cveId":11621,"releaseId":17,"cycle":18,"description":11622,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":11623,"url":11624},{"cveId":11621,"releaseId":31,"cycle":32,"description":11622,"severity":101,"cvssScore":469,"epssScore":9,"inKev":42,"publishedAt":11623,"url":11624},{"cveId":11628,"releaseId":17,"cycle":18,"description":11629,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11630,"url":11631},"CVE-2024-26586","In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_acl_tcam: Fix stack corruption\n\nWhen tc filters are first added to a net device, the corresponding local\nport gets bound to an ACL group in the device. The group contains a list\nof ACLs. In turn, each ACL points to a different TCAM region where the\nfilters are stored. During forwarding, the ACLs are sequentially\nevaluated until a match is found.\n\nOne reason to place filters in different regions is when they are ","2024-02-22T17:15:08.89+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26586",{"cveId":11633,"releaseId":25,"cycle":26,"description":11634,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11635,"url":11636},"CVE-2023-52444","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid dirent corruption\n\nAs Al reported in link[1]:\n\nf2fs_rename()\n...\n\tif (old_dir != new_dir && !whiteout)\n\t\tf2fs_set_link(old_inode, old_dir_entry,\n\t\t\t\t\told_dir_page, new_dir);\n\telse\n\t\tf2fs_put_page(old_dir_page, 0);\n\nYou want correct inumber in the \"..\" link.  And cross-directory\nrename does move the source to new parent, even if you'd been asked\nto leave a whiteout in the old place.\n\n[1] https:\u002F\u002Flore.kernel.or","2024-02-22T17:15:08.43+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52444",{"cveId":11633,"releaseId":17,"cycle":18,"description":11634,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11635,"url":11636},{"cveId":11633,"releaseId":31,"cycle":32,"description":11634,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11635,"url":11636},{"cveId":11640,"releaseId":17,"cycle":18,"description":11641,"severity":101,"cvssScore":102,"epssScore":9,"inKev":42,"publishedAt":11642,"url":11643},"CVE-2024-26584","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: handle backlogging of crypto requests\n\nSince we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our\nrequests to the crypto API, crypto_aead_{encrypt,decrypt} can return\n -EBUSY instead of -EINPROGRESS in valid situations. For example, when\nthe cryptd queue for AESNI is full (easy to trigger with an\nartificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued\nto the backlog but still processed. In that cas","2024-02-21T15:15:09.42+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-26584",{"cveId":11645,"releaseId":17,"cycle":18,"description":11646,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11647,"url":11648},"CVE-2023-52439","In the Linux kernel, the following vulnerability has been resolved:\n\nuio: Fix use-after-free in uio_open\n\ncore-1\t\t\t\tcore-2\n-------------------------------------------------------\nuio_unregister_device\t\tuio_open\n\t\t\t\tidev = idr_find()\ndevice_unregister(&idev->dev)\nput_device(&idev->dev)\nuio_device_release\n\t\t\t\tget_device(&idev->dev)\nkfree(idev)\nuio_free_minor(minor)\n\t\t\t\tuio_release\n\t\t\t\tput_device(&idev->dev)\n\t\t\t\tkfree(idev)\n-------------------------------------------------------\n\nIn the core-1 uio_","2024-02-20T21:15:08.213+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52439",{"cveId":11650,"releaseId":17,"cycle":18,"description":11651,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11652,"url":11653},"CVE-2023-52436","In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: explicitly null-terminate the xattr list\n\nWhen setting an xattr, explicitly null-terminate the xattr list.  This\neliminates the fragile assumption that the unused xattr space is always\nzeroed.","2024-02-20T21:15:08.06+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-52436",{"cveId":11650,"releaseId":31,"cycle":32,"description":11651,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11652,"url":11653},{"cveId":11650,"releaseId":25,"cycle":26,"description":11651,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11652,"url":11653},{"cveId":11657,"releaseId":31,"cycle":32,"description":11658,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11659,"url":11660},"CVE-2024-0639","A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net\u002Fsctp\u002Fsocket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system.","2024-01-17T16:15:46.81+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-0639",{"cveId":11657,"releaseId":25,"cycle":26,"description":11658,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11659,"url":11660},{"cveId":11657,"releaseId":17,"cycle":18,"description":11658,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11659,"url":11660},{"cveId":11664,"releaseId":17,"cycle":18,"description":11665,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11666,"url":11667},"CVE-2023-4244","A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\n\n\nDue to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability.\n\n\n\nWe recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8.","2023-09-06T14:15:11.877+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-4244",{"cveId":11664,"releaseId":31,"cycle":32,"description":11665,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11666,"url":11667},{"cveId":11664,"releaseId":25,"cycle":26,"description":11665,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11666,"url":11667},{"cveId":11671,"releaseId":31,"cycle":32,"description":11672,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":11673,"url":11674},"CVE-2023-3640","A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in \u002Farch\u002Fx86\u002Fmm\u002Fcpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. This is","2023-07-24T16:15:13.063+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-3640",{"cveId":11671,"releaseId":25,"cycle":26,"description":11672,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":11673,"url":11674},{"cveId":11671,"releaseId":17,"cycle":18,"description":11672,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":11673,"url":11674},{"cveId":11678,"releaseId":17,"cycle":18,"description":11679,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11680,"url":11681},"CVE-2023-3609","A use-after-free vulnerability in the Linux kernel's net\u002Fsched: cls_u32 component can be exploited to achieve local privilege escalation.\n\n\n\nIf tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.\n\n\n\nWe recommend upgrading past commit 04c55383fa","2023-07-21T21:15:11.743+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-3609",{"cveId":11678,"releaseId":25,"cycle":26,"description":11679,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11680,"url":11681},{"cveId":11684,"releaseId":31,"cycle":32,"description":11685,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11686,"url":11687},"CVE-2023-3390","A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net\u002Fnetfilter\u002Fnf_tables_api.c.\n\nMishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue.\n\nWe recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97","2023-06-28T21:15:10.447+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-3390",{"cveId":11684,"releaseId":17,"cycle":18,"description":11685,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11686,"url":11687},{"cveId":11684,"releaseId":25,"cycle":26,"description":11685,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11686,"url":11687},{"cveId":11691,"releaseId":17,"cycle":18,"description":11692,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11693,"url":11694},"CVE-2023-1829","A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root.\n\n\nWe recommend upgrading past commit   8c710f75256bb3cf05ac7b1672c82b92c43f3d","2023-04-12T12:15:07.08+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-1829",{"cveId":11691,"releaseId":31,"cycle":32,"description":11692,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11693,"url":11694},{"cveId":11691,"releaseId":25,"cycle":26,"description":11692,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11693,"url":11694},{"cveId":11698,"releaseId":17,"cycle":18,"description":11699,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11700,"url":11701},"CVE-2023-1281","Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()' is called with the destroyed tcf_ext. A local attacker user can use this vulnerability to elevate its privileges to root.\n\n\nThis issue affects Linux Kernel: from 4.14 before git commit ee059170b1f7e94e55fa6cadee544e176a6e59c2.","2023-03-22T14:15:16.09+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-1281",{"cveId":11698,"releaseId":25,"cycle":26,"description":11699,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11700,"url":11701},{"cveId":11704,"releaseId":17,"cycle":18,"description":11705,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11706,"url":11707},"CVE-2022-3636","A vulnerability was identified in Linux Kernel 33fc42de33278b2b3ec6f3390512987bc29a62b7. This affects the function __mtk_ppe_check_skb of the file drivers\u002Fnet\u002Fethernet\u002Fmediatek\u002Fmtk_ppe.c of the component Ethernet Handler. Such manipulation leads to use after free. The name of the patch is 17a5f6a78dc7b8db385de346092d7d9f9dc24df6. It is best practice to apply a patch to resolve this issue. No released Linux Kernel version was ever affected by this CVE.","2022-10-21T11:15:09.633+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-3636",{"cveId":11704,"releaseId":31,"cycle":32,"description":11705,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11706,"url":11707},{"cveId":11704,"releaseId":25,"cycle":26,"description":11705,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11706,"url":11707},{"cveId":11711,"releaseId":31,"cycle":32,"description":11712,"severity":58,"cvssScore":11713,"epssScore":9,"inKev":42,"publishedAt":11714,"url":11715},"CVE-2022-3566","A vulnerability was identified in Linux Kernel up to 4.19.316\u002F5.4.278\u002F5.10.220\u002F5.15.161. This impacts the function tcp_getsockopt\u002Ftcp_setsockopt of the component TCP Handler. Such manipulation leads to race condition. A high complexity level is associated with this attack. The exploitability is said to be difficult. The vulnerability was introduced in 2.6.12, commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (\"Linux-2.6.12-rc2\"). Upgrading to version 4.19.317, 5.4.279, 5.10.221, 5.15.162 and 6.1 w",4.6,"2022-10-17T19:15:10.33+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-3566",{"cveId":11711,"releaseId":25,"cycle":26,"description":11712,"severity":58,"cvssScore":11713,"epssScore":9,"inKev":42,"publishedAt":11714,"url":11715},{"cveId":11711,"releaseId":17,"cycle":18,"description":11712,"severity":58,"cvssScore":11713,"epssScore":9,"inKev":42,"publishedAt":11714,"url":11715},{"cveId":11719,"releaseId":31,"cycle":32,"description":11720,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11721,"url":11722},"CVE-2022-3534","A vulnerability has been found in Linux Kernel up to 5.10.162\u002F5.15.85\u002F6.0.15\u002F6.1.1. The impacted element is the function btf_dump_name_dups of the file tools\u002Flib\u002Fbpf\u002Fbtf_dump.c of the component libbpf. The manipulation leads to use after free. Upgrading to version 5.10.163, 5.15.86, 6.0.16, 6.1.2 and 6.2 is sufficient to resolve this issue. The identifier of the patch is c61650b869e0b6fb0c0a28ed42d928eea969afc8\u002Ffbe08093fb2334549859829ef81d42570812597d\u002F8c64a8e76eb85d422af5ec60ccbf26e3ead8c333\u002Fa73","2022-10-17T09:15:12.75+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-3534",{"cveId":11719,"releaseId":17,"cycle":18,"description":11720,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11721,"url":11722},{"cveId":11719,"releaseId":25,"cycle":26,"description":11720,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11721,"url":11722},{"cveId":11726,"releaseId":17,"cycle":18,"description":11727,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11728,"url":11729},"CVE-2022-1353","A vulnerability was found in the pfkey_register function in net\u002Fkey\u002Faf_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.","2022-04-29T16:15:08.853+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-1353",{"cveId":11726,"releaseId":31,"cycle":32,"description":11727,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11728,"url":11729},{"cveId":11726,"releaseId":25,"cycle":26,"description":11727,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11728,"url":11729},{"cveId":11733,"releaseId":31,"cycle":32,"description":11734,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11735,"url":11736},"CVE-2022-0330","A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.","2022-03-25T19:15:10.027+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-0330",{"cveId":11733,"releaseId":17,"cycle":18,"description":11734,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11735,"url":11736},{"cveId":11733,"releaseId":25,"cycle":26,"description":11734,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11735,"url":11736},{"cveId":11740,"releaseId":17,"cycle":18,"description":11741,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11742,"url":11743},"CVE-2022-0492","A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel\u002Fcgroup\u002Fcgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.","2022-03-03T19:15:08.633+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2022-0492",{"cveId":11740,"releaseId":31,"cycle":32,"description":11741,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11742,"url":11743},{"cveId":11740,"releaseId":25,"cycle":26,"description":11741,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11742,"url":11743},{"cveId":11747,"releaseId":17,"cycle":18,"description":11748,"severity":40,"cvssScore":7436,"epssScore":9,"inKev":42,"publishedAt":11749,"url":11750},"CVE-2021-20322","A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.","2022-02-18T18:15:09.013+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-20322",{"cveId":11752,"releaseId":17,"cycle":18,"description":11753,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11754,"url":11755},"CVE-2021-45485","In the IPv6 implementation in the Linux kernel before 5.13.3, net\u002Fipv6\u002Foutput_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.","2021-12-25T02:15:06.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-45485",{"cveId":11752,"releaseId":25,"cycle":26,"description":11753,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11754,"url":11755},{"cveId":11752,"releaseId":31,"cycle":32,"description":11753,"severity":40,"cvssScore":110,"epssScore":9,"inKev":42,"publishedAt":11754,"url":11755},{"cveId":11759,"releaseId":17,"cycle":18,"description":11760,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":11761,"url":11762},"CVE-2021-44733","A use-after-free exists in drivers\u002Ftee\u002Ftee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.","2021-12-22T17:15:09.123+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-44733",{"cveId":11759,"releaseId":25,"cycle":26,"description":11760,"severity":40,"cvssScore":234,"epssScore":9,"inKev":42,"publishedAt":11761,"url":11762},{"cveId":11765,"releaseId":17,"cycle":18,"description":11766,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11767,"url":11768},"CVE-2021-42252","An issue was discovered in aspeed_lpc_ctrl_mmap in drivers\u002Fsoc\u002Faspeed\u002Faspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.","2021-10-11T19:15:07.713+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-42252",{"cveId":11765,"releaseId":25,"cycle":26,"description":11766,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11767,"url":11768},{"cveId":11771,"releaseId":17,"cycle":18,"description":11772,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11773,"url":11774},"CVE-2021-41864","prealloc_elems_and_freelist in kernel\u002Fbpf\u002Fstackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.","2021-10-02T00:15:07.503+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-41864",{"cveId":11771,"releaseId":25,"cycle":26,"description":11772,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11773,"url":11774},{"cveId":11771,"releaseId":31,"cycle":32,"description":11772,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11773,"url":11774},{"cveId":11778,"releaseId":25,"cycle":26,"description":11779,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11780,"url":11781},"CVE-2021-3483","A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected","2021-05-17T12:15:07.523+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-3483",{"cveId":11778,"releaseId":17,"cycle":18,"description":11779,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11780,"url":11781},{"cveId":11778,"releaseId":31,"cycle":32,"description":11779,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11780,"url":11781},{"cveId":11785,"releaseId":17,"cycle":18,"description":11786,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11787,"url":11788},"CVE-2021-33033","The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net\u002Fipv4\u002Fcipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value.","2021-05-14T23:15:09.78+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-33033",{"cveId":11785,"releaseId":31,"cycle":32,"description":11786,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11787,"url":11788},{"cveId":11785,"releaseId":25,"cycle":26,"description":11786,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11787,"url":11788},{"cveId":11792,"releaseId":25,"cycle":26,"description":11793,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11794,"url":11795},"CVE-2021-23134","Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.","2021-05-12T23:15:07.707+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-23134",{"cveId":11792,"releaseId":17,"cycle":18,"description":11793,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11794,"url":11795},{"cveId":11792,"releaseId":31,"cycle":32,"description":11793,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11794,"url":11795},{"cveId":11799,"releaseId":17,"cycle":18,"description":11800,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11801,"url":11802},"CVE-2021-3501","A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.","2021-05-06T13:15:12.84+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-3501",{"cveId":11799,"releaseId":31,"cycle":32,"description":11800,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11801,"url":11802},{"cveId":11799,"releaseId":25,"cycle":26,"description":11800,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11801,"url":11802},{"cveId":11806,"releaseId":31,"cycle":32,"description":11807,"severity":58,"cvssScore":11808,"epssScore":9,"inKev":42,"publishedAt":11809,"url":11810},"CVE-2021-23133","A race condition in Linux kernel SCTP sockets (net\u002Fsctp\u002Fsocket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CG",6.7,"2021-04-22T18:15:08.123+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-23133",{"cveId":11806,"releaseId":17,"cycle":18,"description":11807,"severity":58,"cvssScore":11808,"epssScore":9,"inKev":42,"publishedAt":11809,"url":11810},{"cveId":11806,"releaseId":25,"cycle":26,"description":11807,"severity":58,"cvssScore":11808,"epssScore":9,"inKev":42,"publishedAt":11809,"url":11810},{"cveId":11814,"releaseId":31,"cycle":32,"description":11815,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11816,"url":11817},"CVE-2021-27365","An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.","2021-03-07T05:15:13.623+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-27365",{"cveId":11814,"releaseId":25,"cycle":26,"description":11815,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11816,"url":11817},{"cveId":11814,"releaseId":17,"cycle":18,"description":11815,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11816,"url":11817},{"cveId":11821,"releaseId":31,"cycle":32,"description":11822,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11823,"url":11824},"CVE-2021-27364","An issue was discovered in the Linux kernel through 5.11.3. drivers\u002Fscsi\u002Fscsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.","2021-03-07T05:15:13.437+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2021-27364",{"cveId":11821,"releaseId":25,"cycle":26,"description":11822,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11823,"url":11824},{"cveId":11821,"releaseId":17,"cycle":18,"description":11822,"severity":40,"cvssScore":41,"epssScore":9,"inKev":42,"publishedAt":11823,"url":11824},{"cveId":11828,"releaseId":17,"cycle":18,"description":11829,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":11830,"url":11831},"CVE-2020-29372","An issue was discovered in do_madvise in mm\u002Fmadvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e.","2020-11-28T07:15:11.727+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2020-29372",{"cveId":11828,"releaseId":25,"cycle":26,"description":11829,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":11830,"url":11831},{"cveId":11828,"releaseId":31,"cycle":32,"description":11829,"severity":58,"cvssScore":214,"epssScore":9,"inKev":42,"publishedAt":11830,"url":11831},{"cveId":11835,"releaseId":17,"cycle":18,"description":11836,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11837,"url":11838},"CVE-2020-28941","An issue was discovered in drivers\u002Faccessibility\u002Fspeakup\u002Fspk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.","2020-11-19T19:15:11.797+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2020-28941",{"cveId":11835,"releaseId":31,"cycle":32,"description":11836,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11837,"url":11838},{"cveId":11835,"releaseId":25,"cycle":26,"description":11836,"severity":58,"cvssScore":59,"epssScore":9,"inKev":42,"publishedAt":11837,"url":11838},{"cveId":11842,"releaseId":31,"cycle":32,"description":11843,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11844,"url":11845},"CVE-2020-11725","snd_ctl_elem_add in sound\u002Fcore\u002Fcontrol.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later affects a private_size*count multiplication for unspecified \"interesting side effects.\" NOTE: kernel engineers dispute this finding, because it could be relevant only if new callers were added that were unfamiliar with the misuse of the info->owner field to represent data unrelated to the \"owner\" concept. The existing callers, SNDRV_CTL_IOCTL_ELEM_ADD and SNDRV_CTL_IOCTL_ELEM_REPL","2020-04-12T22:15:11.9+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2020-11725",{"cveId":11842,"releaseId":25,"cycle":26,"description":11843,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11844,"url":11845},{"cveId":11842,"releaseId":17,"cycle":18,"description":11843,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11844,"url":11845},{"cveId":11849,"releaseId":31,"cycle":32,"description":11850,"severity":58,"cvssScore":11713,"epssScore":9,"inKev":42,"publishedAt":11851,"url":11852},"CVE-2019-15213","An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers\u002Fmedia\u002Fusb\u002Fdvb-usb\u002Fdvb-usb-init.c driver.","2019-08-19T22:15:11.253+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2019-15213",{"cveId":11849,"releaseId":25,"cycle":26,"description":11850,"severity":58,"cvssScore":11713,"epssScore":9,"inKev":42,"publishedAt":11851,"url":11852},{"cveId":11849,"releaseId":17,"cycle":18,"description":11850,"severity":58,"cvssScore":11713,"epssScore":9,"inKev":42,"publishedAt":11851,"url":11852},{"cveId":11856,"releaseId":17,"cycle":18,"description":11857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11858,"url":11859},"CVE-2018-10902","It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation.","2018-08-21T19:29:00.22+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2018-10902",{"cveId":11856,"releaseId":25,"cycle":26,"description":11857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11858,"url":11859},{"cveId":11856,"releaseId":31,"cycle":32,"description":11857,"severity":40,"cvssScore":50,"epssScore":9,"inKev":42,"publishedAt":11858,"url":11859},{"cveId":11863,"releaseId":17,"cycle":18,"description":11864,"severity":58,"cvssScore":11865,"epssScore":9,"inKev":42,"publishedAt":11866,"url":11867},"CVE-1999-0524","ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.",4,"1997-08-01T04:00:00+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-1999-0524",{"cveId":11863,"releaseId":31,"cycle":32,"description":11864,"severity":58,"cvssScore":11865,"epssScore":9,"inKev":42,"publishedAt":11866,"url":11867},{"cveId":11863,"releaseId":25,"cycle":26,"description":11864,"severity":58,"cvssScore":11865,"epssScore":9,"inKev":42,"publishedAt":11866,"url":11867},"5"]