SB20260925213 - openEuler 22.03 LTS SP4 update for kernel



SB20260925213 - openEuler 22.03 LTS SP4 update for kernel

Published: September 25, 2026

Security Bulletin ID SB20260925213
CSH Severity
High
Patch available
YES
Number of vulnerabilities 60
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 7% Medium 15% Low 78%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 60 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2026-80737)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a use-after-free in the AMBA PL011 serial driver's DMA shutdown handling when DMA activity is being terminated. A local user can trigger DMA shutdown while TX callbacks or RX polling remain active to cause memory corruption.


2) Out-of-bounds write (CVE-ID: CVE-2026-74443)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to modify authenticated command fields.

The vulnerability exists due to an out-of-bounds write in vmw_cmd_dma() in the vmwgfx command verifier when processing a dma command with an undersized header body size. A local user can submit a specially crafted command to modify authenticated command fields.

The issue arises from a suffix pointer underflow that can clobber fields in a previously relocated command in the device-visible command stream.


3) Out-of-bounds read (CVE-ID: CVE-2026-74444)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in vmw_cmd_draw() when processing a user-supplied command stream containing an undersized DRAW_PRIMITIVES header. A local user can supply a crafted command stream to disclose sensitive information.

The issue is triggered when header->size is smaller than the command body size, causing an unsigned subtraction to wrap and a subsequent bounds check to be bypassed.


4) Out-of-bounds read (CVE-ID: CVE-2026-74549)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to out-of-bounds read in nct6775_update_pwm() in the nct6775-core hwmon driver when iterating over pwm channels for nct6116 weight-control registers. A local user can trigger access to unsupported weight registers to cause a denial of service.

The issue affects nct6116 configurations where bits 3 or 4 of has_pwm are set, causing out-of-bounds values to be used as hardware register addresses for subsequent read and write operations.


5) Use-after-free (CVE-ID: CVE-2026-74730)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the NFS FREE_STATEID handling in fs/nfs/nfs4proc.c when processing a delayed FREE_STATEID operation. A local user can trigger a delayed FREE_STATEID operation to cause a denial of service.


6) Out-of-bounds read (CVE-ID: CVE-2026-74752)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in SCTP COOKIE_ECHO handling when processing peer-controlled cookie AUTH fields with cookie authentication disabled. A remote attacker can send a forged cookie with a crafted RANDOM length to disclose sensitive information.

The issue is reachable when cookie authentication is disabled, and malformed AUTH parameters restored from the cookie are not validated against local backing arrays.


7) Out-of-bounds write (CVE-ID: CVE-2026-74752)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in SCTP COOKIE_ECHO handling when processing peer-controlled cookie AUTH fields with cookie authentication disabled. A remote attacker can send a forged cookie with a crafted HMAC identifier to execute arbitrary code.

The issue is reachable when cookie authentication is disabled, and malformed AUTH parameters restored from the cookie are not validated against local backing arrays.


8) Integer overflow (CVE-ID: CVE-2026-80540)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to an integer overflow in the amdgpu UVD decode message handler when processing crafted decode parameters. A local user can supply a crafted pitch value to trigger the overflow and execute arbitrary code.

The issue is in the Linux kernel DRM AMDGPU UVD decode path.


9) Improper input validation (CVE-ID: CVE-2026-80541)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in amdgpu_gem_create_ioctl() when processing GEM create requests with invalid domain combinations. A local user can submit a specially crafted domain combination to cause a denial of service.

The issue is triggered when CPU, GTT, or VRAM domains are combined with DOORBELL, GDS, GWS, or OA domains, causing amdgpu_bo_placement_from_domain() to exceed AMDGPU_BO_MAX_PLACEMENTS and hit BUG_ON().


10) Out-of-bounds write (CVE-ID: CVE-2026-80569)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in the synaptics-rmi4 F54 diagnostics report handling in rmi_f54_work() when processing a malicious or malfunctioning RMI4 device report with larger F55 electrode counts than F54 counts. A local user can provide a specially crafted device that reports inconsistent electrode counts to execute arbitrary code.

The issue can also cause an out-of-bounds read during the subsequent V4L2 dequeue memcpy().


11) Heap-based buffer overflow (CVE-ID: CVE-2026-80570)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code or cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in rmi_f54_buffer_queue() when handling a failed report operation after the V4L2 format has been changed to a smaller size. A local user can trigger an error path that leaves a stale larger report size and cause it to be copied into a smaller buffer to execute arbitrary code or cause a denial of service.

The issue is caused by failure to clear f54->report_size on certain error paths in rmi_f54_work().


12) Type Confusion (CVE-ID: CVE-2026-80694)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper type handling in mtk_poll_controller and mtk_handle_irq_rx when handling ndo_poll_controller calls with CONFIG_NET_POLL_CONTROLLER enabled. A local user can trigger ndo_poll_controller to cause a denial of service.

The issue results from passing a net_device pointer where a struct mtk_eth pointer is expected.


13) Improper Initialization (CVE-ID: CVE-2026-80707)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper initialization in j1939_session_fresh_new() in the can j1939 transport component when allocating a receive buffer. A local user can trigger allocation of a buffer containing residual data to disclose sensitive information.


14) Out-of-bounds read (CVE-ID: CVE-2026-80717)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in sctp_process_param() when processing a malformed SCTP Adaptation Layer Indication parameter in an INIT chunk. A remote attacker can send a specially crafted SCTP INIT request to disclose sensitive information.

When the malformed parameter is the last parameter in the INIT chunk, four bytes from the receive-buffer tail may be copied into the state cookie returned in the INIT ACK.


15) Use-after-free (CVE-ID: CVE-2026-80726)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a use-after-free in the KVM x86 MMU when creating a child shadow page from an invalid parent shadow page. A local user can trigger KVM to create such a child shadow page to cause memory corruption.

The condition involves an invalid shadow page being present on the list of active MMU pages.


16) Race condition (CVE-ID: CVE-2026-74437)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in uvc_status_stop in the uvcvideo driver when handling asynchronous control status events. A local user can trigger a deadlock condition to cause a denial of service.

Exploitation requires a UVC camera with an asynchronous control.


17) Integer overflow (CVE-ID: CVE-2026-89557)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an integer overflow.

The vulnerability exists due to improper input validation in the super_1_load() MD superblock loader when processing a crafted on-disk superblock. A local user can supply a crafted on-disk superblock to trigger an integer overflow.


18) Incorrect calculation (CVE-ID: CVE-2026-89586)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to incorrect calculation in ata_scsi_write_same_xlat() and ata_format_dsm_trim_descr() when issuing SCSI WRITE SAME commands with the UNMAP bit set. A local user can issue a SCSI WRITE SAME command with the UNMAP bit set to cause a denial of service.

The issue affects devices whose logical sector size exceeds 2048 bytes.


19) Out-of-bounds read (CVE-ID: CVE-2026-89608)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to improper bounds checking in ecryptfs_parse_packet_set() when parsing an eCryptfs version 1 file header. A local user can trigger parsing of an eCryptfs version 1 file header to perform an out-of-bounds read.


20) Out-of-bounds read (CVE-ID: CVE-2026-89631)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the CIFSTCon() SMB client tree connect response parser when processing a tree connect response with a byte count smaller than two. A remote attacker can send a malformed tree connect response to disclose sensitive information.

Disclosed bytes are exposed through /proc/fs/cifs/DebugData.


21) Out-of-bounds write (CVE-ID: CVE-2026-89633)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause out-of-bounds reads and writes.

The vulnerability exists due to improper input validation in coalesce_t2() when processing SMB transaction responses containing server-supplied DataOffset fields. A remote attacker can send a crafted response with malicious DataOffset values to cause out-of-bounds reads and writes.


22) Use-after-free (CVE-ID: CVE-2026-89637)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory leaks and use-after-free conditions.

The vulnerability exists due to use-after-free in the SMB client cifs_check_trans2() function when processing a malformed secondary TRANSACT2 response. A remote attacker can send a malformed secondary TRANSACT2 response to cause memory leaks and use-after-free conditions.

Exploitation requires that a valid primary TRANSACT2 response has already been received.


23) Out-of-bounds read (CVE-ID: CVE-2026-89649)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the CephFS __build_xattrs() function when processing metadata-server-supplied extended attribute blobs. A remote privileged user can provide a crafted extended attribute blob with a final attribute value length that exceeds the available data to disclose sensitive information.

A local user must invoke getxattr(2) on a CephFS file.


24) Out-of-bounds read (CVE-ID: CVE-2026-89650)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds read in the kernel.

The vulnerability exists due to an out-of-bounds read in ceph_mdsmap_decode() in fs/ceph/mdsmap.c when processing an MDS map with a per-mds info version of 2 or 3 and an oversized num_export_targets field. A remote attacker can send a specially crafted MDS map to cause an out-of-bounds read in the kernel.

On-path exploitation applies to unsigned or unencrypted messenger sessions.


25) Out-of-bounds write (CVE-ID: CVE-2026-89652)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause memory corruption.

The vulnerability exists due to improper bounds checking in the CephFS NFS-export get_name functions when processing LOOKUPNAME replies containing oversized dentry names. A remote user can return a specially crafted LOOKUPNAME reply to cause memory corruption.

The issue is reachable when a CephFS mount is re-exported over NFS.


26) Use-after-free (CVE-ID: CVE-2026-89655)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in __kick_flushing_caps() when processing FLUSH_ACK messages during cap flushing. A remote attacker can send a FLUSH_ACK message during cap flushing to trigger a use-after-free condition.

Exploitation requires the FLUSH_ACK to be processed after i_ceph_lock is released and before list iteration resumes.


27) Out-of-bounds read (CVE-ID: CVE-2026-89846)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in qla2x00_status_entry() in the qla2xxx SCSI driver when processing an FCP response containing an oversized response information length. A remote attacker can send a crafted FCP response with an oversized rsp_info_len value to disclose sensitive information.


28) Use-after-free (CVE-ID: CVE-2026-89847)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in qla2x00_async_iocb_timeout() in the qla2xxx SCSI driver when an async IOCB timeout races with response interrupt completion. A remote attacker can trigger the race condition to compromise confidentiality, integrity, and availability.


29) Use of uninitialized resource (CVE-ID: CVE-2026-89859)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in qla2x00_do_dport_diagnostics() when handling dport diagnostic requests. A local user can submit a dport diagnostic request with a partial payload to disclose sensitive information.


30) Use-after-free (CVE-ID: CVE-2026-90013)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free kernel crash.

The vulnerability exists due to a use-after-free in tracefs options files when an options file is opened while another task removes its associated tracing instance. A local user can open an options file for a tracing instance and trigger removal of that instance to cause a use-after-free kernel crash.


31) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-64458)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or perform an out-of-bounds read.

The vulnerability exists due to improper handling of exceptional conditions in damon_hot_score() and damon_max_nr_accesses() when processing user-controlled DAMON monitoring intervals via sysfs. A local user can write zero or excessively large interval values to sysfs settings to cause a denial of service or perform an out-of-bounds read.

Exploitation requires sysfs write permission.


32) Out-of-bounds read (CVE-ID: CVE-2024-56614)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the xsk_map_delete_elem() function in net/xdp/xskmap.c. A local user can perform a denial of service (DoS) attack.


33) Input validation error (CVE-ID: CVE-2025-40269)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the snd_usb_endpoint_set_params() function in sound/usb/endpoint.c. A local user can perform a denial of service (DoS) attack.


34) Race condition (CVE-ID: CVE-2026-31548)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in cfg80211 PMSR handling when closing the nl80211 socket that originated a PMSR request while the interface is concurrently being torn down. A local user can trigger concurrent abort processing and interface teardown to cause a denial of service.

The issue can result in the driver's abort_pmsr callback operating on a torn-down interface.


35) Use-after-free (CVE-ID: CVE-2026-43303)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the swap subsystem when handling stale page->private values on reallocated and split pages. A local user can trigger swapoff operations after causing affected page state reuse to cause a denial of service.

The issue occurs because tail pages can retain stale page->private values after split_page(), leading swap_count_continued() to follow an invalid continuation list and access poisoned list entries.


36) Use-after-free (CVE-ID: CVE-2026-46004)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the caiaq driver setup_card() error handling when probing the device. A local user can trigger a probe error to cause a denial of service.

The issue occurs because execution continues after freeing the sound card during certain error paths.


37) NULL pointer dereference (CVE-ID: CVE-2026-52929)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null-pointer dereference in the SCTP stream scheduler state handling in net/sctp/stream.c when processing a denied ADD_OUT_STREAMS operation and a later stream re-add. A remote attacker can trigger SCTP stream reset operations that leave stale removed stream metadata behind to cause a denial of service.

The issue occurs because removed outgoing stream state is not fully rolled back, leaving scheduler-private stream metadata inconsistent for later reuse.


38) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-52954)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of duplicate rbtree keys in decode_choose_args() when processing a crafted CEPH_MSG_OSD_MAP message containing duplicate choose_args_index values. A remote attacker can send a specially crafted message to cause a denial of service.


39) Out-of-bounds write (CVE-ID: CVE-2026-52969)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in kvm_reset_dirty_gfn() and the KVM dirty ring handling logic when processing rewritten dirty ring entries from a vcpu file descriptor. A local user can modify slot and offset fields in crafted dirty ring entries to cause memory corruption.

The issue is reachable from a process holding /dev/kvm and affects the legacy MMU path with shadow paging, allocated shadow roots, or a write-tracked slot.


40) Use-after-free (CVE-ID: CVE-2026-52982)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in rtl8150_start_xmit() when submitting a USB transmit URB and updating transmit statistics. A local user can trigger concurrent URB completion to cause a denial of service.

The issue is caused by reading skb->len after usb_submit_urb() returns, while the skb may already have been freed by the completion path on another CPU in softirq context.


41) Race condition (CVE-ID: CVE-2026-53242)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in snd_pcm_drain() when handling linked PCM streams during concurrent unlink operations. A local user can trigger concurrent drain and unlink activity to cause a denial of service.

The issue can corrupt wait queue lists and lead to a kernel panic through a NULL function pointer dereference during a subsequent wake-up.


42) Use of uninitialized resource (CVE-ID: CVE-2026-63870)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use of uninitialized memory in lowpan_xmit() in the ieee802154 6LoWPAN transmit path when processing a non-IPv6 packet queued for transmission on a 6LoWPAN interface. A local user can queue a non-IPv6 packet for transmission to cause a denial of service.

The issue occurs because address information in skb headroom may remain uninitialized and is later copied and used by the transmit path.


43) Out-of-bounds write (CVE-ID: CVE-2026-63916)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in wacom_hid_set_device_mode() when handling a HID feature report where HID_DG_INPUTMODE is mapped to a field other than the first one. A local user can connect or emulate a crafted device to trigger the out-of-bounds write and cause a denial of service.

The issue occurs when the first field in the feature report has a report_count smaller than the usage index of HID_DG_INPUTMODE.


44) NULL pointer dereference (CVE-ID: CVE-2026-64048)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in smc_v2_determine_accepted_chid and smc_conn_create when processing a crafted SMC-Dv2 accept reply with CHID 0. A remote attacker can send a specially crafted reply to trigger a kernel fault and cause a denial of service.

Exploitation requires a malicious peer to reply to an SMC-Dv2-only proposal.


45) Heap-based buffer overflow (CVE-ID: CVE-2026-64449)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the SLAVE-path helpers buffer_to_user() and buffer_from_user() in drivers/staging/vme_user/vme_user.c when processing read and write operations with an offset and count that exceed the fixed kern_buf size. A local user can issue crafted read or write operations to cause a denial of service or execute arbitrary code.

The issue occurs when the configured slave window exceeds the 128 KiB kern_buf allocation.


46) Improper locking (CVE-ID: CVE-2024-56531)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the snd_usb_caiaq_input_free() function in sound/usb/caiaq/input.c, within the setup_card(), init_card() and snd_disconnect() functions in sound/usb/caiaq/device.c, within the snd_usb_caiaq_audio_init() function in sound/usb/caiaq/audio.c. A local user can perform a denial of service (DoS) attack.


47) Use-after-free (CVE-ID: CVE-2026-64582)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to use-after-free in rxe_mmap in the RDMA/rxe subsystem when processing a memory mapping request concurrently with a DESTROY_CQ ioctl. A local user can trigger a race condition to cause a denial of service or execute arbitrary code.

Exploitation requires winning a narrow race window between the mmap path and concurrent object destruction.


48) Integer overflow (CVE-ID: CVE-2026-68108)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause out-of-bounds memory access.

The vulnerability exists due to integer overflow in amdgpu_vce_ring_parse_cs() in the VCE command stream parser when processing crafted VCE command streams with oversized image dimensions. A local user can submit a specially crafted command stream to cause out-of-bounds memory access.

The issue occurs when image dimensions wrap the calculated buffer size and bypass validation before reaching the GPU firmware.


49) Heap-based buffer overflow (CVE-ID: CVE-2026-68320)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in sctp_association_init and SCTP authentication chunk handling when processing endpoint authentication chunk lists containing more than 16 entries. A local user can add excessive chunk identifiers to trigger memory corruption and cause a denial of service.


50) Race condition (CVE-ID: CVE-2026-68404)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in nl80211_netlink_notify() and cfg80211 wireless device autodisconnect handling when releasing a NETLINK_GENERIC socket that owns a connection. A local user can release a crafted netlink socket to cause a denial of service.

The issue occurs because autodisconnect work can be queued after teardown has cancelled pending work and after the wireless device has been removed from the device list.


51) Out-of-bounds read (CVE-ID: CVE-2026-68470)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the mac80211 RX path when processing unsupported extension frames and S1G beacon extension frames. A remote attacker can send a specially crafted wireless frame to cause a denial of service.

The issue affects extension-frame handling before unsupported extension subtypes are dropped, and S1G beacon processing requires the target system to receive crafted 802.11 frames.


52) Double free (CVE-ID: CVE-2026-72102)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in dm_early_create in drivers/md/dm-ioctl.c when resuming a device-mapper device after swapping in a new table. A local user can trigger a dm_resume failure to cause a denial of service.


53) Heap-based buffer overflow (CVE-ID: CVE-2026-72106)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in list_version_get_info in dm-ioctl when processing ioctl requests. A local user can send a specially crafted ioctl request to cause a denial of service.


54) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-72108)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause metadata inconsistency and a denial of service.

The vulnerability exists due to improper state management in dm-thin metadata snapshot handling in drivers/md/dm-thin-metadata.c when reserving or releasing a metadata snapshot and a subsequent metadata commit fails. A local user can issue crafted dmsetup messages to trigger a commit failure and cause metadata inconsistency and a denial of service.

Exploitation requires the ability to manage a thin-pool metadata device and trigger snapshot reserve or release operations under commit-failure conditions.


55) Integer overflow (CVE-ID: CVE-2026-72200)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to integer overflow in the NTFS mapping-pairs parser when parsing a corrupted NTFS attribute. A local user can supply a crafted NTFS runlist to cause a denial of service.

The issue can occur when a mapping-pairs entry sets the accumulated LCN to S64_MAX and a subsequent entry adds a delta of 1.


56) Integer underflow (CVE-ID: CVE-2026-72225)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to integer underflow in jbd2_journal_initialize_fast_commit() when initializing fast commit journal metadata. A local user can trigger journal initialization with crafted journal parameters to cause a denial of service.

The issue can corrupt j_last, j_fc_first, and j_free, leading to journal abort.


57) Improper input validation (CVE-ID: CVE-2026-72397)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to send incorrect voltage commands to a PMBus device.

The vulnerability exists due to improper input validation in pmbus_data2reg_vid() in the pmbus core when converting user-supplied voltage values for PMBUS_VOUT_COMMAND. A local user can request a voltage using a non-VR11 VID mode to send incorrect voltage commands to a PMBus device.

Only drivers that select a non-VR11 VID mode and expose a regulator or hwmon vout setter are affected.


58) Race condition (CVE-ID: CVE-2026-74330)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in configfs directory entry child traversal when traversing s_children lists while concurrent cursor movement or freeing can occur. A local user can trigger concurrent configfs operations to cause a denial of service.

The issue affects configfs directory handling in fs/configfs/dir.c.


59) Use-after-free (CVE-ID: CVE-2026-74359)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in configfs_lookup() when handling subsequent getdents(2) operations in a directory after inode allocation failure. A local user can trigger inode allocation failure and then access the affected directory to cause a denial of service.

The issue occurs because a dangling pointer remains in the configfs_dirent structure and is later dereferenced to obtain an inode number.


60) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-74374)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state handling in the md/raid1 and md/raid10 read request paths when processing split and resubmitted failed bios in the error path. A local user can trigger I/O that causes failed bios to be split and resubmitted to cause a denial of service.

The issue can lead to incorrect memory allocation flags being used under memory pressure, which may result in a deadlock.


Remediation

Install update from vendor's website.