SB2026093022 - Ubuntu update for linux
Published: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 101 vulnerabilities.
1) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-80665)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper exception handling in KVM arm64 nested virtualization VNCR translation handling when processing VNCR aborts after kvm_translate_vncr() fails to resolve a PFN. A local user can trigger a translation failure involving a GFN outside of the memslots to cause a denial of service.
The issue occurs because late failures may be returned without the expected abort state being prepared for fault injection.
2) Race condition (CVE-ID: CVE-2026-74439)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in device_pasid_table_teardown() when tearing down scalable-mode context entries. A local user can trigger teardown of a PASID table entry to cause a denial of service.
The issue arises because hardware may fetch a torn entry while the Present bit remains set, which can result in spurious faults or stale walks to freed memory.
3) Use-after-free (CVE-ID: CVE-2026-74436)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in rxrpc_kernel_charge_accept() and the rxrpc service backlog handling when concurrent socket teardown and kernel accept preallocation occur. A local attacker can trigger concurrent operations that reuse a freed backlog structure to cause a denial of service.
The issue arises from a race condition between kernel preallocation work and socket teardown in the RxRPC subsystem.
4) Use-after-free (CVE-ID: CVE-2026-74434)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption and trigger a use-after-free.
The vulnerability exists due to a use-after-free in rxrpc_recvmsg_oob() when processing an out-of-band message with MSG_PEEK. A local user can read a challenge with MSG_PEEK so that the same sk_buff becomes reachable from both queues to cause memory corruption and trigger a use-after-free.
The issue occurs because the message remains on recvmsg_oobq while also being added to pending_oobq, and the resulting queue corruption is triggered when the socket is closed and both queues are drained.
5) Use-after-free (CVE-ID: CVE-2026-74433)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in rxgk_issue_challenge() when handling RxRPC challenge transmission. A local user can trigger the vulnerable code path to cause a denial of service.
6) Deadlock (CVE-ID: CVE-2026-74428)
CWE-ID: CWE-833 - Deadlock
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double unlock in rxrpc_recvmsg() in the RxRPC recvmsg handler when processing out-of-band messages. A local user can trigger the vulnerable code path to cause a denial of service.
7) Improper resource shutdown or release (CVE-ID: CVE-2026-74427)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper shutdown handling in the afs network namespace preallocation work logic when tearing down an afs network namespace. A local user can trigger network namespace teardown to cause a denial of service.
The issue involves cancellation and requeue behavior of the preallocated rxrpc call, connection, and peer charger while incoming calls are being disabled.
8) NULL pointer dereference (CVE-ID: CVE-2026-74406)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in vxlan_gro_prepare_receive() when processing packets during GRO handling. A local attacker can trigger concurrent socket state changes to cause a denial of service.
9) Use-after-free (CVE-ID: CVE-2026-74401)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the DLM send_queue handling in fs/dlm/midcomms.c when processing a high volume of DLM messages. A local user can trigger heavy DLM message activity to cause a denial of service.
The issue occurs when message sequence numbers in the ordered send queue are not assigned in the required order, leading to refcounting problems.
10) Race condition (CVE-ID: CVE-2026-74398)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in addrconf_dad_failure in the IPv6 address configuration subsystem when handling duplicate address detection failure processing concurrently with IPv6 address deletion. A local attacker can trigger concurrent state transitions to cause a denial of service.
The issue can lead to a general protection fault when a deleted IPv6 address entry is processed a second time through scheduled DAD work.
11) Integer overflow (CVE-ID: CVE-2026-74394)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the immediate data length check in the RDMA/srpt subsystem when processing user-supplied immediate data received over the network. A remote attacker can send a specially crafted network request with an oversized length value to cause a denial of service.
The length field is user-controlled and may wrap the computed request size, bypassing the bounds check before a very large length is passed to sg_init_one().
12) Out-of-bounds write (CVE-ID: CVE-2026-74384)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the nvme multipath namespace head flexible array member current_path[] when handling sparse NUMA node IDs during namespace path revalidation. A local user can trigger nvme multipath operations on a system with sparse NUMA node IDs to cause a denial of service.
Only systems using nvme multipath on architectures where NUMA node IDs are sparse are affected.
13) Improper resource shutdown or release (CVE-ID: CVE-2026-74376)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the md/raid10 discard handling logic when reusing an r10bio for discard operations. A local user can trigger discard operations on a reused r10bio to cause a denial of service.
The issue occurs when a discard reuses an r10bio that was previously used for a read, leaving read_slot non-negative and causing cleanup to skip releasing the replacement bio.
14) Out-of-bounds read (CVE-ID: CVE-2026-74361)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the nvme_query_fdp_granularity function when processing an FDP index value. A local user can supply a crafted FDP index value to cause a denial of service.
15) Out-of-bounds read (CVE-ID: CVE-2026-74350)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the ocfs2 fast symlink read path when processing a malformed zero-cluster symlink inode. A local user can provide a crafted filesystem image containing an invalid fast symlink to disclose sensitive information.
The issue is triggered when the inline symlink payload is not NUL-terminated at the recorded size or when the recorded size exceeds the inline fast-symlink capacity.
16) Use-after-free (CVE-ID: CVE-2026-74345)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in the RDMA/siw connection management endpoint handling code when processing a malformed MPA request during connection establishment. A remote attacker can send a malformed MPA request to cause a denial of service.
The issue is triggered when the new endpoint is closed during connection establishment.
17) Use-after-free (CVE-ID: CVE-2026-74310)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in vhost_zerocopy_complete in the vhost/net subsystem when processing zerocopy TX descriptor completion callbacks for cloned skbs. A local user can trigger cloned skb completion callbacks to dereference freed ubuf state and cause a denial of service.
Exploitation requires delayed completion after backend removal while another cloned skb reference still carries the same ubuf_info.
18) Out-of-bounds read (CVE-ID: CVE-2026-74287)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in SCTP parameter processing when parsing malformed embedded address parameters in INIT or ASCONF messages. A remote attacker can send a specially crafted SCTP parameter with an embedded address length that exceeds the enclosing parameter bounds to disclose sensitive information.
The issue affects ADD_IP, DEL_IP, and SET_PRIMARY parameters that contain embedded address parameters.
19) Double free (CVE-ID: CVE-2026-74269)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in the bnxt driver receive path in bnxt_rx_multi_page_skb when processing XDP head-grow adjustments. A local user can trigger crafted XDP head adjustment behavior to cause a denial of service.
The issue occurs because a head underflow can corrupt page pool fragment reference counts, causing a page to be prematurely recycled while still in use.
20) Race condition (CVE-ID: CVE-2026-74268)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in tcp_set_state() and tcp_call_bpf() when force-closing a child socket whose inherited sock_ops callback flags remain set after setup failure. A remote attacker can send network traffic that triggers child socket setup failure to cause a denial of service.
The issue occurs before the child socket is ever established and affects forced-close paths that reach tcp_done() without the expected socket lock.
21) Improper Initialization (CVE-ID: CVE-2026-74267)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in sch_codel when peeking queued packets after packet drops. A local user can trigger packet drops during peek to cause a denial of service.
The issue can incorrectly invoke the parent qlen_notify callback while a packet still remains queued, which may deactivate the parent class unexpectedly.
22) Use-after-free (CVE-ID: CVE-2026-74255)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to use-after-free in tipc_l2_send_msg() when handling TIPC layer 2 media disable operations concurrently with RCU readers. A local user can trigger concurrent access to a freed device pointer to execute arbitrary code or cause a denial of service.
The issue is caused by a race condition involving b->media_ptr and network-device lifetime management.
23) Use of Uninitialized Variable (CVE-ID: CVE-2026-72501)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the BNXT_RE_METHOD_ALLOC_PAGE handler in drivers/infiniband/hw/bnxt_re/uapi.c when processing page allocation requests. A local user can trigger the handler so that an uninitialized dpi value is copied to user space to disclose sensitive information.
24) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-72496)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper exception handling in bnxt_qplib_alloc_dpi when mapping device memory with ioremap. A local user can trigger an ioremap failure to cause a denial of service.
25) Race condition (CVE-ID: CVE-2026-72495)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the bnxt_re RDMA ucontext WC page allocation handler when processing repeated concurrent requests to allocate WC pages for the same ucontext. A local user can send repeated allocation requests to cause a denial of service.
Only one WC page per ucontext is supported.
26) Race condition (CVE-ID: CVE-2026-72494)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in the irdma cqp request completion handling when waiting for cqp request completion. A local user can trigger a race condition to cause a denial of service.
The issue arises from missing memory barriers around the request_done flag.
27) Use-after-free (CVE-ID: CVE-2026-72493)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition leading to use-after-free in enqueue_to_backlog() when processing packets during device unregistration. A local attacker can trigger packet transmission during device unregistration to cause a denial of service.
The issue occurs because a packet can escape backlog flushing during network namespace exit or similar device unregistration timing.
28) Race condition (CVE-ID: CVE-2026-72491)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in net/9p RDMA transport state handling in trans_rdma.c when processing RDMA connection events and receive completions concurrently with RDMA requests. A local user can trigger concurrent state transitions to corrupt the connection state machine and cause a denial of service.
The race can lead to lost state transitions during teardown and may result in use-after-free on RDMA request objects.
29) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-72477)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of an inconsistent inode state in ntfs3 rename handling when renaming files or directories. A local user can trigger a rename failure that leaves the inode inconsistent to cause a denial of service.
The issue affects the ntfs3 filesystem code path that handles failed rename rollback.
30) Use-after-free (CVE-ID: CVE-2026-72473)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the xprtrdma request handling logic when processing RPC-over-RDMA send and reply completion. A local user can trigger request reuse while the HCA is still DMA-reading from its send buffer to cause a denial of service.
The issue occurs for Sends carrying only pre-registered buffers, where the request could be returned to the free pool before Send-side completion.
31) Use-after-free (CVE-ID: CVE-2026-72472)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the NFS file lock list handling code when traversing file locks during lock reclaim and delegation lock processing. A local user can trigger concurrent lock and unlock operations to cause a denial of service.
The issue affects NFS lock recovery and delegation-related paths, including reclaim and delegation recall handling.
32) Out-of-bounds read (CVE-ID: CVE-2026-72466)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read and improper resource management in rpcrdma_is_bcall() when processing a short or malformed reply. A remote attacker can send a specially crafted reply to cause a denial of service.
The issue can misclassify a reply as a backchannel call and orphan a persistently DMA-mapped receive buffer, which can drain the Receive queue and lead to RNR NAKs in the peer.
33) Use-after-free (CVE-ID: CVE-2026-72463)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in the xfrm async resumption handling in net/xfrm/xfrm_input.c when processing xfrm packets and resuming transport processing asynchronously. A remote attacker can send crafted traffic that triggers xfrm_rcv_cb to modify skb->dev and cause a denial of service.
The issue involves a race condition with tunnel device teardown and affects handling of both IPv4 and IPv6 transport finish paths.
34) Race condition (CVE-ID: CVE-2026-72451)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in the xfrm input state cache insertion code in xfrm_input_state_lookup() when processing xfrm input state lookups. A remote attacker can trigger concurrent state destruction during cache insertion to cause a denial of service.
35) Improper input validation (CVE-ID: CVE-2026-72442)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in nf_flow_ip6_tunnel_proto() in the netfilter flowtable IPv6 tunnel handling code when processing IPv6-in-IPv6 encapsulated packets. A remote attacker can send specially crafted IPv6 tunnel traffic to cause a denial of service.
The issue arises because the fast path does not handle IPv6 extension headers in this encapsulation case.
36) Race condition (CVE-ID: CVE-2026-72436)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in netfilter ipset hash types when lockless RCU readers process set data in parallel with add, delete, or garbage-collection operations. A local user can trigger concurrent ipset operations to cause a denial of service.
The issue affects readers that are not protected by the region lock and are not in set destroy or new or temporary set creation phases.
37) Type Confusion (CVE-ID: CVE-2026-72429)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to type confusion in the IPv6 IOAM dst cache handling in net/ipv6/ioam6_iptunnel.c when processing IOAM tunnel state that uses a dummy dst_entry. A local user can trigger the vulnerable code path to cause a denial of service.
The issue can lead to invalid pointer access because rt6_get_cookie() may read fields from the wrong object after treating a dst_entry as part of a struct rt6_info.
38) Use-after-free (CVE-ID: CVE-2026-72422)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in smb3_preauth_hash_rsp() when processing concurrent SMB2 NEGOTIATE requests on the same connection. A remote attacker can send concurrent SMB2 NEGOTIATE requests that trigger a race and dereference freed memory to cause a denial of service.
The issue is a race between the SMB2 NEGOTIATE handler and the response send path, where a NULL check can be bypassed by concurrent freeing of conn->preauth_info before dereference.
39) Out-of-bounds read (CVE-ID: CVE-2026-72417)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in nf_flow_ip4_tunnel_proto() when processing malformed IP headers. A remote attacker can send a specially crafted packet to cause a denial of service.
40) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-72412)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause guest memory corruption.
The vulnerability exists due to improper state management in s390 page table entry handling when updating present ptes for guest memory mappings. A local user can trigger page table updates involving reused guest pages to cause guest memory corruption.
The issue affects KVM on s390 systems where the _PAGE_UNUSED bit can remain set after a page becomes used again.
41) Out-of-bounds write (CVE-ID: CVE-2026-72399)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in enetc_xdp_xmit when processing xdp_frame structures with too many fragments. A local user can provide a crafted xdp_frame with more fragments than ENETC_MAX_SKB_FRAGS to cause a denial of service.
The issue occurs because the xdp_redirect_arr array is sized to ENETC_MAX_SKB_FRAGS while an xdp_frame may contain a greater number of fragments.
42) Improper input validation (CVE-ID: CVE-2026-72398)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to tamper with SCTP association handling and cause a denial of service.
The vulnerability exists due to improper input validation in SCTP COOKIE-ECHO processing paths when processing a cookie containing a reconstructed INIT chunk while cookie authentication is disabled. A remote attacker can send a specially crafted COOKIE-ECHO packet to tamper with SCTP association handling and cause a denial of service.
The issue only arises when cookie authentication is disabled.
43) Use-after-free (CVE-ID: CVE-2026-72393)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in fbnic_tx_lso in the fbnic transmit offload path when processing a specially crafted GSO skb that triggers skb reallocation. A local user can send crafted traffic to trigger the stale shared-info pointer dereference to cause a denial of service.
The issue occurs because skb_cow_head() may reallocate the skb and its shared info before the cached pointer is reused.
44) Use-after-free (CVE-ID: CVE-2026-72381)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in ksmbd_vfs_compare_durable_owner() when processing concurrent SMB2 durable reconnect requests on the same persistent_id. A remote user can trigger concurrent durable reconnect operations to cause a denial of service.
The issue occurs because a comparison of owner.name can race with memory being freed in the durable file reopen path.
45) Improper Initialization (CVE-ID: CVE-2026-72366)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource initialization in netfs_create_write_req() when handling write operations during asynchronous cache object creation. A local user can trigger a write operation before the fscache cookie is fully enabled to cause a denial of service.
The issue occurs because caching may be skipped while asynchronous cache object creation has not progressed far enough for the cookie to be enabled.
46) Race condition (CVE-ID: CVE-2026-72355)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the netfs subrequest list handling in fs/netfs/read_retry.c and fs/netfs/write_retry.c when walking the subrequest list during read or write retry processing. A local user can trigger concurrent subrequest activity to cause a denial of service.
Exploitation requires concurrent access to the affected netfs retry paths.
47) Out-of-bounds read (CVE-ID: CVE-2026-72351)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in gue_remcsum() and gue_gro_remcsum() when processing malformed GUE packets with the REMCSUM private flag set but without the required REMCSUM metadata fields. A remote attacker can send a specially crafted packet to disclose sensitive information.
The issue occurs because option validation accepts packets that contain only the private flags field even when additional REMCSUM start and offset fields are expected.
48) Improper input validation (CVE-ID: CVE-2026-72348)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass packet-filtering rules.
The vulnerability exists due to improper input validation in the ip6tables ah, hbh, and rt IPv6 extension header match handlers when processing malformed IPv6 packets with advertised extension header lengths that exceed the available skb data. A remote attacker can send a specially crafted IPv6 packet to bypass packet-filtering rules.
The issue affects handling of malformed IPv6 authentication, hop-by-hop, and routing extension headers.
49) Off-by-one (CVE-ID: CVE-2026-72339)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an off-by-one error in the qede_rx_build_skb() and qede_tpa_rx_build_skb() functions when handling a NULL return from qede_build_skb() under memory pressure. A local user can trigger memory pressure and network receive processing to cause memory corruption.
The issue can desynchronize the BD ring, which can corrupt DMA page reference counts and lead to SLUB freelist corruption.
50) Use-after-free (CVE-ID: CVE-2026-72329)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the liquidio SR-IOV VF pci_dev lookup handling when processing an OCTEON_VF_FLR_REQUEST mailbox command. A local user can trigger a VF FLR request that causes dereference of a stale pci_dev pointer to cause a denial of service.
Exploitation requires the affected device to be operating in SR-IOV mode with allocated virtual functions.
51) Use-after-free (CVE-ID: CVE-2026-72323)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the IGMP timer callback when processing incoming IGMP queries during device teardown. A remote attacker can send a crafted IGMP query to cause a denial of service.
Exploitation requires a race between device destruction and IGMP query processing.
52) Use-after-free (CVE-ID: CVE-2026-72322)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in the IPv6 MLD delayed work handling in net/ipv6/mcast.c when processing incoming MLD queries during device teardown. A remote attacker can send crafted MLD query traffic to trigger a kernel panic and cause a denial of service.
The issue arises from a race condition between device destruction and packet receive processing under RCU protection.
53) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-72320)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass netfilter rules.
The vulnerability exists due to improper handling of inverted lookups in nft_lookup_eval() when processing catchall elements for interval sets. A local user can trigger a crafted lookup condition to bypass netfilter rules.
The issue affects inverted lookups using catchall elements for the open-ended default range in interval sets.
54) Improper input validation (CVE-ID: CVE-2026-72319)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ip_vs_in_icmp in the IPVS subsystem when processing ICMP error packets from tunnels. A remote attacker can send a specially crafted ICMP error packet to cause a denial of service.
The issue involves inner IP headers not being ensured in skb headroom after outer headers are stripped, and additional length checks were required for the inner headers.
55) Out-of-bounds read (CVE-ID: CVE-2026-72318)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in parse_dfs_referrals() when processing a malicious DFS referral response from a server. A remote attacker can supply crafted referral string offsets to cause an out-of-bounds read and disclose sensitive information.
The issue occurs when DfsPathOffset or NetworkAddressOffset points beyond the end of the response buffer, leading to a negative length being forwarded as a size_t in the non-Unicode path.
56) Use-after-free (CVE-ID: CVE-2026-72317)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the SUNRPC TLS connect_worker when handling a failed TLS handshake on a TLS-secured transport. A local user can trigger a failed TLS handshake that causes the upper rpc_clnt to be freed before the queued worker dereferences it to cause a denial of service.
The issue affects the TLS transport path; the non-TLS connect worker does not use the saved client pointer.
57) Use-after-free (CVE-ID: CVE-2026-72299)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in TIPC enqueue tracepoint queue dumping in tipc_sk_enqueue() when dumping socket queues during message enqueue processing. A local user can trigger crafted TIPC socket activity to cause a denial of service.
The issue is reachable while the socket is owned by user context, because the held spinlock protects the backlog queue but does not serialize access to sk_receive_queue.
58) Improper input validation (CVE-ID: CVE-2026-72296)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ife_decode() when processing malformed IFE frames. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue can crash the kernel when the inner Ethernet header is not sufficiently accessible from the linear data area before the packet is passed to eth_type_trans().
59) Race condition (CVE-ID: CVE-2026-72289)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in vgic_prune_ap_list() in the KVM arm64 virtual generic interrupt controller when migrating an interrupt to another vCPU while locks are temporarily dropped. A local user can trigger interrupt migration during this race to cause a denial of service.
The issue can result in list_del() being performed on an interrupt entry that has already been removed from the ap_list.
60) Use-after-free (CVE-ID: CVE-2026-72288)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the KVM arm64 virtual generic interrupt controller (vgic) AP list handling when racing interrupt affinity changes with LPI disabling. A local user can trigger concurrent interrupt state changes to cause a denial of service.
The issue occurs during LPI handling involving multiple vCPUs.
61) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-72287)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute code in the host kernel.
The vulnerability exists due to improper state management in KVM nVMX nested VM-entry control checks when entering non-root mode with a crafted vTPR and TPR threshold combination. A local privileged user can supply crafted nested VMX state to cause KVM to run L1 with an L1-controlled CR3 to execute code in the host kernel.
The issue arises when EPT is disabled, and the consistency check was performed only in a late validation path.
62) Improper access control (CVE-ID: CVE-2026-72279)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access control in the KVM arm64 nested virtualization VNCR mapping logic when handling writes to an L1 VNCR backed by a read-only PFN. A local user can attempt to write to a read-only endpoint to cause a denial of service.
The issue affects the handling of read-only memslots and promotes the resulting fault to a synchronous external abort.
63) Improper Initialization (CVE-ID: CVE-2026-72278)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of vncr translation state in the arm64 kvm nested virtualization vncr handling logic when processing vncr aborts after a read-only translation is cached and a subsequent write abort occurs. A local user can trigger vncr abort conditions to cause a denial of service.
The issue occurs in nested virtualization on arm64 systems involving vncr page access.
64) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-72277)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of non-memory PFNs in KVM nested virtualization on arm64 when constructing an l1 vncr mapping. A local user can trigger translation of a vncr mapping backed by a non-memory pfn to cause a denial of service.
The issue can result in an SError on writeback or an injected synchronous external abort in the guest.
65) Use-after-free (CVE-ID: CVE-2026-72251)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in nf_nat_sip in net/netfilter/nf_nat_sip.c when handling cloned socket buffers during SIP NAT processing. A local user can trigger packet processing with a cloned skb to cause a denial of service.
The issue occurs in the reply-direction destination port mangling path for SIP traffic.
66) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-72249)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in nf_flow_tunnel_ipip_push and related flowtable tunnel header handling in netfilter when processing flow offload traffic with IPIP encapsulation. A local user can trigger packet processing that uses the route from the opposite direction to calculate headroom, causing a denial of service.
The issue affects headroom calculation and ip header fragmentation state during flowtable tunnel encapsulation.
67) NULL pointer dereference (CVE-ID: CVE-2026-72248)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to invalid dst usage in the Linux kernel netfilter flowtable tunnel transmit path when handling direct xmit flows over IPIP tunnels. A local user can trigger crafted flow handling to cause a denial of service.
The issue occurs with the combination of IPIP tunnel support and direct xmit, such as through a bridge device.
68) Use-after-free (CVE-ID: CVE-2026-72234)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in net/batman-adv/routing.c when processing batman-adv unicast packets. A local user can send a specially crafted packet to cause a denial of service.
69) Integer overflow (CVE-ID: CVE-2026-72226)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an out-of-bounds read.
The vulnerability exists due to an integer overflow in the batadv_tt_tvlv_unicast_handler_v1 function when processing a TT unicast TVLV containing a crafted number of VLAN entries. A remote attacker can send a specially crafted TVLV message to cause an out-of-bounds read.
70) Use-after-free (CVE-ID: CVE-2026-72222)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to a use-after-free in the sunrpc TLS handshake callback handling in svc_tcp_handshake() and svc_tcp_handshake_done() when a connection close overlaps an asynchronous TLS handshake. A remote attacker can trigger a connection close during the TLS handshake to cause memory corruption.
The issue is reachable on TLS-enabled NFS servers, and signal delivery during the interruptible wait can trigger the affected race window.
71) Race condition (CVE-ID: CVE-2026-72221)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in svc_tcp_handshake() in the sunrpc server socket handling code when processing a TLS handshake callback during handshake cancellation. A remote attacker can trigger a TLS handshake timeout or interruption and cause concurrent handshake completion to corrupt the embedded swait_queue or tear down the connection to cause a denial of service.
The issue occurs when cancellation loses the race to handshake completion and the callback is still in flight.
72) Double free (CVE-ID: CVE-2026-72220)
CWE-ID: CWE-415 - Double Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to double free in sunrpc request handling when processing RPC requests. A remote attacker can send crafted RPC traffic that triggers stale rq_procinfo release handling to cause a denial of service.
The issue can also result in a use-after-free condition if reused state from a previous RPC is referenced.
73) Out-of-bounds write (CVE-ID: CVE-2026-72217)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in xdr_buf_to_bvec() when processing client-supplied RPC payload sizes. A remote attacker can send a specially crafted RPC request to cause memory corruption.
The out-of-bounds store can write one element past the end of the bio_vec array into adjacent slab memory, and the written length and offset fields are derived from client-controlled payload sizes.
74) Stack-based buffer overflow (CVE-ID: CVE-2026-72194)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in indx_find_buffer() in the ntfs3 filesystem driver when mounting a crafted NTFS filesystem and deleting a file that triggers index rebalancing. An attacker with physical access can provide a malicious NTFS image with circular index node references to cause a denial of service.
User interaction may be required in environments where removable media is mounted through desktop automount.
75) Out-of-bounds write (CVE-ID: CVE-2026-72192)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to overwrite adjacent heap memory.
The vulnerability exists due to an out-of-bounds write in indx_insert_into_root in the ntfs3 index handling code when processing a crafted mounted NTFS image during file creation. A local user can create a sufficiently long file name in a directory with a full resident root to overwrite adjacent heap memory.
The overwritten bytes are copied from on-disk NTFS entries and are attacker-controlled, and exploitation depends on the surrounding slab layout.
76) Out-of-bounds write (CVE-ID: CVE-2026-72191)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in indx_insert_into_buffer in the ntfs3 filesystem code when processing a crafted NTFS filesystem image during file creation in a mounted directory. A local user can mount a specially crafted NTFS image and trigger filesystem operations to cause a denial of service.
Triggering the issue requires local mounting of an attacker-supplied filesystem image, such as via loopback, removable media, or USB, and a filesystem operation such as creating a file in the mounted directory.
77) Use-after-free (CVE-ID: CVE-2026-72139)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in tcp_connect() and tcp_clear_md5_list() when reconciling TCP MD5 and TCP-AO authentication state during connection setup. A local user can trigger concurrent socket operations that race with RCU readers to cause a denial of service.
The race occurs while the socket is in TCP_SYN_SENT and already present in the inet ehash, where softirq RX-path readers may access the authentication data through RCU-protected lookups.
78) Double free (CVE-ID: CVE-2026-72137)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in nat_keepalive_send() when handling send errors after handing a keepalive skb to the IPv4 or IPv6 output path. A local user can trigger an error during keepalive packet transmission to cause a denial of service.
The issue occurs because the skb may already have been consumed by the networking stack before an error is returned.
79) Heap-based buffer overflow (CVE-ID: CVE-2026-72130)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in nvmet_execute_auth_receive() and the DH-HMAC-CHAP response builders when processing AUTH_RECEIVE commands with a too-short allocation length. A remote user can send a specially crafted AUTH_RECEIVE command to cause a denial of service.
This is reachable only when in-band DH-HMAC-CHAP authentication is configured on the target.
80) Out-of-bounds read (CVE-ID: CVE-2026-72129)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in nvmet_rdma_use_inline_sg() and inline scatterlist handling in the NVMe target RDMA component when processing host-controlled inline data with a nonzero offset. A remote user can send crafted inline data offsets and lengths to cause a denial of service.
The issue can be triggered when inline_data_size is configured larger than PAGE_SIZE, and page-spanning in-bounds ranges may also cause the scatterlist to be under-counted.
81) Out-of-bounds write (CVE-ID: CVE-2026-72098)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in dm-verity fec calculation when processing erasure data during FEC decoding. A local user can trigger crafted corruption conditions to cause memory corruption.
The out-of-bounds write can occur when the erasure count exceeds the intended Reed-Solomon roots limit and the decoder writes past the end of the lambda array into the syndrome buffer.
82) Use-after-free (CVE-ID: CVE-2026-72085)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a refcount underflow leading to use-after-free in xen-scsiback request handling when processing pvSCSI requests before command submission. A remote user can submit requests with a bad grant reference or an unknown request type to cause a denial of service.
Under panic_on_warn, triggering the refcount underflow can panic the host. The issue can also leak every command tag of a LUN session, stopping the LUN.
83) Out-of-bounds read (CVE-ID: CVE-2026-72084)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in iSCSI PR-OUT TransportID parsing in the Linux kernel SCSI target subsystem when processing a crafted PERSISTENT RESERVE OUT TransportID buffer. A remote attacker can send a specially crafted PR OUT request to cause a denial of service.
The issue is reachable through any fabric that delivers a PR OUT to a device exported through an iSCSI target portal group, including a guest via vhost-scsi.
84) Use-after-free (CVE-ID: CVE-2026-72083)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in core_scsi3_emulate_pro_register_and_move() when processing a crafted iSCSI TransportID in a PERSISTENT RESERVE OUT REGISTER AND MOVE parameter list. A remote user can send a specially crafted request to cause a denial of service.
The issue is triggered when the parameter list spans more than one page, causing the ISID pointer to reference an unmapped region after the buffer is torn down.
85) Use-after-free (CVE-ID: CVE-2026-72069)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in rt_spin_unlock(), rt_read_unlock(), and rt_write_unlock() when releasing RCU protection before completing unlock operations. A local user can trigger concurrent lock and RCU operations to execute arbitrary code.
The issue affects the RT spinlock and rwlock substitutions where unlock handling does not preserve the expected non-RT RCU protection semantics.
86) Improper input validation (CVE-ID: CVE-2026-72065)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper input validation in the mana RX completion queue handling in mana_process_rx_cqe() when processing packet length values reported by the NIC. An attacker with physical access can supply an invalid packet length via a malicious or compromised NIC device to cause a denial of service.
The reported packet length is supplied by the NIC device and is not sufficiently validated before skb processing.
87) Improper locking (CVE-ID: CVE-2026-72064)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization for cpu access in the mana RX buffer handling in the Linux kernel MANA network driver when processing received packets from page pool fragments. A local user can trigger packet reception on an affected interface to cause a denial of service.
The issue occurs when page pool fragments are used with frag_count greater than 1 on configurations that require explicit DMA syncing, such as systems booted with swiotlb=force.
88) Out-of-bounds write (CVE-ID: CVE-2026-72046)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the gve DQO RX header buffer handling when processing out-of-order RX completions with header-split and HW-GRO enabled. A local user can trigger packet flows that cause header buffer reuse while still owned by the device to cause a denial of service.
Exploitation requires header-split and HW-GRO to be enabled, and completion reordering can occur with multiple interleaved flows.
89) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-72041)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in espintcp_sendskmsg_locked in net/xfrm/espintcp.c when handling partial sends of sk_msg data. A local user can trigger partial send conditions to cause a denial of service.
90) Out-of-bounds read (CVE-ID: CVE-2026-72033)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in fill_from_part() in the OrangeFS directory handling code when processing a crafted readdir entry trailer supplied by a userspace client. A local user can supply a crafted directory entry with a wrapped length value to cause a denial of service.
The issue occurs because a directory entry size computed in size_t is truncated to a 32-bit value, which can bypass a bounds check and lead to a read far past the directory part.
91) Use of Uninitialized Variable (CVE-ID: CVE-2026-72020)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and corrupt forwarded TCP traffic.
The vulnerability exists due to use of uninitialized memory in ip_vs_conn_new and TCP sequence handling in IPVS when processing a malformed sync message that omits sequence data. A remote user can send a specially crafted sync message to disclose sensitive information and corrupt forwarded TCP traffic.
The issue affects connections learned from a sync message when sequence flags are preserved without valid sequence data, causing stale slab bytes to be used in TCP sequence and acknowledgment number rewriting by an IPVS application helper.
92) Out-of-bounds write (CVE-ID: CVE-2026-72014)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to corrupt kernel memory.
The vulnerability exists due to an out-of-bounds write in recv_dless_read() when processing a crafted P_DATA_REPLY from a DRBD peer. A remote attacker can send a specially crafted data reply to corrupt kernel memory.
A node that reads from its peer, such as a diskless node or a node using read-balancing to the peer, is exposed in the default configuration. A man-in-the-middle DRBD peer can also exploit the issue.
93) Improper input validation (CVE-ID: CVE-2026-68477)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect packet processing.
The vulnerability exists due to improper handling of ipv6 transport offsets in ipvs application and icmpv6 response processing when handling ipv6 packets with extension headers. A remote attacker can send specially crafted ipv6 traffic to cause incorrect packet processing.
The issue affects TCP application handling and ICMPv6 checksum validation in IPVS for IPv6 traffic.
94) Use-after-free (CVE-ID: CVE-2026-68476)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in __ip_vs_get_out_rt() handling of skb head reallocation in net/netfilter/ipvs/ip_vs_xmit.c when processing packets in ip_vs_bypass_xmit(). A local user can trigger skb head reallocation and subsequent use of a stale IP header pointer to cause a denial of service.
95) Improper access control (CVE-ID: CVE-2026-68457)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass intended file permission checks.
The vulnerability exists due to improper access control in ksmbd FSCTL mutation handlers when processing SET_SPARSE, SET_ZERO_DATA, or SET_COMPRESSION operations on an open SMB handle. A remote user can invoke these operations so they are performed with ksmbd worker credentials to bypass intended file permission checks.
The issue arises because helper calls may independently revalidate inode permissions, ownership, or LSM policy instead of relying solely on the SMB handle access mask.
96) Path traversal (CVE-ID: CVE-2026-68083)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access files outside the exported share.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in ksmbd_vfs_kern_path_create() when handling SMB create, mkdir, or hardlink operations with crafted path components. A remote user can race a missing path component and use a ".." path element to access files outside the exported share.
Exploitation requires authentication to the SMB service and a race condition between the rooted lookup and the create path resolution.
97) Out-of-bounds read (CVE-ID: CVE-2026-64551)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose uninitialized memory.
The vulnerability exists due to an out-of-bounds read in sctp_sf_do_5_2_6_stale() when processing an ERROR chunk with a STALE_COOKIE cause in the COOKIE_ECHOED state. A local user can send a specially crafted SCTP packet to disclose uninitialized memory.
The leaked value is echoed to the peer in the Cookie Preservative of the reply INIT. Exploitation is reachable by a peer that can drive an association into COOKIE_ECHOED, including an unprivileged process using a raw SCTP socket in a user and network namespace.
98) Use-after-free (CVE-ID: CVE-2026-64541)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in smc_cdc_rx_handler() when handling SMC-R CDC messages for a connection after releasing conns_lock. A local user can trigger a concurrent socket close while the handler continues to dereference the freed socket to cause a denial of service.
Only SMC-R is affected.
99) Use-after-free (CVE-ID: CVE-2026-64535)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in the NVMe/TCP target digest error handling in nvmet_tcp_try_recv_ddgst() and queue teardown logic when processing a digest mismatch on a non-final H2C_DATA PDU during an R2T-based data transfer. A remote user can trigger a digest mismatch to cause a denial of service.
Exploitation requires data digest to be enabled on the NVMe/TCP connection.
100) Use-after-free (CVE-ID: CVE-2026-64534)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in nvmet_tcp_try_recv_ddgst() when processing a command with a data digest mismatch after request initialization previously failed. A remote attacker can send a specially crafted request to cause a denial of service.
The issue can lead to a refcount underflow, kernel warnings, and a permanent workqueue deadlock.
101) Use-after-free (CVE-ID: CVE-2026-64530)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in tcf_qevent_handle in net/sched/cls_api.c when handling TC_ACT_CONSUMED during qevent processing of fragmented traffic. A local user can send specially crafted fragmented network traffic to trigger use of an skb after ownership has been transferred and cause a denial of service.
Exploitation requires RED qdisc qevents together with ct defragmentation and traffic that produces out-of-order fragments.
Remediation
Install update from vendor's website.