SB20261001134 - Ubuntu update for linux-nvidia-tegra
Published: October 1, 2026 Updated: October 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 542 vulnerabilities.
1) Improper locking (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to improper memory synchronization in broadcast TLBI completion in the arm64 TLB invalidation handling when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger affected memory access patterns to disclose sensitive information, modify data, or cause a denial of service.
The issue affects completion of memory accesses translated by an invalidated TLB entry, while TLB entries themselves are still invalidated correctly.
2) Race condition (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to improper memory synchronization in broadcast TLB invalidation completion handling in the arm64 CPU errata handling for affected Arm CPUs when performing broadcast TLB invalidation sequences. A local user can trigger memory accesses relying on an invalidated TLB entry to disclose sensitive information, modify data, or cause a denial of service.
The issue affects only the completion of memory accesses translated by an invalidated TLB entry; the TLB entries themselves are still invalidated correctly.
3) Improper locking (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to improper memory access ordering in arm64 TLB invalidation handling when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger affected memory access completion conditions to disclose sensitive information, modify data, or cause a denial of service.
The issue affects only memory accesses translated by an invalidated TLB entry; TLB entries themselves are still invalidated correctly.
4) Improper locking (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to improper synchronization in broadcast TLB invalidation handling in the arm64 TLB invalidation logic when processing TLBI and DSB sequences on affected Arm CPUs. A local user can trigger memory accesses involving translations from an invalidated TLB entry to disclose sensitive information, modify data, or cause a denial of service.
The issue affects only the completion of memory accesses translated by an invalidated TLB entry and does not prevent the actual invalidation of TLB entries.
5) Improper locking (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper hardware synchronization in broadcast TLBI completion on affected arm64 CPUs when performing broadcast TLB invalidation. A local user can trigger memory access activity that relies on an invalidated TLB entry to cause a denial of service.
The issue affects only the completion of memory accesses translated by an invalidated TLB entry; the TLB invalidation itself still occurs correctly.
6) Race condition (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in broadcast TLBI completion in the arm64 TLB invalidation handling when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger memory access patterns that rely on invalidated TLB entries to cause a denial of service.
The issue affects the completion of memory accesses translated by an invalidated TLB entry, while the TLB invalidation itself still occurs correctly.
7) Race condition (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in broadcast TLB invalidation completion handling in the arm64 CPU errata logic when performing memory accesses translated by an invalidated TLB entry after a TLBI;DSB sequence. A local user can trigger affected memory access patterns to cause a denial of service.
The issue affects certain Arm CPUs on arm64 systems and does not prevent invalidation of TLB entries themselves.
8) Improper locking (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper hardware synchronization in arm64 TLB invalidation handling when processing broadcast TLB invalidation sequences on affected Arm CPUs. A local user can trigger memory accesses that rely on an invalidated TLB entry to cause a denial of service.
The issue affects only the completion of memory accesses translated by an invalidated TLB entry and does not affect the actual invalidation of TLB entries.
9) Race condition (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in broadcast TLB invalidation completion handling in the arm64 TLB invalidation logic when performing memory accesses translated by an invalidated TLB entry after a TLBI;DSB sequence. A local user can trigger affected memory access patterns to cause a denial of service.
The issue affects only the completion of memory accesses translated by an invalidated TLB entry and does not prevent the actual invalidation of TLB entries.
10) Improper locking (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper memory synchronization in broadcast TLB invalidation completion handling in the arm64 CPU errata logic when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger memory access patterns that rely on invalidated TLB entries to cause a denial of service.
The issue affects only completion of memory accesses translated by an invalidated TLB entry and does not prevent the actual invalidation of TLB entries.
11) Improper access control (CVE-ID: CVE-2025-10263)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper access control in Stage 2 translation handling when invalidating translation lookaside buffer entries on affected Arm systems. A local user can trigger writes from a malicious guest after write permissions have been revoked to escalate privileges.
Only Xen on Arm in multi-core configurations is affected. The issue does not affect reads.
12) Out-of-bounds read (CVE-ID: CVE-2026-74569)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in ct_sip_get_header() in the nf_conntrack_sip SIP connection-tracking helper when processing NAT-rewritten SIP messages over TCP. A remote attacker can send a specially crafted SIP message with a long Contact list to cause a denial of service.
The issue is triggered by integer wraparound in size-change tracking during repeated URI rewriting, which can produce an invalid length value for a subsequent header parse.
13) Heap-based buffer overflow (CVE-ID: CVE-2026-74556)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in iscsi_tcp_hdr_dissect() in libiscsi_tcp when processing a crafted iSCSI SCSI Command Response pdu. A remote attacker can send a specially crafted response with an oversized data segment to cause a denial of service.
The issue occurs because sense or response data for ISCSI_OP_SCSI_CMD_RSP can exceed the fixed 8192-byte connection buffer while remaining within the negotiated maximum receive data segment length.
14) Use-after-free (CVE-ID: CVE-2026-74541)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the Bluetooth ISO socket handling code when disconnecting an ISO connection and later releasing the socket. A local user can trigger connection teardown that leaves a stale iso_data pointer to cause a denial of service.
15) Improper locking (CVE-ID: CVE-2026-74538)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in iso_connect_ind when handling Bluetooth ISO connection indication events. A local user can trigger a race condition to cause a denial of service.
The issue occurs because iso_pi(sk)->conn may be accessed after the socket has transitioned away from the LISTEN or CONNECT states.
16) Incorrect Comparison (CVE-ID: CVE-2026-74521)
CWE-ID: CWE-697 - Incorrect Comparison
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass client identity checks.
The vulnerability exists due to improper comparison of fixed-size binary data in ksmbd SMB3 multichannel session binding and FSCTL_VALIDATE_NEGOTIATE_INFO handling when processing ClientGUID values. A remote user can send a crafted ClientGUID containing embedded NUL bytes to bypass client identity checks.
17) Off-by-one (CVE-ID: CVE-2026-74495)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an off-by-one error in the igbvf TX DMA error cleanup logic when handling TX buffer mapping errors. A local user can trigger a DMA mapping failure after one or more successful mappings to cause a denial of service.
The issue can leak exactly one DMA mapping for the packet head when a fragment mapping fails after earlier mappings succeed.
18) Use-after-free (CVE-ID: CVE-2026-74493)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in __smc_lgr_terminate() in the SMC networking subsystem when terminating a link group while a concurrent close unregisters a connection. A local user can trigger overlapping close and link group termination operations to cause a denial of service.
The issue is caused by a race condition involving socket reference handling for a connection stored in lgr->conns_all.
19) Use-after-free (CVE-ID: CVE-2026-74480)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in br_multicast_leave_group() in the bridge multicast handling code when processing fast-leave operations on port groups. A local user can trigger deletion of a matching port group to cause a denial of service.
The issue can occur when multicast-to-unicast had been enabled, allowing multiple port groups for the same port and group with different source MAC addresses, and is later disabled so entries are matched by port only.
20) Use-after-free (CVE-ID: CVE-2026-74478)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in vector_mmsg_rx() when processing packets with an overlay header that fails verification. A remote attacker can send a specially crafted packet to cause a denial of service.
Only GRE and L2TPv3 transports are affected, and exploitation can be triggered on a cookie or session-id mismatch without authentication.
21) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-74476)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of non-linear skb fragment metadata in veth_convert_skb_to_xdp_buff() when processing frag_list skbs before exposing them to XDP. A local user can trigger processing of a crafted non-linear skb with frag_list data to cause a denial of service.
The issue can lead to a crash in memcpy() from __xsk_rcv() in AF_XDP copy mode.
22) Race condition (CVE-ID: CVE-2026-74475)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in route_shortcircuit() in the VXLAN implementation when processing neighbour hardware addresses. A local attacker can trigger concurrent updates to cause a denial of service.
23) Out-of-bounds read (CVE-ID: CVE-2026-74474)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the vxlan transmit path header handling in vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get() when processing crafted socket buffers. A local user can provide a specially crafted skb layout to cause a denial of service.
The issue occurs because network-layer header availability is checked without accounting for the MAC header offset during transmit processing.
24) Out-of-bounds read (CVE-ID: CVE-2026-74473)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in route_shortcircuit() in drivers/net/vxlan/vxlan_core.c when processing packets with a non-linear buffer layout. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue occurs because the network header may not be fully pulled into the linear buffer before ip_hdr(skb)->daddr or ipv6_hdr(skb)->daddr is dereferenced.
25) Race condition (CVE-ID: CVE-2026-74440)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to read or write memory being moved.
The vulnerability exists due to a race condition in xe_exec_ioctl() when scheduling user jobs that use external buffer objects mapped by the VM without waiting on their dma-resv KERNEL fences. A local user can submit a job using an external buffer object while a kernel operation on that buffer object is still in flight to read or write memory being moved.
Long-running mode is excluded from this behavior.
26) Race condition (CVE-ID: CVE-2026-74439)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in device_pasid_table_teardown() when tearing down scalable-mode context entries. A local user can trigger teardown of a PASID table entry to cause a denial of service.
The issue arises because hardware may fetch a torn entry while the Present bit remains set, which can result in spurious faults or stale walks to freed memory.
27) Use-after-free (CVE-ID: CVE-2026-74436)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in rxrpc_kernel_charge_accept() and the rxrpc service backlog handling when concurrent socket teardown and kernel accept preallocation occur. A local attacker can trigger concurrent operations that reuse a freed backlog structure to cause a denial of service.
The issue arises from a race condition between kernel preallocation work and socket teardown in the RxRPC subsystem.
28) Improper resource shutdown or release (CVE-ID: CVE-2026-74427)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper shutdown handling in the afs network namespace preallocation work logic when tearing down an afs network namespace. A local user can trigger network namespace teardown to cause a denial of service.
The issue involves cancellation and requeue behavior of the preallocated rxrpc call, connection, and peer charger while incoming calls are being disabled.
29) Integer overflow (CVE-ID: CVE-2026-74417)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer overflow in radeon_align_pitch() when creating a dumb buffer. A local user can supply crafted width or bits-per-pixel values to cause a denial of service.
The issue can result in an invalid pitch or a zero-sized dumb buffer.
30) Integer overflow (CVE-ID: CVE-2026-74411)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer truncation in rtw89_update_6ghz_rnr_chan when processing 6 GHz scan parameters. A local user can trigger Wi-Fi scanning with a large number of 6 GHz parameters to cause a denial of service.
The issue can result in a kernel soft lockup during 6 GHz Wi-Fi scanning and may lead to a system panic.
31) Out-of-bounds read (CVE-ID: CVE-2026-74410)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in rtw_pci_rx_napi() when processing firmware RX descriptors on the PCIe transport path. A local attacker can provide a crafted descriptor with a length value that exceeds the DMA buffer size to disclose sensitive information.
The issue occurs because the computed receive length can exceed the size of the pre-allocated DMA buffer before data is copied.
32) Out-of-bounds read (CVE-ID: CVE-2026-74408)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in ath_tx_edma_tasklet() when processing a firmware-provided tx status queue ID. A local attacker can provide an invalid queue ID value to trigger an out-of-bounds array access and cause a denial of service.
33) Race condition (CVE-ID: CVE-2026-74407)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in the ath11k PCI shutdown and SSR recovery handling when shutdown or reboot overlaps with WLAN firmware crash recovery. A local attacker can trigger a reboot during concurrent SSR activity to cause a denial of service.
This issue affects only PCI/MHI-based devices; AHB-based ath11k devices are not affected in normal SSR flows.
34) NULL pointer dereference (CVE-ID: CVE-2026-74406)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in vxlan_gro_prepare_receive() when processing packets during GRO handling. A local attacker can trigger concurrent socket state changes to cause a denial of service.
35) Race condition (CVE-ID: CVE-2026-74405)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition leading to refcount corruption in the OPP core when adding and looking up dynamic OPP entries concurrently. A local user can trigger concurrent OPP addition and lookup operations to cause a denial of service.
The issue can lead to a potential premature free of a newly added OPP object.
36) Use-after-free (CVE-ID: CVE-2026-74401)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the DLM send_queue handling in fs/dlm/midcomms.c when processing a high volume of DLM messages. A local user can trigger heavy DLM message activity to cause a denial of service.
The issue occurs when message sequence numbers in the ordered send queue are not assigned in the required order, leading to refcounting problems.
37) Race condition (CVE-ID: CVE-2026-74398)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in addrconf_dad_failure in the IPv6 address configuration subsystem when handling duplicate address detection failure processing concurrently with IPv6 address deletion. A local attacker can trigger concurrent state transitions to cause a denial of service.
The issue can lead to a general protection fault when a deleted IPv6 address entry is processed a second time through scheduled DAD work.
38) Integer overflow (CVE-ID: CVE-2026-74394)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the immediate data length check in the RDMA/srpt subsystem when processing user-supplied immediate data received over the network. A remote attacker can send a specially crafted network request with an oversized length value to cause a denial of service.
The length field is user-controlled and may wrap the computed request size, bypassing the bounds check before a very large length is passed to sg_init_one().
39) Out-of-bounds write (CVE-ID: CVE-2026-74384)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the nvme multipath namespace head flexible array member current_path[] when handling sparse NUMA node IDs during namespace path revalidation. A local user can trigger nvme multipath operations on a system with sparse NUMA node IDs to cause a denial of service.
Only systems using nvme multipath on architectures where NUMA node IDs are sparse are affected.
40) Improper resource shutdown or release (CVE-ID: CVE-2026-74376)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the md/raid10 discard handling logic when reusing an r10bio for discard operations. A local user can trigger discard operations on a reused r10bio to cause a denial of service.
The issue occurs when a discard reuses an r10bio that was previously used for a read, leaving read_slot non-negative and causing cleanup to skip releasing the replacement bio.
41) Out-of-bounds read (CVE-ID: CVE-2026-74350)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the ocfs2 fast symlink read path when processing a malformed zero-cluster symlink inode. A local user can provide a crafted filesystem image containing an invalid fast symlink to disclose sensitive information.
The issue is triggered when the inline symlink payload is not NUL-terminated at the recorded size or when the recorded size exceeds the inline fast-symlink capacity.
42) Use-after-free (CVE-ID: CVE-2026-74345)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in the RDMA/siw connection management endpoint handling code when processing a malformed MPA request during connection establishment. A remote attacker can send a malformed MPA request to cause a denial of service.
The issue is triggered when the new endpoint is closed during connection establishment.
43) Use-after-free (CVE-ID: CVE-2026-74310)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in vhost_zerocopy_complete in the vhost/net subsystem when processing zerocopy TX descriptor completion callbacks for cloned skbs. A local user can trigger cloned skb completion callbacks to dereference freed ubuf state and cause a denial of service.
Exploitation requires delayed completion after backend removal while another cloned skb reference still carries the same ubuf_info.
44) Improper access control (CVE-ID: CVE-2026-74305)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass intended cgroup storage compatibility checks.
The vulnerability exists due to improper access control in bpf prog-array compatibility checks when validating tail-call chains involving cgroup local storage. A local user can load a storage-less BPF program that performs tail calls to bridge between programs with incompatible storage cookies to bypass intended cgroup storage compatibility checks.
Exploitation requires the ability to load and use BPF programs that participate in tail-call chains.
45) Use-after-free (CVE-ID: CVE-2026-74302)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to use-after-free in hci_unregister_dev() when a timeout fires during device teardown. A local user can trigger device teardown and a timer callback to dereference freed memory to cause a denial of service or execute arbitrary code.
The freed memory may include the hdev->reset function pointer.
46) Out-of-bounds read (CVE-ID: CVE-2026-74287)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in SCTP parameter processing when parsing malformed embedded address parameters in INIT or ASCONF messages. A remote attacker can send a specially crafted SCTP parameter with an embedded address length that exceeds the enclosing parameter bounds to disclose sensitive information.
The issue affects ADD_IP, DEL_IP, and SET_PRIMARY parameters that contain embedded address parameters.
47) Improper resource shutdown or release (CVE-ID: CVE-2026-74280)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the sg_cleanup path in drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c when cleaning up DMA mappings after a setup failure. A local user can trigger the cleanup path to cause a denial of service.
The issue uses the wrong loop index during DMA unmapping, which can leak successfully mapped entries while repeatedly unmapping the failed one.
48) Improper resource shutdown or release (CVE-ID: CVE-2026-74279)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the sg_cleanup error path in setup_sgio_components() when cleaning up DMA mappings after a mapping failure. A local user can trigger the error path to cause a denial of service.
The issue leaks successfully mapped DMA entries while repeatedly unmapping the failed entry.
49) Double free (CVE-ID: CVE-2026-74269)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in the bnxt driver receive path in bnxt_rx_multi_page_skb when processing XDP head-grow adjustments. A local user can trigger crafted XDP head adjustment behavior to cause a denial of service.
The issue occurs because a head underflow can corrupt page pool fragment reference counts, causing a page to be prematurely recycled while still in use.
50) Race condition (CVE-ID: CVE-2026-74268)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in tcp_set_state() and tcp_call_bpf() when force-closing a child socket whose inherited sock_ops callback flags remain set after setup failure. A remote attacker can send network traffic that triggers child socket setup failure to cause a denial of service.
The issue occurs before the child socket is ever established and affects forced-close paths that reach tcp_done() without the expected socket lock.
51) Improper Initialization (CVE-ID: CVE-2026-74267)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in sch_codel when peeking queued packets after packet drops. A local user can trigger packet drops during peek to cause a denial of service.
The issue can incorrectly invoke the parent qlen_notify callback while a packet still remains queued, which may deactivate the parent class unexpectedly.
52) Race condition (CVE-ID: CVE-2026-74264)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the network device watchdog code when concurrent watchdog operations are performed. A local user can trigger concurrent watchdog activity to cause a denial of service.
The issue can lead to list corruption and a kernel crash.
53) Use-after-free (CVE-ID: CVE-2026-74255)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to use-after-free in tipc_l2_send_msg() when handling TIPC layer 2 media disable operations concurrently with RCU readers. A local user can trigger concurrent access to a freed device pointer to execute arbitrary code or cause a denial of service.
The issue is caused by a race condition involving b->media_ptr and network-device lifetime management.
54) Use-after-free (CVE-ID: CVE-2026-72499)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the bnxt_re CQ destruction logic when handling an NQ interrupt during completion queue teardown. A local user can trigger completion queue destruction while an interrupt arrives to cause a denial of service.
The issue occurs because the toggle page may be written after it has already been freed during firmware teardown.
55) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-72496)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper exception handling in bnxt_qplib_alloc_dpi when mapping device memory with ioremap. A local user can trigger an ioremap failure to cause a denial of service.
56) Race condition (CVE-ID: CVE-2026-72495)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the bnxt_re RDMA ucontext WC page allocation handler when processing repeated concurrent requests to allocate WC pages for the same ucontext. A local user can send repeated allocation requests to cause a denial of service.
Only one WC page per ucontext is supported.
57) Race condition (CVE-ID: CVE-2026-72494)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in the irdma cqp request completion handling when waiting for cqp request completion. A local user can trigger a race condition to cause a denial of service.
The issue arises from missing memory barriers around the request_done flag.
58) Race condition (CVE-ID: CVE-2026-72491)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in net/9p RDMA transport state handling in trans_rdma.c when processing RDMA connection events and receive completions concurrently with RDMA requests. A local user can trigger concurrent state transitions to corrupt the connection state machine and cause a denial of service.
The race can lead to lost state transitions during teardown and may result in use-after-free on RDMA request objects.
59) Use-after-free (CVE-ID: CVE-2026-72489)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in nvec_rx_completed() when handling an incomplete RX transfer. A local user can trigger an incomplete RX transfer to execute arbitrary code.
The freed message slot may be reallocated by a concurrent call to nvec_msg_alloc() before the code reads the message type byte.
60) Out-of-bounds read (CVE-ID: CVE-2026-72488)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in sdw_add_element_group_count when processing SoundWire group rate and lane entries. A local user can trigger the vulnerable code path to cause a denial of service.
The issue occurs because the loop iterates with an index equal to the element count.
61) Out-of-bounds read (CVE-ID: CVE-2026-72487)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in pci_get_rom_size in drivers/pci/rom.c when processing a broken PCI ROM image. A local user can provide a malformed ROM layout to trigger a kernel crash and cause a denial of service.
On some arm64 systems, exploitation may instead trigger an alignment fault due to unaligned IOMEM access.
62) Use-after-free (CVE-ID: CVE-2026-72473)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the xprtrdma request handling logic when processing RPC-over-RDMA send and reply completion. A local user can trigger request reuse while the HCA is still DMA-reading from its send buffer to cause a denial of service.
The issue occurs for Sends carrying only pre-registered buffers, where the request could be returned to the free pool before Send-side completion.
63) Use-after-free (CVE-ID: CVE-2026-72472)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the NFS file lock list handling code when traversing file locks during lock reclaim and delegation lock processing. A local user can trigger concurrent lock and unlock operations to cause a denial of service.
The issue affects NFS lock recovery and delegation-related paths, including reclaim and delegation recall handling.
64) Out-of-bounds read (CVE-ID: CVE-2026-72466)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read and improper resource management in rpcrdma_is_bcall() when processing a short or malformed reply. A remote attacker can send a specially crafted reply to cause a denial of service.
The issue can misclassify a reply as a backchannel call and orphan a persistently DMA-mapped receive buffer, which can drain the Receive queue and lead to RNR NAKs in the peer.
65) Use-after-free (CVE-ID: CVE-2026-72454)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition leading to use-after-free in the mipi i3c hci address-to-device lookup function i3c_hci_addr_to_dev() when handling in-band interrupt events in the irq handler. A local attacker can trigger concurrent device addition or removal while an in-band interrupt is being processed to cause a denial of service.
The issue arises because the irq handler cannot take the bus lock protecting the device list.
66) Race condition (CVE-ID: CVE-2026-72451)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in the xfrm input state cache insertion code in xfrm_input_state_lookup() when processing xfrm input state lookups. A remote attacker can trigger concurrent state destruction during cache insertion to cause a denial of service.
67) Race condition (CVE-ID: CVE-2026-72436)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in netfilter ipset hash types when lockless RCU readers process set data in parallel with add, delete, or garbage-collection operations. A local user can trigger concurrent ipset operations to cause a denial of service.
The issue affects readers that are not protected by the region lock and are not in set destroy or new or temporary set creation phases.
68) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-72434)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper shutdown of delayed work in the ipset garbage collector in netfilter when destroying a set with timeouts enabled. A local user can destroy a crafted set to cause a denial of service.
Only sets configured with timeout support are affected.
69) Use-after-free (CVE-ID: CVE-2026-72422)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in smb3_preauth_hash_rsp() when processing concurrent SMB2 NEGOTIATE requests on the same connection. A remote attacker can send concurrent SMB2 NEGOTIATE requests that trigger a race and dereference freed memory to cause a denial of service.
The issue is a race between the SMB2 NEGOTIATE handler and the response send path, where a NULL check can be bypassed by concurrent freeing of conn->preauth_info before dereference.
70) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-72421)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass intended unreachable routing behavior.
The vulnerability exists due to improper control flow in fib_lookup() in the IPv4 FIB lookup logic when performing route lookups with CONFIG_IP_MULTIPLE_TABLES enabled and no rule added. A local user can configure routes that trigger lookup of the merged local/main table followed by the default table to bypass intended unreachable routing behavior.
The issue occurs because an error route result from the local or main table can be overwritten by a subsequent lookup in the default table.
71) Out-of-bounds write (CVE-ID: CVE-2026-72399)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in enetc_xdp_xmit when processing xdp_frame structures with too many fragments. A local user can provide a crafted xdp_frame with more fragments than ENETC_MAX_SKB_FRAGS to cause a denial of service.
The issue occurs because the xdp_redirect_arr array is sized to ENETC_MAX_SKB_FRAGS while an xdp_frame may contain a greater number of fragments.
72) Improper input validation (CVE-ID: CVE-2026-72398)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to tamper with SCTP association handling and cause a denial of service.
The vulnerability exists due to improper input validation in SCTP COOKIE-ECHO processing paths when processing a cookie containing a reconstructed INIT chunk while cookie authentication is disabled. A remote attacker can send a specially crafted COOKIE-ECHO packet to tamper with SCTP association handling and cause a denial of service.
The issue only arises when cookie authentication is disabled.
73) Use-after-free (CVE-ID: CVE-2026-72383)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to use-after-free in sctp_free_addr_wq() and sctp_addr_wq_timeout_handler() when handling addr_wq_timer teardown. A local attacker can trigger a race condition to cause a denial of service.
The issue arises because a timer handler may continue running after the associated wait queue has been freed.
74) Out-of-bounds write (CVE-ID: CVE-2026-72380)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in pvcalls_front_event_handler() when processing a backend-supplied ring response with an out-of-range req_id. A local user can supply a crafted backend response to cause memory corruption.
The issue affects the Xen pvcalls frontend in deployments where the frontend does not trust its backend.
75) Out-of-bounds read (CVE-ID: CVE-2026-72351)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in gue_remcsum() and gue_gro_remcsum() when processing malformed GUE packets with the REMCSUM private flag set but without the required REMCSUM metadata fields. A remote attacker can send a specially crafted packet to disclose sensitive information.
The issue occurs because option validation accepts packets that contain only the private flags field even when additional REMCSUM start and offset fields are expected.
76) Improper input validation (CVE-ID: CVE-2026-72348)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass packet-filtering rules.
The vulnerability exists due to improper input validation in the ip6tables ah, hbh, and rt IPv6 extension header match handlers when processing malformed IPv6 packets with advertised extension header lengths that exceed the available skb data. A remote attacker can send a specially crafted IPv6 packet to bypass packet-filtering rules.
The issue affects handling of malformed IPv6 authentication, hop-by-hop, and routing extension headers.
77) Off-by-one (CVE-ID: CVE-2026-72339)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an off-by-one error in the qede_rx_build_skb() and qede_tpa_rx_build_skb() functions when handling a NULL return from qede_build_skb() under memory pressure. A local user can trigger memory pressure and network receive processing to cause memory corruption.
The issue can desynchronize the BD ring, which can corrupt DMA page reference counts and lead to SLUB freelist corruption.
78) Use-after-free (CVE-ID: CVE-2026-72329)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the liquidio SR-IOV VF pci_dev lookup handling when processing an OCTEON_VF_FLR_REQUEST mailbox command. A local user can trigger a VF FLR request that causes dereference of a stale pci_dev pointer to cause a denial of service.
Exploitation requires the affected device to be operating in SR-IOV mode with allocated virtual functions.
79) Use-after-free (CVE-ID: CVE-2026-72323)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the IGMP timer callback when processing incoming IGMP queries during device teardown. A remote attacker can send a crafted IGMP query to cause a denial of service.
Exploitation requires a race between device destruction and IGMP query processing.
80) Use-after-free (CVE-ID: CVE-2026-72322)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in the IPv6 MLD delayed work handling in net/ipv6/mcast.c when processing incoming MLD queries during device teardown. A remote attacker can send crafted MLD query traffic to trigger a kernel panic and cause a denial of service.
The issue arises from a race condition between device destruction and packet receive processing under RCU protection.
81) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-72320)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass netfilter rules.
The vulnerability exists due to improper handling of inverted lookups in nft_lookup_eval() when processing catchall elements for interval sets. A local user can trigger a crafted lookup condition to bypass netfilter rules.
The issue affects inverted lookups using catchall elements for the open-ended default range in interval sets.
82) Improper input validation (CVE-ID: CVE-2026-72319)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ip_vs_in_icmp in the IPVS subsystem when processing ICMP error packets from tunnels. A remote attacker can send a specially crafted ICMP error packet to cause a denial of service.
The issue involves inner IP headers not being ensured in skb headroom after outer headers are stripped, and additional length checks were required for the inner headers.
83) Out-of-bounds read (CVE-ID: CVE-2026-72318)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in parse_dfs_referrals() when processing a malicious DFS referral response from a server. A remote attacker can supply crafted referral string offsets to cause an out-of-bounds read and disclose sensitive information.
The issue occurs when DfsPathOffset or NetworkAddressOffset points beyond the end of the response buffer, leading to a negative length being forwarded as a size_t in the non-Unicode path.
84) Use-after-free (CVE-ID: CVE-2026-72317)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the SUNRPC TLS connect_worker when handling a failed TLS handshake on a TLS-secured transport. A local user can trigger a failed TLS handshake that causes the upper rpc_clnt to be freed before the queued worker dereferences it to cause a denial of service.
The issue affects the TLS transport path; the non-TLS connect worker does not use the saved client pointer.
85) Use-after-free (CVE-ID: CVE-2026-72299)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in TIPC enqueue tracepoint queue dumping in tipc_sk_enqueue() when dumping socket queues during message enqueue processing. A local user can trigger crafted TIPC socket activity to cause a denial of service.
The issue is reachable while the socket is owned by user context, because the held spinlock protects the backlog queue but does not serialize access to sk_receive_queue.
86) Improper input validation (CVE-ID: CVE-2026-72296)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ife_decode() when processing malformed IFE frames. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue can crash the kernel when the inner Ethernet header is not sufficiently accessible from the linear data area before the packet is passed to eth_type_trans().
87) Race condition (CVE-ID: CVE-2026-72289)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in vgic_prune_ap_list() in the KVM arm64 virtual generic interrupt controller when migrating an interrupt to another vCPU while locks are temporarily dropped. A local user can trigger interrupt migration during this race to cause a denial of service.
The issue can result in list_del() being performed on an interrupt entry that has already been removed from the ap_list.
88) Use-after-free (CVE-ID: CVE-2026-72288)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the KVM arm64 virtual generic interrupt controller (vgic) AP list handling when racing interrupt affinity changes with LPI disabling. A local user can trigger concurrent interrupt state changes to cause a denial of service.
The issue occurs during LPI handling involving multiple vCPUs.
89) Use-after-free (CVE-ID: CVE-2026-72255)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in nf_queue handling of bridge fake dst references when processing bridged packets queued to NFQUEUE. A local user can queue bridged packets to NFQUEUE during bridge device teardown to cause a denial of service.
The issue affects systems with CONFIG_BRIDGE_NETFILTER enabled and involves queued packets carrying a fake rtable associated with a bridge device.
90) Use-after-free (CVE-ID: CVE-2026-72251)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in nf_nat_sip in net/netfilter/nf_nat_sip.c when handling cloned socket buffers during SIP NAT processing. A local user can trigger packet processing with a cloned skb to cause a denial of service.
The issue occurs in the reply-direction destination port mangling path for SIP traffic.
91) Use-after-free (CVE-ID: CVE-2026-72234)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in net/batman-adv/routing.c when processing batman-adv unicast packets. A local user can send a specially crafted packet to cause a denial of service.
92) Integer overflow (CVE-ID: CVE-2026-72226)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an out-of-bounds read.
The vulnerability exists due to an integer overflow in the batadv_tt_tvlv_unicast_handler_v1 function when processing a TT unicast TVLV containing a crafted number of VLAN entries. A remote attacker can send a specially crafted TVLV message to cause an out-of-bounds read.
93) Use-after-free (CVE-ID: CVE-2026-72222)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to a use-after-free in the sunrpc TLS handshake callback handling in svc_tcp_handshake() and svc_tcp_handshake_done() when a connection close overlaps an asynchronous TLS handshake. A remote attacker can trigger a connection close during the TLS handshake to cause memory corruption.
The issue is reachable on TLS-enabled NFS servers, and signal delivery during the interruptible wait can trigger the affected race window.
94) Race condition (CVE-ID: CVE-2026-72221)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in svc_tcp_handshake() in the sunrpc server socket handling code when processing a TLS handshake callback during handshake cancellation. A remote attacker can trigger a TLS handshake timeout or interruption and cause concurrent handshake completion to corrupt the embedded swait_queue or tear down the connection to cause a denial of service.
The issue occurs when cancellation loses the race to handshake completion and the callback is still in flight.
95) Out-of-bounds write (CVE-ID: CVE-2026-72217)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in xdr_buf_to_bvec() when processing client-supplied RPC payload sizes. A remote attacker can send a specially crafted RPC request to cause memory corruption.
The out-of-bounds store can write one element past the end of the bio_vec array into adjacent slab memory, and the written length and offset fields are derived from client-controlled payload sizes.
96) Integer overflow (CVE-ID: CVE-2026-72200)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer overflow in the NTFS mapping-pairs parser when parsing a corrupted NTFS attribute. A local user can supply a crafted NTFS runlist to cause a denial of service.
The issue can occur when a mapping-pairs entry sets the accumulated LCN to S64_MAX and a subsequent entry adds a delta of 1.
97) Stack-based buffer overflow (CVE-ID: CVE-2026-72194)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in indx_find_buffer() in the ntfs3 filesystem driver when mounting a crafted NTFS filesystem and deleting a file that triggers index rebalancing. An attacker with physical access can provide a malicious NTFS image with circular index node references to cause a denial of service.
User interaction may be required in environments where removable media is mounted through desktop automount.
98) Out-of-bounds write (CVE-ID: CVE-2026-72192)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to overwrite adjacent heap memory.
The vulnerability exists due to an out-of-bounds write in indx_insert_into_root in the ntfs3 index handling code when processing a crafted mounted NTFS image during file creation. A local user can create a sufficiently long file name in a directory with a full resident root to overwrite adjacent heap memory.
The overwritten bytes are copied from on-disk NTFS entries and are attacker-controlled, and exploitation depends on the surrounding slab layout.
99) Out-of-bounds write (CVE-ID: CVE-2026-72191)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in indx_insert_into_buffer in the ntfs3 filesystem code when processing a crafted NTFS filesystem image during file creation in a mounted directory. A local user can mount a specially crafted NTFS image and trigger filesystem operations to cause a denial of service.
Triggering the issue requires local mounting of an attacker-supplied filesystem image, such as via loopback, removable media, or USB, and a filesystem operation such as creating a file in the mounted directory.
100) Heap-based buffer overflow (CVE-ID: CVE-2026-72130)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in nvmet_execute_auth_receive() and the DH-HMAC-CHAP response builders when processing AUTH_RECEIVE commands with a too-short allocation length. A remote user can send a specially crafted AUTH_RECEIVE command to cause a denial of service.
This is reachable only when in-band DH-HMAC-CHAP authentication is configured on the target.
101) Out-of-bounds read (CVE-ID: CVE-2026-72129)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in nvmet_rdma_use_inline_sg() and inline scatterlist handling in the NVMe target RDMA component when processing host-controlled inline data with a nonzero offset. A remote user can send crafted inline data offsets and lengths to cause a denial of service.
The issue can be triggered when inline_data_size is configured larger than PAGE_SIZE, and page-spanning in-bounds ranges may also cause the scatterlist to be under-counted.
102) Use-after-free (CVE-ID: CVE-2026-72126)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the isotp socket release and receive timer handling in net/can/isotp.c when processing concurrent CAN ISO-TP socket release and network device unregister events. A local user can trigger the race condition to cause a denial of service.
The issue occurs because an in-flight receive handler may re-arm a timer on a socket that has already been freed.
103) Use-after-free (CVE-ID: CVE-2026-72125)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free race in the Linux kernel CAN ISO-TP socket handling in net/can/isotp.c when releasing a socket concurrently with NETDEV_UNREGISTER. A local user can trigger concurrent socket release and device unregistration to cause a denial of service.
The issue can leave a stale CAN filter referencing a freed socket.
104) Race condition (CVE-ID: CVE-2026-72124)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the can isotp socket transmission state machine in net/can/isotp.c when handling concurrent send, receive, echo, timer, and socket release events. A local user can trigger concurrent state transitions to cause a denial of service.
The issue affects TX state handling across sendmsg(), the RX path, and hrtimer callbacks.
105) Improper input validation (CVE-ID: CVE-2026-72111)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass BPF memory safety checks.
The vulnerability exists due to improper register state handling in check_mem_access() in the BPF verifier when processing a context load of an LSM hook return value. A local user can load a hook return value into a register with stale bounds to bypass BPF memory safety checks.
The issue arises from a verifier/runtime mismatch because the verifier may treat the register as having a narrower range than the actual runtime value.
106) Out-of-bounds write (CVE-ID: CVE-2026-72098)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in dm-verity fec calculation when processing erasure data during FEC decoding. A local user can trigger crafted corruption conditions to cause memory corruption.
The out-of-bounds write can occur when the erasure count exceeds the intended Reed-Solomon roots limit and the decoder writes past the end of the lambda array into the syndrome buffer.
107) Use-after-free (CVE-ID: CVE-2026-72085)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a refcount underflow leading to use-after-free in xen-scsiback request handling when processing pvSCSI requests before command submission. A remote user can submit requests with a bad grant reference or an unknown request type to cause a denial of service.
Under panic_on_warn, triggering the refcount underflow can panic the host. The issue can also leak every command tag of a LUN session, stopping the LUN.
108) Out-of-bounds read (CVE-ID: CVE-2026-72084)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in iSCSI PR-OUT TransportID parsing in the Linux kernel SCSI target subsystem when processing a crafted PERSISTENT RESERVE OUT TransportID buffer. A remote attacker can send a specially crafted PR OUT request to cause a denial of service.
The issue is reachable through any fabric that delivers a PR OUT to a device exported through an iSCSI target portal group, including a guest via vhost-scsi.
109) Use-after-free (CVE-ID: CVE-2026-72083)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in core_scsi3_emulate_pro_register_and_move() when processing a crafted iSCSI TransportID in a PERSISTENT RESERVE OUT REGISTER AND MOVE parameter list. A remote user can send a specially crafted request to cause a denial of service.
The issue is triggered when the parameter list spans more than one page, causing the ISID pointer to reference an unmapped region after the buffer is torn down.
110) Use-after-free (CVE-ID: CVE-2026-72071)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in user_event_mm_dup() and the user_events enabler handling in kernel/trace/trace_events_user.c when walking the parent mm enabler list during fork() while an enabler is concurrently unregistered. A local user can register an enabler and then concurrently unregister it and call fork() to cause a denial of service.
Exploitation requires access to open user_events_data and a race between concurrent operations in a multithreaded process.
111) Use-after-free (CVE-ID: CVE-2026-72069)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in rt_spin_unlock(), rt_read_unlock(), and rt_write_unlock() when releasing RCU protection before completing unlock operations. A local user can trigger concurrent lock and RCU operations to execute arbitrary code.
The issue affects the RT spinlock and rwlock substitutions where unlock handling does not preserve the expected non-RT RCU protection semantics.
112) Improper input validation (CVE-ID: CVE-2026-72065)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper input validation in the mana RX completion queue handling in mana_process_rx_cqe() when processing packet length values reported by the NIC. An attacker with physical access can supply an invalid packet length via a malicious or compromised NIC device to cause a denial of service.
The reported packet length is supplied by the NIC device and is not sufficiently validated before skb processing.
113) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-72041)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in espintcp_sendskmsg_locked in net/xfrm/espintcp.c when handling partial sends of sk_msg data. A local user can trigger partial send conditions to cause a denial of service.
114) Out-of-bounds read (CVE-ID: CVE-2026-72033)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in fill_from_part() in the OrangeFS directory handling code when processing a crafted readdir entry trailer supplied by a userspace client. A local user can supply a crafted directory entry with a wrapped length value to cause a denial of service.
The issue occurs because a directory entry size computed in size_t is truncated to a 32-bit value, which can bypass a bounds check and lead to a read far past the directory part.
115) Use of Uninitialized Variable (CVE-ID: CVE-2026-72020)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and corrupt forwarded TCP traffic.
The vulnerability exists due to use of uninitialized memory in ip_vs_conn_new and TCP sequence handling in IPVS when processing a malformed sync message that omits sequence data. A remote user can send a specially crafted sync message to disclose sensitive information and corrupt forwarded TCP traffic.
The issue affects connections learned from a sync message when sequence flags are preserved without valid sequence data, causing stale slab bytes to be used in TCP sequence and acknowledgment number rewriting by an IPVS application helper.
116) Out-of-bounds write (CVE-ID: CVE-2026-72014)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to corrupt kernel memory.
The vulnerability exists due to an out-of-bounds write in recv_dless_read() when processing a crafted P_DATA_REPLY from a DRBD peer. A remote attacker can send a specially crafted data reply to corrupt kernel memory.
A node that reads from its peer, such as a diskless node or a node using read-balancing to the peer, is exposed in the default configuration. A man-in-the-middle DRBD peer can also exploit the issue.
117) Improper input validation (CVE-ID: CVE-2026-68477)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect packet processing.
The vulnerability exists due to improper handling of ipv6 transport offsets in ipvs application and icmpv6 response processing when handling ipv6 packets with extension headers. A remote attacker can send specially crafted ipv6 traffic to cause incorrect packet processing.
The issue affects TCP application handling and ICMPv6 checksum validation in IPVS for IPv6 traffic.
118) Use-after-free (CVE-ID: CVE-2026-68476)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in __ip_vs_get_out_rt() handling of skb head reallocation in net/netfilter/ipvs/ip_vs_xmit.c when processing packets in ip_vs_bypass_xmit(). A local user can trigger skb head reallocation and subsequent use of a stale IP header pointer to cause a denial of service.
119) Out-of-bounds read (CVE-ID: CVE-2026-68470)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the mac80211 RX path when processing unsupported extension frames and S1G beacon extension frames. A remote attacker can send a specially crafted wireless frame to cause a denial of service.
The issue affects extension-frame handling before unsupported extension subtypes are dropped, and S1G beacon processing requires the target system to receive crafted 802.11 frames.
120) Use of Uninitialized Variable (CVE-ID: CVE-2026-68461)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of uninitialized memory in fwnode_init() in the firmware node handling code when initializing a fwnode_handle allocated on the stack or with a non-zeroing heap allocation. A local user can trigger dereference of an uninitialized secondary pointer to cause a denial of service.
Exploitation requires control over the lifetime and initialization context of the firmware node object.
121) Improper access control (CVE-ID: CVE-2026-68457)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass intended file permission checks.
The vulnerability exists due to improper access control in ksmbd FSCTL mutation handlers when processing SET_SPARSE, SET_ZERO_DATA, or SET_COMPRESSION operations on an open SMB handle. A remote user can invoke these operations so they are performed with ksmbd worker credentials to bypass intended file permission checks.
The issue arises because helper calls may independently revalidate inode permissions, ownership, or LSM policy instead of relying solely on the SMB handle access mask.
122) Out-of-bounds read (CVE-ID: CVE-2026-68431)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in ksmbd connection request handling when processing short SMB2 transform requests on an SMB 2.1 connection. A remote attacker can send a specially crafted truncated transform packet to disclose sensitive information.
The issue occurs when a transform packet is accepted even though the negotiated dialect does not provide transform handling.
123) Use-after-free (CVE-ID: CVE-2026-68426)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in validate_xmit_xfrm() in net/xfrm/xfrm_device.c when processing GSO segment lists with asynchronous crypto handling. A local user can trigger asynchronous processing that steals a segment and leaves a stale skb->prev pointer to cause a denial of service.
The issue occurs when a stolen segment remains referenced as the list tail and is later dereferenced by validate_xmit_skb_list().
124) Out-of-bounds read (CVE-ID: CVE-2026-68388)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in smb3_simple_fallocate_range() when handling server-reported allocated ranges during fallocate operations. A local user can trigger fallocate on an SMB client mount backed by a server that returns overlapping or malformed allocated ranges to cause a denial of service.
A later write to a skipped hole may fail with ENOSPC.
125) Use-after-free (CVE-ID: CVE-2026-68381)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in async oplock and lease break notification handling in fs/smb/server/oplock.c when processing asynchronous oplock break notifications during connection teardown. A remote user can trigger a race condition to cause a denial of service.
Exploitation requires a race between connection teardown and an oplock or lease break notification.
126) Out-of-bounds read (CVE-ID: CVE-2026-68343)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in parse_dfs_referrals() in the SMB client DFS referral parser when processing a malformed DFS referral response with an oversized PathConsumed value. A remote attacker can send a specially crafted DFS referral response to cause an out-of-bounds read.
The issue occurs when PathConsumed is larger than the search name length used for later DFS path parsing.
127) Use-after-free (CVE-ID: CVE-2026-68302)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or potentially execute arbitrary code.
The vulnerability exists due to use-after-free in the AMT packet handling logic in drivers/net/amt.c when processing crafted network packets that trigger skb header pulls and head reallocation. A remote attacker can send specially crafted packets to cause a denial of service or potentially execute arbitrary code.
The issue affects multiple AMT receive and transmit paths that cache skb header pointers and later dereference them after helpers such as pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(), iptunnel_pull_header(), ip_mc_check_igmp(), or ipv6_mc_check_mld() move the skb head.
128) Improper Authentication (CVE-ID: CVE-2026-68300)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass authentication.
The vulnerability exists due to improper authentication in sctp_auth_chunk_verify() when processing SCTP chunks with a NULL auth_chunk. A remote user can send a specially crafted SCTP chunk to bypass authentication.
This can occur for new connections or when no AUTH chunk precedes a COOKIE-ECHO chunk.
129) Out-of-bounds read (CVE-ID: CVE-2026-68229)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in _cedrus_write_ref_list() when processing malformed or unsupported H.264 reference list entries. A local user can provide crafted stateless slice control reference list entries to disclose sensitive information.
130) Race condition (CVE-ID: CVE-2026-68228)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the wave5 encoder buffer handling in drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c when processing encoder completion and re-queuing buffers. A local user can queue the same buffer before it is removed from the m2m ready queue to cause a denial of service.
The issue can result in a self-referential ready-queue entry, after which list pointers are poisoned when the entry is deleted.
131) Improper resource shutdown or release (CVE-ID: CVE-2026-68213)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in rtl2832_sdr_start_streaming() and queued buffer handling when handling start_streaming() failures. A local user can trigger a streaming start failure to cause a denial of service.
The issue occurs because buffers queued before streaming are not returned to the videobuf2 framework on error paths, which can trigger a WARN_ON and leak queued buffers.
132) Improper resource shutdown or release (CVE-ID: CVE-2026-68210)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the stm32 dcmi driver async notifier handling when probing the device and reset operations fail. A local user can trigger a probe failure to cause a denial of service.
The issue occurs because the notifier remains registered on the error path when probe exits before the normal remove path is reached.
133) Improper resource shutdown or release (CVE-ID: CVE-2026-68209)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the sun4i_csi_start_streaming() path of the sun4i-csi driver when handling streaming startup with an unsupported CSI format. A local user can trigger streaming initialization with a format that has no matching CSI format to cause a denial of service.
The issue occurs because queued video buffers are not returned on the error path after they have already been handed to the driver by the vb2 framework.
134) Improper input validation (CVE-ID: CVE-2026-68206)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the V4L2 HEVC slice control validation path when processing HEVC slice parameters. A local user can supply crafted active L0/L1 reference counts to cause a denial of service.
The issue affects stateless HEVC drivers, and validation was missing before driver-specific code consumed the shared control data.
135) Use-after-free (CVE-ID: CVE-2026-68198)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in aggr_reset_state() in the ath6kl wireless driver when handling a race between timer callback execution and TID state teardown. A local user can trigger the race condition to cause a denial of service.
The timer callback may continue accessing rx_tid[] and stat[] fields after the associated aggr_conn structure is freed, and it can re-arm itself while the reset routine is running.
136) Use-after-free (CVE-ID: CVE-2026-68162)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the SCTP auth_enable sysctl handler when handling writes to an already opened sysctl file during network namespace teardown. A local user can write to the auth_enable sysctl entry to cause a denial of service.
The issue is exposed during initialization before the SCTP control socket exists and during teardown after the control socket has been released.
137) Improper resource shutdown or release (CVE-ID: CVE-2026-68161)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown in SCTP UDP tunnel sockets during net namespace teardown when tearing down a network namespace with SCTP UDP tunneling enabled. A local user can trigger namespace teardown while the sockets remain installed to cause a denial of service.
Only systems using per-network-namespace SCTP UDP tunneling are affected.
138) Out-of-bounds read (CVE-ID: CVE-2026-68160)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in ceph_handle_caps() and ceph_update_snap_trace() when processing a crafted Ceph MDS caps message with a malicious snap_trace_len value. A remote attacker can send a specially crafted message to disclose sensitive information.
Exploitation requires a malicious or compromised MDS to send a version 1 message so the IMPORT path is reached without prior version-gated validation of snap_trace_len.
139) Out-of-bounds write (CVE-ID: CVE-2026-68159)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a stack out-of-bounds write in __decode_pg_temp(), __decode_pg_upmap_items(), and OSDMap handling in net/ceph/osdmap.c when processing a crafted OSDMap containing an oversized pg_temp, pg_upmap, or pg_upmap_items entry. A remote attacker can send a specially crafted OSDMap entry to cause a denial of service.
The issue is triggered when the decoded list is later copied into the fixed-size on-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE].
140) Integer overflow (CVE-ID: CVE-2026-68158)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an integer overflow in decode_new_up_state_weight() when processing a corrupted CEPH_MSG_OSD_MAP message containing a crafted osdmap. A remote attacker can send a specially crafted message to disclose sensitive information.
The issue can lead to out-of-bounds reads while decoding the new_state portion of the osdmap.
141) Use-after-free (CVE-ID: CVE-2026-68156)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the Ceph authorizer handling code when processing a rebuilt authorizer during a messenger reconnect. A local user can trigger an authorizer update that reallocates the buffer and then cause a reconnect to use a stale pointer to cause a denial of service.
The issue is triggered when a newer service ticket causes the authorizer to be rebuilt and the rebuilt authorizer no longer fits in the existing buffer.
142) Out-of-bounds read (CVE-ID: CVE-2026-68154)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in crush_decode and the CRUSH mapper when parsing a malformed CRUSH map. A local user can supply a crafted CRUSH map with a zero bucket type to cause a denial of service.
The issue arises because bucket type 0 is reserved for devices, and an invalid map can make the mapper treat a negative bucket ID as a device and index the OSD weight array with a negative value.
143) Use-after-free (CVE-ID: CVE-2026-68152)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to use-after-free in the AMT delayed work handling in drivers/net/amt.c when processing queued delayed work during device removal. A local user can trigger a race condition involving AMT device shutdown to cause a denial of service or execute arbitrary code.
The issue occurs because delayed work items can be re-queued from event_wq after cancellation and then access a freed amt_dev structure after the netdev has been released.
144) Use-after-free (CVE-ID: CVE-2026-68147)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a use-after-free.
The vulnerability exists due to a use-after-free in fscrypt_destroy_inline_crypt_key() and fscrypt_get_devices() in fs/crypto/inline_crypt.c when evicting inline encryption keys for filesystem block devices. A local user can trigger key eviction during inode eviction under direct reclaim to cause a use-after-free.
The issue occurs when dynamic allocation of the block-device array fails, causing key memory to be freed without first evicting the key from all associated block devices.
145) Use-after-free (CVE-ID: CVE-2026-68144)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in pep_get_sb() when processing Phonet socket buffer data. A remote attacker can send a specially crafted network packet to cause a denial of service.
146) Race condition (CVE-ID: CVE-2026-68138)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition leading to use-after-free and double-free in qdisc_get_rtab() and qdisc_put_rtab() when processing concurrent RTM_NEWTFILTER requests that add flower filters with a police action carrying the same rate. A local user can send concurrent netlink filter configuration requests to cause a denial of service.
The corrupted qdisc_rate_table object is shared system-wide because the affected rate-table list is process-global rather than per-network-namespace.
147) Use-after-free (CVE-ID: CVE-2026-68137)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in x25_kill_by_neigh() when handling termination of an X.25 neighbour while walking the global X.25 socket list. A local user can trigger concurrent socket release and neighbour teardown operations to cause a denial of service.
The issue is triggered by a race condition after the list lock is dropped and before the socket lifetime is pinned.
148) Improper input validation (CVE-ID: CVE-2026-68136)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state validation in skb_gro_receive_list() in the GRO subsystem when processing flush-marked aggregated packets. A remote attacker can send specially crafted network traffic to cause a denial of service.
The issue can corrupt the frag_list chain and later trigger a kernel panic when skb_segment() processes the malformed packet state.
149) Use-after-free (CVE-ID: CVE-2026-68127)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free.
The vulnerability exists due to use-after-free in ila_update_ipv6_locator() and ila_csum_adjust_transport() when processing a crafted IPv6 packet routed through a configured ILA checksum-adjust-transport route or receive-side mapping. A remote attacker can send a specially crafted IPv6 packet to trigger a use-after-free.
Exploitation requires a configured ILA checksum-adjust-transport route or receive-side mapping.
150) Out-of-bounds write (CVE-ID: CVE-2026-68124)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to perform out-of-bounds heap writes.
The vulnerability exists due to an out-of-bounds write in the MCTP serial receive state machine in drivers/net/mctp/mctp-serial.c when processing a zero-length MCTP serial frame. A local privileged user can send a specially crafted zero-length frame followed by data bytes to perform out-of-bounds heap writes.
Exploitation requires attaching the N_MCTP line discipline and bringing the resulting mctpserial network device up before sending bytes through the tty receive path.
151) Integer underflow (CVE-ID: CVE-2026-68123)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer underflow in queue_userspace_packet() in the openvswitch subsystem when processing userspace actions on segmented gso packets after truncation. A local user can send a specially crafted packet that triggers truncation and segmentation handling to cause a denial of service.
The issue occurs because truncation state is reused across smaller gso segments, allowing the preserved length value to exceed the current packet length.
152) Use-after-free (CVE-ID: CVE-2026-68117)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in tipc_sk_create() and tipc_release() in the TIPC socket handling code when handling a failed accept() path after socket insertion failure. A local user can trigger creation of a large number of TIPC sockets and invoke accept() to cause a denial of service.
The issue is reached when the per-netns TIPC socket rhashtable hits its maximum size, leaving a pre-allocated child socket with a dangling sock->sk pointer during release.
153) Path traversal (CVE-ID: CVE-2026-68083)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access files outside the exported share.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in ksmbd_vfs_kern_path_create() when handling SMB create, mkdir, or hardlink operations with crafted path components. A remote user can race a missing path component and use a ".." path element to access files outside the exported share.
Exploitation requires authentication to the SMB service and a race condition between the rooted lookup and the create path resolution.
154) Out-of-bounds read (CVE-ID: CVE-2026-68082)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in decode_lockers() in net/ceph/cls_lock_client.c when parsing OSD-supplied lock information. A remote user can send a specially crafted OSD reply to disclose sensitive information.
Exploitation requires control of a malicious or compromised OSD and can be triggered against kernel clients that issue the lock.get_info class method, such as during RBD exclusive lock acquisition in a multi-tenant Ceph deployment.
155) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-64598)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of an error pointer in smb2_aead_req_alloc() when processing SMB client requests. A local user can trigger the bug to cause a denial of service.
156) Double free (CVE-ID: CVE-2026-64597)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to double free in SMB2_close() in the SMB client close request handling when processing a response-bearing attempt that returns a replayable error. A remote user can trigger a replay sequence that causes the same response buffer to be freed twice to cause a denial of service.
157) Use-after-free (CVE-ID: CVE-2026-64586)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the brcmfmac bus_reset work handling when a reset is scheduled during device removal. A local user can trigger a bus reset through the debugfs "reset" entry to cause a denial of service.
The issue affects shared bus_reset work across PCIe, SDIO, and USB removal paths, and brcmf_fw_crashed() could also be triggered before driver attachment completed.
158) Use-after-free (CVE-ID: CVE-2026-64564)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in sctp_process_asconf_param() when processing crafted SCTP ASCONF DEL-IP parameters. A remote attacker can send a specially crafted SCTP ASCONF message to cause a denial of service.
The issue can occur when a single ASCONF carries DEL-IP parameters that free the cached transport and a later wildcard DEL-IP reuses the dangling transport pointer.
159) Use-after-free (CVE-ID: CVE-2026-64562)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in KVM nested VMX shadow VMCS handling when freeing nested virtualization state asynchronously with respect to loaded VMCS clearing during vCPU migration. A local user can trigger nested virtualization cleanup and vCPU migration to execute VMCLEAR on a freed shadow VMCS and cause a denial of service.
The issue occurs because vmcs01 may still reference the shadow VMCS until explicit VMCLEAR completes.
160) Improper Initialization (CVE-ID: CVE-2026-64561)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the KVM x86 shadow MMU page fault handling code when processing stale page faults after reclaiming shadow pages. A local user can trigger page faults that lead KVM to map memory into an invalid root to cause a denial of service.
The issue occurs when reclaiming shadow pages invalidates an in-use root, causing child shadow pages created during map or fetch operations to inherit an invalid role and violate the invariant that invalid shadow pages must not appear on the list of active MMU pages.
161) Use-after-free (CVE-ID: CVE-2026-64557)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in l2cap_sock_new_connection_cb() in the Bluetooth L2CAP subsystem when handling a newly enqueued child socket reachable through the accept queue after the parent socket lock is released. A remote attacker can trigger a crafted Bluetooth L2CAP connection to execute arbitrary code.
The issue occurs because another task may accept and free the child socket before the callback dereferences it.
162) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64555)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause incorrect hypervisor state handling.
The vulnerability exists due to improper state management in kvm_hyp_handle_mops() when handling a MOPS exception during nested virtualization. A local user can trigger this code path to cause incorrect hypervisor state handling.
The issue affects arm64 KVM in nested virtualization scenarios.
163) Use-after-free (CVE-ID: CVE-2026-64554)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in br_ip6_fragment() when processing crafted IPv6 packets on a cloned skb. A local user can send a specially crafted packet to cause a denial of service.
The issue results from dereferencing a stale prevhdr pointer after skb_checksum_help() reallocates the skb head, and the resulting write can trigger a kernel panic.
164) Out-of-bounds write (CVE-ID: CVE-2026-64552)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in receive_big() when processing a device-announced packet length from a virtio backend. A remote attacker can announce a specially crafted length value to cause memory corruption.
The issue can result in a NULL fragment being handed up the receive path.
165) Out-of-bounds read (CVE-ID: CVE-2026-64551)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose uninitialized memory.
The vulnerability exists due to an out-of-bounds read in sctp_sf_do_5_2_6_stale() when processing an ERROR chunk with a STALE_COOKIE cause in the COOKIE_ECHOED state. A local user can send a specially crafted SCTP packet to disclose uninitialized memory.
The leaked value is echoed to the peer in the Cookie Preservative of the reply INIT. Exploitation is reachable by a peer that can drive an association into COOKIE_ECHOED, including an unprivileged process using a raw SCTP socket in a user and network namespace.
166) Integer overflow (CVE-ID: CVE-2026-64548)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow leading to an out-of-bounds write in bpf_msg_push_data() when processing a crafted len value in the copy fallback path. A local user can supply a crafted len value to cause a denial of service.
Exploitation requires access to BPF-driven sockmap message processing and occurs when the scatterlist ring is full or nearly full.
167) Use-after-free (CVE-ID: CVE-2026-64541)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in smc_cdc_rx_handler() when handling SMC-R CDC messages for a connection after releasing conns_lock. A local user can trigger a concurrent socket close while the handler continues to dereference the freed socket to cause a denial of service.
Only SMC-R is affected.
168) Use-after-free (CVE-ID: CVE-2026-64535)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in the NVMe/TCP target digest error handling in nvmet_tcp_try_recv_ddgst() and queue teardown logic when processing a digest mismatch on a non-final H2C_DATA PDU during an R2T-based data transfer. A remote user can trigger a digest mismatch to cause a denial of service.
Exploitation requires data digest to be enabled on the NVMe/TCP connection.
169) Use-after-free (CVE-ID: CVE-2026-64534)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in nvmet_tcp_try_recv_ddgst() when processing a command with a data digest mismatch after request initialization previously failed. A remote attacker can send a specially crafted request to cause a denial of service.
The issue can lead to a refcount underflow, kernel warnings, and a permanent workqueue deadlock.
170) Use-after-free (CVE-ID: CVE-2026-64530)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in tcf_qevent_handle in net/sched/cls_api.c when handling TC_ACT_CONSUMED during qevent processing of fragmented traffic. A local user can send specially crafted fragmented network traffic to trigger use of an skb after ownership has been transferred and cause a denial of service.
Exploitation requires RED qdisc qevents together with ct defragmentation and traffic that produces out-of-order fragments.
171) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-64529)
CWE-ID: CWE-668 - Exposure of resource to wrong sphere
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to affect device configuration and control operations.
The vulnerability exists due to an exposed attack surface in the qat_adf_ctl character device and its ioctl interface when handling ioctl requests for device configuration, start, stop, status query, and enumeration. A local user can send crafted ioctl requests to affect device configuration and control operations.
The ioctl interface was not part of any public uAPI header.
172) Use-after-free (CVE-ID: CVE-2026-64523)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in handshake_req_submit() and the net/handshake request handling code when processing a pending handshake request while the associated socket file is released concurrently. A local user can trigger a race involving socket teardown and handshake submission to cause a denial of service.
The issue arises because a socket reference alone does not keep the backing struct socket alive, and a concurrent cancellation or completion path can race request cleanup.
173) Out-of-bounds read (CVE-ID: CVE-2026-64518)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in tcp_ao_established_key() when processing TCP_TIME_WAIT sockets from tcp_v[46]_timewait_ack(). A local attacker can trigger the vulnerable code path to cause a denial of service.
The issue occurs because the code may access sock locking state on a timewait socket that does not contain sk_lock.
174) Use-after-free (CVE-ID: CVE-2026-64510)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the ACPI NFIT core when handling a subsequent ACPI Machine Check Exception after a failed or incomplete NFIT initialization and shutdown path. A local attacker can trigger the vulnerable initialization state to cause a denial of service.
The issue occurs because a freed acpi_desc object may remain referenced in the acpi_descs list and later be accessed by nfit_handle_mce().
175) Use-after-free (CVE-ID: CVE-2026-64475)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the VGA arbiter callback handling in vfio_pci_core_register_device() when registration of a vfio PCI device fails after VGA arbiter client initialization. A local user can trigger device registration failure and leave a stale callback referencing freed device data to cause a denial of service.
The issue occurs on the error path and depends on a stale VGA arbiter registration remaining after the vfio device state has been freed.
176) Out-of-bounds read (CVE-ID: CVE-2026-64450)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the TIPC broadcast Gap ACK blocks handling in tipc_bcast_sync_rcv() when processing a crafted broadcast PROTOCOL/STATE_MSG. A remote attacker can send a specially crafted broadcast STATE_MSG with a malformed Gap ACK blocks record to cause a denial of service.
Exploitation requires a TIPC neighbour that has negotiated TIPC_GAP_ACK_BLOCK.
177) Improper input validation (CVE-ID: CVE-2026-64445)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in OnAuth() when processing seq=3 shared-key authentication responses. A remote attacker can send a specially crafted authentication frame to cause a denial of service.
The issue is triggered when the Challenge Text information element length differs from the required 128 bytes.
178) Out-of-bounds read (CVE-ID: CVE-2026-64445)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in OnAuth() when processing crafted shared-key authentication frames. A remote attacker can send a specially crafted authentication frame to disclose sensitive information.
The issue occurs in the shared-key authentication path when the Privacy bit is set and the frame is too short to contain a valid WEP IV and ICV.
179) Out-of-bounds read (CVE-ID: CVE-2026-64441)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in IE and WPS attribute parsing functions in drivers/staging/rtl8723bs/core/rtw_ieee80211.c when parsing crafted information element buffers. A local user can provide a specially crafted buffer to disclose sensitive information.
The issue affects rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr().
180) Use-after-free (CVE-ID: CVE-2026-64438)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the VF2PF response workqueue handling in the intel_qat SR-IOV implementation when processing VF2PF messages during SR-IOV teardown. A local user can trigger concurrent VF2PF work so that a queued or in-flight worker dereferences freed per-VF state to cause a denial of service.
The issue occurs because PF-side response work stores a raw pointer to per-VF state that may be freed by adf_disable_sriov() before queued work completes.
181) Use-after-free (CVE-ID: CVE-2026-64408)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in bnep_add_connection() during network device registration when handling a concurrent controller teardown. A local user can trigger a race condition to cause a denial of service.
182) Path traversal (CVE-ID: CVE-2026-64400)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to create files or directories outside the exported share.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in __ksmbd_vfs_kern_path() when processing crafted paths with parent-directory components during caseless lookup retry. A remote user can send a specially crafted path to create files or directories outside the exported share.
The issue occurs because an -EXDEV error from path traversal detection is not handled before the caseless retry logic runs, and exploitation is limited to zero-length files or directories.
183) Improper access control (CVE-ID: CVE-2026-64399)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to overwrite file data.
The vulnerability exists due to improper access control in the FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() when processing SMB ioctl requests that clone file ranges. A remote user can use the operation on a read-only share or with a destination handle lacking FILE_WRITE_DATA permission to overwrite file data.
The issue affects destination files through vfs_clone_file_range() and can be triggered with a handle opened with only FILE_WRITE_ATTRIBUTES.
184) Use-after-free (CVE-ID: CVE-2026-64397)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in smb2_query_dir() and the ksmbd directory enumeration state when handling concurrent QUERY_DIRECTORY requests using the same file handle. A remote user can send concurrent QUERY_DIRECTORY requests on the same file handle to cause a denial of service.
The issue occurs because a pointer to stack-allocated private data is stored in shared readdir state and can be overwritten while an iterate_dir() callback is still using it.
185) Use-after-free (CVE-ID: CVE-2026-64396)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in the SMB2 lock handling logic in fs/smb/server/smb2pdu.c when canceling a deferred SMB2_LOCK request. A remote user can send crafted SMB lock and cancellation requests to cause a denial of service.
The issue is triggered by a race between deferred-lock cleanup and asynchronous cancellation while processing blocking byte-range locks.
186) Improper access control (CVE-ID: CVE-2026-64394)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify file access control metadata to grant additional access.
The vulnerability exists due to improper access control in smb2_set_info_sec() when handling SMB2_SET_INFO requests with InfoType SMB2_O_INFO_SECURITY. A remote user can send a specially crafted SMB2_SET_INFO request over a handle opened with FILE_WRITE_ATTRIBUTES only to modify file access control metadata to grant additional access.
The issue affects the SECURITY arm of SMB2 SET_INFO, where no per-handle check for FILE_WRITE_DAC or FILE_WRITE_OWNER is performed before rewriting the file's owner or DACL.
187) Improper access control (CVE-ID: CVE-2026-64393)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass intended permission checks.
The vulnerability exists due to improper access control in SMB2 SET_INFO handlers when processing SET_INFO requests. A remote user can send a specially crafted SET_INFO request to bypass intended permission checks.
The issue arises because path-based VFS helpers perform permission and LSM checks using worker credentials instead of the credentials captured when the file handle was opened.
188) Improper access control (CVE-ID: CVE-2026-64392)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass filesystem permission checks and delete files or remove ADS xattrs.
The vulnerability exists due to improper access control in ksmbd delete-on-close handling when tearing down deferred or durable handles without request work. A remote user can open a file and trigger delete-on-close processing to bypass filesystem permission checks and delete files or remove ADS xattrs.
The issue occurs because final close operations run with ksmbd worker credentials instead of the credentials captured when the file was opened.
189) Improper access control (CVE-ID: CVE-2026-64391)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass permission checks for alternate data stream I/O.
The vulnerability exists due to improper access control in ksmbd alternate data stream handling when processing read and write operations on alternate data streams. A remote user can access a file over SMB and perform alternate data stream read or write operations to bypass permission checks for alternate data stream I/O.
Alternate data streams are stored as extended attributes, and the vulnerable paths recheck inode permissions and LSM policy using the current task credentials instead of the credentials captured when the SMB handle was opened.
190) Use-after-free (CVE-ID: CVE-2026-64390)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in ksmbd byte-range lock handling when processing smb2 lock requests in smb3 multichannel environments. A remote attacker can trigger concurrent lock traversal and removal to cause a denial of service.
The issue occurs because a lock list entry can be removed under a different spinlock than the one protecting the list it belongs to.
191) Double free (CVE-ID: CVE-2026-64387)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in SMB2_query_directory in the SMB client when handling replayed query directory responses and reinitialization failures. A local user can trigger a replayable error and subsequent cleanup conditions to cause a denial of service.
192) Double free (CVE-ID: CVE-2026-64386)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a double free in query_info() in the smb client when handling replayable query_info requests. A remote user can trigger a replayable error sequence to cause a denial of service.
193) Double free (CVE-ID: CVE-2026-64385)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to double free in SMB2_ioctl() when handling replayable ioctl responses. A remote user can trigger a replayable error condition to cause a denial of service.
194) Double free (CVE-ID: CVE-2026-64384)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in SMB change notify handling in fs/smb/client/smb2pdu.c when processing replayable error conditions during change notify requests. A local user can trigger a replayable error and subsequent cleanup to free the same response buffer twice to cause a denial of service.
195) Double free (CVE-ID: CVE-2026-64383)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to double free in SMB2_flush() when handling replay attempts for flush responses. A remote user can trigger a replayable flush response followed by a failed retry to cause a denial of service.
196) Double free (CVE-ID: CVE-2026-64382)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in SMB2_open() when handling replayable error conditions during SMB2 open request processing. A local user can trigger a replayable error that leads to stale response buffer bookkeeping to cause a denial of service.
The issue affects the Linux kernel SMB client implementation.
197) Out-of-bounds write (CVE-ID: CVE-2026-64364)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the HID multitouch driver when processing input from a crafted USB or Bluetooth HID multitouch device that advertises a large contact count. An attacker with physical access can provide a crafted device to corrupt adjacent members of struct mt_device and cause a denial of service.
The issue is reachable from an untrusted USB or Bluetooth HID multitouch device, and the kernel panic can be triggered from timer context through the sticky-fingers release path.
198) Integer overflow (CVE-ID: CVE-2026-64361)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow in check_and_correct_requested_length() in the hfs and hfsplus filesystem code when processing crafted filesystem metadata. A local user can trigger an underflowed length value that bypasses a bounds check to cause a denial of service.
Exploitation can result in a read far beyond the node buffer during a subsequent memmove operation.
199) Out-of-bounds read (CVE-ID: CVE-2026-64355)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in dev_map_enqueue_clone() and dev_map_redirect_clone() when cloning fragmented native XDP frames or nonlinear generic XDP packets for devmap broadcast redirects. A local user can trigger clone-based broadcast handling with a crafted fragmented frame to cause a denial of service.
The issue occurs because fragment metadata is not present in the linear cloned frame, and later frame return can interpret uninitialized tail data as skb_shared_info.
200) Out-of-bounds read (CVE-ID: CVE-2026-64320)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to an out-of-bounds heap read in nvmet_execute_disc_get_log_page() in the NVMe target discovery controller when handling a host-supplied log page offset in a Discovery Get Log Page request. A remote attacker can send a specially crafted request with an out-of-range offset to disclose sensitive information or cause a denial of service.
The issue is reachable before authentication by any TCP, RDMA, or FC peer that can reach the nvmet target.
201) Out-of-bounds read (CVE-ID: CVE-2026-64319)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in nvmet_auth_reply() when processing a crafted DHCHAP_REPLY message. A remote attacker can send a specially crafted authentication reply message with inconsistent hash and DH value lengths to disclose sensitive information.
Exploitation is possible pre-authentication when DH authentication is configured.
202) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-64315)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the caam crypto driver setkey handlers when dumping key material during key setup with dynamic debug enabled. A local user can access debug output containing sensitive key material to disclose sensitive information.
Exposure occurs at runtime when CONFIG_DYNAMIC_DEBUG is enabled.
203) Integer overflow (CVE-ID: CVE-2026-64313)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause incorrect cryptographic computation.
The vulnerability exists due to an integer overflow in crypto/ecc.c when performing elliptic curve multiplication. A local user can trigger the vulnerable arithmetic path to cause incorrect cryptographic computation.
204) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64303)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption or trigger a use-after-free.
The vulnerability exists due to improper resource shutdown in the fsl-lpspi dma transfer error path in drivers/spi/spi-fsl-lpspi.c when preparing a tx dma descriptor after the rx dma channel has already been submitted and issued. A local user can trigger a tx prepare failure during a spi dma transfer to cause memory corruption or trigger a use-after-free.
The issue occurs because the spi core unmaps dma buffers after the error is returned while the rx dma engine may continue writing to those buffers.
205) Improper input validation (CVE-ID: CVE-2026-64280)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in afu_ioctl_dma_map() when handling a DFL_FPGA_PORT_DMA_MAP ioctl request with a user-supplied length. A local user can provide an excessively large length value to cause a denial of service.
206) Out-of-bounds read (CVE-ID: CVE-2026-64269)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to an out-of-bounds read in rdma_write_sg when processing an RTRS READ response with an attacker-controlled descriptor length. A remote attacker can advertise a crafted desc[0].len value larger than max_chunk_size to disclose sensitive information or cause a denial of service.
With no IOMMU or in passthrough mode, adjacent host memory may be returned to the peer; with a translating IOMMU, the out-of-range access is expected to fault and abort the connection.
207) Out-of-bounds write (CVE-ID: CVE-2026-64268)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to write out of bounds.
The vulnerability exists due to an out-of-bounds write in siw_proc_rresp() in drivers/infiniband/sw/siw/siw_qp_rx.c when processing Read Response DDP segments for an outstanding RREAD over an established RDMA connection. A remote user can send Read Response segments with more total payload than requested while keeping the DDP Last flag clear to write out of bounds.
Exploitation requires a connected siw peer on an established RDMA connection over routable TCP.
208) Use-after-free (CVE-ID: CVE-2026-64249)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in child_regions_with_firmware() in drivers/fpga/of-fpga-region.c when handling child FPGA region data. A local user can trigger the error path to cause a denial of service.
209) Out-of-bounds read (CVE-ID: CVE-2026-64247)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in hv_is_vp_in_sparse_set() when handling a paravirtual TLB flush for an L2 guest with a copied VP ID from the enlightened VMCS. A local user can provide a crafted VP ID value to cause a denial of service.
The issue can also cause KVM to perform an unnecessary TLB flush for an L2 vCPU.
210) Out-of-bounds read (CVE-ID: CVE-2026-64237)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the elan_i2c firmware update handler when processing a crafted firmware file. A local user can provide a specially crafted firmware file to disclose sensitive information.
211) Out-of-bounds read (CVE-ID: CVE-2026-64231)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in msm_disp_snapshot_add_block when dumping DSI host registers after the IO base address is adjusted by io_offset. A local user can trigger register dumping to cause a denial of service.
The issue affects DSI 6G platforms.
212) Out-of-bounds read (CVE-ID: CVE-2026-64225)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the cgx_speed_mbps array access in link_status_user_format() when processing firmware-reported link status values. A local user can trigger an out-of-range RESP_LINKSTAT_SPEED value to cause a denial of service.
213) Use-after-free (CVE-ID: CVE-2026-64221)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the ti-qspi driver when handling DMA setup failure during probe. A local user can trigger a DMA setup failure and subsequent use of a released DMA channel pointer to cause a denial of service.
The issue occurs when the driver falls back to PIO mode after DMA setup failure.
214) Use of Uninitialized Variable (CVE-ID: CVE-2026-64220)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of uninitialized memory in fwnode_init() when initializing a firmware node allocated on the stack or with a non-zeroing heap allocation. A local user can trigger code paths that dereference the uninitialized secondary pointer to cause a denial of service.
The issue can occur when a temporary software node is used and its lifetime is controlled by the caller.
215) Out-of-bounds read (CVE-ID: CVE-2026-64219)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in dc->links[] access within dc_process_dmub_aux_transfer_async() when handling a link_index value without bounds checking. A local user can supply an invalid link_index to cause a denial of service.
216) Stack-based buffer overflow (CVE-ID: CVE-2026-64219)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in dc_process_dmub_aux_transfer_async() when processing an aux transfer payload. A local user can pass a payload length greater than 16 to cause a denial of service.
217) Use-after-free (CVE-ID: CVE-2026-64218)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in batadv_bla_purge_backbone_gw() in the bridge loop avoidance component when purging stale backbone gateway entries. A local user can trigger report_work to access freed memory to cause a denial of service.
The issue occurs when associated report_work is still running or pending during backbone gateway cleanup.
218) Out-of-bounds write (CVE-ID: CVE-2026-64217)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in netfs_extract_user_iter() when extracting user-supplied pages from an iov_iter. A local user can trigger an extract_pages overrun to cause memory corruption.
The issue occurs if iov_iter_extract_pages() overfills the pages array, causing excess pages to be included in the constructed iterator.
219) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-64214)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access of per-CPU preemption state in arch_irq_work_raise() when handling machine check exceptions in real mode. A local user can trigger a machine check exception that reaches arch_irq_work_raise() to cause a denial of service.
The issue occurs in NMI context on powerpc systems, where accessing preempt_count from real mode can fault and panic the kernel.
220) Deadlock (CVE-ID: CVE-2026-64206)
CWE-ID: CWE-833 - Deadlock
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper locking in the Bluetooth L2CAP connection teardown path when canceling pending receive work during connection deletion. A remote attacker can trigger Bluetooth L2CAP traffic and connection teardown to cause a denial of service.
The issue can deadlock between the pending_rx_work worker and the teardown path in l2cap_conn_del().
221) Out-of-bounds read (CVE-ID: CVE-2026-64191)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds read and out-of-bounds write in stub_xfer() in the i2c-stub driver when handling an I2C_SMBUS ioctl with I2C_SMBUS_I2C_BLOCK_DATA and an invalid block length. A local user can issue a crafted ioctl request with data->block[0] greater than 32 to cause a denial of service.
The issue affects the development and test i2c-stub driver, which is not built by default and must be loaded with a chip_addr= parameter.
222) Operation on a Resource after Expiration or Release (CVE-ID: CVE-2026-64185)
CWE-ID: CWE-672 - Operation on a Resource after Expiration or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in sysfs_update_group() and internal_create_group() when handling updates to a named sysfs group after create_files() fails. A local user can trigger an update operation that causes file creation to fail to cause a denial of service.
The issue affects the update path for an already existing named sysfs group, which may be silently removed instead of left intact.
223) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64184)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper release of a resource in damon_sysfs_memcg_path_to_id() in mm/damon/sysfs-schemes.c when iterating memory cgroups and breaking out of the mem_cgroup_iter() loop early. A local user can trigger the affected code path to cause a denial of service.
The issue results from a leaked cgroup reference because mem_cgroup_iter_break() is not called before exiting the iteration.
224) NULL pointer dereference (CVE-ID: CVE-2026-64183)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the EFI runtime workqueue handling for ACPI PRM calls when invoking EFI runtime calls during early initialization. A local user can trigger early PRM-related runtime calls to cause a denial of service.
The issue occurs when ACPI PRM accesses happen before the EFI runtime workqueue has been allocated during system initialization.
225) Improper resource shutdown or release (CVE-ID: CVE-2026-64182)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in memblk_nr_poison_inc() and memblk_nr_poison_sub() in drivers/base/memory.c when updating poison accounting for a memory block. A local user can trigger repeated successful memory block lookups to cause a denial of service.
226) Improper resource shutdown or release (CVE-ID: CVE-2026-64180)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in remove_memory_blocks_and_altmaps() in mm/memory_hotplug.c when removing memory blocks and their altmaps. A local user can trigger memory block removal operations to cause a denial of service.
227) Improper resource shutdown or release (CVE-ID: CVE-2026-64179)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in ipc_imem_init() when handling error paths after ipc_protocol_init(). A local user can trigger initialization failures to cause a denial of service.
228) Use-after-free (CVE-ID: CVE-2026-64178)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to a use-after-free in the bnep_add_connection function when reading dev->name during connection setup while a concurrent connection deletion tears down the net_device. A local privileged user can trigger concurrent bnep_add_connection and bnep_del_connection operations to disclose sensitive information.
Exploitation requires CAP_NET_ADMIN and a tight race window during net_device teardown.
229) Improper locking (CVE-ID: CVE-2026-64177)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in pep_do_rcv() in net/phonet/pep.c when forwarding an skb to a child socket via sk_receive_skb(). A local user can trigger socket backlog processing that acquires the child socket lock with bottom halves enabled to cause a denial of service.
The issue can lead to an inconsistent lock state and a self-deadlock on the same CPU when packets are received for the same child socket.
230) Infinite loop (CVE-ID: CVE-2026-64174)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper loop state management in cfg80211_merge_profile() when processing a specially crafted malicious beacon containing split Multi-BSSID non-transmitted BSS profile elements. A remote attacker can send a specially crafted beacon to cause a denial of service.
The issue can cause the kernel to spend excessive time in the affected function for each beacon received.
231) Improper resource shutdown or release (CVE-ID: CVE-2026-64173)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in tracing_map_elt_free() in kernel/trace/tracing_map.c when handling allocation failures during tracing map element initialization. A local user can trigger an allocation failure path to cause a denial of service.
232) Improper handling of exceptional conditions (CVE-ID: CVE-2026-64170)
CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of error pointers in the spi-qup DMA initialization logic when handling DMA setup failures during driver probe. A local user can trigger a DMA setup failure and subsequent probe error or driver unbind to cause a denial of service.
The issue can lead to dereferencing an error pointer or attempting to release a DMA channel a second time.
233) NULL pointer dereference (CVE-ID: CVE-2026-64168)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an error pointer dereference in the sprd spi driver probe error-handling path when handling DMA setup failure during probe. A local user can trigger a probe path that falls back from DMA to PIO mode and reaches late error handling to cause a denial of service.
The issue occurs because the driver may attempt to release DMA channels after DMA setup has failed.
234) NULL pointer dereference (CVE-ID: CVE-2026-64166)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the arm_ffa bus match callback when registering a buggy FF-A driver without an id_table. A local user can register a crafted FF-A driver to cause a denial of service.
235) NULL pointer dereference (CVE-ID: CVE-2026-64165)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in intcp_init_early when performing early initialization before the memory management subsystem is initialized. A local attacker can trigger the vulnerable initialization path to cause a denial of service.
The issue affects ARM Integrator/CP systems using Device Tree, and the failure may manifest as either a kernel crash or an -ENOMEM condition that prevents sched_clock_register from being called.
236) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64163)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state reset in lib/tests/test_kprobes.c when running the kprobes sanity tests multiple times. A local user can trigger repeated test runs to cause a denial of service.
The issue occurs because static kprobe and kretprobe objects retain leftover address and flag data between test runs, which leads to failed re-registration and an eventual kernel crash.
237) Race condition (CVE-ID: CVE-2026-64160)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in netfslib size handling when concurrently updating or reading remote_i_size and zero_point. A local user can trigger concurrent filesystem operations to cause a denial of service.
The issue can corrupt i_size_seqcount and make subsequent i_size_read() calls loop forever, and the advisory highlights 32-bit systems as affected by tearing concerns.
238) Improper resource shutdown or release (CVE-ID: CVE-2026-64155)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in ath11k WMI WOW command handling in drivers/net/wireless/ath/ath11k/wmi.c when sending WOW host wakeup and WOW enable commands. A local user can trigger error paths to cause a denial of service.
239) Unchecked Return Value (CVE-ID: CVE-2026-64153)
CWE-ID: CWE-252 - Unchecked Return Value
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of error codes in msm_iommu_map() in the drm/msm iommu mapping logic when mapping scatter-gather tables. A local user can trigger an error condition to cause a denial of service.
240) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-64148)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper error handling in pdsc_devcmd_wait() when handling firmware crash or command timeout conditions. A local user can trigger the vulnerable code path to cause a denial of service.
The issue causes stale success status to be returned instead of propagating an error, which can prevent proper recovery handling.
241) NULL pointer dereference (CVE-ID: CVE-2026-64147)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of error pointers and a missing reference release in pds_core debugfs handling when performing firmware reset recovery or checking for an existing debugfs entry. A local user can trigger the vulnerable code path to cause a denial of service.
The crash condition occurs when CONFIG_DEBUG_FS is disabled.
242) Improper resource shutdown or release (CVE-ID: CVE-2026-64144)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the btmtk USB Bluetooth driver when handling failed or killed control urbs. A local user can trigger error paths to cause a denial of service.
243) Out-of-bounds read (CVE-ID: CVE-2026-64138)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the ksmbd smbacl.c ACL inheritance logic when processing owner and group SIDs from a parent security descriptor. A remote user can provide a specially crafted parent security descriptor to cause a denial of service.
The issue occurs during ACL inheritance in ksmbd.
244) Improper access control (CVE-ID: CVE-2026-64137)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to affect service availability.
The vulnerability exists due to improper access control in the CIFS SWN netlink notify handler when sending witness notification commands. A local user can send crafted RESOURCE_CHANGE or CLIENT_MOVE notifications to affect service availability.
The intended sender is the cifs.witness helper, but any local process could send notifications to the in-kernel witness handler.
245) Improper access control (CVE-ID: CVE-2026-64137)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in the CIFS SWN generic netlink multicast group when joining the multicast group and receiving registration messages. A local user can join the CIFS_GENL_MCGRP_SWN group to disclose sensitive information.
For NTLM-authenticated mounts, exposed registration messages may include the username, domain, and password attributes copied from the CIFS session.
246) Race condition (CVE-ID: CVE-2026-64136)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in smb2_find_smb_sess_tcon_unlocked() when handling SMB tree connection lookups. A local user can trigger concurrent access to corrupt tc_count handling and cause a denial of service.
247) Stack-based buffer overflow (CVE-ID: CVE-2026-64135)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in adm1266_nvmem_read_blackbox() when processing an SMBus block response from a device. A local user can return a block length larger than the allocated buffer to cause a denial of service.
The issue occurs before the return-length check rejects an unexpected response.
248) NULL pointer dereference (CVE-ID: CVE-2026-64134)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the ALSA PCM interleaved_copy() function when handling silencing operations with NULL data. A local user can trigger a crafted PCM data transfer path to cause a denial of service.
The issue is architecture-dependent and was reported to cause failures on RISC-V systems.
249) Out-of-bounds read (CVE-ID: CVE-2026-64133)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the find_control() function in the ALSA asihpi driver when reading cached control information with an out-of-range control index. A local user can provide a crafted control index to cause a denial of service.
250) NULL pointer dereference (CVE-ID: CVE-2026-64128)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in iso_recv() in the Bluetooth ISO subsystem when processing an ISO_END frame without a prior ISO_START on a fresh ISO connection. A remote attacker can send a specially crafted Bluetooth ISO frame sequence to cause a denial of service.
For BIS, exploitation does not require pairing and can be triggered by a broadcaster on the air.
251) Information disclosure (CVE-ID: CVE-2026-64127)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information leak caused by incorrect size and source-pointer arguments in l2cap_ecred_reconfigure() in the Bluetooth L2CAP subsystem when sending an L2CAP_ECRED_RECONFIGURE_REQ packet to a paired Bluetooth peer. A remote attacker can trigger ecred reconfiguration handling to disclose sensitive information.
The malformed packet copies bytes from kernel stack memory and can expose a kernel stack address to the peer. Exploitation requires Bluetooth connectivity with a paired peer.
252) Out-of-bounds read (CVE-ID: CVE-2026-64126)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the Bluetooth MGMT add_ext_adv_data() handler when processing a crafted MGMT_OP_ADD_EXT_ADV_DATA command with inconsistent length fields. A local privileged user can send a specially crafted management command to disclose sensitive information.
Exploitation requires CAP_NET_ADMIN in the initial user namespace, and exposed memory may be read back via MGMT_OP_GET_ADV_INSTANCE.
253) Improper Initialization (CVE-ID: CVE-2026-64125)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper hardware state management in bcmgenet_eee_enable_set in the Broadcom GENET network driver when enabling energy-efficient ethernet settings. A local user can enable the affected settings to cause a denial of service.
On affected systems, RX traffic can stop flowing while the link remains up, and on some boards the resulting corruption can lead to a paging fault in skb_release_data via bcmgenet_rx_poll on an LPI exit.
254) Out-of-bounds read (CVE-ID: CVE-2026-64121)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in ifb_get_ethtool_stats in the IFB network driver when handling ethtool statistics requests on a device with more RX queues than TX queues. A local user can request ethtool statistics for a crafted asymmetric IFB device to disclose sensitive information.
Exploitation requires an IFB device configuration where the RX queue count exceeds the TX queue count.
255) Double free (CVE-ID: CVE-2026-64118)
CWE-ID: CWE-415 - Double Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in qed_cid_map_free() in the QLogic qed driver context management code when handling failed CID bitmap allocations. A local user can trigger the failing allocation path to cause a denial of service.
Exploitation requires device-specific setup to reach the affected allocation failure path.
256) Use-after-free (CVE-ID: CVE-2026-64117)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in ieee80211_invoke_fast_rx() when processing mesh forwarding in the unicast forward path. A local user can trigger mesh data handling that causes freed memory to be accessed to cause a denial of service.
The issue occurs because skb->cb storage is reused by mesh forwarding code before the caller finishes consuming the RX status, and the no-route path can free the skb before the stale status is accessed.
257) NULL pointer dereference (CVE-ID: CVE-2026-64116)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in ipv6_hop_ioam() when processing an IPv6 IOAM Hop-by-Hop option during concurrent interface teardown. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue occurs because IPv6 interface state can be cleared concurrently through RCU, allowing __in6_dev_get(skb->dev) to return NULL while the packet is being handled.
258) Use-after-free (CVE-ID: CVE-2026-64115)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in vmci_transport_recv_connecting_server() and vmci_transport_recv_listen() when processing a peer reset during the connection handshake. A remote attacker can send a reset packet during the handshake to cause a denial of service.
The issue is triggered by a race involving pending socket cleanup in the VMCI vsock transport.
259) Out-of-bounds read (CVE-ID: CVE-2026-64114)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in the raw_send_hdrinc IPv4 packet handling in the Linux kernel when processing a malformed IP_HDRINCL packet with an IPv4 header length value less than 5. A local user can send a specially crafted packet through a raw socket to cause a denial of service.
Exploitation requires CAP_NET_RAW. Triggering the reproduced crash path also requires a matching xfrm AH policy on the outgoing route, and loopback does not reach the affected path.
260) Use-after-free (CVE-ID: CVE-2026-64113)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in ixgbevf_clean_rx_irq() when processing received frames that trigger VEPA multicast source pruning. A local user can trigger this code path to cause a denial of service.
The issue occurs in NAPI softirq context when a freed skb is reused on the next loop iteration because the pointer is not cleared before continuing.
261) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-64112)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a time-of-check time-of-use race condition in the rbd lock_dwork handling in drivers/block/rbd.c when unmapping an image while exclusive lock work is being queued. A local user can trigger image unmap operations during concurrent I/O activity to cause a denial of service.
The issue can result in lock acquisition work executing after device and image release operations have freed or reset internal state.
262) Improper locking (CVE-ID: CVE-2026-64111)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass security restrictions.
The vulnerability exists due to improper locking in lsm_set_self_attr() when setting a process security attribute. A local user can invoke the syscall while the process is being ptraced to bypass security restrictions.
This affects SELinux and AppArmor checks related to ptrace during security context transitions.
263) Use-after-free (CVE-ID: CVE-2026-64109)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in unix_stream_data_wait() in net/unix/af_unix.c when processing racing recv() operations on the same AF_UNIX stream socket. A local user can trigger concurrent peek and normal receive operations to cause a denial of service.
Exploitation requires a race condition between a peeking recv() call and a normal recv() call on the same socket.
264) Use-after-free (CVE-ID: CVE-2026-64108)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free condition in the cifs deferred file close handling when processing deferred file close work during unmount. A local user can open and close a file and trigger unmount activity to cause a denial of service.
The issue can be triggered because deferred close work may run after the filesystem is being unmounted, leading to a busy dentry warning.
265) Improper input validation (CVE-ID: CVE-2026-64106)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in vgic_its_restore_dte() when restoring an ITS Device Table Entry. A remote user can supply a restored DTE with an out-of-range Size field to cause a denial of service.
Exploitation requires the ability to restore crafted KVM ITS device state on arm64 systems.
266) Use-after-free (CVE-ID: CVE-2026-64103)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the isci completion tasklet in the ISCI driver when removing a device or unloading the driver while queued tasklet processing is still possible. A local user can trigger device removal or driver unload to cause a denial of service.
The stale callback may dereference ihost and access ihost->smu_registers after the host lifetime ends.
267) Integer underflow (CVE-ID: CVE-2026-64102)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service and disclose kernel memory contents.
The vulnerability exists due to an integer underflow in the Soft-iWARP receive path (siw_get_hdr/siw_tcp_rx_data) when processing a malformed iWARP FPDU with an MPA length smaller than the fixed header length for the opcode. A remote user can send a specially crafted FPDU to cause a denial of service and disclose kernel memory contents.
The issue is triggered by a malicious connected siw peer, and the negative signed length is later promoted to size_t during skb_copy_bits processing.
268) Use-after-free (CVE-ID: CVE-2026-64099)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the v3d CPU job ioctl error path when handling CPU job submission failures. A local user can trigger an error path with crafted CPU job submissions to cause a denial of service.
The same error path can also trigger a NULL dereference and leak one sync object reference per query.
269) Improper locking (CVE-ID: CVE-2026-64098)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock handling in virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() when updating planes and flushing framebuffer resources. A local user can trigger error conditions that leave the dma_resv lock unheld and then reach fence-list updates to cause a denial of service.
The issue can race with concurrent readers or writers and corrupt the dma_resv fence list. The reported trigger used fault injection on the DRM_IOCTL_MODE_CURSOR path.
270) Out-of-bounds read (CVE-ID: CVE-2026-64097)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in get_gpio_i2c_info() and bios_parser_get_gpio_pin_info() when parsing a malformed VBIOS GPIO pin LUT table. A local attacker can supply a crafted VBIOS image with an invalid structuresize field to disclose sensitive information.
271) Use-after-free (CVE-ID: CVE-2026-64096)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in batadv_mcast_purge_orig() and orig_node RCU release handling when releasing orig_node entries while concurrent RCU readers are still accessing multicast-related references. A local user can trigger concurrent access to freed entries to cause a denial of service.
The issue affects RCU-protected readers accessing references such as orig->mcast_want_all_ipv6_node after the referenced entries have been removed and freed.
272) Race condition (CVE-ID: CVE-2026-64093)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in batman-adv tp_meter timer handling in batadv_tp_sender_cleanup() when shutting down the sender timer during cleanup. A local user can trigger timer re-arming after cleanup to cause a denial of service.
The issue occurs because the timer may be re-armed after its reference has already been released.
273) Improper resource shutdown or release (CVE-ID: CVE-2026-64092)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown handling in the batman-adv tp_meter receiver shutdown logic when stopping receiver sessions and handling timer expiration. A local user can trigger the affected code path to cause a denial of service.
The issue arises from a reference leak involving tp_vars during coordination between batadv_tp_receiver_shutdown() and batadv_tp_stop_all().
274) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-64091)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition leading to an out-of-bounds write in batadv_tt_prepare_tvlv_local_data in the batman-adv translation table handling when generating local TT TVLV data for reported VLANs. A local user can trigger concurrent VLAN translation table entry changes to cause a denial of service.
The issue arises from a time-of-check time-of-use condition where the number of non-empty VLANs can increase after buffer sizing but before the buffer is filled.
275) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-64089)
CWE-ID: CWE-195 - Signed to Unsigned Conversion Error
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an integer signedness error in batadv_send_my_tt_response() and batadv_tt_prepare_tvlv_local_data() when processing a translation table changeset length value larger than 32767. A local user can trigger the vulnerable code path to disclose sensitive information.
The issue occurs because a negative sign-extended length can cause a full-sized buffer to be allocated while only a small portion is populated, leaving the remaining bytes uninitialized.
276) Use of Uninitialized Variable (CVE-ID: CVE-2026-64088)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to uninitialized memory exposure in batadv_send_other_tt_response() and batadv_tt_prepare_tvlv_global_data() when handling tt changeset response data. A remote attacker can trigger processing of an oversized tt_buff_len value to disclose sensitive information.
The issue is caused by a signed integer field wrapping to a negative value and then being widened with sign extension, resulting in a fully allocated buffer that is only partially initialized.
277) Out-of-bounds write (CVE-ID: CVE-2026-64087)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in adm1266_nvmem_read_blackbox() when processing a malformed BLACKBOX_INFO response. A local user can provide a device response with an implausible blackbox record count to cause a denial of service.
The issue can be triggered by a non-responsive slave returning 0xff, bus corruption, or firmware bugs in the device response.
278) Out-of-bounds write (CVE-ID: CVE-2026-64086)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in adm1266_pmbus_block_xfer() and read_buf in the adm1266 PMBus driver when processing a max-length block read response with a PEC byte. A local user can trigger the driver to process a crafted response to cause a denial of service.
The same condition can also cause an out-of-bounds read during the subsequent PEC comparison.
279) Out-of-bounds write (CVE-ID: CVE-2026-64085)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in adm1266_nvmem_read_blackbox() when processing device-supplied blackbox records. A local user can provide a device response with more than 64 bytes in a trailing record to cause a denial of service.
The issue occurs because the helper may write up to 255 bytes into a 64-byte record slot before the returned length is validated.
280) Out-of-bounds write (CVE-ID: CVE-2026-64084)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information and corrupt memory.
The vulnerability exists due to an out-of-bounds read and out-of-bounds write in adm1266_gpio_get_multiple() in the adm1266 PMBus driver when iterating a caller-supplied gpio mask. A local user can trigger access to bits beyond the end of the supplied mask and bits arrays to disclose sensitive information and corrupt memory.
The iteration uses a PMBus command value as the scan bound instead of the number of PDIO pins.
281) Use of Uninitialized Variable (CVE-ID: CVE-2026-64083)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an uninitialized stack memory exposure in the adm1266 GPIO accessors when processing short block-read responses from the device. A local user can trigger a short block-read response to disclose sensitive information.
The leaked bits can reach userspace through gpiolib interfaces including sysfs and character-device ioctls.
282) Use of Uninitialized Variable (CVE-ID: CVE-2026-64082)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt register state and disclose kernel stack contents.
The vulnerability exists due to use of uninitialized stack data in compat_riscv_gpr_set() and compat_restore_sigcontext() when handling failed user memory copies. A local user can provide crafted user-supplied register or signal context data that triggers a copy failure to corrupt register state and disclose kernel stack contents.
The issue affects the RISC-V compatibility signal and ptrace handling paths.
283) Race condition (CVE-ID: CVE-2026-64077)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the ebtables table registration and unregistration logic when handling table initialization and teardown. A local user can trigger ebtables operations to cause a denial of service.
The issue involves exposure of a partially filled table structure and unsafe teardown ordering in the bridge netfilter ebtables subsystem.
284) Race condition (CVE-ID: CVE-2026-64076)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in ebtables initialization in net/bridge/netfilter/ebtables.c when registering and exposing sockopts globally during module initialization. A local user can trigger access to the exposed sockopts during the initialization window to cause a denial of service.
285) Use-after-free (CVE-ID: CVE-2026-64073)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in irq_work_single() when synchronizing irq_work on PREEMPT_RT systems. A local user can trigger concurrent irq_work activity and free the work structure after BUSY is cleared to cause a denial of service.
The issue affects non-HARD irq_work processed by per-CPU kthreads on PREEMPT_RT.
286) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64064)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in netfs_invalidate_folio() when handling a folio that was dirtied by a streaming write and then truncated before being read via mmap(). A local user can truncate the file and trigger a subsequent mmap read to cause a kernel oops and denial of service.
Exploitation requires a local sequence involving streaming writes followed by truncation and mmap-based access.
287) Race condition (CVE-ID: CVE-2026-64056)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in gmac_rx() in the cortina gemini ethernet driver when processing fragmented packets on systems using both ethernet ports. A local user can trigger concurrent packet reception to cause a denial of service.
The issue arises because a packet assembly sk_buff was shared between the two ports.
288) Improper Initialization (CVE-ID: CVE-2026-64055)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the gmac_rx() NAPI poll function when assembling packets from a ring buffer. A local user can trigger processing of fragmented packets across poll cycles to cause a denial of service.
The issue occurs when the ring buffer is completely emptied before a packet has been fully assembled.
289) Use-after-free (CVE-ID: CVE-2026-64051)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in qaic_gem_object_mmap when mapping a buffer object into memory with scatter-gather segments that extend beyond the virtual memory area. A local user can trigger the mapping of an oversized buffer object to cause a denial of service.
The issue occurs because memory beyond the requested virtual memory area can remain mapped after munmap() unmaps only the virtual memory area region.
290) NULL pointer dereference (CVE-ID: CVE-2026-64048)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in smc_v2_determine_accepted_chid and smc_conn_create when processing a crafted SMC-Dv2 accept reply with CHID 0. A remote attacker can send a specially crafted reply to trigger a kernel fault and cause a denial of service.
Exploitation requires a malicious peer to reply to an SMC-Dv2-only proposal.
291) Off-by-one (CVE-ID: CVE-2026-64047)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an off-by-one error in tls_push_record() in the net/tls subsystem when chaining a wrapped sk_msg scatterlist ring. A local user can trigger the wrapped ring condition to cause a denial of service.
The issue occurs when the sk_msg scatterlist ring wraps with sg.end less than sg.start.
292) Improper input validation (CVE-ID: CVE-2026-64046)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the net/tls plaintext scatter-gather list handling when processing TLS 1.3 records with a plain text scatter-gather list that wraps and has end = 0. A local user can trigger a chain-after-chain scatterlist layout to cause a denial of service.
The issue affects the case where the wrapping slot is reused for chaining to the content type entry, creating illegal input for the crypto subsystem.
293) Out-of-bounds read (CVE-ID: CVE-2026-64039)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in msm_disp_state_print_regs and related snapshot dumping logic when processing unaligned DSI register regions. A local user can trigger snapshotting of a specially positioned unaligned region to cause a denial of service.
The issue occurs because some DSI data regions are shifted by 4 bytes, causing the last registers in the region to be handled incorrectly.
294) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-64034)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass bounds validation.
The vulnerability exists due to a time-of-check time-of-use double-fetch in mana_hwc_rx_event_handler() and mana_hwc_handle_resp() when reading hwc_msg_id from a DMA-coherent buffer. A remote attacker can modify the DMA-visible hwc_msg_id value between reads to bypass bounds validation.
Exploitation requires hardware or a host environment able to alter shared, unencrypted DMA-coherent memory between the check and the subsequent use, such as in confidential VM environments.
295) Use-after-free (CVE-ID: CVE-2026-64033)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in rtrs_srv_create_path_files() cleanup logic when handling an error path during sysfs path file creation. A local user can trigger a failure in a later cleanup step to cause a denial of service.
The issue occurs before the function returns success, in a failure path where sysfs root folders may already exist and the kobject may already have been initialized.
296) Use-after-free (CVE-ID: CVE-2026-64032)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the bridge multicast handling in net/bridge/br_multicast.c when removing a bridge port after toggling multicast snooping states. A local user can trigger bridge port state transitions that leave a multicast context enabled on a freed bridge port to cause a denial of service.
The issue occurs when per-VLAN multicast snooping is enabled and global multicast snooping is toggled in a way that leaves both per-port and per-{port, VLAN} multicast contexts enabled on the same port.
297) Use-after-free (CVE-ID: CVE-2026-64029)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in seq_ump_process_event() and snd_rawmidi_kernel_write1() when processing sequencer events during concurrent output teardown. A local user can trigger concurrent event delivery and output close operations to cause a denial of service.
The issue arises from a race condition between the event_input path and the last output unuse path, where the rawmidi substream runtime may be freed while still in use.
298) Use-after-free (CVE-ID: CVE-2026-64025)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a use-after-free in sk_psock_verdict_data_ready in the Linux kernel BPF sockmap/skmsg handling when processing socket data with a TLS RX context present. A local user can trigger the race condition to cause a denial of service or execute arbitrary code.
Exploitation requires a socket to be inserted into a sockmap before TLS RX is configured.
299) Out-of-bounds read (CVE-ID: CVE-2026-64018)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in mana_hwc_rx_event_handler() when processing hardware-modifiable WQE contents from DMA-coherent memory. A local attacker can modify the derived rx_req_idx value to cause a denial of service.
In confidential VMs such as SEV-SNP and TDX, the affected DMA-coherent memory is shared unencrypted and hardware can modify WQE contents at any time.
300) Race condition (CVE-ID: CVE-2026-64015)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in find_key_to_update in the keyring code when looking up keys for update without holding the RCU read lock. A local user can trigger concurrent key lookup and garbage-collection activity to cause a denial of service.
The issue affects persistent key handling, which uses a different locking model.
301) Use-after-free (CVE-ID: CVE-2026-64011)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in llcp_sock_release() when releasing an LLCP socket in connecting state. A local user can trigger socket release in that state to cause a denial of service.
302) Use-after-free (CVE-ID: CVE-2026-64010)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free race condition in nfc_llcp_recv_cc() when processing an NFC LLCP connection acceptance packet concurrently with socket release. A local user can trigger concurrent connection handling and socket release to cause a denial of service.
The issue occurs during a connection state transition when a socket can be moved from the connecting_sockets list to the sockets list after it has already been unlinked and marked for destruction.
303) Use-after-free (CVE-ID: CVE-2026-64007)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption or a denial of service.
The vulnerability exists due to a use-after-free in synproxy_tstamp_adjust() in the netfilter synproxy implementation when processing crafted TCP packets that trigger header rewriting on a cloned or non-linear skb. A remote attacker can send a specially crafted packet to cause memory corruption or a denial of service.
The issue affects checksum updates after the packet buffer is made writable, which can result in a write to freed slab memory or a transmitted packet with a stale checksum.
304) Out-of-bounds read (CVE-ID: CVE-2026-64000)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in supervision frame handling in net/hsr/hsr_forward.c when processing truncated supervision frames. A remote attacker can send a specially crafted frame to cause a denial of service.
305) Use-after-free (CVE-ID: CVE-2026-63994)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() when processing tunnel PMTU ICMP and ICMPv6 packet generation. A local user can trigger skb_cow() reallocation while stale network header pointers are still used to cause a denial of service.
306) Use-after-free (CVE-ID: CVE-2026-63993)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in the vxlan_xmit_one function in drivers/net/vxlan/vxlan_core.c when processing packets after skb_tunnel_check_pmtu() updates the skb head. A local user can trigger the vulnerable code path to execute arbitrary code.
307) Out-of-bounds read (CVE-ID: CVE-2026-63992)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in iptunnel_pmtud_check_icmp() when processing ICMP packets without a valid transport header. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue occurs because the function may be called while the skb transport header is not set.
308) Integer overflow (CVE-ID: CVE-2026-63984)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to corrupt memory in a forwarded packet.
The vulnerability exists due to an integer overflow in ipv6_rpl_srh_decompress() and ipv6_rpl_srh_rcv() when processing a crafted IPv6 RPL source routing header. A remote attacker can send a specially crafted packet to corrupt memory in a forwarded packet.
The issue occurs because the computed hdrlen value can truncate to zero for a large segment count, causing the compressed header to overlap the decompressed routing data.
309) Improper locking (CVE-ID: CVE-2026-63980)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock handling in the net/handshake subsystem when canceling a TLS handshake from softirq context while the same lock is held in process context on the same CPU. A local user can trigger a TLS handshake cancellation race to cause a denial of service.
The issue results in a deadlock.
310) Use-after-free (CVE-ID: CVE-2026-63979)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the net/handshake accept-side request handling code when processing queued handshake requests during concurrent cancellation. A local user can trigger a race condition to cause a denial of service.
The issue occurs because the accept side dereferences req->hr_sk->sk_socket->file after the request is removed from the pending list, while a concurrent cancellation path can release sock->file, clear sk_socket, or free the associated struct socket.
311) Race condition (CVE-ID: CVE-2026-63978)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in net/handshake request draining during net namespace exit when canceling pending handshake requests concurrently with namespace teardown. A local user can trigger concurrent handshake request cancellation and net namespace destruction to cause a denial of service.
The issue affects pending handshake requests that have not yet been accepted and can result in list corruption or a request being freed while still linked on the drain loop's local list.
312) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-63976)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in the Bluetooth L2CAP ECRED reconfiguration response handler when processing a replayed failure response after a successful reconfiguration. A remote attacker can replay a failure response with a stale ident value to cause a denial of service.
The issue can destroy an already-established channel by causing the kernel to match a subsequent response against a recycled ident value.
313) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-63975)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of channel deletion during list iteration in l2cap_ecred_conn_rsp in the Bluetooth L2CAP subsystem when processing a crafted L2CAP credit-based connection response with an already-assigned destination CID. A remote attacker can send a specially crafted Bluetooth packet to cause a denial of service.
The issue occurs when a duplicate destination CID is received for an L2CAP extended credit based connection response.
314) Race condition (CVE-ID: CVE-2026-63974)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in hci_dev_close_sync() in the Bluetooth HCI subsystem when closing a device during the reset path. A local user can trigger Bluetooth device reset and close operations to cause a denial of service.
315) Improper access control (CVE-ID: CVE-2026-63952)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass write sealing protections and modify a memfd that appears to be write sealed.
The vulnerability exists due to improper access control in memfd_add_seals() in mm/memfd.c when adding SEAL_EXEC to a memfd with writable mappings. A local user can add a seal combination that implies SEAL_WRITE after the writable-mapping check to bypass write sealing protections and modify a memfd that appears to be write sealed.
The issue occurs because SEAL_EXEC implies SEAL_WRITE, but the implied seal was applied only after the check for writable mappings.
316) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-63948)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a reference leak in l2cap_chan_timeout() in the Bluetooth L2CAP subsystem when handling a channel timeout with a null connection pointer. A local user can trigger this condition to cause a denial of service.
317) Out-of-bounds read (CVE-ID: CVE-2026-63947)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in hidp_input_report() when processing truncated Bluetooth HIDP input packets. A remote user can send a specially crafted truncated packet to disclose sensitive information.
Exploitation requires a paired Bluetooth device.
318) Use-after-free (CVE-ID: CVE-2026-63946)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in iso_recv_frame in the Bluetooth ISO subsystem when processing received Bluetooth ISO frames. A local user can trigger concurrent socket teardown and frame handling to cause a denial of service.
Exploitation requires a race condition between frame reception and iso_sock_kill() freeing the socket.
319) Race condition (CVE-ID: CVE-2026-63945)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition leading to a null pointer dereference or use-after-free in iso_sock_clear_timer in the Bluetooth ISO socket handling code when closing a socket concurrently with connection deletion. A local user can trigger concurrent socket operations to cause a denial of service.
320) Use-after-free (CVE-ID: CVE-2026-63944)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in hci_le_create_cis_sync in the Bluetooth HCI synchronization logic when processing concurrent Bluetooth connection state changes during LE Create CIS handling. A local user can trigger a concurrent disconnect to cause a denial of service.
The stale pointer is dereferenced after both rcu_read_lock() and hci_dev_lock(hdev) are released, and the queued cancellation path does not match the pending work item because it is queued with NULL data but dequeued with the connection pointer.
321) Integer underflow (CVE-ID: CVE-2026-63940)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer underflow in KVM SEV Port I/O handling in arch/x86/kvm/svm/sev.c when processing Port I/O requests with a length or count of 0. A local user can trigger a zero-length Port I/O request to cause a denial of service.
The issue affects the handling of VMGEXIT and string I/O requests in the KVM SEV implementation.
322) Incorrect calculation (CVE-ID: CVE-2026-63926)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper offset calculation in bpf_msg_push_data() in the sockmap BPF subsystem when inserting data into the middle of a scatterlist entry. A local user can trigger the inconsistent split layout to cause a denial of service.
Exploitation requires access to BPF sockmap functionality.
323) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2026-63924)
CWE-ID: CWE-823 - Use of Out-of-range Pointer Offset
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper pointer handling in the IPv6 extension header parser in net/ipv6/exthdrs.c when processing IPv6 jumbo hop-by-hop options. A remote attacker can send a specially crafted IPv6 packet to cause a denial of service.
324) Use-after-free (CVE-ID: CVE-2026-63922)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free risk from stale pointer reuse in ip6_parse_tlv() in net/ipv6/exthdrs.c when parsing IPv6 TLVs containing the HAO option. A remote attacker can send a specially crafted IPv6 packet to cause a denial of service.
The issue occurs when handling a cloned skb where header expansion moves the skb head and invalidates the cached network header pointer.
325) Improper access control (CVE-ID: CVE-2026-63921)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to redirect packets across network namespaces.
The vulnerability exists due to improper access control in vti6_siocdevprivate() in the IPv6 VTI tunnel handling code when processing SIOCCHGTUNNEL requests on a migrated tunnel. A local user can supply tunnel parameters that collide with a tunnel in the creation namespace to redirect packets across network namespaces.
Exploitation is reachable from an unprivileged user namespace and can have cross-tenant scope on container hosts.
326) Use-after-free (CVE-ID: CVE-2026-63919)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in xfrm transport-mode deferred reinjection handling in net/xfrm/xfrm_input.c when processing deferred transport reinjection callbacks that use a stored network namespace pointer. A local user can trigger deferred transport reinjection with a dangling net namespace reference to cause a denial of service.
327) Use-after-free (CVE-ID: CVE-2026-63917)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the vti6 tunnel handling code in net/ipv6/ip6_vti.c when changing the configuration of a vti6 device after moving it across network namespaces. A local user can move a vti6 device between namespaces and then change its link parameters to cause a denial of service.
The issue is reachable from an unprivileged user namespace and may have cross-tenant impact on container hosts.
328) Out-of-bounds write (CVE-ID: CVE-2026-63916)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in wacom_hid_set_device_mode() when handling a HID feature report where HID_DG_INPUTMODE is mapped to a field other than the first one. A local user can connect or emulate a crafted device to trigger the out-of-bounds write and cause a denial of service.
The issue occurs when the first field in the feature report has a report_count smaller than the usage index of HID_DG_INPUTMODE.
329) Out-of-bounds read (CVE-ID: CVE-2026-63915)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in HCP header parsing in nfc_hci_recv_from_llc() and nci_hci_data_received_cb() when processing a 0-byte HCP frame from an NFC peer. A remote attacker can send a malformed HCP frame to cause a denial of service.
A non-final fragmented 0-byte frame can also underflow the reassembly length to UINT_MAX and trigger skb_over_panic() during reassembly.
330) Improper access control (CVE-ID: CVE-2026-63914)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in xfrm migrate notification handling in net/xfrm/xfrm_user.c and net/key/af_key.c when broadcasting successful XFRM_MSG_MIGRATE or SADB_X_MIGRATE events across network namespaces. A local user can trigger a migration notification from a non-init network namespace to disclose sensitive information.
An IKE daemon running in the initial network namespace may receive migration notifications originating from other network namespaces, including selector, old and new endpoint addresses, and the km_address.
331) Improper input validation (CVE-ID: CVE-2026-63912)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the ESP out-of-place fast path in net/ipv4/esp4.c and net/ipv6/esp6.c when processing packet data with a combined aligned data length and trailer length exceeding a page. A local user can trigger this condition to cause a denial of service.
The issue affects both IPv4 and IPv6 ESP processing paths.
332) Use-after-free (CVE-ID: CVE-2026-63906)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in omap2430_probe() in the omap2430 USB driver when handling a crafted platform device state. A local user can trigger the vulnerable code path to cause a denial of service.
The issue occurs because a device tree node reference is released before its last access in both the success and error paths.
333) Integer overflow (CVE-ID: CVE-2026-63893)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an integer overflow leading to an out-of-bounds read in tb_property_entry_valid() in the thunderbolt property parser when processing a crafted XDomain property block from a peer device. A remote attacker can send crafted property entries with wrapped value and length fields to disclose sensitive information.
For TEXT-typed entries using the "deviceid" or "vendorid" keys, leaked data may be exposed through the per-XDomain sysfs device_name or vendor_name attributes. The disclosed data is NUL-bounded and the attacker controls an offset rather than an absolute address.
334) Double free (CVE-ID: CVE-2026-63888)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a double free in iscsit_handle_text_cmd() when handling a Text PDU with a bad DataDigest on connections using ErrorRecoveryLevel greater than 0. A remote user can send a specially crafted text request to cause a denial of service.
On hardened kernels the flaw can trigger a remote kernel BUG(), while on non-hardened kernels it can corrupt the slab freelist. A follow-up Text Request on the same ITT or session teardown can free the same pointer again.
335) Out-of-bounds read (CVE-ID: CVE-2026-63888)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in iscsit_handle_text_cmd() when processing Text PDUs with DataDigest enabled. A remote user can send a specially crafted text request to cause a denial of service.
The issue is triggered when DataDigest is negotiated for the connection.
336) Heap-based buffer overflow (CVE-ID: CVE-2026-63887)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in iscsi_encode_text_output() when processing iSCSI login text parameters. A remote attacker can send a specially crafted login request with many minimal key-value pairs to cause a denial of service.
The issue can be triggered by expansion of unknown keys into larger "NotUnderstood" response records during login negotiation.
337) Heap-based buffer overflow (CVE-ID: CVE-2026-63886)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in chap_server_compute_hash() in the iSCSI target CHAP authentication handling when processing a specially crafted base64-encoded CHAP_R response. A remote user can send a specially crafted CHAP authentication response to cause a denial of service.
The issue affects the BASE64 CHAP_R decoding path; the mutual CHAP CHAP_C decoding path is not affected.
338) Race condition (CVE-ID: CVE-2026-63858)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in nf_tables hook handling when deleting device hooks for chains or flowtables while netlink dump path readers access the RCU-protected hook list. A local user can trigger hook deletion and concurrent netlink dump operations to cause a denial of service.
The issue affects the netfilter nf_tables subsystem and involves device hook deletion transactions.
339) Improper input validation (CVE-ID: CVE-2026-63853)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the VCN v4.0 encoder ring submission handling when processing command submissions with user fences. A local user can submit a crafted command stream with a user fence to cause a denial of service.
The issue affects VCN v4.0 encoder functionality, and stems from unsupported 64-bit user fence writes being accepted.
340) Use-after-free (CVE-ID: CVE-2026-63831)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or corrupt data.
The vulnerability exists due to use-after-free in the mac802154 llsec crypto processing in net/mac802154/llsec.c when performing in-place cryptographic transformations on shared skb data. A local user can trigger concurrent 802.15.4 traffic with security enabled to cause a denial of service or corrupt data.
The issue can affect both RX and TX paths when skb data buffers are shared across clones.
341) Improper access control (CVE-ID: CVE-2026-63830)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to modify the page cache contents.
The vulnerability exists due to improper access control in the sk_msg scatter-gather handling logic when processing SK_MSG transformations and BPF message helpers. A local user can trigger scatterlist entry transfers, shifts, splits, or copies that desynchronize sg.copy state to modify the page cache contents.
Exploitation requires the ability to reach a later SK_MSG verdict that exposes sg_virt(sge) as writable BPF ctx->data.
342) Improper access control (CVE-ID: CVE-2026-63829)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to modify tunnel configuration across network namespaces.
The vulnerability exists due to improper access control in ipgre_changelink() and erspan_changelink() when handling RTM_NEWLINK changelink requests for GRE tunnel devices. A local privileged user can send a crafted RTM_NEWLINK request to modify tunnel configuration across network namespaces.
The issue occurs when the device network namespace differs from the tunnel link network namespace, because the check was performed only against dev_net(dev).
343) Improper access control (CVE-ID: CVE-2026-63828)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass AppArmor connect restrictions.
The vulnerability exists due to improper access control in apparmor_socket_sendmsg() when processing sendmsg()/sendto() calls with MSG_FASTOPEN and a supplied destination address. A local user can send a crafted fast open request to bypass AppArmor connect restrictions.
The issue affects implicit TCP and MPTCP connection establishment performed as part of sendmsg() fast open handling.
344) Out-of-bounds write (CVE-ID: CVE-2026-63825)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in inflate_fast() when processing IP payload compression data concurrently on multiple cpus. A local user can trigger concurrent execution of the vulnerable code path to cause a denial of service.
The issue occurs because global gcov counters can change between multiple loads during execution, producing inconsistent loop values.
345) Out-of-bounds read (CVE-ID: CVE-2026-63818)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in f2fs_recover_orphan_inodes() when mounting a crafted f2fs image and replaying orphan inodes from the checkpoint pack. A local user can provide a crafted filesystem image with a corrupted orphan block entry count to cause a denial of service.
The issue occurs when the orphan block entry count is larger than F2FS_ORPHANS_PER_BLOCK, causing the recovery code to read past the ino[] array and interpret subsequent data as inode numbers.
346) Out-of-bounds read (CVE-ID: CVE-2026-63815)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in f2fs_fill_dentries() and inline directory handling when mounting a crafted filesystem image and reading an inline directory. A local user can mount a specially crafted image and read a crafted directory to disclose sensitive information.
Exploitation requires the flexible_inline_xattr feature to be enabled.
347) Use-after-free (CVE-ID: CVE-2026-63808)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in exfat_find_dir_entry() when parsing a crafted exFAT filesystem image. A local user can supply a crafted exFAT image to trigger a kernel fault and cause a denial of service.
The issue occurs on the TYPE_EXTEND path after a directory entry buffer is released and then dereferenced.
348) Out-of-bounds read (CVE-ID: CVE-2026-63807)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in the KVM x86 shadow MMU hugepage recovery logic when recovering hugepages for a direct shadow page whose gfn falls outside the target memslot. A local user can create a guest hugepage mapping that extends below the bounds of a memslot to cause a denial of service.
The issue can manifest as a host page fault in kernel mode during hugepage recovery.
349) Use-after-free (CVE-ID: CVE-2026-63804)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in gfs2_qd_dealloc when processing pending RCU callbacks during filesystem unmount. A local user can trigger quota object disposal and unmount-related cleanup to cause a denial of service.
The issue occurs because an RCU callback may access the superblock after it has already been freed.
350) Use-after-free (CVE-ID: CVE-2026-63801)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in tipc_aead_decrypt_done in the TIPC crypto subsystem when processing crafted encrypted frames during asynchronous decryption. A remote attacker can send crafted encrypted frames to trigger a read from freed memory and cause a denial of service.
Exploitation requires the asynchronous decryption path to be used and can occur while the associated network namespace is being torn down.
351) Use-after-free (CVE-ID: CVE-2026-63800)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in pnfs_update_layout() when handling the NFS_LAYOUT_RETURN branch. A local user can trigger the vulnerable code path to cause a denial of service.
352) Use-after-free (CVE-ID: CVE-2026-63797)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in rpmsg_chrdev_probe() and the rpmsg character device endpoint callback handling in drivers/rpmsg/rpmsg_char.c when processing callbacks during a probe error path. A local user can trigger endpoint creation failure and concurrent callback handling to cause a denial of service.
The issue occurs because the default endpoint's priv pointer can reference freed memory before endpoint setup has completed.
353) Out-of-bounds read (CVE-ID: CVE-2026-63796)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the ocfs2 group descriptor bitmap handling in fs/ocfs2/suballoc.c when processing a crafted group bitmap descriptor. A local user can provide a descriptor with oversized bg_size or bg_bits values to cause a denial of service.
Exploitation requires access to a malicious ocfs2 filesystem image or on-disk metadata.
354) Use-after-free (CVE-ID: CVE-2026-63795)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in p9_client_walk() when handling a failed non-cloning walk after a request has been sent. A local user can trigger a multi-component walk split into multiple p9_client_walk() calls to cause a denial of service.
The issue occurs because fid may alias oldfid, causing a reference owned by the caller to be dropped while the caller still expects the object to remain valid.
355) Use-after-free (CVE-ID: CVE-2026-53399)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in the nfsd layout stateid handling in fs/nfsd/nfs4layouts.c when processing layout stateid allocation failures after a setlease error. A remote user can trigger a setlease failure and subsequent IDR walker access to dereference a dangling pointer to cause a denial of service.
The issue occurs because a published stateid remains referenced in the IDR after the associated memory is freed, and a related destructor path may access uninitialized delayed work on the same failure path.
356) Improper Initialization (CVE-ID: CVE-2026-53398)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper initialization in nfsd4_decode_secinfo_no_name() when processing a truncated XDR stream for the SECINFO_NO_NAME operation. A remote attacker can send a specially crafted request to cause a denial of service.
The issue occurs because stale union contents from a previous operation can leave sin_exp non-NULL, leading the error cleanup path to call exp_put() on an invalid value.
357) Use-after-free (CVE-ID: CVE-2026-53384)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a use-after-free in the 8250_dw serial driver when handling a failed clock notifier registration during device probe. A local user can trigger the error path and access the stale port slot to cause a denial of service or execute arbitrary code.
The issue occurs because the 8250 port remains registered after probe failure while its associated driver data has already been freed.
358) Race condition (CVE-ID: CVE-2026-53368)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause file system inconsistency.
The vulnerability exists due to a race condition in f2fs nat_entry flag handling in fs/f2fs/node.c when syncing files and writing checkpoints concurrently. A local user can trigger file write, fsync, and checkpoint activity to cause file system inconsistency.
The issue can leave an inode marked with DENT_BIT_SHIFT after it has already been checkpointed, which may be detected by fsck.
359) Race condition (CVE-ID: CVE-2026-53361)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in unix_gc() and unix_peek_fpl() in the af_unix garbage collection logic when processing MSG_PEEK operations during garbage collection scheduling. A local user can trigger concurrent garbage collection activity to cause a denial of service.
The issue occurs because gc_in_progress may be false while unix_gc() is running, which can confuse garbage collection by MSG_PEEK.
360) Improper locking (CVE-ID: CVE-2026-53358)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in l2cap_sock_cleanup_listen() when cleaning up listening L2CAP channels. A local user can trigger a race condition to cause a denial of service.
The issue involves incorrect lock ordering between conn->lock, chan->lock, and sk_lock during Bluetooth L2CAP channel cleanup.
361) Use-after-free (CVE-ID: CVE-2026-53357)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in l2cap_sock_cleanup_listen() and bt_accept_dequeue() in the Bluetooth L2CAP socket handling code when racing listen socket cleanup with a concurrent HCI disconnect. A local user can trigger a listen/close versus HCI-disconnect race to cause a denial of service.
The issue occurs during cleanup of not-yet-accepted child sockets on a listening socket.
362) Use-after-free (CVE-ID: CVE-2026-53355)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the rds ib connection teardown path when unwinding a failed queue pair setup. A local user can trigger a setup failure after allocating the send ring to cause a denial of service.
The issue occurs when rds_ib_setup_qp() fails after allocating i_sends but before allocating i_recvs, leaving a stale pointer that may be treated as a live allocation during a later shutdown pass.
363) Race condition (CVE-ID: CVE-2026-53354)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in broadcast TLBI completion handling in the arm64 CPU errata logic when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger memory management activity to cause a denial of service.
The issue affects completion of memory accesses translated by an invalidated TLB entry, while TLB invalidation itself still occurs correctly.
364) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53284)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in btrfs_write_and_wait_transaction() and the dirty_pages io tree when handling failed transaction writeback. A remote attacker can trigger write errors that cause dirty extent buffer records to be released prematurely to cause a denial of service.
The issue can leave dirty extent buffers uncleared during transaction cleanup and trigger warnings during filesystem unmount.
365) Use-after-free (CVE-ID: CVE-2026-53281)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a NULL pointer dereference and use-after-free in the Intel VT-d IOMMU PASID teardown logic when detaching a domain that was not attached to the IOMMU or when a PASID entry is not found. A local user can trigger teardown operations on an invalid or missing PASID association to cause a denial of service or execute arbitrary code.
The issue can also corrupt reference counts, which may prematurely drop a shared domain reference to zero for remaining active devices.
366) Use-after-free (CVE-ID: CVE-2026-53275)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in __mld_query_work in net/ipv6/mcast.c when processing crafted MLD queries. A remote attacker can send a specially crafted MLD query packet to cause a denial of service.
The issue occurs because a pointer to the multicast group address is dereferenced after skb header reallocation following pskb_may_pull() calls.
367) Use-after-free (CVE-ID: CVE-2026-53273)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the optee supplicant request handling in drivers/tee/optee/supp.c when a client exits before the supplicant finishes processing its request. A local user can trigger a race condition to cause a denial of service.
The issue occurs because the request can be freed by the client while its request ID remains referenced on the supplicant path.
368) Use-after-free (CVE-ID: CVE-2026-53270)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to a use-after-free in the IPVS scheduler handling in ip_vs_edit_service() when editing a service and unbinding the old scheduler. A local privileged user can trigger service reconfiguration while packets are being scheduled to cause a denial of service.
The issue occurs because packets may continue using the old scheduler after its scheduling data has been freed following an RCU grace period.
369) Race condition (CVE-ID: CVE-2026-53269)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the synproxy hook reference counting logic in netfilter when concurrently adding the first iptables target or nftables expression. A local user can trigger concurrent registration or teardown operations to cause a denial of service.
The issue affects on-demand netfilter hook registration performed by the SYNPROXY infrastructure from both iptables and nftables frontends.
370) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53266) Exploited
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper memory handling in the ebtables SNAT target ARP sender hardware address rewrite in net/bridge/netfilter/ebt_snat.c when processing ARP packets in bridge netfilter hooks. A local user can trigger ARP sender hardware address rewriting on a crafted nonlinear skb to cause a denial of service.
Exploitation requires the ARP sender hardware address rewrite path to be reached with a nonlinear skb fragment backed by a splice-imported file page.
371) Use-after-free (CVE-ID: CVE-2026-53264)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the net/sched action lifecycle handling in act_api when NEWTFILTER and DELFILTER are run concurrently. A local user can trigger concurrent filter operations to cause a denial of service.
The issue arises from a race between action lookup and action deletion under RCU-protected access.
372) Use-after-free (CVE-ID: CVE-2026-53262)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to use-after-free in pppol2tp_ioctl() when processing ioctl requests while a concurrent socket close frees the associated l2tp_session after a controllable sleep during copy_from_user(). A local user can trigger a userfaultfd-assisted page fault sleep and race a socket close to dereference a stale session pointer to cause a denial of service or execute arbitrary code.
Exploitation requires local access to issue the ioctl and induce the race condition.
373) Use-after-free (CVE-ID: CVE-2026-53256)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in rfcomm_connect_ind() and rfcomm_get_sock_by_channel() when handling RFCOMM connection indications for a listener socket during a concurrent close. A remote attacker can trigger a race condition to cause a denial of service.
The issue occurs in the Linux kernel Bluetooth RFCOMM socket handling path when a listener socket is closed while a child socket is being queued, and KASAN reported the resulting slab-use-after-free in lock_sock_nested().
374) Out-of-bounds read (CVE-ID: CVE-2026-53254)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the Bluetooth RFCOMM MCC handlers when processing truncated MCC frames from a remote Bluetooth device. A remote attacker can send specially crafted truncated MCC frames to cause a denial of service.
The issue affects the RFCOMM MCC handling paths including rfcomm_recv_mcc(), rfcomm_recv_pn(), rfcomm_recv_rpn(), rfcomm_recv_rls(), and rfcomm_recv_msc().
375) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-53250)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause out-of-bounds memory access.
The vulnerability exists due to a time-of-check time-of-use race condition in xsk_skb_metadata() when processing transmit metadata from a userspace-writable UMEM buffer. A local user can race to overwrite csum_start and csum_offset between validation and assignment to cause out-of-bounds memory access.
The issue occurs during checksum computation in the transmit path.
376) Use-after-free (CVE-ID: CVE-2026-53239)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in xfrm_policy_bysel_ctx() and inexact bin handling in the xfrm policy subsystem when processing concurrent policy deletion and hash rebuild operations. A local user can trigger a race condition to cause a denial of service.
The issue occurs because an inexact bin may be freed during a window after the policy lock is released and before pruning is performed.
377) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53232)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the phy probing logic for the sfp upstream handling when probe failure paths are processed. A local user can trigger phy probing failure and subsequent SFP events to cause a denial of service.
The issue can leave a dangling upstream reference on the sfp-bus that may later be used during SFP events.
378) Out-of-bounds read (CVE-ID: CVE-2026-53230)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in mlx5_query_nic_vport_mac_list when querying a VF vport MAC list with a larger configured maximum than the PF capability-based buffer size. A local user can configure or trigger processing of a VF vport with a larger MAC list to cause a denial of service.
The issue occurs in the mlx5 driver while handling vport address list updates.
379) Improper input validation (CVE-ID: CVE-2026-53221)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause traffic to be associated with the wrong tunnel.
The vulnerability exists due to improper input validation in vti6_tnl_lookup() when matching IPv6 VTI tunnels during fallback wildcard tunnel searches. A remote attacker can send network traffic that triggers a hash collision and incorrect tunnel selection to cause traffic to be associated with the wrong tunnel.
The issue occurs because candidate tunnels in the fallback search were not verified to actually use wildcard local or remote addresses.
380) Out-of-bounds read (CVE-ID: CVE-2026-53217)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to disclose sensitive information.
The vulnerability exists due to improper memory synchronization in mvpp2_rx() in the mvpp2 network driver when processing received packets on non-coherent DMA systems. A local attacker can send network traffic that triggers reception of a crafted frame to disclose sensitive information.
Only non-coherent DMA systems are affected.
381) Out-of-bounds write (CVE-ID: CVE-2026-53216)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt memory or cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the mvpp2 XDP receive path when processing packets with XDP tail adjustment on short RX buffers. A local user can trigger bpf_xdp_adjust_tail() on a packet to corrupt memory or cause a denial of service.
The issue occurs because the XDP frame size is initialized larger than the actual backing buffer size for short BM pool buffers.
382) Use-after-free (CVE-ID: CVE-2026-53198)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in smb2_cancel in ksmbd when handling a second SMB2_CANCEL for the same AsyncId after cancellation of a deferred byte-range lock. A remote user can send specially crafted SMB2_CANCEL requests to cause a denial of service.
Exploitation requires authentication to the SMB service and involves a deferred SMB2_LOCK request that blocks.
383) Heap-based buffer overflow (CVE-ID: CVE-2026-53196)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in get_manuf_info() in the io_ti USB serial driver when processing a crafted USB device EEPROM descriptor. An attacker with physical access can connect a malicious USB device with a forged Size field to trigger the overflow and cause a denial of service or execute arbitrary code.
The out-of-bounds access is compounded because a checksum routine also iterates over the device-controlled length after the EEPROM data is read.
384) Out-of-bounds read (CVE-ID: CVE-2026-53186)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in srp_process_rsp() when processing a crafted SRP_RSP response from an SRP target. A remote user can send a specially crafted SRP_RSP with SRP_RSP_FLAG_SNSVALID set and a large resp_data_len value to cause a denial of service.
Exploitation requires that the initiator is logged into a malicious or compromised SRP target on the InfiniBand or RoCE fabric.
385) Use-after-free (CVE-ID: CVE-2026-53185)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in zram_bvec_write_partial() when processing partial writes for ZRAM_WB slots. A local user can trigger an asynchronous backing device read and subsequent access to a freed page to cause a denial of service.
The issue occurs because the read operation may still be in flight when the buffer page is freed.
386) Resource exhaustion (CVE-ID: CVE-2026-53183)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in MPTCP DSS option handling in net/mptcp/options.c when processing incoming MPTCP traffic with out-of-order data in the MPTCP sequence space or data landing in the backlog. A remote attacker can send traffic that triggers artificial inflation of the MPTCP receive window to cause a denial of service.
The issue can allow incoming traffic to exceed the receiver rcvbuf size even when the sender is not misbehaving.
387) Improper input validation (CVE-ID: CVE-2026-53182)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in nl80211_parse_rnr_elems() when parsing nested NL80211_ATTR_EMA_RNR_ELEMS input. A local user can send a specially crafted nl80211 message to cause a denial of service.
The issue is related to the element count being stored in a u8-backed cfg80211_rnr_elems::cnt field and incremented past its supported limit.
388) Integer underflow (CVE-ID: CVE-2026-53159)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt a DMA address.
The vulnerability exists due to an integer underflow in fastrpc_get_args() when processing a user-provided pointer that falls in a gap before a returned VMA. A local user can supply a crafted pointer value to corrupt a DMA address.
The corrupted DMA address is sent to the DSP.
389) Out-of-bounds write (CVE-ID: CVE-2026-53148)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in tb_xdp_properties_request() in the thunderbolt xdomain handler when processing a crafted XDomain response from a malicious peer. A remote attacker can send a response with a forged length field to cause memory corruption.
390) Integer overflow (CVE-ID: CVE-2026-53133)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer overflow in __rdma_block_iter_next() in the RDMA umem block iterator when reassembling split scatter-gather entries during IOMMU-backed mapping linearization. A local user can trigger processing of a very large mapped block to cause a denial of service.
The issue occurs for block sizes greater than or equal to 4G when a single large block is split across multiple scatter-gather entries.
391) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-53132)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in virtio_transport_inc_rx_pkt() and the virtio vsock receive queue when processing crafted packets with zero-length payloads and the VIRTIO_VSOCK_SEQ_EOM flag. A local user can send a large number of specially crafted packets to cause a denial of service.
The issue occurs because queued packets may not increase the tracked byte count, allowing the receive queue to grow excessively.
392) Improper input validation (CVE-ID: CVE-2026-53131)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in netfilter Ethernet header handling when processing packets that reach ip6t_eui64, xt_mac, ipset bitmap:ip,mac, hash:ip,mac, hash:mac, or nf_log_syslog code paths without a valid Ethernet MAC header. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue occurs because these paths access eth_hdr(skb) after insufficient validation that the skb is associated with an Ethernet device and that a full MAC header is present.
393) Use-after-free (CVE-ID: CVE-2026-53129)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to use-after-free in mb_cache_destroy() and mb_cache_shrink_worker() when destroying an mbcache instance while scheduled shrink work is pending or running. A local privileged user can trigger the last put of a mounted ext2, ext4, or ocfs2 filesystem to cause a denial of service.
The issue is only reachable when the attacker can trigger teardown of the cache for a mounted filesystem.
394) Use-after-free (CVE-ID: CVE-2026-53120)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the pci driver matching logic when probing a driver through __driver_attach__(). A local user can trigger concurrent access to the driver_override field to cause a denial of service.
The issue occurs because the bus match callback accesses driver_override without the device lock held.
395) Use-after-free (CVE-ID: CVE-2026-53118)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the vdpa driver_override handling in the vDPA bus match callback when probing a driver through __driver_attach(). A local user can trigger driver matching while the driver_override field is accessed without the device lock to cause a denial of service.
The issue occurs because the bus match callback is invoked without the device lock held during this code path.
396) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53109)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in pte_frag_destroy when freeing cached page table fragments during process exit. A local user can trigger process exit with a crafted memory state to cause a denial of service.
The issue affects the powerpc page table fragment handling path for hash with 64K page size and can occur in a corner case involving deferred PTE table freeing in parallel with do_exit().
397) Improper input validation (CVE-ID: CVE-2026-53091)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of gso packet headers in qdisc_pkt_len_segs_init() when processing malicious gso packets. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue affects the transmit path for gso packets and malformed packets may be dropped during processing.
398) Improper access control (CVE-ID: CVE-2026-53090)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass BPF verifier checks.
The vulnerability exists due to improper access control in the Linux kernel BPF verifier when analyzing ld_{abs,ind} instructions in subprograms. A local user can load a crafted BPF program to bypass BPF verifier checks.
The issue affects subprograms where ld_{abs,ind} instructions are permitted, including cases involving BTF-annotated subprograms with scalar return types.
399) Use-after-free (CVE-ID: CVE-2026-53089)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() when querying info for an offloaded BPF map or program during network namespace destruction. A local user can query crafted offloaded BPF map or program information to cause a denial of service.
The issue occurs because the associated network namespace may be racing with teardown and its reference count may already have reached zero.
400) Out-of-bounds read (CVE-ID: CVE-2026-53078)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in BPF sock_ops context field access handling when accessing ctx fields with the same destination and source register. A local user can trigger the flawed register handling to cause a denial of service.
The issue occurs when the fullsock or locked_tcp_sock check is false, causing a stale ctx pointer to be retained and used as a bogus socket pointer.
401) Out-of-bounds read (CVE-ID: CVE-2026-53078)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in BPF sock_ops context field access handling when accessing ctx fields with the same destination and source register. A local user can trigger the flawed register handling to disclose sensitive information.
The issue occurs when the fullsock or locked_tcp_sock check is false, causing a stale ctx pointer to be retained.
402) Race condition (CVE-ID: CVE-2026-53070)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in SCTP over UDP transmission handling in net/sctp/ipv6.c and net/sctp/protocol.c when transmitting SCTP packets over UDP. A local user can trigger SCTP over UDP traffic to cause a denial of service.
Exploitation requires SCTP over UDP to be enabled.
403) Improper access control (CVE-ID: CVE-2026-53053)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access of device identifier data in clone_alias() in the AMD IOMMU subsystem when processing PCI DMA aliases. A local user can trigger alias cloning for a device to cause a denial of service.
Incorrect source device identifiers can cause wrong or stale device table entries to be propagated to an alias device.
404) Use-after-free (CVE-ID: CVE-2026-53025)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the greybus raw character device handling in drivers/staging/greybus/raw.c when closing an opened character device after the associated raw bundle has been disconnected. A local user can keep the character device open and then close it after disconnect to cause a denial of service.
Exploitation requires that the character device remain opened by an application while the associated raw bundle is disconnected.
405) Use-after-free (CVE-ID: CVE-2026-53024)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the greybus raw character device write handler when writing to the device after disconnect. A local user can write to the chardev after disconnect to cause a denial of service.
The issue can lead to a kernel panic.
406) Double free (CVE-ID: CVE-2026-53009)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in ice_xmit_frame_ring() and tx ring buffer cleanup when handling transmit error paths and interface shutdown. A local user can trigger transmit checksum or tso failure conditions and then bring the interface down to cause a denial of service.
The issue occurs because a tx_buf entry can remain marked as valid and continue to reference an skb that was already freed in the error path.
407) Use-after-free (CVE-ID: CVE-2026-53005)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the AF_UNIX SOCKMAP handling and garbage collection logic when processing socket buffers carrying SCM file descriptor attributes through SOCKMAP. A local user can send crafted AF_UNIX messages with SCM file descriptor attributes through SOCKMAP to cause a denial of service.
The issue arises because redirected socket buffers are not visible to AF_UNIX garbage collection, and user interaction is not required.
408) Use-after-free (CVE-ID: CVE-2026-53000)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in netfilter nat hook operations when dumping active netfilter hooks from userspace or handling partial hook exposure on error paths. A local user can trigger hook inspection while freed hook operation structures are still referenced to cause a denial of service.
The issue affects nat hook registration and unregistration paths, including interaction with the nfnetlink hook dump subsystem.
409) Use-after-free (CVE-ID: CVE-2026-52991)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in pressure_write() in kernel/cgroup/cgroup.c when handling a write to a pressure cgroup file during concurrent cgroup file release. A local user can write crafted pressure data while racing cgroup file release to cause a denial of service.
The issue occurs because the of->priv pointer may be freed concurrently and later dereferenced.
410) Race condition (CVE-ID: CVE-2026-52988)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in nf_tables commit phase hook list handling in netfilter when publishing new hooks while concurrent netlink dump list traversal via rcu is in progress. A local user can trigger concurrent ruleset updates to cause a denial of service.
411) Out-of-bounds read (CVE-ID: CVE-2026-52956)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in __ceph_x_decrypt() when processing a crafted Ceph authentication reply message. A remote attacker can send a specially crafted message frame to cause a denial of service.
The issue can be triggered when the ciphertext is too short to contain a ceph_x_encrypt_header, such as in a FRAME_TAG_AUTH_REPLY_MORE message.
412) NULL pointer dereference (CVE-ID: CVE-2026-52941)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the smc_msg_event tracepoint when processing sendmsg() or recvmsg() on an SMC-D socket with the tracepoint enabled. A local user can trigger socket activity on an SMC-D socket to cause a denial of service.
Exploitation requires the tracepoint to be enabled, and the crash occurs on the first sendmsg() or recvmsg() on an affected SMC-D socket.
413) Integer overflow (CVE-ID: CVE-2026-52934)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt kernel memory.
The vulnerability exists due to an integer overflow leading to an out-of-bounds write in batadv_tvlv_container_ogm_append() and batadv_tvlv_container_list_size() when processing registered TVLV containers. A local user can cause the accumulated TVLV size to exceed U16_MAX and trigger an undersized allocation to corrupt kernel memory.
414) Improper resource shutdown or release (CVE-ID: CVE-2026-52926)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in batman-adv gateway client teardown logic when tearing down and later recreating a mesh. A local user can trigger mesh teardown to cause a denial of service.
The issue leaves stale current gateway state behind across cleanup, which can break a later mesh recreation.
415) NULL pointer dereference (CVE-ID: CVE-2026-52922)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in batadv_dat_forward_data() when forwarding data to DHT candidates. A local attacker can trigger an allocation failure and reach unconditional dereference of a NULL skb pointer to cause a denial of service.
416) Off-by-one (CVE-ID: CVE-2026-52921)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an off-by-one error in the netfilter ipset hash set range iteration logic when processing IPv4 ranges in hash:ip,mark, hash:ip,port, hash:ip,port,ip, and hash:ip,port,net set variants. A local user can supply a crafted range request to cause a denial of service.
A later retry may continue from an unintended position after traversal advances past the end of the requested range.
417) Use-after-free (CVE-ID: CVE-2026-52919)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service and trigger a use-after-free.
The vulnerability exists due to a use-after-free in batadv_tp_sender_shutdown() and batadv_tp_send() in the batman-adv tp_meter component when shutting down the throughput meter sender through multiple paths. A local user can trigger timeout, cancellation, or normal completion paths to cause a denial of service and trigger a use-after-free.
The issue occurs because the sending counter can underflow to a negative value, causing the sender kernel thread to continue running after interface removal.
418) Race condition (CVE-ID: CVE-2026-52918)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in bt_sock_poll() and the Bluetooth accept queue when polling Bluetooth sockets. A local user can trigger concurrent socket teardown and accept queue access to cause a denial of service.
The issue occurs because the accept queue is walked without synchronization while child teardown can unlink a socket and drop its last reference.
419) Uncontrolled Recursion (CVE-ID: CVE-2026-52916)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in batadv_batman_skb_recv() and fragment reassembly handling in the batman-adv fragmentation component when processing nested BATADV_UNICAST_FRAG packets. A remote attacker can send a specially crafted fragmented packet to cause a denial of service.
The issue occurs when a reassembled payload is itself another BATADV_UNICAST_FRAG packet, leading to unbounded kernel stack growth until exhaustion.
420) Out-of-bounds read (CVE-ID: CVE-2026-52915)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in hbh_mt6_check() in net/ipv6/netfilter/ip6t_hbh.c when processing user-supplied rule setup data. A local user can supply an oversized option list to cause a denial of service.
The issue is triggered because the fixed-size opts array stores at most 16 option descriptors.
421) Use-after-free (CVE-ID: CVE-2026-52912)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in nf_queue when reinjecting queued bridge LOCAL_IN packets. A remote attacker can trigger packet queueing and later reinjection to cause a denial of service.
The issue occurs because skb->dev can still reference a freed bridge master device while the packet remains queued.
422) Out-of-bounds read (CVE-ID: CVE-2026-52910)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the reuseport cBPF program handling in sk_reuseport_prog_free() when detaching or replacing a reuseport program while UDP packets are being processed concurrently. A local user can trigger concurrent reuseport program updates and packet transmission to cause a denial of service.
The issue occurs because the classic BPF reuseport program may be freed before RCU readers have completed.
423) Improper access control (CVE-ID: CVE-2026-52909)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to move a fallback tunnel device to another network namespace.
The vulnerability exists due to improper access control in the ip6_vti fallback tunnel device initialization when initializing the per-network-namespace fallback device. A local user can move the ip6_vti0 device to another network namespace to move a fallback tunnel device to another network namespace.
The issue affects the per-netns fallback tunnel device ip6_vti0.
424) Improper access control (CVE-ID: CVE-2026-52908)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain write access to memory regions that were not properly pinned as writable.
The vulnerability exists due to improper access control in RDMA memory region re-registration handling when changing IB_MR_REREG_ACCESS from read-only to read-write. A local user can re-register a memory region with writable access to gain write access to memory regions that were not properly pinned as writable.
The issue occurs when a driver reuses an existing umem during memory region re-registration.
425) Use-after-free (CVE-ID: CVE-2026-46330)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the SMC TCP ULP support in net/smc/af_smc.c when converting an active TCP socket into an SMC socket by modifying open-file VFS structures in place. A local user can trigger the flawed socket conversion to cause a denial of service.
The issue stems from in-place modification of struct file, dentry, and inode objects that are expected to remain immutable for an open file.
426) Race condition (CVE-ID: CVE-2026-46324)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in netfilter nf_tables netlink hooks when concurrent dumpers walk hook lists during hook unregistration. A local user can trigger concurrent netlink operations to cause a denial of service.
427) Improper resource shutdown or release (CVE-ID: CVE-2026-46320)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in tap_get_user_xdp() when processing XDP frames. A local user can send a crafted short frame or trigger skb allocation failure to cause a denial of service.
Each rejected frame in a batch leaks one page-frag chunk.
428) Use of uninitialized resource (CVE-ID: CVE-2026-46315)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to uninitialized memory usage in io_uring IORING_OP_WAITID result handling when copying waitid result data to userspace. A local user can trigger a wait operation that completes without reporting a child event to disclose sensitive information.
The issue occurs because stale bytes from reused io_kiocb command storage may be copied to userspace siginfo when no child event information is written.
429) Use-after-free (CVE-ID: CVE-2026-46275)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the hci_uart line discipline lifecycle management when closing or initializing a Bluetooth HCI UART device. A local user can trigger a hangup or race the close and initialization paths to cause a denial of service.
The issue involves workqueue handling and teardown ordering in the close and initialization error paths.
430) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-46203)
CWE-ID: CWE-668 - Exposure of resource to wrong sphere
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access to hardware registers in cadence-quadspi driver unbind handling when unbinding the driver while the controller is runtime suspended. A local user can trigger driver unbind to cause a denial of service.
431) Race condition (CVE-ID: CVE-2026-46181)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in mlx4_srq_event() when handling RDMA SRQ events. A local user can trigger an event for a partially initialized srq object to cause a denial of service.
The issue can occur if an event is delivered before the srq object has finished initializing.
432) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-46175)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause file system inconsistency.
The vulnerability exists due to improper state management in f2fs node block migration when performing foreground garbage collection of node blocks. A local user can trigger node block migration and subsequent file system checking to cause file system inconsistency.
The issue occurs because dentry and fsync marks are not cleared during foreground garbage collection, which can cause fsck to misinterpret migrated node blocks as fsync-written data.
433) Improper resource shutdown or release (CVE-ID: CVE-2026-46170)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the mptcp path manager ADD_ADDR retransmission timer handling when processing ADD_ADDR retransmissions. A local user can trigger ADD_ADDR retransmissions to cause a system hang.
The issue occurs when the last socket reference is released from the timer handler, leading to an indefinite wait on the same timer.
434) Improper resource shutdown or release (CVE-ID: CVE-2026-46158)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the mptcp path manager ADD_ADDR retransmission handling when retransmitting ADD_ADDR messages. A local user can trigger ADD_ADDR retransmissions to cause a denial of service.
435) Out-of-bounds read (CVE-ID: CVE-2026-46130)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in fec_decode_bufs() in dm-verity-fec when decoding parity bytes split across parity blocks. A local user can trigger the vulnerable code path to disclose sensitive information.
The issue occurs only for certain non-default fec_roots values and when the maximum number of buffers cannot be allocated due to low-memory conditions.
436) Improper access control (CVE-ID: CVE-2026-46054)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass SELinux access controls.
The vulnerability exists due to improper access control in SELinux overlayfs mmap() and mprotect() access checks when handling mmap() and mprotect() operations on overlayfs filesystems. A local user can map or change protections on an overlayfs file to bypass SELinux access controls.
437) Race condition (CVE-ID: CVE-2026-45944)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in the Intel VT-d IOMMU context entry teardown logic when tearing down context entries. A local attacker can trigger use of a torn context entry to cause a denial of service.
The issue arises because the hardware may observe a partially updated 128-bit context entry while the Present bit remains set, resulting in unpredictable behavior or spurious faults.
438) Improper access control (CVE-ID: CVE-2026-45932)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass permission checks.
The vulnerability exists due to improper access control in BPF_PROG_DETACH for tcx or netkit devices when detaching a program without providing a program file descriptor. A local user can invoke the detach operation without the required capability checks to bypass permission checks.
The issue occurs only when no program file descriptor is supplied to the detach operation.
439) Race condition (CVE-ID: CVE-2026-45894)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the Intel VT-d scalable mode PASID table entry handling when tearing down an active PASID entry. A local user can trigger concurrent PASID entry teardown to cause a denial of service.
The issue can lead to unpredictable behavior or spurious faults if the IOMMU hardware observes a torn read of the entry.
440) Improper input validation (CVE-ID: CVE-2026-45850)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ipvs checksum validation when processing IPv6 packets with extension headers. A remote attacker can send specially crafted IPv6 packets to cause a denial of service.
441) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-43464)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the mlx5e RX XDP multi-buffer handling for legacy RQ when processing XDP multi-buf programs that modify the XDP buffer layout. A local user can trigger XDP actions that alter buffer fragments to cause a denial of service.
The issue can lead to a negative page fragment reference count during page release.
442) Race condition (CVE-ID: CVE-2026-43353)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in hci_dma_dequeue_xfer() in the mipi-i3c-hci driver when handling multiple transfer timeouts concurrently. A local user can trigger concurrent timeout conditions to cause a denial of service.
The issue occurs because parallel invocations may stop or restart the DMA ring at unexpected times while processing incomplete transfers.
443) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-43352)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the DMA ring abort handling logic in the mipi-i3c-hci driver when processing DMA dequeue operations. A local user can trigger ring abort handling in an invalid ring state to cause a denial of service.
The issue can occur when the ring is already stopped, and the abort sequence may reset hardware ring pointers and disrupt controller state.
444) Use-after-free (CVE-ID: CVE-2026-43303)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the swap subsystem when handling stale page->private values on reallocated and split pages. A local user can trigger swapoff operations after causing affected page state reuse to cause a denial of service.
The issue occurs because tail pages can retain stale page->private values after split_page(), leading swap_count_continued() to follow an invalid continuation list and access poisoned list entries.
445) NULL pointer dereference (CVE-ID: CVE-2026-43263)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the wave5 decoder IRQ handler when handling concurrent decoder instance creation and destruction. A local user can trigger repeated multi-instance operations to cause a denial of service.
The issue occurs because the shared struct vpu_instance may be accessed after decoder structures are removed during interrupt handling.
446) Out-of-bounds read (CVE-ID: CVE-2026-43213)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds access in the rtw89_pci TX release report handling when processing an abnormal sequence number in a TX release report. A local attacker can trigger an abnormal TX release report to cause a denial of service.
The issue can lead to a kernel NULL pointer dereference.
447) Out-of-bounds read (CVE-ID: CVE-2026-43172)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the SMEM parsing logic when processing firmware-reported LMAC configuration data. A local user can provide crafted firmware data to cause a denial of service.
Exploitation requires the firmware to report three LMACs, a condition that does not exist in hardware.
448) Use-after-free (CVE-ID: CVE-2026-43126)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a use-after-free in the ALSA OSS mixer layer when handling OSS mixer accesses during device disconnection. A local user can trigger concurrent mixer control operations on a disconnecting sound card to cause a denial of service or execute arbitrary code.
The issue arises because pending kcontrol operation calls may not be caught while the device is being disconnected.
449) Use-after-free (CVE-ID: CVE-2026-43116)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in netfilter ctnetlink expectation handling when processing expectation add, delete, get, or event operations. A local user can trigger access to an invalid master conntrack object to cause a denial of service.
450) NULL pointer dereference (CVE-ID: CVE-2026-43101)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in __ioam6_fill_trace_data() when processing ipv6 ioam trace data. A local user can trigger the vulnerable code path to cause a denial of service.
451) Out-of-bounds write (CVE-ID: CVE-2026-43048)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read and out-of-bounds write in hid_report_raw_event() when processing an incoming event buffer that is smaller than the associated report size. A local attacker can provide a crafted HID event buffer to cause a denial of service.
452) Out-of-bounds read (CVE-ID: CVE-2026-43042)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in the mpls forwarding and route dump codepaths when handling concurrent platform label table resizes. A local user can trigger concurrent route operations to cause a denial of service.
The issue arises from an inconsistent view of the platform_labels and platform_label pair during a resize operation.
453) Improper locking (CVE-ID: CVE-2026-43029)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in mptcp_recvmsg() when receiving data with MSG_PEEK and MSG_WAITALL flags. A local user can call recvmsg() with these flags to cause a denial of service.
454) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-43009)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass BPF verifier state tracking.
The vulnerability exists due to improper state management in the BPF verifier backtrack_insn logic when processing BPF atomic fetch instructions. A local user can load a crafted BPF program to bypass BPF verifier state tracking.
The issue occurs because atomic fetch operations are not tracked correctly for precision propagation, which can cause the verifier to incorrectly treat distinct execution states as equivalent and prune branches that should remain separate.
455) Out-of-bounds read (CVE-ID: CVE-2026-31771)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the Bluetooth HCI event handling logic when processing a short HCI event frame. A local attacker can send a specially crafted HCI event frame to cause a denial of service.
The issue occurs because wake reason storage is reached before per-event minimum payload length validation is enforced.
456) Use-after-free (CVE-ID: CVE-2026-31663)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in xfrm_input_resume and transport_finish when processing packets after asynchronous crypto completion. A local user can trigger a race with device teardown to cause a denial of service.
457) Stack-based buffer overflow (CVE-ID: CVE-2026-31630)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in the AF_RXRPC procfs helpers when formatting socket addresses for procfs output with "%pISpc". A local user can trigger address formatting with a specially crafted IPv6 address representation to cause a denial of service.
The issue occurs because the fixed 50-byte stack buffers are too small for the longest current IPv6-with-port textual form, including certain ISATAP address formats.
458) Improper handling of exceptional conditions (CVE-ID: CVE-2026-31568)
CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper exception handling in the s390 secure storage access handling for donated memory when accessing donated memory pages in kernel context. A local user can trigger secure storage access exceptions involving donated memory to cause a denial of service.
459) NULL pointer dereference (CVE-ID: CVE-2026-31560)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in spi-dw-dma error logging when handling an error after a transaction finishes without a current message. A local user can trigger an error condition to cause a denial of service.
460) Use-after-free (CVE-ID: CVE-2026-31493)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use-after-free in admin queue completion handling when processing admin queue completions with an error. A local user can trigger an admin command completion error to disclose sensitive information.
461) Race condition (CVE-ID: CVE-2026-31486)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in pmbus regulator operations when accessing PMBus registers and shared data. A local user can trigger concurrent regulator callbacks and voltage operations to cause a denial of service.
462) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-31479)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the xe virtual memory bind/unwind handling in drm/xe when processing crafted VM bind and rebind operations during 3D workloads. A local user can trigger bind operations that cause overlapping VMA re-insertion and leave the VM in a bad state to cause a denial of service.
The issue can be triggered on the unwind path, including with a vector of binds, when a rebind occurs in the middle of a VMA and compatible mapped ends are skipped.
463) Improper input validation (CVE-ID: CVE-2026-31420)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in br_mrp_start_test(), br_mrp_start_in_test(), and br_mrp_start_in_test_parse() when processing user-supplied netlink attributes. A local user can supply a zero interval value to cause a denial of service.
A zero interval causes delayed work to be rescheduled with no delay, creating a tight loop that allocates and transmits MRP test frames until system memory is exhausted and the kernel panics via OOM deadlock.
464) Race condition (CVE-ID: CVE-2026-23469)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in the drm/imagination GPU driver interrupt handling during runtime power management suspend when suspending the GPU while an IRQ handler is still running on another CPU core. A local attacker can trigger GPU activity that races with runtime suspend to cause a denial of service.
This issue can lead to kernel crashes or a kernel panic when the IRQ handler accesses GPU registers while the GPU is suspended.
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the bridge CFM component when handling peer MEP deletion. A local user can trigger the deletion of a peer MEP, leading to a use-after-free condition if a delayed work item is rescheduled after cancellation but before memory is freed, resulting in a system crash.
The race condition occurs because br_cfm_frame_rx() runs in softirq context under RCU read lock and can re-schedule the delayed work between the cancellation and the memory release.
466) Out-of-bounds read (CVE-ID: CVE-2026-23327)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service, disclose sensitive information, and potentially execute arbitrary code.
The vulnerability exists due to improper input validation in the CXL mailbox command handler when processing user-supplied payloads. A local user can send a specially crafted raw mailbox command with an undersized payload to trigger an out-of-bounds read in the kernel, leading to memory disclosure, system crash, or potential code execution.
The issue specifically occurs in the cxl_payload_from_user_allowed() function, where the payload size is not validated before accessing its contents, resulting in a slab-out-of-bounds read during UUID comparison.
467) Double free (CVE-ID: CVE-2026-23240)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the tls_sw_cancel_work_tx() function in net/tls/tls_sw.c. A local user can perform a denial of service (DoS) attack.
468) Double free (CVE-ID: CVE-2026-23239)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the espintcp_close() function in net/xfrm/espintcp.c. A local user can perform a denial of service (DoS) attack.
469) Out-of-bounds read (CVE-ID: CVE-2026-23208)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the prepare_playback_urb() function in sound/usb/pcm.c. A local user can perform a denial of service (DoS) attack.
470) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2025-71289)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper error handling in attr_set_size() during file truncation when truncating files on ntfs3. A local user can truncate a file in a way that triggers an attr_set_size() failure to cause a denial of service.
The inode may be left in an inconsistent state if the error is ignored.
471) Use-after-free (CVE-ID: CVE-2025-71202)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the kernel_pgtable_work_func() function in mm/pgtable-generic.c. A local user can escalate privileges on the system.
472) Use-after-free (CVE-ID: CVE-2025-71074)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ffs_ep0_read(), ffs_epfile_io(), ffs_dmabuf_put() and ffs_epfiles_create() functions in drivers/usb/gadget/function/f_fs.c. A local user can escalate privileges on the system.
473) Use-after-free (CVE-ID: CVE-2025-71073)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the lkkbd_connect() and lkkbd_disconnect() functions in drivers/input/keyboard/lkkbd.c. A local user can escalate privileges on the system.
474) Use-after-free (CVE-ID: CVE-2025-68822)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the alps_disconnect() function in drivers/input/mouse/alps.c. A local user can escalate privileges on the system.
475) Double free (CVE-ID: CVE-2025-68745)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the drivers/scsi/qla2xxx/qla_target.h. A local user can perform a denial of service (DoS) attack.
476) Resource management error (CVE-ID: CVE-2025-68360)
CWE-ID: CWE-399 - Resource Management Errors
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the include/linux/soc/mediatek/mtk_wed.h. A local user can perform a denial of service (DoS) attack.
477) Use-after-free (CVE-ID: CVE-2025-68304)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the sco_disconn_cfm() function in net/bluetooth/sco.c. A local user can escalate privileges on the system.
478) Incorrect calculation (CVE-ID: CVE-2025-68174)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect calculation within the kfd_process_destroy_pdds() and kfd_create_process_device_data() functions in drivers/gpu/drm/amd/amdkfd/kfd_process.c. A local user can perform a denial of service (DoS) attack.
479) NULL pointer dereference (CVE-ID: CVE-2025-40354)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the drivers/gpu/drm/amd/display/dc/inc/hw/hw_shared.h. A local user can perform a denial of service (DoS) attack.
480) Use-after-free (CVE-ID: CVE-2025-40344)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the avs_dai_fe_shutdown() function in sound/soc/intel/avs/pcm.c. A local user can escalate privileges on the system.
481) Use-after-free (CVE-ID: CVE-2025-40274)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the kvm_gmem_bind() function in virt/kvm/guest_memfd.c. A local user can escalate privileges on the system.
482) Input validation error (CVE-ID: CVE-2025-40203)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the SYSCALL_DEFINE4() and do_listmount() functions in fs/namespace.c. A local user can perform a denial of service (DoS) attack.
483) Input validation error (CVE-ID: CVE-2025-40170)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the sk_clone_lock(), sk_dst_gso_max_size() and sk_setup_caps() functions in net/core/sock.c. A local user can perform a denial of service (DoS) attack.
484) Use-after-free (CVE-ID: CVE-2025-40168)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the smc_clc_prfx_match6_rcu() function in net/smc/smc_clc.c. A local user can escalate privileges on the system.
485) Use-after-free (CVE-ID: CVE-2025-40158)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ip6_finish_output2() and ip6_finish_output() functions in net/ipv6/ip6_output.c. A local user can escalate privileges on the system.
486) Use-after-free (CVE-ID: CVE-2025-40139)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the smc_clc_msg_hdr_valid(), smc_clc_prfx_set4_rcu() and smc_clc_prfx_set() functions in net/smc/smc_clc.c. A local user can escalate privileges on the system.
487) Improper locking (CVE-ID: CVE-2025-40075)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the tcpm_new(), __tcp_get_metrics_req() and tcp_get_metrics() functions in net/ipv4/tcp_metrics.c. A local user can perform a denial of service (DoS) attack.
488) Use-after-free (CVE-ID: CVE-2025-40074)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ipv4_neigh_lookup() function in net/ipv4/route.c. A local user can escalate privileges on the system.
489) Use-after-free (CVE-ID: CVE-2025-40064)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the smc_pnet_find_ism_by_pnetid() function in net/smc/smc_pnet.c. A local user can escalate privileges on the system.
490) Use-after-free (CVE-ID: CVE-2025-40054)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the f2fs_merge_page_bio() function in fs/f2fs/data.c. A local user can escalate privileges on the system.
491) Improper error handling (CVE-ID: CVE-2025-40040)
CWE-ID: CWE-388 - Error Handling
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the rust/bindings/bindings_helper.h. A local user can perform a denial of service (DoS) attack.
492) Input validation error (CVE-ID: CVE-2025-40025)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the check_index_in_prev_nodes() function in fs/f2fs/recovery.c. A local user can perform a denial of service (DoS) attack.
493) NULL pointer dereference (CVE-ID: CVE-2025-39990)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the get_helper_proto() function in kernel/bpf/verifier.c. A local user can perform a denial of service (DoS) attack.
494) Improper resource shutdown or release (CVE-ID: CVE-2025-39958)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to properly release resources within the get_iota_region_flag(), s390_iommu_attach_device() and s390_attach_dev_identity() functions in drivers/iommu/s390-iommu.c. A local user can perform a denial of service (DoS) attack.
495) Input validation error (CVE-ID: CVE-2025-39933)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the recv_done() function in fs/smb/client/smbdirect.c. A local user can perform a denial of service (DoS) attack.
496) Use-after-free (CVE-ID: CVE-2025-39896)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the drivers/accel/ivpu/ivpu_pm.h. A local user can escalate privileges on the system.
497) Buffer overflow (CVE-ID: CVE-2025-39862)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the mt7915_mac_full_reset() function in drivers/net/wireless/mediatek/mt76/mt7915/mac.c. A local user can perform a denial of service (DoS) attack.
498) Use-after-free (CVE-ID: CVE-2025-39859)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ptp_ocp_detach() function in drivers/ptp/ptp_ocp.c. A local user can escalate privileges on the system.
499) Improper error handling (CVE-ID: CVE-2025-39789)
CWE-ID: CWE-388 - Error Handling
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the crypto_aegis128_aesni_process_ad(), crypto_aegis128_aesni_process_crypt(), crypto_aegis128_aesni_setauthsize(), crypto_aegis128_aesni_crypt(), crypto_aegis128_aesni_encrypt() and crypto_aegis128_aesni_decrypt() functions in arch/x86/crypto/aegis128-aesni-glue.c. A local user can perform a denial of service (DoS) attack.
500) Integer underflow (CVE-ID: CVE-2025-39677)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to integer underflow within the pie_change() function in net/sched/sch_pie.c, within the hhf_change() function in net/sched/sch_hhf.c, within the fq_pie_change() function in net/sched/sch_fq_pie.c, within the fq_codel_change() function in net/sched/sch_fq_codel.c, within the fq_load_priomap() and fq_change() functions in net/sched/sch_fq.c, within the codel_change() function in net/sched/sch_codel.c. A local user can execute arbitrary code.
501) Race condition (CVE-ID: CVE-2025-38717)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition within the psock_write_space() and kcm_release() functions in net/kcm/kcmsock.c. A local user can escalate privileges on the system.
502) Out-of-bounds read (CVE-ID: CVE-2025-38636)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the kernel/trace/rv/rv_trace.h. A local user can perform a denial of service (DoS) attack.
503) Memory leak (CVE-ID: CVE-2025-38565)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the mutex_unlock() and vm_flags_set() functions in kernel/events/core.c. A local user can perform a denial of service (DoS) attack.
504) Memory leak (CVE-ID: CVE-2025-38563)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the perf_mmap_pfn_mkwrite() function in kernel/events/core.c. A local user can perform a denial of service (DoS) attack.
505) Improper privilege management (CVE-ID: CVE-2025-38498)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to read and manipulate data.
The vulnerability exists due to improperly imposed permissions within the do_change_type() function in fs/namespace.c. A local user can read and manipulate data.
506) Improper locking (CVE-ID: CVE-2025-38242)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the move_swap_pte() function in mm/userfaultfd.c. A local user can perform a denial of service (DoS) attack.
507) Double free (CVE-ID: CVE-2025-38206)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the exfat_free_upcase_table() function in fs/exfat/nls.c. A local user can perform a denial of service (DoS) attack.
508) Out-of-bounds read (CVE-ID: CVE-2025-38204)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the dtInitRoot() and add_missing_indices() functions in fs/jfs/jfs_dtree.c. A local user can perform a denial of service (DoS) attack.
509) Use-after-free (CVE-ID: CVE-2025-38187)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the r535_gsp_rpc_push() function in drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/rpc.c. A local user can escalate privileges on the system.
510) Use-after-free (CVE-ID: CVE-2025-38069)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the pci_epf_test_set_bar() and pci_epf_test_free_space() functions in drivers/pci/endpoint/functions/pci-epf-test.c. A local user can escalate privileges on the system.
511) Resource management error (CVE-ID: CVE-2025-38064)
CWE-ID: CWE-399 - Resource Management Errors
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the virtio_irq_get_affinity() and __register_virtio_driver() functions in drivers/virtio/virtio.c. A local user can perform a denial of service (DoS) attack.
512) Race condition (CVE-ID: CVE-2025-37906)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition within the ublk_start_cancel(), ublk_uring_cmd_cancel_fn() and ublk_cancel_queue() functions in drivers/block/ublk_drv.c. A local user can escalate privileges on the system.
513) Improper error handling (CVE-ID: CVE-2025-37876)
CWE-ID: CWE-388 - Error Handling
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the netfs_init() function in fs/netfs/main.c. A local user can perform a denial of service (DoS) attack.
514) Use-after-free (CVE-ID: CVE-2025-37776)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the free_opinfo(), opinfo_get_list(), opinfo_put(), opinfo_add(), opinfo_del() and smb_break_all_levII_oplock() functions in fs/smb/server/oplock.c. A local user can escalate privileges on the system.
515) Improper locking (CVE-ID: CVE-2025-23132)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the f2fs_sync_fs(), f2fs_remount(), limit_reserve_root(), f2fs_quota_sync(), f2fs_quota_on(), __f2fs_quota_off(), f2fs_quota_off(), f2fs_dquot_initialize(), f2fs_update_time() and kill_f2fs_super() functions in fs/f2fs/super.c, within the block_operations(), f2fs_unlock_all() and f2fs_issue_checkpoint() functions in fs/f2fs/checkpoint.c. A local user can perform a denial of service (DoS) attack.
516) Memory leak (CVE-ID: CVE-2025-22109)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the ax25_get_route() function in net/ax25/ax25_route.c, within the ax25_connect() function in net/ax25/af_ax25.c. A local user can perform a denial of service (DoS) attack.
517) Input validation error (CVE-ID: CVE-2025-22108)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the bnxt_xmit_bd() function in drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c, within the bnxt_start_xmit() and dma_unmap_addr_set() functions in drivers/net/ethernet/broadcom/bnxt/bnxt.c. A local user can perform a denial of service (DoS) attack.
518) Out-of-bounds read (CVE-ID: CVE-2025-22104)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the vnic_add_client_data(), send_login(), handle_query_ip_offload_rsp() and handle_login_rsp() functions in drivers/net/ethernet/ibm/ibmvnic.c. A local user can perform a denial of service (DoS) attack.
519) Out-of-bounds read (CVE-ID: CVE-2025-21985)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the populate_dml_output_cfg_from_stream_state() and map_dc_state_into_dml_display_cfg() functions in drivers/gpu/drm/amd/display/dc/dml2/dml2_translation_helper.c, within the dml21_map_dc_state_into_dml_display_cfg() function in drivers/gpu/drm/amd/display/dc/dml2/dml21/dml21_translation_helper.c. A local user can perform a denial of service (DoS) attack.
520) Improper error handling (CVE-ID: CVE-2025-21984)
CWE-ID: CWE-388 - Error Handling
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the validate_dst_vma(), move_swap_pte(), move_pages_pte() and pte_to_swp_entry() functions in mm/userfaultfd.c. A local user can perform a denial of service (DoS) attack.
521) Use-after-free (CVE-ID: CVE-2025-21693)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the zswap_pool_create(), zswap_cpu_comp_prepare(), zswap_cpu_comp_dead(), zswap_compress() and zswap_decompress() functions in mm/zswap.c. A local user can escalate privileges on the system.
522) Incorrect calculation (CVE-ID: CVE-2025-21687)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect calculation within the vfio_platform_read_mmio() and vfio_platform_write_mmio() functions in drivers/vfio/platform/vfio_platform_common.c. A local user can perform a denial of service (DoS) attack.
523) Input validation error (CVE-ID: CVE-2024-58241)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the hci_dev_close_sync() function in net/bluetooth/hci_sync.c. A local user can perform a denial of service (DoS) attack.
524) Resource management error (CVE-ID: CVE-2024-58100)
CWE-ID: CWE-399 - Resource Management Errors
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the kvfree(), jit_subprogs(), bpf_check_attach_target() and bpf_check() functions in kernel/bpf/verifier.c. A local user can perform a denial of service (DoS) attack.
525) Resource management error (CVE-ID: CVE-2024-58098)
CWE-ID: CWE-399 - Resource Management Errors
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the check_func_call(), mark_subprog_changes_pkt_data(), visit_func_call_insn() and visit_insn() functions in kernel/bpf/verifier.c. A local user can perform a denial of service (DoS) attack.
526) Input validation error (CVE-ID: CVE-2024-58094)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the jfs_truncate_nolock() function in fs/jfs/inode.c. A local user can perform a denial of service (DoS) attack.
527) NULL pointer dereference (CVE-ID: CVE-2024-58089)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the btrfs_run_delalloc_range() function in fs/btrfs/inode.c, within the find_next_delalloc_bitmap(), writepage_delalloc() and extent_writepage() functions in fs/btrfs/extent_io.c. A local user can perform a denial of service (DoS) attack.
528) Use-after-free (CVE-ID: CVE-2024-57857)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the siw_query_device(), siw_query_port() and siw_query_qp() functions in drivers/infiniband/sw/siw/siw_verbs.c, within the siw_device_create(), siw_netdev_event() and siw_newlink() functions in drivers/infiniband/sw/siw/siw_main.c, within the siw_create_listen() and siw_cep_set_free_and_put() functions in drivers/infiniband/sw/siw/siw_cm.c. A local user can escalate privileges on the system.
529) Input validation error (CVE-ID: CVE-2024-56591)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the hci_conn_del() function in net/bluetooth/hci_conn.c. A local user can perform a denial of service (DoS) attack.
530) Improper locking (CVE-ID: CVE-2024-56552)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the handle_sched_done() function in drivers/gpu/drm/xe/xe_guc_submit.c. A local user can perform a denial of service (DoS) attack.
531) Buffer overflow (CVE-ID: CVE-2024-53098)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the user_fence_create() function in drivers/gpu/drm/xe/xe_sync.c. A local user can perform a denial of service (DoS) attack.
532) Input validation error (CVE-ID: CVE-2024-52560)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the compare_attr(), mi_new_attt_id(), mi_enum_attr(), mi_format_new() and mi_insert_attr() functions in fs/ntfs3/record.c, within the ni_std(), ni_std5(), ni_find_attr(), ni_enum_attr_ex(), ni_load_attr(), ni_remove_attr(), al_remove_le(), ni_ins_new_attr(), ni_try_remove_attr_list(), ni_create_attr_list(), ni_ins_attr_ext(), ni_insert_attr(), ni_expand_mft_list(), ni_expand_list() and ni_write_inode() functions in fs/ntfs3/frecord.c, within the mi_find_attr() and attr_collapse_range() functions in fs/ntfs3/attrib.c. A local user can perform a denial of service (DoS) attack.
533) Use-after-free (CVE-ID: CVE-2024-50217)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the btrfs_close_one_device() function in fs/btrfs/volumes.c. A local user can escalate privileges on the system.
534) Use-after-free (CVE-ID: CVE-2024-50106)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the destroy_delegation(), nfsd4_revoke_states(), nfs4_laundromat(), nfsd4_free_stateid() and nfsd4_delegreturn() functions in fs/nfsd/nfs4state.c. A local user can escalate privileges on the system.
535) NULL pointer dereference (CVE-ID: CVE-2024-49940)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the pppol2tp_session_setsockopt() function in net/l2tp/l2tp_ppp.c, within the l2tp_nl_cmd_session_modify() function in net/l2tp/l2tp_netlink.c, within the l2tp_v3_session_get(), l2tp_session_register(), l2tp_recv_common(), EXPORT_SYMBOL_GPL(), l2tp_session_set_header_len() and l2tp_session_create() functions in net/l2tp/l2tp_core.c. A local user can perform a denial of service (DoS) attack.
536) Reachable assertion (CVE-ID: CVE-2024-49932)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to reachable assertion within the relocate_one_folio() function in fs/btrfs/relocation.c. A local user can perform a denial of service (DoS) attack.
537) Memory leak (CVE-ID: CVE-2024-44964)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the idpf_rx_init_buf_tail(), idpf_vport_open(), idpf_init_task(), idpf_initiate_soft_reset() and idpf_open() functions in drivers/net/ethernet/intel/idpf/idpf_lib.c. A local user can perform a denial of service (DoS) attack.
538) Use-after-free (CVE-ID: CVE-2024-44932)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the idpf_vport_intr_napi_dis_all() and idpf_vport_intr_rel() functions in drivers/net/ethernet/intel/idpf/idpf_txrx.c, within the idpf_vport_stop(), idpf_vport_open() and idpf_send_map_unmap_queue_vector_msg() functions in drivers/net/ethernet/intel/idpf/idpf_lib.c. A local user can escalate privileges on the system.
539) Improper locking (CVE-ID: CVE-2024-43872)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the next_ceqe_sw_v2(), hns_roce_v2_msix_interrupt_eq(), hns_roce_ceq_work(), __hns_roce_request_irq() and __hns_roce_free_irq() functions in drivers/infiniband/hw/hns/hns_roce_hw_v2.c. A local user can perform a denial of service (DoS) attack.
540) Improper error handling (CVE-ID: CVE-2024-41008)
CWE-ID: CWE-388 - Error Handling
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the kfd_smi_event_update_thermal_throttling() function in drivers/gpu/drm/amd/amdkfd/kfd_smi_events.c, within the sdma_v4_4_2_print_iv_entry() function in drivers/gpu/drm/amd/amdgpu/sdma_v4_4_2.c, within the sdma_v4_0_print_iv_entry() function in drivers/gpu/drm/amd/amdgpu/sdma_v4_0.c, within the gmc_v9_0_process_interrupt() function in drivers/gpu/drm/amd/amdgpu/gmc_v9_0.c, within the gmc_v8_0_process_interrupt() function in drivers/gpu/drm/amd/amdgpu/gmc_v8_0.c, within the gmc_v11_0_process_interrupt() function in drivers/gpu/drm/amd/amdgpu/gmc_v11_0.c, within the gmc_v10_0_process_interrupt() function in drivers/gpu/drm/amd/amdgpu/gmc_v10_0.c, within the amdgpu_vm_ptes_update() function in drivers/gpu/drm/amd/amdgpu/amdgpu_vm_pt.c, within the amdgpu_vm_validate(), amdgpu_vm_wait_idle(), amdgpu_vm_init(), amdgpu_vm_fini() and amdgpu_vm_ioctl() functions in drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c, within the amdgpu_coredump() function in drivers/gpu/drm/amd/amdgpu/amdgpu_reset.c, within the amdgpu_job_timedout() function in drivers/gpu/drm/amd/amdgpu/amdgpu_job.c, within the amdgpu_gem_object_open() function in drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c, within the amdgpu_debugfs_vm_info_show() function in drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c. A local user can perform a denial of service (DoS) attack.
541) Input validation error (CVE-ID: CVE-2024-35948)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the bch2_sb_clean_validate_late() function in fs/bcachefs/sb-clean.c. A local user can perform a denial of service (DoS) attack.
542) Numeric Truncation Error (CVE-ID: CVE-2024-14040)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause incorrect nexthop group behavior.
The vulnerability exists due to an integer truncation issue in the nexthop group weight handling in the Linux kernel when processing nexthop group configuration. A local user can supply specially crafted weight values to cause incorrect nexthop group behavior.
The issue arises in environments using large ECMP weight ratios that exceed 8-bit weight representation.
Remediation
Install update from vendor's website.