SB2026100410 - Debian update for linux



SB2026100410 - Debian update for linux

Published: October 4, 2026

Security Bulletin ID SB2026100410
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1332
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 3% Medium 9% Low 88%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1332 vulnerabilities.


1) Input validation error (CVE-ID: CVE-2024-52560)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the compare_attr(), mi_new_attt_id(), mi_enum_attr(), mi_format_new() and mi_insert_attr() functions in fs/ntfs3/record.c, within the ni_std(), ni_std5(), ni_find_attr(), ni_enum_attr_ex(), ni_load_attr(), ni_remove_attr(), al_remove_le(), ni_ins_new_attr(), ni_try_remove_attr_list(), ni_create_attr_list(), ni_ins_attr_ext(), ni_insert_attr(), ni_expand_mft_list(), ni_expand_list() and ni_write_inode() functions in fs/ntfs3/frecord.c, within the mi_find_attr() and attr_collapse_range() functions in fs/ntfs3/attrib.c. A local user can perform a denial of service (DoS) attack.


2) Input validation error (CVE-ID: CVE-2024-58094)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the jfs_truncate_nolock() function in fs/jfs/inode.c. A local user can perform a denial of service (DoS) attack.


3) Input validation error (CVE-ID: CVE-2024-58095)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the extAlloc() and extRecord() functions in fs/jfs/jfs_extent.c. A local user can perform a denial of service (DoS) attack.


4) Use-after-free (CVE-ID: CVE-2025-21817)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the queue_attr_store() function in block/blk-sysfs.c. A local user can escalate privileges on the system.


5) Out-of-bounds read (CVE-ID: CVE-2025-22104)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the vnic_add_client_data(), send_login(), handle_query_ip_offload_rsp() and handle_login_rsp() functions in drivers/net/ethernet/ibm/ibmvnic.c. A local user can perform a denial of service (DoS) attack.


6) Input validation error (CVE-ID: CVE-2025-22108)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the bnxt_xmit_bd() function in drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c, within the bnxt_start_xmit() and dma_unmap_addr_set() functions in drivers/net/ethernet/broadcom/bnxt/bnxt.c. A local user can perform a denial of service (DoS) attack.


7) Improper locking (CVE-ID: CVE-2025-22127)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the f2fs_read_multi_pages() function in fs/f2fs/data.c, within the f2fs_compress_ctx_add_page() function in fs/f2fs/compress.c. A local user can perform a denial of service (DoS) attack.


8) NULL pointer dereference (CVE-ID: CVE-2025-38203)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the jfs_ioc_trim() function in fs/jfs/jfs_discard.c. A local user can perform a denial of service (DoS) attack.


9) Division by zero (CVE-ID: CVE-2025-38205)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a division by zero error within the populate_dummy_dml_surface_cfg() function in drivers/gpu/drm/amd/display/dc/dml2/dml2_translation_helper.c. A local user can perform a denial of service (DoS) attack.


10) Double free (CVE-ID: CVE-2025-38206)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a double free error within the exfat_free_upcase_table() function in fs/exfat/nls.c. A local user can perform a denial of service (DoS) attack.


11) Improper locking (CVE-ID: CVE-2025-38237)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the fimc_is_hw_change_mode() function in drivers/media/platform/samsung/exynos4-is/fimc-is-regs.c. A local user can perform a denial of service (DoS) attack.


12) NULL pointer dereference (CVE-ID: CVE-2025-38621)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the rdev_is_spare() and rdev_addable() functions in drivers/md/md.c. A local user can perform a denial of service (DoS) attack.


13) Improper locking (CVE-ID: CVE-2025-39833)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the hfcpci_softirq() and HFC_init() functions in drivers/isdn/hardware/mISDN/hfcpci.c. A local user can perform a denial of service (DoS) attack.


14) Resource management error (CVE-ID: CVE-2025-39925)

CWE-ID: CWE-399 - Resource Management Errors

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the j1939_sk_netdev_event_netdown() function in net/can/j1939/socket.c. A local user can perform a denial of service (DoS) attack.


15) Use-after-free (CVE-ID: CVE-2025-40064)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the smc_pnet_find_ism_by_pnetid() function in net/smc/smc_pnet.c. A local user can escalate privileges on the system.


16) Improper error handling (CVE-ID: CVE-2025-40102)

CWE-ID: CWE-388 - Error Handling

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling within the kvm_arch_vcpu_ioctl() function in arch/arm64/kvm/arm.c. A local user can perform a denial of service (DoS) attack.


17) Use-after-free (CVE-ID: CVE-2025-40139)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the smc_clc_msg_hdr_valid(), smc_clc_prfx_set4_rcu() and smc_clc_prfx_set() functions in net/smc/smc_clc.c. A local user can escalate privileges on the system.


18) Use-after-free (CVE-ID: CVE-2025-40168)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the smc_clc_prfx_match6_rcu() function in net/smc/smc_clc.c. A local user can escalate privileges on the system.


19) Memory leak (CVE-ID: CVE-2026-23137)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the attach_node_and_children() and unittest_data_add() functions in drivers/of/unittest.c. A local user can perform a denial of service (DoS) attack.


20) Race condition (CVE-ID: CVE-2026-43198)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a race condition in tcp_v6_syn_recv_sock() when handling IPv6 TCP connection requests. A remote attacker can send network traffic that triggers the race to cause a denial of service.

The issue occurs because a child socket may become visible in the TCP ehash table before its IPv6 state is fully initialized.


21) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-43344)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of offline CPU and topology lookup conditions in the Intel uncore PMON initialization logic when initializing uncore PCI devices on affected platforms. A local user can trigger the vulnerable code path to cause a denial of service.

The issue can occur when all CPUs associated with a UBOX device are offline or when NUMA is disabled on a NUMA-capable platform.


22) Use-after-free (CVE-ID: CVE-2026-45963)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the nau8821 jack detection work handler when unloading the driver while jack detection work is pending. A local user can unload the driver while delayed work remains scheduled to cause a denial of service.


23) Improper access control (CVE-ID: CVE-2026-52944)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass permission checks and modify file sparse attributes.

The vulnerability exists due to improper access control in fsctl_set_sparse() when handling FSCTL_SET_SPARSE requests. A remote user can send a crafted FSCTL_SET_SPARSE request on an opened file to bypass permission checks and modify file sparse attributes.

The issue affects both clients on read-only shares and clients on writable shares that lack FILE_WRITE_DATA or FILE_WRITE_ATTRIBUTES access.


24) Use-after-free (CVE-ID: CVE-2026-53010)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to use-after-free in smb2_open during durable reconnect handling when processing a durable reconnect request. A remote user can trigger an error condition during durable reconnect to cause a denial of service.

The issue can occur if a subsequent error happens after the durable file descriptor reference is dropped early, or if a scavenger accesses the file before smb2_open returns.


25) Use-after-free (CVE-ID: CVE-2026-53089)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() when querying info for an offloaded BPF map or program during network namespace destruction. A local user can query crafted offloaded BPF map or program information to cause a denial of service.

The issue occurs because the associated network namespace may be racing with teardown and its reference count may already have reached zero.


26) Memory leak (CVE-ID: CVE-2026-53102)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in the mt76 wireless driver MCU request handling code when processing error paths after allocating an skb. A local user can trigger an intermediate failure to cause a denial of service.


27) Improper resource shutdown or release (CVE-ID: CVE-2026-53113)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in ath11k beacon template setup functions when handling error paths during beacon template setup. A local user can trigger error conditions in beacon template setup to cause a denial of service.

The issue affects the ath11k driver code paths in ath11k_mac_setup_bcn_tmpl_ema() and ath11k_mac_setup_bcn_tmpl_mbssid().


28) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-53250)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause out-of-bounds memory access.

The vulnerability exists due to a time-of-check time-of-use race condition in xsk_skb_metadata() when processing transmit metadata from a userspace-writable UMEM buffer. A local user can race to overwrite csum_start and csum_offset between validation and assignment to cause out-of-bounds memory access.

The issue occurs during checksum computation in the transmit path.


29) NULL pointer dereference (CVE-ID: CVE-2026-53313)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace() when handling error paths. A local user can trigger the vulnerable code path to cause a denial of service.


30) Race condition (CVE-ID: CVE-2026-64058)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in netfs_read_folio() when handling a folio with ongoing writeback. A local user can trigger concurrent read and writeback activity to cause a denial of service.


31) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64070)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in sysfs show() callbacks in arch/powerpc/perf/hv-gpci.c when handling repeated sysfs reads. A local user can repeatedly read the affected sysfs entries to cause a denial of service.

On CONFIG_PREEMPT=y kernels, repeated successful reads can leave preemption disabled and a subsequent user-mode page fault may be forced to SIGSEGV, with the resulting coredump triggering a kernel scheduling while atomic condition.


32) Use of Uninitialized Variable (CVE-ID: CVE-2026-64082)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt register state and disclose kernel stack contents.

The vulnerability exists due to use of uninitialized stack data in compat_riscv_gpr_set() and compat_restore_sigcontext() when handling failed user memory copies. A local user can provide crafted user-supplied register or signal context data that triggers a copy failure to corrupt register state and disclose kernel stack contents.

The issue affects the RISC-V compatibility signal and ptrace handling paths.


33) Race condition (CVE-ID: CVE-2026-64210)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the mlx5e ICOSQ handling in the Linux kernel mlx5 driver when processing NAPI poll work during CPU affinity changes. A local user can trigger concurrent ICOSQ operations to cause a denial of service.

The issue occurs when affinity changes while XSK work remains pending.


34) Race condition (CVE-ID: CVE-2026-68286)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a race condition in net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe() in net/core/drop_monitor.c when updating 64-bit per-CPU statistics after releasing drop_queue.lock with interrupts re-enabled. A local attacker can trigger reentrant execution during the stats update to cause a denial of service.

On 32-bit architectures, a nested interrupt on the same CPU during the seqcount-based update can corrupt the seqcount state or statistics value.


35) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-68287)

CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper calculation of buffer size in net/core/drop_monitor.c when handling 64-bit drop monitor attributes on affected architectures. A local user can trigger packet report generation to cause a denial of service.

This affects 32-bit architectures without CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS because 64-bit netlink attributes may require additional padding for alignment.


36) Use of uninitialized resource (CVE-ID: CVE-2026-68288)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to uninitialized memory exposure in NET_DM_ATTR_PAYLOAD handling in net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() when constructing netlink messages containing packet payload data. A local user can receive a specially crafted netlink message to disclose sensitive information.

The issue occurs when the packet payload length is not 4-byte aligned, causing 1 to 3 padding bytes to remain uninitialized and be leaked to user space.


37) Integer overflow (CVE-ID: CVE-2026-68289)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to integer overflow in tipc_recvmsg() and tipc_recvstream() when processing oversized user-supplied buffer lengths. A local user can supply an excessively large buffer length via io_uring provided buffers to cause a denial of service.

The issue can trigger a WARN_ON that may lead to a kernel panic on systems configured with panic_on_warn.


38) NULL pointer dereference (CVE-ID: CVE-2026-68303)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the vc4_hvs_unbind and vc4_v3d_unbind functions when unbinding dependent vc4 drivers after vc4-drm removal. A local user can trigger driver unbind operations to cause a denial of service.

The issue occurs because the dependent drivers access master driver data after the vc4-drm device has already been removed.


39) NULL pointer dereference (CVE-ID: CVE-2026-68337)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the bpf_redirect helpers and skb_do_redirect() when processing tc BPF programs attached to a proper qdisc without a bpf_net_context. A local user can attach or run a BPF program that calls a redirect helper or returns TC_ACT_REDIRECT to cause a denial of service.

The issue occurs on qdisc paths where tc BPF execution does not establish the required per-task network context.


40) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-72334)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of malformed packet sequences in the Bluetooth ISO packet reassembly logic in net/bluetooth/iso.c when processing malformed ISO_START, ISO_CONT, and ISO_END frames from a Bluetooth controller. A remote attacker can send a specially crafted sequence of malformed Bluetooth ISO frames to cause a denial of service.

The issue can lead to a kernel panic when an oversized ISO_END frame is processed, and malformed fragment sequences can also leave an unfinished receive buffer allocated.


41) Information disclosure (CVE-ID: CVE-2026-72402)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in the BPF verifier log output in print_bpf_insn() when printing ldimm64 instructions with pointer-bearing pseudo sources. A local user can trigger verifier logging of crafted BPF instructions to disclose sensitive information.

The issue occurs when pointer leaks are not allowed but certain pseudo source types are still resolved to kernel pointer values before the verifier log prints the instruction.


42) Memory leak (CVE-ID: CVE-2026-72413)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in SCTP INIT handling in net/sctp/sm_statefuns.c when processing INIT chunks with unrecognized parameters. A remote attacker can send a specially crafted INIT chunk to cause a denial of service.

The issue occurs when err_chunk is allocated by sctp_verify_init() and is not freed on certain error and success return paths.


43) Improper resource shutdown or release (CVE-ID: CVE-2026-72438)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown in raid10_handle_discard() in drivers/md/raid10.c when handling discard requests and discard split allocation failures. A local user can trigger discard failure paths to cause a denial of service.

The issue is caused by missing releases of writes_pending and barrier references on certain error paths.


44) NULL pointer dereference (CVE-ID: CVE-2026-72485)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of allocation failure in coresight platform connection management functions when processing device probe data. A local user can trigger memory allocation failure during probe cleanup to cause a denial of service.

The issue occurs because cleanup code iterates connection entries up to inconsistent counter values and dereferences NULL or uninitialized pointers, leading to a kernel panic.


45) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-72496)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in bnxt_qplib_alloc_dpi when mapping device memory with ioremap. A local user can trigger an ioremap failure to cause a denial of service.


46) Improper input validation (CVE-ID: CVE-2026-74258)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in bpf_uprobe_multi_link_attach in kernel/trace/bpf_trace.c when processing user-supplied uprobe_multi array pointers. A local user can supply crafted user-space pointers to trigger a kernel fault and cause a denial of service.

The issue involves missing bounds validation with access_ok before __get_user accesses user-space data.


47) Race condition (CVE-ID: CVE-2026-74268)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper state management in tcp_set_state() and tcp_call_bpf() when force-closing a child socket whose inherited sock_ops callback flags remain set after setup failure. A remote attacker can send network traffic that triggers child socket setup failure to cause a denial of service.

The issue occurs before the child socket is ever established and affects forced-close paths that reach tcp_done() without the expected socket lock.


48) Use-after-free (CVE-ID: CVE-2026-74289)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in fib_leaf_notify() and fib_info reference handling when dumping IPv4 fib_info entries under RCU during fib notifier processing. A local user can trigger network namespace cleanup or device reload operations that invoke affected fib notifier paths to cause a denial of service.

The issue was reported through the netdevsim notifier path, and IPv6 is not affected by the same condition.


49) Out-of-bounds read (CVE-ID: CVE-2026-74291)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the ASoC topology parser when parsing a malformed topology blob with non-NUL-terminated PCM, DAI, or stream capability name fields. A local user can supply a specially crafted topology blob to disclose sensitive information.


50) Improper input validation (CVE-ID: CVE-2026-74294)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the AIU HDMI and internal codec mux put callbacks when processing written enumerated control values. A local user can supply an out-of-range enum value to cause a denial of service.


51) Race condition (CVE-ID: CVE-2026-74334)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the RDMA nldev resource tracking code when accessing memory region protection domain data during memory region re-registration. A local user can trigger concurrent memory region re-registration and netlink resource access to cause a denial of service.

The issue involves user memory regions whose protection domain pointer can change during in-place re-registration.


52) Use-after-free (CVE-ID: CVE-2026-74496)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in fou_create() and fou_from_sock() when handling concurrent socket activity after a failed FOU port creation. A local user can request local port 0 and trigger concurrent receive processing to cause a denial of service.

The issue is reachable when local port 0 is requested and the creation path fails after the object remains reachable through sk_user_data.


53) Incorrect Comparison (CVE-ID: CVE-2026-74521)

CWE-ID: CWE-697 - Incorrect Comparison

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass client identity checks.

The vulnerability exists due to improper comparison of fixed-size binary data in ksmbd SMB3 multichannel session binding and FSCTL_VALIDATE_NEGOTIATE_INFO handling when processing ClientGUID values. A remote user can send a crafted ClientGUID containing embedded NUL bytes to bypass client identity checks.


54) Improper update of reference count (CVE-ID: CVE-2026-74735)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper reference counting in the l2tp seq_file handlers for /proc/net/pppol2tp and /sys/kernel/debug/l2tp/tunnels when closing the file before reading to end-of-file. A local user can close the file early to cause a denial of service.

The issue occurs because tunnel and session references kept in seq_file private iteration state are not dropped on release.


55) Use-after-free (CVE-ID: CVE-2026-74753)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a use-after-free in perf_event_open() group handling in kernel/events/core.c when attaching a new event to a group leader in the EXIT state. A local user can open a perf event as a sibling of a detached leader to execute arbitrary code.

The issue occurs because a sibling event can retain a group_leader pointer to a freed event after remove-on-exec detaches the original leader.


56) Use-after-free (CVE-ID: CVE-2026-80521)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code or cause a denial of service.

The vulnerability exists due to a use-after-free in unix_del_edge() and the af_unix garbage collector when processing concurrent socket edge updates and garbage collection. A local user can trigger concurrent send() and close() operations on crafted unix socket reference cycles to execute arbitrary code or cause a denial of service.

The issue occurs in a race window where a new edge becomes visible to garbage collection before its skb is queued, allowing a dead strongly connected component to be partially freed while stale scc_entry state remains reachable during a later GC walk.


57) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-80671)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exceptional condition handling in register_pid() in tools/perf/builtin-sched.c when reallocating sched->tasks while processing untrusted perf.data. A local user can supply crafted input that triggers realloc failure to cause a denial of service.

Direct reassignment of the realloc result can leak the original pointer and leave task state corrupted because the task count is updated before successful reallocation.


58) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-80671)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exceptional condition handling in register_pid() in tools/perf/builtin-sched.c when processing untrusted perf.data that triggers allocation failure. A local user can supply crafted input that causes an allocation failure to cause a denial of service.

The issue is triggered because allocation failures are handled with a BUG_ON condition that terminates the process.


59) Heap-based buffer overflow (CVE-ID: CVE-2026-80671)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to heap-based buffer overflow in register_pid() in tools/perf/builtin-sched.c when processing an untrusted comm string from perf.data. A local user can supply a crafted perf.data file containing an oversized comm value to cause a denial of service.

The overflow occurs because the comm value is copied into a fixed 20-byte COMM_LEN buffer without a length check.


60) Integer overflow (CVE-ID: CVE-2026-80671)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to integer overflow in register_pid() in tools/perf/builtin-sched.c when processing untrusted perf.data. A local user can supply a crafted perf.data file with a large pid value to cause a denial of service.

The integer overflow can occur on 32-bit systems and may lead to out-of-bounds writes during task array initialization.


61) Out-of-bounds write (CVE-ID: CVE-2026-80755)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds heap write.

The vulnerability exists due to an out-of-bounds write in the SELinux policy permission parser when processing a policy image in which a class declares fewer permissions than its largest permission value. A local user can supply a crafted policy containing such a permission declaration to perform an out-of-bounds heap write.


62) Use-after-free (CVE-ID: CVE-2026-80762)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the Bluetooth hci_update_event_filter_sync() accept-list handling when suspending a Bluetooth controller while an accept-list device is concurrently removed. A local user can trigger concurrent accept-list removal during a controller wait to cause a denial of service.


63) Use-after-free (CVE-ID: CVE-2026-80766)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to trigger a use-after-free condition.

The vulnerability exists due to a race condition in the uclogic HID driver's in-range timer teardown when processing pen reports during device removal. An attacker with physical access can send pen reports during device removal to trigger a use-after-free condition.

The freed memory is dereferenced in timer-softirq context.


64) Use-after-free (CVE-ID: CVE-2026-80768)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause memory corruption.

The vulnerability exists due to a race condition causing a stack-use-after-return write in the FT260 HID driver's I2C read handling when a device response arrives after an I2C read times out. An attacker with physical access can provide a delayed device response containing an attacker-influenced payload to cause memory corruption.


65) Type conversion (CVE-ID: CVE-2026-80774)

CWE-ID: CWE-704 - Type conversion

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of a HID device's USB parent in the ASUS HID driver when handling a uhid-created device that identifies as being on BUS_USB. A local user can create a uhid device with a non-USB parent to trigger a kernel splat and cause a denial of service.


66) Out-of-bounds write (CVE-ID: CVE-2026-80780)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in hid_pidff_init_with_quirks() when initializing force feedback for a malicious USB HID device with an empty inputs list. An attacker with physical access can connect a malicious USB HID device to cause memory corruption.

The issue is reachable during device probing on the hotplug workqueue.


67) Stack-based buffer overflow (CVE-ID: CVE-2026-80783)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service or memory corruption.

The vulnerability exists due to a stack-based buffer overflow in magicmouse_raw_event() when processing a crafted HID report containing nested DOUBLE_REPORT_ID packets. An attacker with physical access can send a crafted HID report to cause a denial of service or memory corruption.


68) Out-of-bounds read (CVE-ID: CVE-2026-80796)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read kernel memory beyond activation parameter data.

The vulnerability exists due to improper bounds checking in the NCI activation parameter extractors when processing a crafted NCI RF_INTF_ACTIVATED_NTF notification. A remote attacker can send a crafted NCI notification with an inconsistent inner length byte to read kernel memory beyond activation parameter data.


69) Missing Encryption of Sensitive Data (CVE-ID: CVE-2026-80806)

CWE-ID: CWE-311 - Missing Encryption of Sensitive Data

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause sensitive data to be stored without encryption.

The vulnerability exists due to incorrect initialization order of encryption flags in the ext4 __ext4_new_inode() function when creating a new encrypted regular file on an ext4 filesystem mounted with dax=always. A local user can create a new encrypted regular file and write data to it to cause sensitive data to be stored without encryption.


70) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-80807)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause list corruption.

The vulnerability exists due to improper range validation in the nilfs2 GC ioctl when processing crafted virtual block descriptors. A local user can submit a crafted GC ioctl request to cause list corruption.

The crafted descriptor can specify an invalid virtual block number or offset that results in a page index of ULONG_MAX.


71) Use-after-free (CVE-ID: CVE-2026-80824)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in usbdev_release() in usbfs when draining completed asynchronous URBs after a USB device is disconnected. A local user can mmap a usbfs device node and submit an asynchronous URB using a mapped buffer before unmapping and closing the associated file descriptor to cause a denial of service.


72) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-80825)

CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of packet buffer headroom in mt7925_usb_sdio_tx_prepare_skb() when forwarding frames from a bridged wired interface to an mt7925u access point. A remote attacker can send a frame that is forwarded through the bridge to cause a denial of service.


73) Use-after-free (CVE-ID: CVE-2026-80826)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to use-after-free in c67x00_add_iso_urb() when processing an isochronous URB whose final packet encounters TD creation failure. A local user can submit such an isochronous URB to cause a use-after-free condition.


74) Out-of-bounds read (CVE-ID: CVE-2026-80827)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to read memory out of bounds.

The vulnerability exists due to improper length validation in the option_instat_callback interrupt URB callback when processing a short interrupt IN packet from a USB device. An attacker with physical access can provide a USB device that sends a crafted short interrupt IN packet to read memory out of bounds.


75) Improper handling of exceptional conditions (CVE-ID: CVE-2026-80828)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to improper handling of exceptional conditions in the ALSA USB-audio usb_audio_resume() function when processing system-resume failures. An attacker with physical access can trigger a system resume while a USB audio component resume operation fails to cause a denial of service.

The condition applies to system-resume errors; runtime-resume errors follow a distinct error path.


76) Out-of-bounds write (CVE-ID: CVE-2026-80829)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in snd_usbmidi_novation_output() when handling USB MIDI output from a device with an undersized bulk OUT endpoint. An attacker with physical access can connect a malicious USB device that advertises a one-byte bulk OUT endpoint to cause memory corruption.


77) Use-after-free (CVE-ID: CVE-2026-80830)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a race condition in usb_wakeup_notification() when an xHCI IRQ invocation occurs concurrently with hub_disconnect(). A local user can trigger concurrent wakeup notification and device disconnection activity to trigger a use-after-free condition.


78) Incorrect calculation (CVE-ID: CVE-2026-80831)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause encryption and decryption operations to process an incorrect number of bytes.

The vulnerability exists due to improper use of an unmapped DMA scatterlist length in mxs_dcp_aes_block_crypt() when processing source scatterlists. A local user can trigger processing of affected source scatterlists to cause encryption and decryption operations to process an incorrect number of bytes.

The issue occurs when CONFIG_NEED_SG_DMA_LENGTH is enabled.


79) Out-of-bounds read (CVE-ID: CVE-2026-80832)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect CCM authentication tags.

The vulnerability exists due to buffer underallocation in qce_aead_ccm_prepare_buf_assoclen() when preparing CCM associated data. A local user can submit a CCM request with associated data to cause incorrect CCM authentication tags.


80) Out-of-bounds read (CVE-ID: CVE-2026-80833)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in the sun8i-ss PRNG generate function when updating the PRNG seed after generating random data. A local user can invoke the PRNG generate function to read out-of-bounds memory.

The issue is limited to systems with sun8i-ss PRNG support enabled.


81) Use-after-free (CVE-ID: CVE-2026-80833)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free.

The vulnerability exists due to failure to stop a DMA operation after an interrupted wait in the sun8i-ss PRNG generate function when a PRNG generation operation is interrupted by a signal. A local user can interrupt a pending PRNG generation operation by sending a signal to cause a use-after-free.

The issue is limited to systems with sun8i-ss PRNG support enabled.


82) Use-after-free (CVE-ID: CVE-2026-80834)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the sun8i-ce crypto_rng interface generate function when an in-progress DMA operation is interrupted by a signal. A local user can interrupt an in-progress PRNG generation operation with a signal to trigger a use-after-free condition.


83) Race condition (CVE-ID: CVE-2026-80835)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause repeated or non-random random-number output.

The vulnerability exists due to improper synchronization in the Qualcomm RNG driver when concurrently using the crypto_rng and hwrng interfaces. A local user can issue concurrent random-number generation operations to cause repeated or non-random random-number output.


84) Out-of-bounds read (CVE-ID: CVE-2026-80836)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in virtio_crypto_dataq_akcipher_callback() when handling a device-reported akcipher response length. A local user can cause a virtio crypto backend to report an oversized result length to disclose sensitive information.


85) Use-after-free (CVE-ID: CVE-2026-80837)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free write.

The vulnerability exists due to a race condition in the nf_tables object notification queue when sending packets through a chain that references a depleted quota object. A remote attacker can send packets through the affected chain to trigger a use-after-free write.


86) Race condition (CVE-ID: CVE-2026-80838)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a race condition in vxlan FDB flush handling when flushing filtered FDB entries whose sole remote matches. A local user can trigger a filtered bulk FDB flush while an RCU reader accesses the parent FDB entry to cause memory corruption.


87) Numeric Truncation Error (CVE-ID: CVE-2026-80839)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read memory beyond the packet buffer.

The vulnerability exists due to numeric truncation in batadv_tvlv_call_handler() when processing a received multicast TVLV with an unrepresentable end offset. A remote attacker can send a multicast TVLV with an oversized end offset to read memory beyond the packet buffer.


88) Out-of-bounds write (CVE-ID: CVE-2026-80840)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds write.

The vulnerability exists due to improper initialization of the IPv4 control block in the IPv6 Segment Routing decapsulation path when processing a specially crafted IPv6 packet containing an encapsulated IPv4 TCP SYN packet. A remote attacker can send a specially crafted packet with controlled IPv6 extension-header and IPv4 option data to cause an out-of-bounds write.


89) Use-after-free (CVE-ID: CVE-2026-80841)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in AF_PACKET TX_RING handling when closing a socket or replacing a transmit ring while transmit skbs remain pending. A local user can close a socket or replace a transmit ring while transmit skbs remain pending to cause a denial of service.

The issue is limited to vmalloc-backed transmit-ring blocks.


90) Use-after-free (CVE-ID: CVE-2026-80842)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to use-after-free in the Linux bridge multicast handling for master VLANs when processing IGMP traffic during master VLAN teardown. A remote attacker can send IGMP traffic to the bridge device while a master VLAN is being removed to cause memory corruption.


91) Memory leak (CVE-ID: CVE-2026-80843)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory management in xfrm_state_construct() when constructing an XFRM state with a truncated authentication algorithm. A local user can trigger XFRM state construction using a truncated authentication algorithm to cause a denial of service.

The issue occurs when the selected authentication algorithm has no sadb_alg_id, such as cmac(aes).


92) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-80844)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds memory access.

The vulnerability exists due to improper validation of routing header segments_left values in ipv6_rearrange_rthdr() when processing raw IPv6 HDRINCL packets with a segments_left value larger than the number of addresses described by hdrlen. A local user can send a crafted packet with an oversized segments_left value to cause an out-of-bounds memory access.


93) Deadlock (CVE-ID: CVE-2026-80845)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock ordering in the xfrm NAT keepalive worker when NAT keepalive processing races with security association deletion. A local user can trigger concurrent NAT keepalive processing and security association deletion to cause a denial of service.


94) NULL pointer dereference (CVE-ID: CVE-2026-80846)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the handle_esp function when processing queued ESP-in-TCP data after its ingress device has been removed. A remote attacker can send ESP-in-TCP records to cause a denial of service.

The condition can occur during veth or network namespace teardown.


95) Division by zero (CVE-ID: CVE-2026-80847)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a divide-by-zero error in tcp_select_initial_window() when processing route-derived advertised MSS values. A local user can configure a route with a too-small RTAX_ADVMSS value to cause a denial of service.

The default advertised MSS path is also affected when the effective advertised MSS is reduced by the route MTU and min_adv_mss.


96) Use-after-free (CVE-ID: CVE-2026-80848)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the espintcp_close routine when closing espintcp sockets while queued reinjection work is running. A local user can race socket closure against queued reinjection work to trigger a use-after-free condition.


97) Use-after-free (CVE-ID: CVE-2026-80849)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to use-after-free in current_key handling in the TCP Authentication Option (TCP-AO) code when processing inbound TCP-AO traffic during a socket reconnect to a different peer. A local user can race inbound TCP-AO processing with reconnecting a socket to another peer to access freed memory.


98) Use-after-free (CVE-ID: CVE-2026-80850)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to use-after-free in TCP-AO information handling in tcp_ao_connect_init() when racing connect() with detaching a veth device from its VRF while sending TCP-AO segments. A local user can trigger access to stale tcp_ao_info data to cause a use-after-free condition.

TCP-AO must be configured.


99) Race condition (CVE-ID: CVE-2026-80851)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the GTP PDP context deletion paths when concurrently deleting a PDP context through GTP_CMD_DELPDP and network device unregistration. A local user can invoke concurrent GTP_CMD_DELPDP and RTM_DELLINK operations to cause a denial of service.


100) Out-of-bounds write (CVE-ID: CVE-2026-80852)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in tls_append_frag() in the TLS device offload implementation when repeatedly splicing small amounts of data into a TLS_TX_ZEROCOPY_RO socket using SPLICE_F_MORE and MSG_MORE. A local user can cause the fragment count to exceed the maximum array bound to cause a denial of service.

The vulnerable path requires TLS device offload support.


101) Use-after-free (CVE-ID: CVE-2026-80854)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the USB gadget f_tcm session teardown path when concurrently unlinking the last LUN and removing a nexus. A local user can overlap last-LUN removal with nexus removal to cause a denial of service.


102) Improper locking (CVE-ID: CVE-2026-80855)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in fuse_open() in fs/fuse/file.c when fuse_dax_break_layouts() fails after a signal interrupts the wait for busy DAX pages to drain during an O_TRUNC open of a DAX-enabled file. A local user can trigger the affected open operation to cause a denial of service.

The stale lock can stall later faults or truncates on the same file.


103) Improper locking (CVE-ID: CVE-2026-80856)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock release in fuse_do_setattr() when processing a DAX truncate operation that requires a writeback flush. A local user can initiate such a setattr operation when the writeback flush fails to cause a denial of service.


104) Race condition (CVE-ID: CVE-2026-80860)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to a race condition in FUSE request handling when interrupting and resending requests. A local user can race interrupt and resend operations to trigger a kernel warning.


105) Improper input validation (CVE-ID: CVE-2026-80861)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the xHCI controller setup routine when initializing an inaccessible xHCI controller. A local user can trigger controller setup while the capability register returns an all-ones value to cause a denial of service.

The issue can cause an alignment fault on arm64 systems.


106) Race condition (CVE-ID: CVE-2026-80862)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in NVMe/TCP page_frag_cache handling when initializing preallocated request PDUs concurrently. A local user can trigger concurrent PDU allocations to cause a denial of service.


107) Out-of-bounds write (CVE-ID: CVE-2026-80863)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in free_rd_atomic_resources() in the RXE RDMA driver when modifying a queue pair's max_dest_rd_atomic setting. A local user can modify a queue pair's max_dest_rd_atomic setting to cause a denial of service.


108) Use-after-free (CVE-ID: CVE-2026-80864)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the RDMA/rxe responder resource handling when modifying IB_QP_MAX_DEST_RD_ATOMIC while the responder task is active. A local user can race the freeing and reallocation of rd_atomic resources to cause a denial of service.


109) Memory leak (CVE-ID: CVE-2026-80878)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper resource management in afs_lookup_volume_rcu() when looking up a volume through RCU and acquiring a reference to a dying volume fails. A local user can trigger a volume lookup that encounters this condition to cause a memory leak.


110) Use-after-free (CVE-ID: CVE-2026-80914)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to use-after-free in the Bluetooth ISO iso_conn_ready function when handling a concurrently closed BIS listener socket. A local user can close a BIS listener socket concurrently with connection readiness processing to trigger a use-after-free.


111) Improper access control (CVE-ID: CVE-2026-80921)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access a device that is no longer available.

The vulnerability exists due to improper access control in KVM s390 VSIE APCB shadowing when shadowing crypto access bits from a format 0 APCB. A local user can use stale crypto access bits to access a device that is no longer available.

The issue affects nested guest environments.


112) Insufficient Entropy (CVE-ID: CVE-2026-80922)

CWE-ID: CWE-331 - Insufficient Entropy

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to distinguish generated output from uniformly random data.

The vulnerability exists due to insufficient entropy in the Qualcomm RNG driver when generating random data. A local user can request random data to distinguish generated output from uniformly random data.


113) Use-after-free (CVE-ID: CVE-2026-80923)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to trigger a use-after-free.

The vulnerability exists due to a dangling pointer in the xHCI debug tty driver when tty driver registration fails and the module is subsequently unloaded. A local privileged user can unload the module after a tty driver registration failure to trigger a use-after-free.


114) Race condition (CVE-ID: CVE-2026-80925)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in VLAN device feature transfer handling when toggling hardware VLAN transmit offload. A local user can toggle hardware VLAN transmit offload during transmit processing to cause a denial of service.


115) Use-after-free (CVE-ID: CVE-2026-80926)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to trigger a use-after-free.

The vulnerability exists due to use-after-free in the ksmbd oplock break notification path when processing an oplock break concurrently with durable-handle connection teardown. A remote user can hold a durable batch oplock and trigger an oplock break during connection teardown to trigger a use-after-free.


116) Use-after-free (CVE-ID: CVE-2026-80928)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free of struct cred.

The vulnerability exists due to a use-after-free in smack_file_send_sigiotask() when accessing the credentials of another task during signal delivery. A local user can trigger the affected credential access during a concurrent credential change to trigger a use-after-free of struct cred.


117) Improper handling of exceptional conditions (CVE-ID: CVE-2026-80930)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an IRQ enable/disable imbalance.

The vulnerability exists due to improper handling of exceptional conditions in the TPM I2C Nuvoton driver's i2c_nuvoton_wait_for_stat() function when waiting for a TPM status interrupt times out or is interrupted. A local user can cause a wait to time out or be interrupted to cause an IRQ enable/disable imbalance.


118) Out-of-bounds write (CVE-ID: CVE-2026-80931)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause an out-of-bounds write.

The vulnerability exists due to improper bounds checking in w1_f19_i2c_master_transfer() in the DS28E17 1-Wire-to-I2C bridge driver when handling an I2C_M_RECV_LEN read with an oversized device-controlled length. An attacker with physical access can supply an oversized length byte through a downstream I2C device to cause an out-of-bounds write.


119) Use-after-free (CVE-ID: CVE-2026-80932)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to improper workqueue synchronization in virtio_vsock_remove() when removing a virtio vsock device. A local user can trigger device removal while dependent work items are queued to cause a use-after-free condition.

The race involves tx_work, send_pkt_work, and rx_work.


120) Out-of-bounds read (CVE-ID: CVE-2026-80933)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read beyond the firmware buffer.

The vulnerability exists due to an out-of-bounds read in the mt7996 EEPROM default firmware handling when parsing a truncated default EEPROM firmware. A local user can provide a truncated default EEPROM firmware to read beyond the firmware buffer.


121) Deadlock (CVE-ID: CVE-2026-80938)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a deadlock in mt7615_suspend() when synchronously canceling mac_work while holding the mt76 mutex. A local user can initiate system suspend while mac_work is running to cause a denial of service.


122) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-80940)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to improper resource cleanup in rtw_pci_probe() when NAPI setup fails during PCI device probing. A local user can trigger a NAPI setup failure during PCI device probing to cause a resource leak.


123) Memory leak (CVE-ID: CVE-2026-80941)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to failure to free memory in rtw_txq_push_skb() when handling a failed HCI transmission. A local user can trigger the transmission path during an HCI write failure to cause a denial of service.


124) Memory leak (CVE-ID: CVE-2026-80942)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the rtl92du_init_sw_vars() error paths when initializing the RTL8192DU wireless driver and a subsequent initialization operation fails. A local user can trigger the affected initialization error path to cause a denial of service.


125) Out-of-bounds read (CVE-ID: CVE-2026-80943)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory out of bounds.

The vulnerability exists due to improper index validation in rtl92du_tx_fill_desc() when processing an 802.11 header with a QoS TID greater than 8. A local user can provide an 802.11 header with a QoS TID greater than 8 to read memory out of bounds.


126) Expired pointer dereference (CVE-ID: CVE-2026-80944)

CWE-ID: CWE-825 - Expired pointer dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an expired pointer dereference in the mwifiex synchronous command response handler when a synchronous command wait is interrupted before a late firmware response is processed. A local user can interrupt a synchronous command wait to cause a denial of service.

The issue was observed during repeated association and disassociation cycles.


127) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-80945)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt decompression results.

The vulnerability exists due to improper DMA mapping lifecycle management in the Intel IAA decompression fallback when processing a software fallback after a hardware analytics error. A local user can trigger the software fallback before the destination buffer is unmapped to corrupt decompression results.

Corruption occurs when SWIOTLB is active and a stale bounce buffer is copied during DMA unmapping.


128) Use-after-free (CVE-ID: CVE-2026-80947)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to trigger a use-after-free.

The vulnerability exists due to a use-after-free in the rtl8xxxu RX URB workqueue teardown when a device is disconnected during active receive traffic. An attacker with physical access can disconnect the device during active receive traffic to trigger a use-after-free.


129) Memory leak (CVE-ID: CVE-2026-80949)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to missing release of memory in brcmf_sdio_read_control() when handling error paths during control-frame reads. A local user can trigger the affected error paths to cause a denial of service.


130) Out-of-bounds write (CVE-ID: CVE-2026-80951)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to write beyond the bounds of the IBI pool.

The vulnerability exists due to improper bounds checking in svc_i3c_master_handle_ibi() when processing in-band interrupt payloads from an I3C device. An attacker with physical access can send an IBI payload larger than the requested maximum payload length to write beyond the bounds of the IBI pool.


131) Use-after-free (CVE-ID: CVE-2026-80952)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose kernel stack contents and cause a use-after-free.

The vulnerability exists due to improper device descriptor lifetime management in i3c_master_unregister_i3c_devs() when unregistering I3C devices. A local user can trigger device unregistration while a modalias is generated to disclose kernel stack contents and cause a use-after-free.

A racing modalias operation can observe a NULL device descriptor and use an uninitialized stack i3c_device_info structure.


132) NULL pointer dereference (CVE-ID: CVE-2026-80963)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the dm-stat_free cleanup function when freeing dm-stats data after per-cpu data allocation fails. A local user can trigger a failed per-cpu data allocation to cause a denial of service.


133) Out-of-bounds read (CVE-ID: CVE-2026-80964)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in the ALSA virmidi driver probe function when manually binding a device through the sysfs interface with an invalid card index. A local user can manually bind a device with an invalid card index to perform an out-of-bounds read.


134) Improper Validation of Array Index (CVE-ID: CVE-2026-80965)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds access.

The vulnerability exists due to improper validation of a card index in the ALSA serial-u16550 driver's snd_serial_probe function when manually binding a device through the sysfs interface. A local user can bind a device with an invalid card index to cause an out-of-bounds access.


135) Improper Validation of Array Index (CVE-ID: CVE-2026-80966)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds access.

The vulnerability exists due to improper validation of an array index in the ALSA portman2x4 driver when binding the driver through sysfs with a negative card index. A local user can supply a negative card index to perform an out-of-bounds access.


136) Improper initialization (CVE-ID: CVE-2026-80967)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization of mutexes in the pcxhr_probe() function when handling an early interrupt during device probe. A local user can trigger an early interrupt during device probe to cause a denial of service.


137) Improper Validation of Array Index (CVE-ID: CVE-2026-80968)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds access.

The vulnerability exists due to improper validation of an array index in the ALSA mts64 driver's snd_mts64_probe function when binding a device through sysfs with a negative card index. A local user can provide a negative card index to cause an out-of-bounds access.


138) Improper Validation of Array Index (CVE-ID: CVE-2026-80969)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds memory access.

The vulnerability exists due to improper validation of an array index in the ALSA mpu401 driver probe routine when manually binding a device through the sysfs interface with an invalid card index. A local user can set an invalid card index to cause an out-of-bounds memory access.


139) Use-after-free (CVE-ID: CVE-2026-80971)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a use-after-free condition.

The vulnerability exists due to use-after-free in the ALSA bcd2000 driver's URB handling when a BCD2000 USB device is disconnected while a rawmidi substream remains open. An attacker with physical access can disconnect the device while the substream remains open to cause a use-after-free condition.


140) Improper Validation of Array Index (CVE-ID: CVE-2026-80972)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds memory access.

The vulnerability exists due to improper validation of a card index in the ALSA aloop driver's loopback_probe function when manually binding a device through the sysfs interface. A local user can provide an invalid card index to perform an out-of-bounds memory access.


141) Out-of-bounds read (CVE-ID: CVE-2026-80973)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to disclose kernel memory.

The vulnerability exists due to an out-of-bounds read in usb6fire_comm_receiver_handler() when processing MIDI events from a connected USB device. An attacker with physical access can provide a MIDI event with an excessive length value to disclose kernel memory.

The receiver is submitted during device probing, and forwarding data through the rawmidi read path requires an open MIDI input substream.


142) Memory leak (CVE-ID: CVE-2026-80974)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper resource management in the SM501 driver remove functions when removing an SM501 device. A local user can trigger removal of an SM501 device to cause a memory leak.


143) Out-of-bounds read (CVE-ID: CVE-2026-80976)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to stale IPv6 control block state in the decap_and_validate() function of the seg6 local processing component when processing a decapsulated IPv6 packet through an End.DX6 or End.DT6 route. A local user can install a local SID and inject a crafted outer IPv6 packet to cause an out-of-bounds read.

The outer packet contains Hop-by-Hop and Destination Options headers followed by an SRH and a minimal inner IPv6 packet.


144) Use-after-free (CVE-ID: CVE-2026-80977)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt memory.

The vulnerability exists due to improper handling of shared zerocopy state in skb_tx_error() when processing cloned socket buffers. A remote attacker can trigger processing of cloned socket buffers to corrupt memory.

The issue can be reached when Open vSwitch processes a non-last OVS_ACTION_ATTR_RECIRC action, the clone encounters a flow miss, and a later local ESP delivery decrypts data in place.


145) Integer overflow (CVE-ID: CVE-2026-80978)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause skb header offsets to wrap.

The vulnerability exists due to an integer overflow in IP tunnel device headroom configuration when configuring a stack of user-created IP tunnel devices. A local user can create a stacked tunnel-device configuration with excessive headroom to cause skb header offsets to wrap.

The affected skb header offsets use a 16-bit representation.


146) Use-after-free (CVE-ID: CVE-2026-80979)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in the SMC connection teardown handling for DMB-nocopy buffers when a receive tasklet is re-armed after a connection is freed. A remote attacker can cause the receive tasklet to access a freed send buffer to cause a denial of service.

Only SMCD links supporting DMB-nocopy are affected.


147) Use-after-free (CVE-ID: CVE-2026-80982)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in smc_rx_pipe_buf_release() when releasing pipe buffers concurrently with connection closure. A local user can cause a pipe buffer release to race with connection cleanup to trigger a use-after-free condition.


148) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-80983)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in smc_switch_conns() when handling connection switches during SMC link failover. A local user can initiate a connection switch during link failover to cause a denial of service.

The target link must go down or the connection must be killed while the switch is in progress.


149) NULL pointer dereference (CVE-ID: CVE-2026-80984)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the SMC-D teardown path when an SMC-D link group terminates while a socket is waiting during teardown. A local user can trigger the teardown race to cause a denial of service.


150) Memory leak (CVE-ID: CVE-2026-80987)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak memory.

The vulnerability exists due to improper error handling in the NTB transport transmit queue when submitting an oversized transmit buffer. A local user can submit an oversized transmit buffer to leak memory.


151) Memory leak (CVE-ID: CVE-2026-80988)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in ntb_transport_tx_enqueue() when transmitting packets while the QP link is down. A local user can submit packets during the link-down condition to cause a denial of service.


152) Incomplete Internal State Distinction (CVE-ID: CVE-2026-80989)

CWE-ID: CWE-372 - Incomplete Internal State Distinction

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper connection state management in tbnet_connected_work() when handling a failed connection setup followed by connection teardown. A remote attacker can trigger a failed connection setup followed by connection teardown to cause a denial of service.

When panic_on_warn is enabled, stopping already stopped rings can be fatal.


153) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-80990)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to improper resource release in tbnet_connected_work() when handling an Rx HopID allocation mismatch during an XDomain connection. An attacker with physical access can trigger an Rx HopID allocation mismatch to cause a denial of service.


154) Use-after-free (CVE-ID: CVE-2026-80991)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free.

The vulnerability exists due to a race condition in ravb_ptp_interrupt() and ravb_ptp_stop() when PTP interrupt handling occurs during PTP clock teardown. A local user can trigger the race to cause a use-after-free.


155) NULL pointer dereference (CVE-ID: CVE-2026-80992)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the Renesas RAVB driver's PTP clock handling when querying hardware timestamping information before a PTP clock is registered or after PTP clock registration fails. A local user can query the PTP clock index to cause a denial of service.


156) Use-after-free (CVE-ID: CVE-2026-80994)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the Open vSwitch flow deletion handling code when processing flow deletion commands. A local user can issue a flow deletion command during a race window to cause a denial of service.


157) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-80996)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause live L2TP objects to accumulate.

The vulnerability exists due to improper error handling in the L2TP netlink tunnel and session create and modify handlers when multicast notification delivery fails after a live operation completes. A local user can issue L2TP netlink create or modify commands that are erroneously reported as failed to cause live L2TP objects to accumulate.


158) Race condition (CVE-ID: CVE-2026-80997)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the IPA modem transmit queue wake handling when transmitting traffic during a device runtime resume. A local user can send network traffic during runtime resume to cause a denial of service.


159) Reliance on undefined behavior (CVE-ID: CVE-2026-80999)

CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to trigger a kernel warning.

The vulnerability exists due to improper GPIO API selection in the rtl83xx_reset_assert() and rtl83xx_reset_deassert() helpers when handling reset GPIOs controlled by sleeping controllers. A local privileged user can trigger device probing with such a GPIO configuration to trigger a kernel warning.


160) Integer underflow (CVE-ID: CVE-2026-81000)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write packet data outside allocated memory.

The vulnerability exists due to an integer underflow in TUN and TAP interface handling in tun_get_user() when processing an oversized headroom request propagated by an OVS port. A local user can configure an OVS port to propagate an oversized headroom request to a TUN or TAP device to write packet data outside allocated memory.


161) Use-after-free (CVE-ID: CVE-2026-81001)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in sl_sync() in the SLIP driver when opening a SLIP line discipline concurrently with SLIP device teardown. A local user can trigger a race between SLIP device opening and teardown to cause a denial of service.


162) Out-of-bounds write (CVE-ID: CVE-2026-81002)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in xdp_convert_zc_to_xdp_frame() when processing an AF_XDP zero-copy packet redirected through cpumap. A local user can submit a crafted AF_XDP zero-copy packet to cause a denial of service.


163) Improper access control (CVE-ID: CVE-2026-81003)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to inject data into existing AF_IUCV sockets and cause a denial of service.

The vulnerability exists due to improper ingress device validation in afiucv_hs_rcv() socket selection when processing a raw ETH_P_AF_IUCV frame received on a network device. A local user can send a crafted raw ETH_P_AF_IUCV frame through its loopback device to inject data into existing AF_IUCV sockets and cause a denial of service.

Exploitation requires CAP_NET_RAW in an unprivileged user and network namespace.


164) NULL pointer dereference (CVE-ID: CVE-2026-81005)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper shutdown state management in the IPMI message handler failed-registration rollback path when asynchronous redo_bmc_reg work retries BMC device-ID probing after a failed registration. A local user can cause BMC device-ID retrieval to fail and trigger a NULL pointer dereference to cause a denial of service.

The issue occurs after the lower driver's shutdown callback has cleared the SI state machine data.


165) Use of Uninitialized Variable (CVE-ID: CVE-2026-81007)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose uninitialized stack memory.

The vulnerability exists due to improper length validation in the ipmb_write() function when writing a zero or short IPMB message. A local user can write a zero or short IPMB message to disclose uninitialized stack memory.


166) Use-after-free (CVE-ID: CVE-2026-81008)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to use-after-free in icc_get() and of_icc_get_by_index() when handling a failed dynamic allocation of a path name. A local user can invoke subsequent interconnect path operations to cause memory corruption.


167) Out-of-bounds read (CVE-ID: CVE-2026-81011)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the hp-bioscfg package parsers when parsing ACPI BIOS configuration attribute packages. A local user can cause the kernel to parse a short package whose name length exceeds its element count to disclose sensitive information.

The condition requires acceptance of packages that are shorter than the element count expected for their attribute type.


168) Off-by-one (CVE-ID: CVE-2026-81012)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds write.

The vulnerability exists due to an off-by-one error in hp_get_string_from_buffer() in the hp-bioscfg driver when converting a string whose length equals the destination buffer size. A local user can cause the function to process such a string to perform an out-of-bounds write.


169) Out-of-bounds read (CVE-ID: CVE-2026-81013)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in validate_password_input() in the hp-bioscfg password attribute handling when writing an empty string to current_password or new_password. A local user can write an empty string to a password attribute to disclose sensitive information.


170) Out-of-bounds read (CVE-ID: CVE-2026-81014)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in the sk_store() and kek_store() functions of the hp-bioscfg driver when handling sysfs writes ending with a trailing newline. A local user can submit a sysfs write with a trailing newline to perform an out-of-bounds read.


171) Out-of-bounds write (CVE-ID: CVE-2026-81017)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read from and write to memory out of bounds.

The vulnerability exists due to improper bounds checking in cros_ec_sensorhub_ring_handler() when processing EC-reported FIFO events. A local user can trigger processing of an EC FIFO event containing an out-of-range sensor number to read from and write to memory out of bounds.


172) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-89438)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access unintended MMIO offsets.

The vulnerability exists due to improper validation of CLOS IDs and logical CPU IDs in the ISST core power feature when handling user-supplied CLOS parameter and association commands. A local user can supply out-of-range CLOS IDs or logical CPU IDs to access unintended MMIO offsets.


173) NULL pointer dereference (CVE-ID: CVE-2026-89439)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the isst_if_get_tpmi_instance_count function in the ISST TPMI core when handling a TPMI instance-count request for a socket whose instance failed to load. A local user can request an instance count for a socket whose instance failed to load to cause a denial of service.


174) Use-after-free (CVE-ID: CVE-2026-89440)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the via-sdmmc card-detect interrupt handler and carddet_work when handling a card-detect interrupt after mmc_add_host() fails. A local user can trigger card-detect interrupt handling against a freed host object to cause a denial of service.


175) NULL pointer dereference (CVE-ID: CVE-2026-89442)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the isst_if_clos_assoc ioctl handler when processing a socket ID for an in-range package without a bound TPMI SST instance. A local user can submit a crafted clos_assoc ioctl request to cause a denial of service.


176) Out-of-bounds read (CVE-ID: CVE-2026-89442)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the isst_if_clos_assoc ioctl handler when processing a user-supplied socket ID equal to topology_max_packages(). A local user can submit a crafted clos_assoc ioctl request to cause a denial of service.


177) Out-of-bounds read (CVE-ID: CVE-2026-89443)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform out-of-bounds reads.

The vulnerability exists due to an out-of-bounds read in the ISST perf mask ioctl handlers when processing user-supplied ioctl input containing an invalid performance level. A local user can submit a crafted ioctl request with an invalid level value to perform out-of-bounds reads.


178) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-89444)

CWE-ID: CWE-532 - Information Exposure Through Log Files

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in the dell-wmi-sysman set_attribute() function when setting BIOS attributes. A local user can cause a BIOS attribute request buffer containing a plaintext administrator password to be logged to disclose sensitive information.


179) Configuration (CVE-ID: CVE-2026-89448)

CWE-ID: CWE-16 - Configuration

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause access control services to remain disabled while the IOMMU is forced on.

The vulnerability exists due to improper configuration handling in detect_intel_iommu() when tboot forces the IOMMU on after ACS was not requested. A local privileged user can configure the system to disable ACS to cause access control services to remain disabled while the IOMMU is forced on.


180) Race condition (CVE-ID: CVE-2026-89451)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in iommu SVA handle initialization when concurrently binding and unbinding an SVA device. A local user can race SVA device binding and unbinding operations to cause a denial of service.


181) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89453)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to failure to release a PCI device reference in iommu_call_iopf_notifier() when handling PPR faults. A local user can trigger PPR fault handling to cause a denial of service.


182) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89454)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to improper resource cleanup in plda_init_interrupts() when initializing interrupts and platform IRQ retrieval or IRQ mapping fails. A local user can trigger an interrupt initialization failure to cause a resource leak.


183) Use-after-free (CVE-ID: CVE-2026-89455)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the PLDA PCIe host controller driver's IRQ-domain teardown routine when removing IRQ domains while devres-managed event IRQs remain mapped. A local user can trigger driver teardown to cause a denial of service.


184) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-89456)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to receive zeroed data for unread portions of a request.

The vulnerability exists due to improper handling of partial-completion length in dasd_default_erp_postaction() when recovering a partially completed ESE read through the ERP chain. A local user can issue a read request that is partially completed and recovered through the ERP chain to receive zeroed data for unread portions of a request.


185) NULL pointer dereference (CVE-ID: CVE-2026-89457)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in s390 DASD sysfs discipline callbacks when reading world-readable sysfs attributes during device initialization. A local user can read a sysfs attribute before private device data is allocated to trigger a kernel panic and cause a denial of service.


186) Unchecked Return Value (CVE-ID: CVE-2026-89458)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an unchecked return value in dasd_int_handler when handling an NRF read of an unallocated ESE track. A local user can trigger a failed ESE read that is completed successfully to disclose sensitive information.

A failed sense-data parse or a current track outside the requested range can leave destination pages untouched.


187) NULL pointer dereference (CVE-ID: CVE-2026-89460)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the s390 CPUMF performance monitoring unit when a CPU is added while a per-task CPUMF performance event is running. A local privileged user can trigger CPU hotplug during execution of a per-task performance event to cause a denial of service.


188) Race condition (CVE-ID: CVE-2026-89461)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the polling callback to continue accessing the fuel gauge after system suspend.

The vulnerability exists due to improper synchronization in the max17040 fuel-gauge driver's suspend handler when system suspend races with the polling callback. A remote attacker can cause system suspend to race with the polling callback to cause the polling callback to continue accessing the fuel gauge after system suspend.

The polling work requeues itself after each poll.


189) Unchecked Return Value (CVE-ID: CVE-2026-89462)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause power-supply properties to report incorrect voltage or state-of-charge values.

The vulnerability exists due to improper error handling in the max17040 power supply driver when an I2C register read fails. A local user can access power-supply properties during a failed I2C register read to cause power-supply properties to report incorrect voltage or state-of-charge values.

A polling worker may replace the cached state of charge with an invalid value and emit a spurious change event.


190) Use-after-free (CVE-ID: CVE-2026-89463)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to use-after-free in the ucs1002 health_poll delayed work when unbinding the ucs1002 driver while health polling work is queued. A local privileged user can cause the driver to be unbound while health polling work is queued to cause a denial of service.

The delayed work can reschedule itself while the chip reports a bad-health condition.


191) Use-after-free (CVE-ID: CVE-2026-89464)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to use-after-free in the twl4030_charger driver's bci work handlers when removing the device while a worker is pending. A local user can trigger device removal while a worker is pending to cause a use-after-free condition.

The USB transceiver notifier can reschedule work after device removal returns.


192) Use-after-free (CVE-ID: CVE-2026-89465)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed rt9455_info memory.

The vulnerability exists due to improper delayed-work cancellation in RT9455 charger driver teardown handling when delayed work is pending during device removal or probe error cleanup. A local user can race delayed work with teardown to access freed rt9455_info memory.

The threaded IRQ handler can queue delayed work, and batt_presence_work can requeue itself or queue max_charging_time_work.


193) Improper Null Termination (CVE-ID: CVE-2026-89466)

CWE-ID: CWE-170 - Improper Null Termination

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper null termination in qcom_battmgr_sc8280xp_strcpy() when copying non-Pascal-style strings from firmware. A local user can read exposed power supply properties containing a full-length firmware string to disclose sensitive information.

The affected fields are model_number, serial_number, and oem_info.


194) Use-after-free (CVE-ID: CVE-2026-89468)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to a use-after-free in the lp8788 charger driver's removal handler when an IRQ thread queues charger_work during device removal. A local user can race IRQ handling with device removal to cause a use-after-free condition.


195) Use-after-free (CVE-ID: CVE-2026-89469)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to improper synchronization in lp8727_release_irq() when the IRQ handler queues delayed work during IRQ release. A local user can trigger a race between IRQ handling and IRQ release to cause a use-after-free condition.


196) Out-of-bounds write (CVE-ID: CVE-2026-89470)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the cros_usbpd-charger driver probe when processing a raw charger port count returned by the embedded controller. An attacker with physical access can cause the embedded controller to report an inaccurate port count to cause memory corruption.

The embedded controller can report a port count of up to 255.


197) Out-of-bounds write (CVE-ID: CVE-2026-89471)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to corrupt kernel memory.

The vulnerability exists due to an out-of-bounds write in cros_usbpd_charger_probe() in the cros_usbpd-charger driver when processing EC-reported USB PD and charger port counts. A local privileged user can cause a compromised EC to report port counts exceeding the fixed ports[] array capacity to corrupt kernel memory.

The ports[] array contains eight entries.


198) Use-after-free (CVE-ID: CVE-2026-89472)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in charger-manager regulator handle management when handling a concurrent write to the externally_control sysfs attribute during device teardown. A local user can write to the externally_control sysfs attribute while charging is enabled to trigger a use-after-free condition.

The sysfs attribute can also be exposed before regulator acquisition completes during probing.


199) Memory leak (CVE-ID: CVE-2026-89473)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak a power_supply reference.

The vulnerability exists due to improper resource lifecycle management in bq25890_fw_probe() when handling secondary charger references during probe failures or driver detach. A local user can trigger a later probe failure or driver detachment to leak a power_supply reference.


200) Use-after-free (CVE-ID: CVE-2026-89474)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the bq256xx charger driver's usb_work handler when queued usb_work executes during device cleanup. A local user can trigger device cleanup while usb_work is queued to cause a denial of service.


201) Use-after-free (CVE-ID: CVE-2026-89475)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the bq24257 charger driver when device removal races with the STAT-pin interrupt handler. A local user can cause the interrupt handler to reschedule delayed work during device removal to cause a denial of service.

The issue applies when input-current-limit autosetting is enabled.


202) Integer underflow (CVE-ID: CVE-2026-89476)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an integer underflow.

The vulnerability exists due to improper tracking of outstanding stream reconfiguration request parameters in SCTP stream reconfiguration response handling when processing duplicate RECONF responses. A remote attacker can send duplicate RECONF responses to cause an integer underflow.

A cached RECONF chunk containing multiple request parameters must have another parameter still outstanding.


203) NULL pointer dereference (CVE-ID: CVE-2026-89477)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in SCTP stream reconfiguration request handling when processing specially crafted SCTP RECONF chunks. A remote attacker can send a specially crafted SCTP RECONF packet to cause a denial of service.

A RECONF chunk containing incoming SSN reset, outgoing SSN reset, and response parameters, or two RECONF chunks in one packet, can trigger the issue.


204) Use-after-free (CVE-ID: CVE-2026-89478)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access freed memory.

The vulnerability exists due to a use-after-free in the SCTP input queue when processing a DATA chunk after an authenticated ASCONF DEL-IP removes its transport. A remote user can cause a delayed SACK to read the freed transport's state to access freed memory.


205) Use-after-free (CVE-ID: CVE-2026-89479)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access freed memory.

The vulnerability exists due to use-after-free in the SCTP endpoint receive loop when processing a specially crafted SCTP packet containing bundled chunks. A remote attacker can send an SCTP packet that deletes an association before subsequent chunks are processed to access freed memory.

Exploitation requires the packet to be processed from the socket backlog in task context.


206) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-89480)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper validation of the received data length in the NVMe/TCP host driver when processing a short C2HData PDU from an NVMe/TCP controller. A remote attacker can respond to a read request with fewer bytes than requested to disclose sensitive information.


207) Improper input validation (CVE-ID: CVE-2026-89481)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in nvme_tcp_handle_r2t() when processing an R2T request for a read command. A remote attacker can send an R2T request for a read command to disclose sensitive information.

The disclosed read destination buffer may contain stale kernel data.


208) Out-of-bounds write (CVE-ID: CVE-2026-89482)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper validation of C2HData requests in the NVMe/TCP receive path when handling C2HData for a WRITE_ZEROES command with a residual iterator on the same tag. A remote attacker can send a C2HData request to trigger a wild memory write and cause a denial of service.


209) Use of uninitialized resource (CVE-ID: CVE-2026-89483)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in the NVMe discard fallback page when processing discard commands. A local user can trigger a discard command that causes uninitialized DSM payload data to be sent to the controller to disclose sensitive information.

Exploitation requires the discard-range allocation to fail under memory pressure.


210) NULL pointer dereference (CVE-ID: CVE-2026-89484)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in nlmclnt_locks_release_private() when releasing a partially initialized file_lock after lockowner allocation failure. A local user can trigger a lockowner allocation failure during NLM file lock initialization to cause a denial of service.

The VFS may release the partially initialized file lock after NLM client processing returns an out-of-memory error.


211) Use-after-free (CVE-ID: CVE-2026-89485)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the lockd nlm_traverse_files() file traversal routine when a concurrent nlm_release_file() frees the saved next file while nlm_file_mutex is dropped. A local user can trigger concurrent file release during file traversal to trigger a use-after-free condition.


212) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-89487)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to modify page-cache data.

The vulnerability exists due to improper handling of zero-copy packet buffer flags in the Open vSwitch datapath when a failed USERSPACE upcall is followed by local ESP-in-UDP delivery. A local user can trigger a failed USERSPACE upcall followed by local ESP-in-UDP delivery to modify page-cache data.

Exploitation requires a MSG_ZEROCOPY packet carrying page-cache fragments.


213) Use-after-free (CVE-ID: CVE-2026-89488)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a slab use-after-free.

The vulnerability exists due to a race condition leading to use-after-free in the Open vSwitch conntrack limit state when tearing down a network namespace while packet processing accesses the state. A local user can tear down a network namespace while packet processing accesses CT limit state to trigger a slab use-after-free.

Exploitation requires a user and network namespace.


214) Untrusted Pointer Dereference (CVE-ID: CVE-2026-89489)

CWE-ID: CWE-822 - Untrusted Pointer Dereference

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code in kernel context.

The vulnerability exists due to improper validation of user pointers in the sys_or1k_atomic syscall when processing syscall arguments. A local user can supply kernel addresses as syscall pointers to execute arbitrary code in kernel context.


215) Incorrect Conversion between Numeric Types (CVE-ID: CVE-2026-89490)

CWE-ID: CWE-681 - Incorrect Conversion between Numeric Types

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service by triggering indefinite directory re-enumeration.

The vulnerability exists due to an incorrect integer conversion in ocfs2_dir_foreach_blk_el() when reading a non-inline directory that crosses the 4 GiB boundary on a 32-bit kernel. A local user can invoke readdir() on an affected directory to cause a denial of service by triggering indefinite directory re-enumeration.

64-bit kernels are unaffected.


216) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89491)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leave heartbeat regions unprotected on subsequent mounts.

The vulnerability exists due to improper error handling in o2hb_region_inc_user() when heartbeat region pinning fails partway through processing. A local user can invoke heartbeat region user registration during a pinning failure to leave heartbeat regions unprotected on subsequent mounts.

Partially pinned regions are not released, and the dependent-user counter remains incremented.


217) Deadlock (CVE-ID: CVE-2026-89491)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a lock order inversion in o2hb_region_pin() when it is invoked from the configfs drop_item callback. A local user can trigger heartbeat-region removal processing to cause a denial of service.


218) Improper locking (CVE-ID: CVE-2026-89491)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in o2hb_region_pin() when calling o2nm_depend_item() while holding o2hb_live_lock. A local user can trigger heartbeat region pinning to cause a denial of service.

The issue manifests as a sleeping-in-atomic-context BUG under CONFIG_DEBUG_ATOMIC_SLEEP.


219) Out-of-bounds read (CVE-ID: CVE-2026-89492)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory beyond the bounds of a directory-index metadata block.

The vulnerability exists due to an out-of-bounds read in the OCFS2 directory index entry-list validation when processing a crafted on-disk image. A local user can supply a crafted image and access an indexed directory to read beyond the entry array.

Exploitation is reachable through path lookup, stat(), or open() operations after the image is mounted.


220) Out-of-bounds write (CVE-ID: CVE-2026-89493)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to perform out-of-bounds memory reads and writes.

The vulnerability exists due to improper validation of refcount record bounds in ocfs2_validate_refcount_block() when processing crafted refcount blocks during reflink operations. A local privileged user can mount a crafted or corrupted ocfs2 image and issue a reflink operation to perform out-of-bounds memory reads and writes.

A raw write to the block device backing an already-mounted ocfs2 filesystem can also introduce a malicious refcount block.


221) Out-of-bounds write (CVE-ID: CVE-2026-89494)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause memory corruption.

The vulnerability exists due to a heap out-of-bounds write in dlm_init_lockres() when processing a DLM_MIG_LOCKRES message with an oversized lock name length. A remote user can send a specially crafted DLM_MIG_LOCKRES message to cause memory corruption.

The sending node must belong to the DLM domain.


222) Out-of-bounds read (CVE-ID: CVE-2026-89494)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in dlm_process_recovery_data() when processing a DLM_MIG_LOCKRES message whose claimed number of locks exceeds the message payload. A remote user can send a specially crafted DLM_MIG_LOCKRES message to cause a denial of service.

The sending node must belong to the DLM domain.


223) Out-of-bounds read (CVE-ID: CVE-2026-89495)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in dlm_process_recovery_data when processing recovery data whose lock count exceeds the message payload. A remote user can send a malformed recovery message with an invalid number of lock entries to cause a denial of service.


224) Heap-based buffer overflow (CVE-ID: CVE-2026-89495)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to corrupt memory or cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in dlm_mig_lockres_handler when processing recovery data with an oversized lock name. A remote user can send a malformed recovery message with an oversized lock name length to corrupt memory or cause a denial of service.


225) Heap-based buffer overflow (CVE-ID: CVE-2026-89495)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to corrupt memory or cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in dlm_migrate_request_handler when processing a DLM_MIGRATE_REQUEST message with an oversized name. A remote user can send a malformed migration request with an oversized name length to corrupt memory or cause a denial of service.


226) Memory leak (CVE-ID: CVE-2026-89496)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper resource release in OCFS2 copy-on-write completion when performing copy_file_range() within the same filesystem. A local user can invoke copy_file_range() to cause a memory leak.


227) Heap-based buffer overflow (CVE-ID: CVE-2026-89497)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write past the end of an allocated keyword buffer.

The vulnerability exists due to a heap-based buffer overflow in orangefs_prepare_cdm_array() when processing a client debug entry that begins with a space. A local user can supply a client debug entry beginning with a space to write past the end of an allocated keyword buffer.


228) Double free (CVE-ID: CVE-2026-89498)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a double-free.

The vulnerability exists due to double free in the OrangeFS readdir downcall handling when processing a readdir downcall with a declared trailer size that exceeds the supplied data. A local user can send a readdir downcall with insufficient trailer data to trigger a double-free.


229) Race condition (CVE-ID: CVE-2026-89501)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a race condition involving cpu_buffer->free_page.

The vulnerability exists due to improper synchronization in trace ring buffer resizing when changing a sub-buffer order. A local user can race sub-buffer resizing with read-page allocation or freeing operations to cause a race condition involving cpu_buffer->free_page.


230) Mismatched Memory Management Routines (CVE-ID: CVE-2026-89502)

CWE-ID: CWE-762 - Mismatched Memory Management Routines

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to mismatched memory management routines in the ring buffer CPU buffer cleanup routine when freeing cpu_buffer->free_page allocated with a sub-buffer order greater than zero. A local user can trigger cleanup of an affected CPU buffer to cause a memory leak.


231) Use-after-free (CVE-ID: CVE-2026-89504)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger use of a dangling device-tree node pointer.

The vulnerability exists due to improper reference counting in as3722_get_regulator_dt_data() when parsing regulator device-tree data. A local user can cause the dangling pointer to be used to trigger use of a dangling device-tree node pointer.


232) Race condition (CVE-ID: CVE-2026-89508)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in ucma_set_ib_path() when concurrently handling SET_OPTION requests and context migration. A local user can trigger a race condition to cause a denial of service.

A bound and address-resolved cm_id and an RDMA device are required.


233) Use-after-free (CVE-ID: CVE-2026-89510)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a use-after-free condition.

The vulnerability exists due to a race condition in the RDMA/cxgb4 device removal and registration work handling when removing an RDMA device while registration work is pending or running. A local privileged user can remove the device while the registration work accesses the device object to cause a use-after-free condition.


234) NULL pointer dereference (CVE-ID: CVE-2026-89511)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the qede driver's TPA fragment processing when handling TPA continuation fragments under memory pressure. A remote attacker can send network traffic that is processed as TPA continuation fragments during memory pressure to cause a denial of service.


235) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89512)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to missing release of a resource after effective lifetime in the scp_get function in drivers/remoteproc/mtk_scp.c when looking up SCP driver data before the driver has been bound. A local user can trigger a failed SCP driver-data lookup to cause a denial of service.


236) Use of uninitialized resource (CVE-ID: CVE-2026-89515)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose uninitialized memory contents.

The vulnerability exists due to use of uninitialized memory in scsi_alloc_sgtables() when processing the last unaligned element of a scatterlist requiring DMA padding. A local user can issue an SCSI generic I/O request with an unaligned final scatterlist element to disclose uninitialized memory contents.


237) Integer underflow (CVE-ID: CVE-2026-89524)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an integer underflow in ath6kl_cfg80211_connect_event() when handling association events with request or response lengths shorter than their fixed information element offsets. A remote attacker can trigger such an association event to disclose sensitive information.


238) Out-of-bounds read (CVE-ID: CVE-2026-89525)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in udf_get_pblock_virt15() when processing a crafted UDF image. A local user can mount a crafted UDF image to cause a denial of service.

The issue affects UDF 1.50 virtual partition mappings that use a VAT.


239) Out-of-bounds read (CVE-ID: CVE-2026-89526)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in RPC/RDMA Read chunk reconstruction when processing crafted Read chunk positions supplied by a remote client. A remote attacker can supply out-of-range or overlapping Read chunk positions to disclose sensitive information.


240) Heap-based buffer overflow (CVE-ID: CVE-2026-89530)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt adjacent slab memory.

The vulnerability exists due to a heap-based buffer overflow in svc_rdma_xb_linearize() when processing oversized inline RPC-over-RDMA replies without a Write list or Reply chunk. A remote attacker can request an oversized inline reply without providing a Write list or Reply chunk to corrupt adjacent slab memory.

The posted scatter/gather entry length can cause the device to read beyond the mapped region.


241) Memory leak (CVE-ID: CVE-2026-89531)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource management in the svcrdma handle_connect_req() connection handler when transport allocation fails while processing connection requests. A remote attacker can send repeated connection attempts during memory pressure to cause a denial of service.


242) Out-of-bounds read (CVE-ID: CVE-2026-89532)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an integer underflow resulting in an out-of-bounds read in the pcl_for_each_segment macro when processing a Write or Reply chunk with zero segments. A remote attacker can send a crafted Write or Reply chunk advertising zero segments to cause a denial of service.

The transport must have negotiated Send-With-Invalidate.


243) Integer underflow (CVE-ID: CVE-2026-89533)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer underflow in svc_rdma_read_chunk_range() when processing a Read chunk segment list with crafted offsets and lengths. A remote attacker can submit a crafted Read chunk to cause a denial of service.


244) Use-after-free (CVE-ID: CVE-2026-89535)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the RDMA transport's svc_rdma_free() function when a concurrent RDMA device unregistration occurs during transport teardown. A local user can trigger the race condition to cause a denial of service.


245) Use-after-free (CVE-ID: CVE-2026-89536)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to a use-after-free in SUNRPC client TLS handshake handling when cancellation loses a race with completion of a TLS handshake callback. A local user can interrupt or time out a synchronous TLS handshake wait while the completion callback is in flight to cause a use-after-free condition.


246) Improper input validation (CVE-ID: CVE-2026-89538)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper input validation in gss_krb5_unwrap_v2() when processing Kerberos v2 wrap tokens with oversized extra count fields. A remote user can send a malformed Kerberos v2 wrap token to cause a denial of service.

The token must be encrypted using a valid GSS context.


247) Memory leak (CVE-ID: CVE-2026-89539)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in gssx_dec_option_array() when processing a reply containing duplicate CREDS_VALUE options. A remote attacker can send a crafted reply containing duplicate CREDS_VALUE options to cause a denial of service.


248) Race condition (CVE-ID: CVE-2026-89540)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to an initialization race condition in the use-gss-proxy proc entry initialization when writing to the newly published proc entry before gssp_lock is initialized. A local user can win the initialization race and write to the proc entry to cause a resource leak.

The race window can widen when the auth_rpcgss module is loaded for live network namespaces.


249) Out-of-bounds read (CVE-ID: CVE-2026-89541)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read out-of-bounds memory.

The vulnerability exists due to improper length validation in gss_unwrap_resp_priv() when processing a crafted RPCSEC_GSS reply. A remote attacker can return a crafted RPCSEC_GSS reply from a krb5p NFS server to read out-of-bounds memory.


250) Out-of-bounds read (CVE-ID: CVE-2026-89542)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper length validation in gss_krb5_unwrap_v2() and its rotation helpers when processing a short or malformed GSS token. A remote user can provide a token shorter than the required header or with a declared length exceeding the buffer bounds to cause a denial of service.

The flawed length arithmetic can result in an out-of-bounds read, an unsigned underflow during cleanup, or a divide-by-zero during buffer rotation.


251) Use-after-free (CVE-ID: CVE-2026-89543)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the Linux kernel SunRPC client pipefs directory handling when accessing stale pipefs entries after a late mount or remount. A local user can invoke rpc_info_open() or rpc_show_info() on a stale pipefs entry to cause a denial of service.


252) NULL pointer dereference (CVE-ID: CVE-2026-89544)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in the SUNRPC gssx XDR option-array decoder when handling an allocation failure while decoding an option array. A local user can trigger the decoder's error path to cause a denial of service.

The affected error paths also include a group_info reference-count leak and a latent use-after-free condition.


253) Use-after-free (CVE-ID: CVE-2026-89545)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to improper RCU synchronization in the SunRPC service request cleanup routine when RCU readers traverse the thread list after a service request is removed. A local user can cause RCU readers to dereference freed request argument memory to trigger a use-after-free.

The issue affects request data accessed by readers such as nfsd_nl_rpc_status_get_dumpit().


254) Unchecked Return Value (CVE-ID: CVE-2026-89547)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to corrupt kernel memory.

The vulnerability exists due to unchecked return values in the SUNRPC RPC service pool counter initialization in __svc_create() when starting an RPC service while per-CPU counter allocation fails. A local privileged user can start an RPC service under allocation failure conditions to corrupt kernel memory.

Exploitation requires memory pressure or fault injection during RPC server startup; a remote peer cannot induce the failed allocation state on its own.


255) Use-after-free (CVE-ID: CVE-2026-89548)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper synchronization in the SUNRPC cache cleanup routine when tearing down a network namespace. A local user can cause cache_clean() to access a freed cache_detail to trigger a use-after-free condition.


256) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-89549)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a service connection to hang indefinitely.

The vulnerability exists due to improper handling of threadless service pools in svc_pool_for_cpu() when routing a transport to a service pool. A remote attacker can initiate a connection that is enqueued on a pool with no service threads to cause a service connection to hang indefinitely.

The condition can occur when a service has fewer threads than configured pools.


257) Division by zero (CVE-ID: CVE-2026-89550)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper input validation in svcauth_gss_unwrap_priv() when handling a crafted short krb5 token. A remote user can send a crafted token that triggers a division by zero to cause a denial of service.

The issue affects krb5 v2 contexts.


258) Integer underflow (CVE-ID: CVE-2026-89551)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause downstream XDR decoders to use an incorrect stream bound.

The vulnerability exists due to an integer underflow in xdr_buf_trim() when processing GSS Kerberos v2 data whose recorded buffer length is smaller than the associated I/O vector lengths. A remote attacker can cause xdr_buf_trim() to consume more bytes than buf->len records to cause downstream XDR decoders to use an incorrect stream bound.


259) NULL pointer dereference (CVE-ID: CVE-2026-89552)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of allocation failures in param_set_charp() when updating charp parameters after slab allocation is available. A local user can update a charp parameter during an allocation failure to cause a denial of service.

The issue can be triggered by a failed zswap compressor update before zswap is initialized.


260) Use-after-free (CVE-ID: CVE-2026-89553)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to a use-after-free in the nouveau GEM information ioctl when racing an information lookup with a GEM close operation. A local user can race an information ioctl with a GEM close operation to trigger a use-after-free.

Only the non-uvmm path is affected.


261) Use of Uninitialized Variable (CVE-ID: CVE-2026-89554)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt the path manager's id-based subflow bookkeeping.

The vulnerability exists due to use of an uninitialized local_id field in mptcp_token_join_cookie_init_state() when reconstructing MP_JOIN request sockets for fourth acknowledgments under SYN cookies. A remote attacker can send concurrent MP_JOIN SYNs to influence the stale address ID and corrupt the path manager's id-based subflow bookkeeping.


262) Use-after-free (CVE-ID: CVE-2026-89555)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free.

The vulnerability exists due to use-after-free in mpls_multipath_hash when processing MPLS packets with inner IP headers in non-linear data and insufficient tailroom in the linear head. A remote attacker can send a legal Geneve packet through a bareudp/MPLS multipath setup to trigger a use-after-free.

The IPv6 processing path can perform a second pull for the larger header.


263) Integer overflow (CVE-ID: CVE-2026-89557)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an integer overflow.

The vulnerability exists due to improper input validation in the super_1_load() MD superblock loader when processing a crafted on-disk superblock. A local user can supply a crafted on-disk superblock to trigger an integer overflow.


264) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-89558)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause silent data corruption.

The vulnerability exists due to incorrect control flow implementation in raid10_sync_request() in drivers/md/raid10.c when recovering RAID10 devices while another mirror remains missing. A local privileged user can write to a degraded RAID10 array and re-add affected devices to cause silent data corruption.

Exploitation requires bitmap-based recovery.


265) Integer overflow (CVE-ID: CVE-2026-89559)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds write.

The vulnerability exists due to an integer overflow in __nd_label_validate() in the libnvdimm label handler when processing a crafted nslot namespace index value. A local user can supply crafted configuration data through ND_CMD_SET_CONFIG_DATA to perform an out-of-bounds write.

The nslot field may also originate from DIMM label storage.


266) Missing Authorization (CVE-ID: CVE-2026-89560)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass Landlock filesystem access restrictions.

The vulnerability exists due to improper access control in Landlock whiteout creation checks when creating whiteout objects with mknod(2) or renameat2(2) using RENAME_WHITEOUT. A local user can create a whiteout object despite denied required Landlock access rights to bypass Landlock filesystem access restrictions.

Normal renames within layered OverlayFS mounts are not affected.


267) NULL pointer dereference (CVE-ID: CVE-2026-89561)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in ipv6_rpl_srh_rcv() when processing RPL segment routing packets after the receiving interface's IPv6 device pointer has been cleared during an MTU transition. A remote attacker can send RPL segment routing packets during the MTU transition to cause a denial of service.


268) Incorrect calculation (CVE-ID: CVE-2026-89562)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect tunnel hardware header length handling.

The vulnerability exists due to improper hardware header length calculation in ip6_gre tunnel configuration when configuring an NBMA ip6gre tunnel. A local user can configure an NBMA ip6gre tunnel to cause incorrect tunnel hardware header length handling.

ip6gretap and ip6erspan use fixed Ethernet hardware header lengths.


269) Double free (CVE-ID: CVE-2026-89563)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in ip6_tnl_xmit() when handling errors after expanding packet headroom. A local user can trigger an error after packet headroom expansion to cause a denial of service.

The issue is reachable when collect_md tunnels reject a non-NONE encapsulation type or when ip6_tnl_encap() fails.


270) Use-after-free (CVE-ID: CVE-2026-89564)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free.

The vulnerability exists due to improper socket reference management in IPv4 and IPv6 multicast forwarding paths when processing non-locally deliverable multicast packets. A remote attacker can send a non-locally deliverable multicast packet to trigger a use-after-free.

Exploitation requires the associated prefetched socket to be destroyed before the socket buffer is freed.


271) Memory leak (CVE-ID: CVE-2026-89565)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a resource leak in ipip_tunnel_rcv() when processing packets in collect_md mode after metadata_dst allocation fails. A local user can trigger packet processing under these conditions to cause a denial of service.

The issue can be triggered through an ipip or mplsip tunnel configured in collect_md mode.


272) Improper locking (CVE-ID: CVE-2026-89566)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in journal_shrink_one_cp_list() when skipping busy checkpoint buffers during checkpoint-list shrinking. A local user can trigger checkpoint-list shrinking under memory pressure to cause a denial of service.

The condition occurs when a checkpoint list contains mostly busy buffers.


273) Resource exhaustion (CVE-ID: CVE-2026-89567)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper scan-budget accounting in the jbd2 checkpoint shrinker when scanning checkpoint lists containing mostly busy buffers. A local user can cause a checkpoint transaction to contain mostly busy buffers to cause a denial of service.


274) Use-after-free (CVE-ID: CVE-2026-89569)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access freed RFCOMM session and data link connection objects.

The vulnerability exists due to use-after-free in the RFCOMM security confirmation handler rfcomm_security_cfm() when processing Bluetooth security confirmations concurrently with RFCOMM session teardown. A remote attacker can trigger the concurrent processing to access freed RFCOMM session and data link connection objects.


275) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89572)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the Apple SoC CPU frequency driver when initializing or exiting CPU frequency policies. A local privileged user can trigger repeated CPU frequency policy initialization failures to cause a denial of service.


276) Out-of-bounds read (CVE-ID: CVE-2026-89573)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to improper validation of array block value sizes in dm-array's get_ablock() and __shadow_ablock() functions when processing crafted dm-cache metadata. A local user can cause a mappings array to reference a hint block with a smaller value size to read out-of-bounds memory.


277) Out-of-bounds read (CVE-ID: CVE-2026-89574)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read beyond the dm-bufio buffer.

The vulnerability exists due to improper validation of on-disk array block headers in the dm-array component when loading dm-cache mappings from on-disk array blocks. A local user can cause dm_cache_load_mappings() to process an array block header whose entry count exceeds its capacity to read beyond the dm-bufio buffer.

The vulnerable path is reached during dm-cache activation.


278) Heap-based buffer overflow (CVE-ID: CVE-2026-89575)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a heap-based buffer overflow.

The vulnerability exists due to improper buffer size calculation in build_constructor_string() when formatting a maximum-length u64 value. A local privileged user can cause sprintf() to write a terminating NUL byte beyond the allocated buffer space to cause a heap-based buffer overflow.


279) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89576)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service through metadata block exhaustion.

The vulnerability exists due to improper resource release in metadata_take_snap() when incrementing metadata block references fails after allocating a shadow superblock. A local user can cause snapshot creation to fail after a shadow block is allocated to cause a denial of service through metadata block exhaustion.


280) Out-of-bounds write (CVE-ID: CVE-2026-89579)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to escalate privileges.

The vulnerability exists due to out-of-bounds memory access in the BPF bloom filter bitset allocation and indexing logic when processing BPF bloom filter map operations on 32-bit kernels. A local privileged user can create a bloom filter map with a maximal bitset and perform updates to escalate privileges.

Exploitation is possible on 32-bit x86 kernels from a binary with CAP_BPF.


281) Out-of-bounds write (CVE-ID: CVE-2026-89580)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write out of bounds.

The vulnerability exists due to a race condition in __bpf_get_stack when a preemptible BPF program accesses a reused per-CPU callchain buffer. A local user can execute a preemptible BPF program to write out of bounds.

The issue can affect non-sleepable raw tracepoint programs on PREEMPT kernels.


282) Incorrect calculation (CVE-ID: CVE-2026-89581)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to incorrect register encoding in the x86 BPF JIT compiler when resolving per-CPU addresses into extended registers. A local user can execute a BPF program that uses an extended register as a per-CPU address destination to cause a denial of service.


283) Double free (CVE-ID: CVE-2026-89582)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a double free.

The vulnerability exists due to a double free in bnx2x_init_firmware() when firmware initialization fails and bnx2x_release_firmware() is subsequently called. A local user can cause firmware initialization to fail and invoke the affected cleanup path to trigger a double free.


284) Out-of-bounds read (CVE-ID: CVE-2026-89583)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in eir_get_service_data() when processing periodic advertising data containing mismatching Service Data fields. A remote attacker can transmit a crafted periodic advertising payload to disclose sensitive information.

Exploitation requires an ISO broadcast sink to process periodic advertising reports from a remote broadcaster.


285) Use-after-free (CVE-ID: CVE-2026-89585)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to use-after-free in the charlcd registration error-handling path when a character LCD registration attempt fails while backlight flashing is enabled. A local user can trigger delayed backlight work after the charlcd object is freed to access freed memory.


286) Incorrect calculation (CVE-ID: CVE-2026-89586)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to incorrect calculation in ata_scsi_write_same_xlat() and ata_format_dsm_trim_descr() when issuing SCSI WRITE SAME commands with the UNMAP bit set. A local user can issue a SCSI WRITE SAME command with the UNMAP bit set to cause a denial of service.

The issue affects devices whose logical sector size exceeds 2048 bytes.


287) Stack-based buffer overflow (CVE-ID: CVE-2026-89587)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt stack memory.

The vulnerability exists due to a stack-based buffer overflow in the query_capability() function when processing firmware _DSM buffer objects. A local user can invoke the PFRU ioctl while firmware returns oversized _DSM buffers to corrupt stack memory.

The affected capability-information structure is stack-allocated in pfru_ioctl().


288) Out-of-bounds read (CVE-ID: CVE-2026-89588)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read past a CPER section.

The vulnerability exists due to incorrect length accounting in ghes_handle_arm_hw_error() when processing ARM hardware error sections. A local user can trigger parsing of a CPER section with a large err_info_num relative to error_data_length to read past a CPER section.


289) Deadlock (CVE-ID: CVE-2026-89589)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper locking in the CXL CPER work registration and unregistration helpers in drivers/acpi/apei/ghes.c when a GHES interrupt arrives while a CPU holds a CXL CPER work lock. A local privileged user can trigger the locking race to cause a denial of service.

The affected CXL CPER post paths execute in hard IRQ context.


290) Integer underflow (CVE-ID: CVE-2026-89593)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect huge-page reservation accounting.

The vulnerability exists due to an integer underflow in __unmap_hugepage_range() in the hugetlb memory-management component when unmapping a parent range whose folio remains mapped by a child. A local user can unmap the parent range before the child range to cause the reserved count to underflow.

The reserved count is restored when the child unmaps the range.


291) Improper initialization (CVE-ID: CVE-2026-89594)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization in the OMAP SSI controller device when performing DMA mapping operations. A local user can trigger DMA mapping operations to cause a denial of service.


292) Race condition (CVE-ID: CVE-2026-89595)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause filesystem monitoring events to be missed.

The vulnerability exists due to a race condition in cached fsnotify object mask recalculation when concurrently updating fanotify or inotify marks on the same connector. A local user can issue concurrent mark updates to cause filesystem monitoring events to be missed.


293) Off-by-one (CVE-ID: CVE-2026-89596)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an off-by-one error in the forcedeth driver's nv_suspend() and nv_resume() functions when suspending or resuming the system. A local user can trigger a system suspend and resume cycle to cause a denial of service.

On systems built with CONFIG_UBSAN_TRAP=y, the out-of-bounds access aborts the running kernel code.


294) Improper resource shutdown or release (CVE-ID: CVE-2026-89597)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to leave a v86d connector callback registered after initialization fails.

The vulnerability exists due to improper resource shutdown or release in uvesafb_init() when platform driver registration fails after registering the v86d connector callback. A local privileged user can initialize uvesafb to leave the callback registered.


295) Improper locking (CVE-ID: CVE-2026-89598)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in the ssd1307fb framebuffer driver when processing framebuffer damage callbacks while preemption is disabled. A local user can trigger a display update to cause a denial of service.

The issue affects SSD1307 framebuffer devices that use I2C transfers.


296) Race condition (CVE-ID: CVE-2026-89599)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a dsicm callback to use an uninitialized mutex.

The vulnerability exists due to a race condition in the dsicm_probe() function of the panel-dsi-cm display driver when a consumer reaches a dsicm callback after the display is registered but before ddata->lock is initialized. A local user can trigger a dsicm callback during this interval to cause a dsicm callback to use an uninitialized mutex.


297) Out-of-bounds write (CVE-ID: CVE-2026-89602)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the z_erofs_gbuf_growsize() global-buffer resizing function when retrying a global-buffer resize with an intermediate size after a partial resize. A local privileged user can trigger a resize retry using an intermediate size to cause memory corruption.

The issue requires some global buffers to have been enlarged by a previous resize attempt.


298) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-89603)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute system calls prohibited by a seccomp filter.

The vulnerability exists due to a race condition in syscall_trace_enter() when a thread is stopped for ptrace while another thread installs a seccomp filter with SECCOMP_FILTER_FLAG_TSYNC. A local user can install a seccomp filter with SECCOMP_FILTER_FLAG_TSYNC while another thread is stopped for ptrace to execute system calls prohibited by the filter.

The system call number may be modified during ptrace handling.


299) Resource exhaustion (CVE-ID: CVE-2026-89604)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the efivarfs statfs() handler when repeatedly invoking statfs() on the efivarfs mount point. A local user can flood the QueryVariableInfo() runtime service with statfs() calls to cause a denial of service.

On x86 systems with a variable store backed by SMM, each runtime-service entry requires a rendezvous of all CPUs.


300) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89605)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to failure to release a message context in ecryptfs messaging when sending a message to the userspace daemon fails. A local user can trigger message delivery failures to exhaust reusable message contexts.


301) Integer underflow (CVE-ID: CVE-2026-89606)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an integer underflow.

The vulnerability exists due to an integer underflow in ecryptfs_parse_tag_70_packet() when parsing malformed tag 70 packets. A local user can provide a tag 70 packet with a body smaller than the required fixed metadata fields to trigger an integer underflow.


302) Out-of-bounds write (CVE-ID: CVE-2026-89607)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to out-of-bounds writes in parse_tag_3_packet() and decrypt_passphrase_encrypted_session_key() when processing a crafted Tag 3 packet through the passphrase decryption path. A local user can supply a crafted Tag 3 packet with an oversized encrypted key size to cause memory corruption.

Only the AES-192 cipher configuration enables exploitation because its key size is set independently of the encrypted key size.


303) Out-of-bounds read (CVE-ID: CVE-2026-89608)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to improper bounds checking in ecryptfs_parse_packet_set() when parsing an eCryptfs version 1 file header. A local user can trigger parsing of an eCryptfs version 1 file header to perform an out-of-bounds read.


304) Improper locking (CVE-ID: CVE-2026-89609)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a race condition.

The vulnerability exists due to improper locking in ecryptfs_exorcise_daemon() when cleaning queued messages from a dying daemon. A local user can move queued message contexts to the free list without holding the required global list lock to trigger a race condition.


305) Out-of-bounds write (CVE-ID: CVE-2026-89615)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds write.

The vulnerability exists due to an out-of-bounds write in the page_lcns[] array handling of the NTFS3 log replay code when processing a crafted log record. A local user can provide a crafted log record with an lcns_follow count that exceeds the target entry's capacity to perform an out-of-bounds write.


306) Use of uninitialized resource (CVE-ID: CVE-2026-89616)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper initialization in ni_read_frame() when reading a crafted compressed NTFS file. A local user can trigger partial LZNT decompression to disclose sensitive information.

Disclosed data can include recently freed kernel page memory and kernel pointers.


307) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-89617)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds memory access.

The vulnerability exists due to improper validation of an on-disk array length in DIR_PAGE_ENTRY entries during NTFS3 log replay when replaying a crafted NTFS log. A local user can provide a crafted lcns_follow value that exceeds the page_lcns[] entry bounds to cause an out-of-bounds memory access.


308) Improper initialization (CVE-ID: CVE-2026-89618)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a false warning.

The vulnerability exists due to improper initialization in eventfs_inode list heads when eventfs_create_dir() fails due to memory pressure. A local user can trigger directory creation failure due to memory pressure to cause a false warning.


309) Out-of-bounds read (CVE-ID: CVE-2026-89621)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to disclose uninitialized kernel memory.

The vulnerability exists due to an out-of-bounds read in mcp2221_raw_event() in the MCP2221 HID driver when handling a short MCP2221_I2C_GET_DATA HID report. An attacker with physical access can send a crafted HID report with a length value exceeding the received report size to disclose uninitialized kernel memory.


310) Use-after-free (CVE-ID: CVE-2026-89622)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause memory corruption.

The vulnerability exists due to a write use-after-free in the MCP2221 HID driver's mcp_i2c_smbus_read() and mcp2221_raw_event() functions when processing a delayed or spurious MCP2221_I2C_GET_DATA report after an I2C/SMBus transfer has ended. An attacker with physical access can trigger a report that writes device data to freed memory to cause memory corruption.


311) Use-after-free (CVE-ID: CVE-2026-89624)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write to freed memory.

The vulnerability exists due to improper resource shutdown in universal_pidff_probe() when opening a surviving /dev/hidrawX device after force-feedback initialization fails. A local user can open the surviving device to write to freed memory.

A descriptor with a PID usage page and no input reports can cause force-feedback initialization to fail after the device starts.


312) Use-after-free (CVE-ID: CVE-2026-89625)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a use-after-free condition.

The vulnerability exists due to use-after-free in GHL poke timer handling in the hid-sony driver when handling driver unbind while a GHL poke URB is in flight. A local privileged user can trigger a driver unbind while the GHL poke URB is in flight to cause a use-after-free condition.

The issue affects Guitar Hero Live dongles, where a URB completion can re-arm the timer after driver teardown.


313) Use-after-free (CVE-ID: CVE-2026-89626)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free.

The vulnerability exists due to improper cleanup in hid_sensor_custom_add_attributes() when creating sysfs groups for custom sensor fields. A local user can trigger a sysfs group creation failure to cause a use-after-free.


314) Memory leak (CVE-ID: CVE-2026-89627)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory release in the ROCcat HID device destruction paths when destroying a device with buffered reports stored in its circular buffer. A local user can trigger the affected device destruction path while buffered reports remain stored to cause a denial of service.

Up to ROCCAT_CBUF_SIZE report buffers per device can become unreachable.


315) Out-of-bounds read (CVE-ID: CVE-2026-89628)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in picolcd_debug_eeprom_read() when reading EEPROM data through the debugfs "eeprom" file. A local privileged user can use a crafted or spoofed picoLCD device to supply an oversized length value to disclose sensitive information.

The debugfs file is accessible only to root.


316) Integer overflow (CVE-ID: CVE-2026-89634)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an integer overflow in symlink_data() in fs/smb/client/smb2file.c when processing an SMB error context with a malformed ErrorDataLength value. A remote attacker can provide a crafted SMB error context to cause a denial of service.


317) Use-after-free (CVE-ID: CVE-2026-89636)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free.

The vulnerability exists due to use-after-free in the SMB client DFS cache's free_tgts() function when using ce->tgthint after its target entries have been freed. A local user can trigger use of the stale target cache hint to cause a use-after-free.


318) Integer underflow (CVE-ID: CVE-2026-89640)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt the ByteCount in a file-clone request.

The vulnerability exists due to an integer underflow in cifs_remap_file_range() when issuing a clone-to-EOF operation with a source offset beyond the end of the source file. A local user can invoke a clone-to-EOF operation with an out-of-range source offset to corrupt the ByteCount in a file-clone request.


319) Use-after-free (CVE-ID: CVE-2026-89643)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a use-after-free in audit_del_rule() when fsnotify automatically removes mixed AUDIT_DIR and AUDIT_EXE rules that share an audit tree. A local privileged user can trigger fsnotify autoremove events to cause a denial of service.


320) Memory leak (CVE-ID: CVE-2026-89644)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to missing release of memory after effective lifetime in btrfs_get_blocks_direct_write() when performing a direct I/O write to a NOCOW range and ordered extent allocation fails. A local user can issue a direct I/O write to a NOCOW range to cause a resource leak.


321) Memory leak (CVE-ID: CVE-2026-89645)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a reference leak.

The vulnerability exists due to improper reference counting in btrfs relocation recovery when handling recovery failures. A local user can trigger a relocation recovery failure to cause a reference leak.

The issue occurs if loading or adding a later root fails, or if the first transaction commit fails during relocation recovery.


322) Infinite loop (CVE-ID: CVE-2026-89647)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an infinite loop in the Ceph dentry lease reclamation logic when processing valid leases with no cap pressure. A local user can cause ceph_cap_reclaim_work() to repeatedly requeue dentry trimming to cause a denial of service.


323) Out-of-bounds read (CVE-ID: CVE-2026-89649)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the CephFS __build_xattrs() function when processing metadata-server-supplied extended attribute blobs. A remote privileged user can provide a crafted extended attribute blob with a final attribute value length that exceeds the available data to disclose sensitive information.

A local user must invoke getxattr(2) on a CephFS file.


324) Out-of-bounds read (CVE-ID: CVE-2026-89650)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds read in the kernel.

The vulnerability exists due to an out-of-bounds read in ceph_mdsmap_decode() in fs/ceph/mdsmap.c when processing an MDS map with a per-mds info version of 2 or 3 and an oversized num_export_targets field. A remote attacker can send a specially crafted MDS map to cause an out-of-bounds read in the kernel.

On-path exploitation applies to unsigned or unencrypted messenger sessions.


325) Out-of-bounds read (CVE-ID: CVE-2026-89651)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the Ceph MDS client handle_session() function when processing MDSCapAuth records in a CEPH_SESSION_OPEN message. A remote attacker can send a specially crafted session-open message to cause a denial of service.

Only CEPH_SESSION_OPEN messages with a message version of 6 or later are affected.


326) Out-of-bounds write (CVE-ID: CVE-2026-89652)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause memory corruption.

The vulnerability exists due to improper bounds checking in the CephFS NFS-export get_name functions when processing LOOKUPNAME replies containing oversized dentry names. A remote user can return a specially crafted LOOKUPNAME reply to cause memory corruption.

The issue is reachable when a CephFS mount is re-exported over NFS.


327) Out-of-bounds write (CVE-ID: CVE-2026-89653)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause an out-of-bounds write.

The vulnerability exists due to improper bounds checking in the fixed stack bitmap used by check_new_map() when processing a decoded MDSMap whose export_targets entries contain an out-of-range rank. A remote user can cause an MDSMap containing an out-of-range export target rank to be decoded to cause an out-of-bounds write.


328) Use-after-free (CVE-ID: CVE-2026-89655)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in __kick_flushing_caps() when processing FLUSH_ACK messages during cap flushing. A remote attacker can send a FLUSH_ACK message during cap flushing to trigger a use-after-free condition.

Exploitation requires the FLUSH_ACK to be processed after i_ceph_lock is released and before list iteration resumes.


329) Out-of-bounds write (CVE-ID: CVE-2026-89656)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write beyond the CRUSH workspace.

The vulnerability exists due to improper validation of bucket IDs in the libceph CRUSH map decoder, crush_decode(), when processing a malformed CRUSH map containing a bucket ID that does not match its array slot. A local user can cause the kernel to process such a map and write past a permutation array into memory beyond the CRUSH workspace.


330) Improper input validation (CVE-ID: CVE-2026-89657)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper input validation in the osd_sparse_read() sparse-read extent map handling when processing a malformed sparse-read reply. A remote user can send a malformed sparse-read reply to cause a denial of service.


331) Use-after-free (CVE-ID: CVE-2026-89658)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper object lifetime management in the NFSD NFSv4 revoked-state cleanup function nfs40_clean_admin_revoked() when periodic revoked-state cleanup races client expiration. A local user can trigger client expiration by writing to the clients/ctl file to trigger a use-after-free condition.


332) Use-after-free (CVE-ID: CVE-2026-89659)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to trigger a use-after-free.

The vulnerability exists due to a use-after-free in NFSD delegation revocation when an expired recalled delegation is revoked concurrently with client teardown. A remote user can race delegation revocation with client teardown to trigger a use-after-free.

During the race window, the delegation is on neither the client's active-delegation list nor revoked-delegation list.


333) Use-after-free (CVE-ID: CVE-2026-89660)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to trigger a use-after-free condition.

The vulnerability exists due to a race condition in nfsd4_revoke_states() when revoking NFS stateids concurrently with client teardown. A local privileged user can cause client teardown to race with state revocation to trigger a use-after-free condition.


334) Use-after-free (CVE-ID: CVE-2026-89662)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in the NFSD __destroy_client() function when processing DESTROY_CLIENTID requests. A remote attacker can trigger client teardown while blocked locks are reaped to cause a denial of service.

The race can result in a NULL dereference in remove_blocked_locks().


335) Use-after-free (CVE-ID: CVE-2026-89663)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in the NFS server copy-notify stateid revocation logic when revoking copy-notify stateids while concurrent holders retain references. A remote attacker can trigger concurrent copy-notify stateid revocation to cause a denial of service.

The issue involves parent-stateid draining, OFFLOAD_CANCEL handling, and laundromat expiry.


336) Integer overflow (CVE-ID: CVE-2026-89665)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause improper filesystem timestamp handling.

The vulnerability exists due to an integer overflow in the NFSv2 sattr decoder in svcxdr_decode_sattr() when decoding NFSv2 SETATTR or CREATE time attributes. A remote attacker can send a crafted NFSv2 request containing an out-of-range useconds value to cause improper filesystem timestamp handling.

The overflow affects 32-bit ILP32 platforms.


337) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-89666)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt on-disk timestamp metadata.

The vulnerability exists due to improper validation of specified quantities in input in NFSv3 SETATTR and create operation handlers when processing client-supplied atime or mtime values with an out-of-range nanoseconds field. A remote attacker can send specially crafted NFSv3 SETATTR, CREATE, MKDIR, SYMLINK, or MKNOD requests to corrupt on-disk timestamp metadata.

Affected filesystems include ext4 and XFS with bigtime support.


338) Race condition (CVE-ID: CVE-2026-89667)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to a race condition in the nfsd file cache when file disposal occurs concurrently with per-network shutdown. A local user can trigger concurrent file disposal and per-network shutdown to cause a resource leak.


339) Use-after-free (CVE-ID: CVE-2026-89669)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to a use-after-free in copy-notify state initialization when racing a crafted OFFLOAD_CANCEL request against COPY_NOTIFY processing. A remote attacker can send a crafted OFFLOAD_CANCEL request to trigger a use-after-free condition.

Exploitation requires a matching client ID and a guessable state object ID.


340) Improper input validation (CVE-ID: CVE-2026-89671)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to remove POSIX ACLs.

The vulnerability exists due to improper input validation in nfsd3_proc_setacl() when processing NFSv3 SETACL requests with omitted ACL mask bits. A remote attacker can send a SETACL request with omitted ACL mask bits to remove POSIX ACLs.


341) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-89672)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to remove POSIX ACLs.

The vulnerability exists due to improper handling of omitted ACL fields in the NFSACL v2 SETACL handler when processing SETACL requests with omitted ACL mask bits. A remote attacker can send a SETACL request with omitted ACL mask bits to remove POSIX ACLs.

A request containing only the NFS_ACL mask bit removes the directory's default ACL, while a request with a zero mask removes both ACL types.


342) Out-of-bounds write (CVE-ID: CVE-2026-89674)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write beyond the reserved XDR buffer or disclose uninitialized kernel memory.

The vulnerability exists due to an incorrect XDR buffer size calculation in nfsd4_ff_encode_layoutget() when encoding layoutget responses with short user or group strings and an odd-sized file handle. A remote attacker can request a layoutget operation to write beyond the reserved XDR buffer or disclose uninitialized kernel memory.


343) Expired pointer dereference (CVE-ID: CVE-2026-89676)

CWE-ID: CWE-825 - Expired pointer dereference

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an expired pointer dereference in the nfsd asynchronous COPY stateid IDR handling when processing asynchronous NFS COPY requests. A remote attacker can submit an asynchronous COPY request to cause a denial of service.

Exploitation requires an IDR walker to dereference reused request memory whose contents resemble an expired NFS4_COPYNOTIFY_STID.


344) Memory leak (CVE-ID: CVE-2026-89680)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in nfsd4_copy() when handling failed inter-server COPY operations. A remote attacker can trigger an inter-server COPY setup failure to cause a denial of service.


345) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89683)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to consume system resources.

The vulnerability exists due to missing release of a resource in nfsd_set_fh_dentry() when processing crafted NFSv3 filehandles targeting a V4ROOT export's fsid. A remote attacker can send a crafted NFSv3 filehandle to consume system resources.

The dentry reference leak is triggered on every request.


346) Race condition (CVE-ID: CVE-2026-89684)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a race condition in the NFS server copy-notification state handling when processing concurrent NFSv4.2 OFFLOAD_CANCEL requests. A remote attacker can send racing OFFLOAD_CANCEL requests to cause a denial of service.


347) Incorrect calculation (CVE-ID: CVE-2026-89685)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a clock domain mismatch in the NFS server clients_still_reclaiming() function when sending CLAIM_PREVIOUS OPEN requests. A remote attacker can send CLAIM_PREVIOUS OPEN requests to cause a denial of service.


348) Race condition (CVE-ID: CVE-2026-89686)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a race condition in nfsd4_alloc_layout_stateid when concurrently revoking a delegation and processing a LAYOUTGET request. A remote attacker can send concurrent NFS requests that trigger delegation recall and layout-state allocation to cause a denial of service.

Exploitation requires one NFS client to hold a delegation and fail to respond to its recall while another client opens the same file.


349) Use-after-free (CVE-ID: CVE-2026-89688)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to trigger a use-after-free.

The vulnerability exists due to improper reference counting in nfs4_preprocess_seqid_op() when retrying a sequence-ID operation replay while replay-owner teardown is underway. A remote user can send a sequence-ID operation replay during replay-owner teardown to trigger a use-after-free.


350) Use-after-free (CVE-ID: CVE-2026-89690)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to use-after-free in the NFS server's NFSv4 compound operation buffer handling when an rpc_status netlink dump reads operation numbers concurrently with NFSv4 compound request completion. A local user can initiate concurrent operations to trigger a use-after-free.


351) Out-of-bounds read (CVE-ID: CVE-2026-89691)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose adjacent slab memory.

The vulnerability exists due to an out-of-bounds read in the RPC status dumpit handler when processing released NFSv4 compound arguments with a stale operation count. A local user can access the netlink status interface to disclose adjacent slab memory.

The exposure requires rq_status_counter to be stuck at an odd value.


352) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-89693)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to create objects without the requested access control lists.

The vulnerability exists due to improper handling of ACL translation errors in nfsd4_create() when processing NFSv4 CREATE requests containing ACLs. A remote attacker can submit a crafted NFSv4 CREATE request that causes ACL translation to fail to create objects without the requested access control lists.


353) Missing Authorization (CVE-ID: CVE-2026-89694)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper access control in the NFS server copy-notify state management function when processing OFFLOAD_CANCEL requests. A remote user can send an OFFLOAD_CANCEL request for another client's copy-notify stateid to cause a denial of service.

Copy-notify stateid object identifiers are allocated cyclically and are guessable.


354) NULL pointer dereference (CVE-ID: CVE-2026-89696)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the NFS server compound request dispatch loop when processing a crafted NFSv4 COMPOUND request involving an inter-SSC COPY operation. A remote attacker can send a crafted NFSv4 COMPOUND request with an operation between a foreign PUTFH and SAVEFH to cause a denial of service.

Only systems with CONFIG_NFSD_V4_2_INTER_SSC enabled are affected.


355) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-89697)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a SETATTR operation without a mount write reference.

The vulnerability exists due to missing mount write reference acquisition in nfsd_proc_setattr() when processing a SETATTR request in the BOTH_TIME_SET branch. A remote attacker can submit a SETATTR request with both time attributes set to perform a SETATTR operation without a mount write reference.


356) Out-of-bounds read (CVE-ID: CVE-2026-89698)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in nfsd_genl_rpc_status_compose_msg() when handling IPv6 NFS client addresses. A local user can request RPC status information through the generic netlink interface to disclose sensitive information.

The IPv6 netlink address attributes can include rq_flags data in place of part of an IPv6 address.


357) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-89699)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled memory allocation in nfsd4_decode_create() when processing NFSv4 CREATE requests for symbolic links. A remote attacker can send crafted requests containing an oversized symbolic-link target length to cause a denial of service.

The allocation can persist until COMPOUND operation teardown.


358) Out-of-bounds read (CVE-ID: CVE-2026-89700)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to read out-of-bounds memory.

The vulnerability exists due to improper length validation in the nfsd netlink listener_set handler when processing a netlink listener configuration containing a malformed socket address. A local privileged user can send a crafted listener configuration with a truncated AF_INET6 socket address to read out-of-bounds memory.

Exploitation requires the CAP_NET_ADMIN capability.


359) Out-of-bounds write (CVE-ID: CVE-2026-89702)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write beyond a reserved trace ring-buffer slot or disclose prior ring-buffer contents.

The vulnerability exists due to an out-of-bounds write in the nfsd_fh_verify and nfsd_fh_verify_err tracepoints when processing NFSv2/v3-over-UDP requests. A remote attacker can send an NFS/UDP request to write a server socket address into a zero-byte trace ring-buffer slot.

When the local server address is shorter than the remote address, unwritten bytes in the oversized slot can be exposed to trace consumers.


360) Use-after-free (CVE-ID: CVE-2026-89703)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to trigger a use-after-free.

The vulnerability exists due to use-after-free in nfsd4_drop_revoked_stid() when handling FREE_STATEID for admin-revoked delegations. A remote user can cause a freed delegation to be added to cl_revoked to trigger a use-after-free.


361) Race condition (CVE-ID: CVE-2026-89704)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause silent data loss.

The vulnerability exists due to a race condition in _nfsd_copy_file_range() when processing asynchronous NFS COPY operations. A remote user can issue concurrent COPY and COMMIT or stable WRITE operations to cause silent data loss.


362) Improper handling of exceptional conditions (CVE-ID: CVE-2026-89706)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause copied data to be silently lost.

The vulnerability exists due to improper handling of writeback errors in the NFS server async COPY operation in _nfsd_copy_file_range() when processing an asynchronous COPY request whose writeback fails. A remote attacker can issue an asynchronous COPY request that encounters a writeback failure to cause copied data to be silently lost.


363) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89707)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper resource release in nfsd_cross_mnt() when handling NFS requests that result in follow_down() errors. A remote user can send NFS requests that trigger failed cross-mount operations to cause a denial of service.

The issue is reachable through nfsd_lookup_dentry or NFSv4 READDIR encoding.


364) Use-after-free (CVE-ID: CVE-2026-89708)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to use-after-free in the NFS server callback session handling when terminating an NFSv4 session while a callback RPC task remains in flight. A remote user can send a DESTROY_SESSION request while a callback RPC task remains in flight to cause a denial of service.


365) Memory leak (CVE-ID: CVE-2026-89710)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a memory leak.

The vulnerability exists due to improper resource cleanup in pnfs_layout_process() in the NFSv4.1 pNFS implementation when processing a new layout stateid returned while a valid stateid is still held. A remote attacker can operate an NFSv4.1 server that returns a new layout stateid to cause a memory leak.


366) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-89711)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a kernel warning.

The vulnerability exists due to an incorrect warning condition in nfsd_mode_check when processing NFS client LOOKUP requests for exported NFS filesystems that lack a lookup method. A remote attacker can issue a LOOKUP request to trigger a kernel warning.

The condition can occur when reexporting an NFS filesystem.


367) Use-after-free (CVE-ID: CVE-2026-89712)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a use-after-free in nfsd4_ssc_expire_umount() when processing concurrent NFS server operations while an expired inter-server source mount is being unmounted. A remote attacker can trigger concurrent operations that cause the expiration walk to dereference a freed nfsd4_ssc_umount_item to cause a denial of service.


368) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-89713)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to truncate append-only files.

The vulnerability exists due to a time-of-check to time-of-use race condition in nfsd_setattr() when handling SETATTR size updates for append-only files. A remote user can issue a SETATTR request that races with a concurrent append to truncate append-only files.


369) NULL pointer dereference (CVE-ID: CVE-2026-89717)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the zram compression algorithm handling when querying the compression algorithm after compressors have been reset. A local user can query the compression algorithm to cause a denial of service.


370) Memory corruption (CVE-ID: CVE-2026-89718)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to access slots outside of table bounds.

The vulnerability exists due to improper synchronization in writeback_store() when a device is reset and reconfigured with a smaller disksize while writeback_store() is waiting to acquire dev_lock. A local privileged user can reset and reconfigure the device with a smaller disksize during the lock acquisition to access slots outside of table bounds.


371) Race condition (CVE-ID: CVE-2026-89719)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds access.

The vulnerability exists due to a race condition in read_block_state() when reading block state information while a zram device is reset and reinitialized with a smaller disk size. A local user can read block state information during this condition to perform an out-of-bounds access.


372) Out-of-bounds read (CVE-ID: CVE-2026-89720)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read beyond allocated memory.

The vulnerability exists due to an out-of-bounds read in ubifs_sb_verify_signature() when mounting a crafted signed UBIFS image. A local user can provide an image with an inflated signature length to read beyond allocated memory.

The signature is processed before it is cryptographically checked.


373) Out-of-bounds read (CVE-ID: CVE-2026-89723)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an out-of-bounds memory access.

The vulnerability exists due to improper deletion of an intermediate B-tree node in the NILFS2 block mapping implementation when truncating a file causes a B-tree mapping to collapse into a direct mapping. A local user can truncate a file to cause a residual B-tree node to be processed as a direct mapping entry and trigger an out-of-bounds memory access.

The residual node remains dirty in the B-tree node cache and can subsequently be processed by the log writer.


374) Out-of-bounds write (CVE-ID: CVE-2026-89724)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt adjacent kernel heap memory.

The vulnerability exists due to an out-of-bounds write in the vicodec FWHT encoder when encoding a four-component pixel format whose planes take the unencoded fallback. A local user can submit a crafted frame to corrupt adjacent kernel heap memory.


375) Out-of-bounds write (CVE-ID: CVE-2026-89725)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write peer-controlled bytes out of bounds into surrounding memory.

The vulnerability exists due to an out-of-bounds write in stm32_rx_done() in the STM32 CEC driver when processing an overlong CEC message from a peer. A remote attacker can send a CEC message without ending it to write peer-controlled bytes out of bounds into surrounding memory.

The driver must be probed and receiving must be enabled.


376) Out-of-bounds read (CVE-ID: CVE-2026-89726)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory beyond the specified length.

The vulnerability exists due to an off-by-one out-of-bounds read in ucs2_strnlen() in lib/ucs2_string.c when processing a UCS-2 string that is not NUL-terminated within the caller-provided maximum length. A local user can supply a non-NUL-terminated UCS-2 string to read memory beyond the specified length.


377) Out-of-bounds write (CVE-ID: CVE-2026-89729)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause an out-of-bounds write.

The vulnerability exists due to an out-of-bounds write in sensor_hub_get_feature() when processing a malicious HID descriptor. An attacker with physical access can provide a HID descriptor advertising a large feature field size to cause an out-of-bounds write.

An IIO caller supplying a small stack buffer can be affected.


378) Out-of-bounds read (CVE-ID: CVE-2026-89730)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in altera_cvp_send_block() in the Altera CvP FPGA driver when processing an input buffer with one to three trailing bytes. A local user can provide a crafted FPGA image with trailing bytes to cause a denial of service.


379) Out-of-bounds read (CVE-ID: CVE-2026-89731)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to improper bounds checking in cxl_rch_get_aer_info() when copying AER capability registers from the RCRB MMIO block. A local user can trigger retrieval of AER information to cause an out-of-bounds read.


380) Deadlock (CVE-ID: CVE-2026-89732)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a deadlock in ffs_ep0_read() in the FunctionFS USB gadget function when a userspace daemon repeatedly reads ep0 while the gadget is asynchronously torn down via configfs. A local user can repeatedly read ep0 during asynchronous gadget teardown to cause a denial of service.


381) Use-after-free (CVE-ID: CVE-2026-89733)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to use-after-free in the UVC gadget function cleanup paths when handling bind errors or unbinding the function. A local user can trigger the affected cleanup paths to access freed memory.


382) Memory leak (CVE-ID: CVE-2026-89735)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper resource cleanup in the Linux kernel MIDI 2 USB gadget function's configfs default groups when tearing down function instances or cleaning up endpoint options. A local user can tear down a MIDI 2 gadget function instance or clean up endpoint options to cause a memory leak.


383) Use-after-free (CVE-ID: CVE-2026-89736)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to use-after-free in the USB gadget u_audio sound card cleanup handling when accessing or closing open ALSA control file descriptors after sound card teardown is initiated. A local user can access or close open ALSA control file descriptors to cause memory corruption.

ALSA control callbacks can dereference private data associated with a freed sound card context.


384) Use-after-free (CVE-ID: CVE-2026-89738)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the at91 UDC driver's polled-VBUS timer and work cycle when removing the driver while a timer callback or work item is pending or running. A local user can unbind the driver while a timer callback or work item is pending or running to cause a denial of service.

Only systems configured to use polled-VBUS mode are affected.


385) Use-after-free (CVE-ID: CVE-2026-89740)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a use-after-free in the i.MX UART driver imx_uart_ports[] table when concurrent UART probe and removal operations occur. A local user can trigger sibling UART operations to trigger a use-after-free condition.


386) Double free (CVE-ID: CVE-2026-89741)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a double-free condition.

The vulnerability exists due to a double free in __video_register_device() when handling a device_register() failure. A local user can trigger a device registration failure to cause a double-free condition.


387) Use-after-free (CVE-ID: CVE-2026-89742)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in dma_req_free() when freeing DMA requests through the RapidIO mport character device interface. A local user can trigger the release of a mapping whose final reference is dropped and subsequently unlock a mutex through the freed mapping to cause a denial of service.


388) Out-of-bounds read (CVE-ID: CVE-2026-89743)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose kernel heap memory.

The vulnerability exists due to an out-of-bounds read in the NSM response-processing path when processing a response length reported by an NSM device backend that exceeds the response buffer. A local user can trigger processing of an oversized reported response length to disclose kernel heap memory.


389) Infinite loop (CVE-ID: CVE-2026-89744)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an infinite loop in fwnode_get_next_child_node() when iterating over children of a fwnode with a secondary fwnode that has more than one child. A local user can trigger the child-node iteration to cause a denial of service.


390) Use-after-free (CVE-ID: CVE-2026-89746)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the Linux kernel trace event histogram trigger handling when a hist trigger references a variable after same-name named triggers have been registered. A local user can write crafted hist triggers to tracefs to cause a denial of service.


391) Use-after-free (CVE-ID: CVE-2026-89747)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the trace_pipe read path when changing the ring buffer sub-buffer order while an event is being processed. A local user can change the sub-buffer order while a trace_pipe reader is dereferencing a peeked event to cause a denial of service.


392) Unchecked Return Value (CVE-ID: CVE-2026-89749)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an unchecked return value in event_test_stuff() when kthread creation fails. A local user can trigger a kthread creation failure that results in an error pointer being passed to kthread_stop() to cause a denial of service.

The failure can occur under memory pressure during the boot-time event self-test.


393) Use-after-free (CVE-ID: CVE-2026-89750)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper reference count handling in the tracing user-events user_event_mm_dup() function when allocating tracing state during task duplication fails. A local user can fork a process to trigger a use-after-free condition.


394) Off-by-one (CVE-ID: CVE-2026-89751)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect port I/O handling.

The vulnerability exists due to an off-by-one error in handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c when emulating port I/O operations. A local user can perform port I/O operations that invoke the affected handlers to cause incorrect port I/O handling.


395) Race condition (CVE-ID: CVE-2026-89752)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the memory.high and memory.max limit update handlers when concurrently updating memory cgroup limits through separate open files. A local user can lower a memory.max limit and restore it through another open file to cause a denial of service.

Exploitation requires a cgroup populated with anonymous memory and swapping disabled.


396) Improper locking (CVE-ID: CVE-2026-89753)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause RCU Tasks stalls.

The vulnerability exists due to improper RCU quiescent-state handling in shrink_lruvec() in mm/vmscan.c when performing direct memory reclaim. A local user can trigger direct memory reclaim to cause RCU Tasks stalls.

The issue occurs on PREEMPTION kernels, where cond_resched() does not report a Tasks-RCU quiescent state.


397) Operation on a Resource after Expiration or Release (CVE-ID: CVE-2026-89755)

CWE-ID: CWE-672 - Operation on a Resource after Expiration or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to stale mapping use in __migrate_device_pages() when migrating device pages after freeing swapcache. A local user can trigger device-page migration involving a folio removed from the swap cache to cause a denial of service.

The issue can occur after a large folio is split into order-0 folios.


398) Improper locking (CVE-ID: CVE-2026-89756)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in migrate_pages_batch() when migrating large batches of folios. A local user can trigger a large batch of folio migrations to cause a denial of service.

On KVM hosts, MMU notifier invalidation callbacks can cause migration batches to run for an extended period.


399) Resource exhaustion (CVE-ID: CVE-2026-89759)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in the kmemleak task stack scanning routine when scanning task stacks on a host with very many threads. A local user can initiate a kmemleak scan that processes task stacks without rescheduling to cause a denial of service.

Task stack scanning must be enabled.


400) Out-of-bounds write (CVE-ID: CVE-2026-89761)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the AppArmor label vector setup used by aa_label_strn_parse() when parsing label names containing multiple "//&"-separated components. A local user can supply a crafted label name to cause memory corruption.

Every label component must resolve to a loaded profile.


401) Use-after-free (CVE-ID: CVE-2026-89762)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in AppArmor credential handling when replacing stale labels while the task uses overridden credentials. A local user can cause stale-label replacement while using overridden credentials to trigger a use-after-free condition.


402) Use-after-free (CVE-ID: CVE-2026-89763)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the trusted TPM key type teardown routine when a trusted key operation races with module teardown. A local user can trigger a race between a trusted key operation and module teardown to cause a denial of service.


403) Use of Uninitialized Variable (CVE-ID: CVE-2026-89765)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose uninitialized kernel stack memory.

The vulnerability exists due to use of uninitialized memory in put_itimerval() when calling getitimer() on native sparc64 systems. A remote attacker can invoke getitimer() to disclose uninitialized kernel stack memory.


404) Incorrect calculation (CVE-ID: CVE-2026-89768)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect file path information to be reported.

The vulnerability exists due to incorrect path handling in backing_file_open() when mapping files through nested overlayfs mounts. A local user can map a file through nested overlayfs mounts to cause incorrect file path information to be reported.

Incorrect paths may be shown in procfs memory-map entries and perf or ftrace mmap records.


405) Race condition (CVE-ID: CVE-2026-89771)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a race condition during ring buffer reads.

The vulnerability exists due to a race condition in Linux kernel ring buffer reader operations when concurrently resizing ring buffer subbuffers and reading ring buffer pages. A local user can invoke concurrent subbuffer resizing and ring buffer read operations to trigger a race condition during ring buffer reads.


406) Out-of-bounds read (CVE-ID: CVE-2026-89776)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose kernel memory.

The vulnerability exists due to an out-of-bounds read in the VXLAN VNI filter entry policy when processing short GROUP or GROUP6 netlink attributes. A remote attacker can submit specially crafted netlink attributes to disclose kernel memory.

The over-read bytes are stored in remote_ip and returned through RTM_GETTUNNEL.


407) Use-after-free (CVE-ID: CVE-2026-89777)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free caused by a dangling pointer in vfio pci MSI permission-table handling when MSI permission-table initialization fails. A local user can cause MSI permission-table initialization to fail and subsequently access MSI configuration to compromise system confidentiality, integrity, and availability.

The per-device structure persists across open and close cycles.


408) Out-of-bounds read (CVE-ID: CVE-2026-89778)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read memory out of bounds.

The vulnerability exists due to an out-of-bounds read in zisofs_fill_pages() when reading a compressed file on a mounted ISO9660 image containing a crafted ZF Rock Ridge record. A remote attacker can provide a crafted ISO9660 image to read memory out of bounds.

The issue is triggered when an empty zisofs block follows a sub-page block with a nonzero page offset.


409) Out-of-bounds read (CVE-ID: CVE-2026-89779)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper bounds validation in the NTFS3 extended-attribute record parser when processing a crafted NTFS image. A remote attacker can provide an extended-attribute record with an undersized size field to disclose sensitive information.


410) NULL pointer dereference (CVE-ID: CVE-2026-89780)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in rmnet_map_deaggregate() when processing an aggregated frame containing a flow-control command. A local user can write a crafted aggregated frame to a tap device file descriptor to cause a denial of service.

Exploitation requires an rmnet link over a tap device with ingress deaggregation and ingress MAP commands enabled.


411) Out-of-bounds read (CVE-ID: CVE-2026-89781)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper validation of an on-disk offset in read_log_rec_buf() when mounting a crafted NTFS image. A remote attacker can mount a crafted NTFS image to compromise confidentiality, integrity, and availability.


412) Numeric Truncation Error (CVE-ID: CVE-2026-89782)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds memory access.

The vulnerability exists due to integer truncation in the NTFS3 restart table handling in fs/ntfs3/fslog.c when replaying a crafted NTFS $LogFile. A remote attacker can mount a crafted NTFS image to cause an out-of-bounds memory access.


413) Out-of-bounds write (CVE-ID: CVE-2026-89783)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an out-of-bounds write in xfrm6_input_addr() when processing an inner IPv6 packet containing a destination-options HAO option or a type-2 routing header. A remote attacker can send a specially crafted packet to compromise confidentiality, integrity, and availability.

Exploitation requires the transport-mode receive path to re-enter IPv6 input with a secpath whose length is at the maximum depth.


414) NULL pointer dereference (CVE-ID: CVE-2026-89784)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in rpcb_register_inet4() and rpcb_register_inet6() when an in-kernel RPC service registers with the local rpcbind after an address-string allocation fails. A local user can cause an in-kernel RPC service to register with the local rpcbind to cause a denial of service.

Exploitation requires sufficient memory pressure for a small GFP_KERNEL allocation to fail.


415) Out-of-bounds read (CVE-ID: CVE-2026-89785)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to read beyond the allocated buffer.

The vulnerability exists due to an out-of-bounds read in ntfs_reparse_init() and ntfs_objid_init() when mounting a crafted NTFS filesystem image containing a malformed resident INDEX_ROOT attribute. A local privileged user can mount a crafted filesystem image to read beyond the allocated buffer.

Exploitation requires CAP_SYS_ADMIN.


416) Out-of-bounds read (CVE-ID: CVE-2026-89786)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.

The vulnerability exists due to an out-of-bounds read in ext4_read_inline_dir() when processing inline directory entries during getdents64() calls. A remote attacker can cause the kernel to process an inline directory entry whose header extends beyond the inline buffer to disclose sensitive information and cause a denial of service.


417) Out-of-bounds read (CVE-ID: CVE-2026-89787)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in ext4_search_dir() when processing a crafted directory entry during a directory lookup. A local user can provide a crafted directory entry to read out-of-bounds memory.

The issue affects casefolded encrypted directories that store hash values in directory entries on the sb_no_casefold_compat_fallback() path.


418) Use-after-free (CVE-ID: CVE-2026-89789)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose and modify sensitive information and cause a denial of service.

The vulnerability exists due to use-after-free in the gtp_newlink() error path in drivers/net/gtp.c when handling gtp_newlink() error paths concurrently with gtp encapsulation receive operations. A local user can trigger the race condition to disclose and modify sensitive information and cause a denial of service.


419) Out-of-bounds read (CVE-ID: CVE-2026-89792)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and cause a denial of service.

The vulnerability exists due to out-of-bounds read in the ksmbd share configuration response handling when processing IPC share configuration responses with malformed variable-length fields. A local user can provide a crafted share configuration response to disclose sensitive information and cause a denial of service.


420) Improper access control (CVE-ID: CVE-2026-89793)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt kernel-written command-buffer fields.

The vulnerability exists due to improper access control in ublk_ch_mmap() when upgrading a read-only ublk character-device mapping with mprotect(). A local user can change the mapping to writable and modify per-queue command-buffer entries to corrupt kernel-written command-buffer fields.


421) Out-of-bounds read (CVE-ID: CVE-2026-89794)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose uninitialized kernel heap memory.

The vulnerability exists due to an out-of-bounds read in the ksmbd smb2_read_pipe() function when handling compound SMB pipe read responses. A remote attacker can issue an SMB pipe read request that causes alignment padding to be included in a response to disclose uninitialized kernel heap memory.


422) Integer overflow (CVE-ID: CVE-2026-89796)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in kdamond_merge_regions() in the DAMON core when merging DAMON regions after online parameter updates. A local user can configure DAMON with an excessively large aggregation interval and numerous non-contiguous regions to cause a denial of service.

Exploitation requires the region count to remain above the user-defined upper limit after aggressive merging.


423) Race condition (CVE-ID: CVE-2026-89798)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in rpcrdma_rn_register() when device removal races with notification registration. A local user can trigger concurrent notification registration and device removal to cause a denial of service.


424) Race condition (CVE-ID: CVE-2026-89799)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper synchronization in bpf_get_stackid when accessing the trace entries buffer returned by get_perf_callchain. A local user can invoke bpf_get_stackid to compromise confidentiality, integrity, and availability.


425) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-89800)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the nouveau UVMM bind-job unwind handling when a later operation in a bind job fails after a successful sparse unmap. A local user can cause a later operation in a bind job to fail after a successful sparse unmap to cause a denial of service.


426) Use-after-free (CVE-ID: CVE-2026-89801)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in the OP_UNMAP_SPARSE arm of nouveau_uvmm_bind_job_submit() when handling failed sparse unmap operations. A local user can submit a sparse unmap operation to compromise confidentiality, integrity, and availability.


427) NULL pointer dereference (CVE-ID: CVE-2026-89802)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the reverse unwind loop of nouveau_uvmm_bind_job_submit() when processing a bind job containing a successful sparse mapping operation followed by a later failing operation. A local user can submit a crafted bind job to cause a denial of service.


428) Use-after-free (CVE-ID: CVE-2026-89803)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a use-after-free in the Nouveau channel teardown handler when a channel-kill event is delivered during channel destruction. A local user can trigger a channel-kill event during the teardown window to execute arbitrary code.

The issue affects Fermi and newer GPUs; the kill event must occur while the channel is being destroyed.


429) NULL pointer dereference (CVE-ID: CVE-2026-89807)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the AMD KFD device queue manager when restoring a CRIU queue through KFD_IOC_CRIU_OP_RESTORE. A local privileged user can issue the ioctl with a crafted queue restore object to cause a denial of service.

Exploitation is limited to queue types for which the restore_mqd callback is not implemented.


430) Improper update of reference count (CVE-ID: CVE-2026-89816)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper reference counting in complete_signaling() in the DRM atomic UAPI when an atomic DRM ioctl using DRM_MODE_PAGE_FLIP_EVENT is blocked while waiting for fences. A local user can issue the atomic DRM ioctl with a sw_sync fence and send a signal to the blocked thread to cause a memory leak.

The condition was observed with amdgpu and vkms.


431) Improper Null Termination (CVE-ID: CVE-2026-89817)

CWE-ID: CWE-170 - Improper Null Termination

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to perform an out-of-bounds read.

The vulnerability exists due to improper null termination in gud_connector_add_tv_mode() when processing TV mode names received from a USB device. An attacker with physical access can provide TV mode names that are not NUL-terminated to perform an out-of-bounds read.


432) Integer overflow (CVE-ID: CVE-2026-89818)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and cause a denial of service.

The vulnerability exists due to an integer overflow in the AMDGPU VCN message parser when processing a VCN message with an oversized buffer count. A local user can submit a specially crafted VCN message to disclose sensitive information and cause a denial of service.

Triggering the issue additionally requires an approximately 4 GiB mapping.


433) Out-of-bounds read (CVE-ID: CVE-2026-89819)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the AMD display plane degamma LUT handling when processing a malformed AMD_PLANE_DEGAMMA_LUT property blob. A local user can set a malformed plane degamma LUT to cause a denial of service or disclose sensitive information.

The AMD_PLANE_DEGAMMA_LUT property is exposed only in builds with AMD_PRIVATE_COLOR defined.


434) Division by zero (CVE-ID: CVE-2026-89821)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a divide-by-zero error in the __is_lut_linear() function when processing a single-entry lookup table. A local user can trigger processing of a single-entry lookup table to cause a denial of service.


435) NULL pointer dereference (CVE-ID: CVE-2026-89822)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in i915_pci_probe() when a device is force-bound through the sysfs driver_override interface. A local user can force-bind a device to the i915 driver to cause a denial of service.


436) Race condition (CVE-ID: CVE-2026-89823)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a race condition in drm_dev_register() error handling when a partially registered DRM minor is opened and an ioctl is processed. A local user can open the registered minor and issue an ioctl while device resources are being torn down to compromise confidentiality, integrity, and availability.


437) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89824)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a resource leak.

The vulnerability exists due to a missing release of an i2c adapter reference in the drm/panel-edp panel driver when handling probe failures or driver unbinding with a devicetree ddc-i2c-bus property referring to the auxiliary ddc bus. A local privileged user can cause a panel driver probe failure or unbind to cause a resource leak.


438) Integer overflow (CVE-ID: CVE-2026-89825)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to integer overflow in the Panthor firmware control interface initialization routines when calculating control-interface offsets from firmware-provided strides. A local user can cause offset calculations to wrap and map invalid firmware control interfaces to compromise confidentiality, integrity, and availability.


439) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-89830)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a permanent leak of valid block counts.

The vulnerability exists due to improper error handling in __allocate_data_block() when a new data block allocation fails. A local user can trigger a data block allocation failure to cause a permanent leak of valid block counts.

The leaked accounting affects total_valid_block_count and i_blocks.


440) Out-of-bounds write (CVE-ID: CVE-2026-89834)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform out-of-bounds I/O.

The vulnerability exists due to incomplete iteration over active curseg types in free_segment_range() when shrinking an F2FS filesystem. A local user can initiate a filesystem shrink operation while active in-memory curseg types reside in the target range to perform out-of-bounds I/O.

Non-persistent in-memory curseg types, including CURSEG_COLD_DATA_PINNED and CURSEG_ALL_DATA_ATGC, can remain in the truncated range.


441) NULL pointer dereference (CVE-ID: CVE-2026-89835)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the f2fs ckpt_thread_ioprio sysfs store path when writing the checkpoint thread I/O priority through sysfs while checkpoint merge is enabled and no checkpoint thread is running. A local user can write a checkpoint thread I/O priority value through sysfs to cause a denial of service.

A read-only mount is one condition in which no checkpoint merge thread is started.


442) Incorrect authorization (CVE-ID: CVE-2026-89839)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to modify the system.advise extended attribute without proper authorization.

The vulnerability exists due to improper authorization in f2fs_xattr_advise_set() when setting the system.advise extended attribute through an idmapped f2fs mount. A local user can attempt to set the system.advise extended attribute to modify the system.advise extended attribute without proper authorization.


443) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-89842)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an unintended firmware doorbell write.

The vulnerability exists due to improper firmware state validation in qla_nvme_xmt_ls_rsp and qla2xxx_process_purls_pkt when handling NVMe LS responses or PURLS packets while firmware is stopped or resetting. A local user can cause an LS reject IOCB to be emitted to trigger an unintended firmware doorbell write.


444) Use of uninitialized resource (CVE-ID: CVE-2026-89843)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of uninitialized stack memory in qla2xxx BSG handlers when processing a short user-supplied BSG request payload. A local user can submit a specially crafted short BSG request to disclose sensitive information.

The information leak occurs in qla2x00_read_fru_status() and qla2x00_read_i2c().


445) Race condition (CVE-ID: CVE-2026-89844)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt host map data.

The vulnerability exists due to improper locking in qla24xx_report_id_acquisition() in the qla2xxx SCSI driver when processing format-1 report ID acquisition. A remote attacker can trigger concurrent host map updates to corrupt host map data.


446) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-89845)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a time-of-check to time-of-use race condition in qla2x00_error_entry() when handling error entries during request-queue teardown. A local user can trigger processing of an error entry while the request queue is being torn down to cause a denial of service.

The response-queue interrupt can remain registered while request queues are being torn down.


447) Out-of-bounds read (CVE-ID: CVE-2026-89846)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in qla2x00_status_entry() in the qla2xxx SCSI driver when processing an FCP response containing an oversized response information length. A remote attacker can send a crafted FCP response with an oversized rsp_info_len value to disclose sensitive information.


448) Use-after-free (CVE-ID: CVE-2026-89847)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in qla2x00_async_iocb_timeout() in the qla2xxx SCSI driver when an async IOCB timeout races with response interrupt completion. A remote attacker can trigger the race condition to compromise confidentiality, integrity, and availability.


449) Use-after-free (CVE-ID: CVE-2026-89848)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in the qla2xxx request queue handling when processing response-queue interrupts during queue teardown. A remote attacker can trigger a late response completion during queue teardown to compromise confidentiality, integrity, and availability.


450) Type Confusion (CVE-ID: CVE-2026-89849)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a wild pointer dereference.

The vulnerability exists due to type confusion in the qla2x00_status_entry() SCSI fast path when processing an unexpected STATUS_TYPE IOCB for a non-SCSI handle. A remote attacker can cause an unexpected STATUS_TYPE IOCB for a non-SCSI handle to be processed to cause a wild pointer dereference.


451) Improper locking (CVE-ID: CVE-2026-89850)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in qla2x00_fw_state_show() when querying firmware state while the chip is down or EEH is busy. A local user can query the firmware state to cause a denial of service.


452) NULL pointer dereference (CVE-ID: CVE-2026-89851)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in qla2x00_dfs_fce_write() when parsing a value written to the debugfs FCE trace interface. A local user can write a valid numeric value to the interface to cause a denial of service.

Invalid values can unintentionally enable FCE tracing.


453) Use of Uninitialized Variable (CVE-ID: CVE-2026-89852)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of an uninitialized variable in qla2x00_get_firmware_state() when querying firmware state through sysfs during a mailbox command failure. A local user can read firmware state through the fw_state or mpi_fw_state sysfs handlers during such a failure to disclose sensitive information.


454) Use-after-free (CVE-ID: CVE-2026-89853)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to a race condition in qla2xxx FCE trace buffer handling when a debugfs FCE disable occurs during firmware dump processing. A local user can disable FCE tracing through debugfs during a firmware dump to trigger a use-after-free.


455) Use-after-free (CVE-ID: CVE-2026-89854)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in the qla2xxx driver's 84xx_fw_version sysfs attribute handler when concurrently reading the attribute during host teardown. A local user can read the 84xx_fw_version sysfs attribute during host teardown to compromise confidentiality, integrity, and availability.


456) Race condition (CVE-ID: CVE-2026-89855)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause corruption of flash version reads.

The vulnerability exists due to improper synchronization in the qla2x00_sysfs_write_reset reset handler when the update cache versions without reset sysfs reset operation is invoked concurrently with a VPD or optrom flash operation. A local user can invoke the reset operation while a concurrent flash operation accesses the same hardware flash registers to cause corruption of flash version reads.


457) Numeric Truncation Error (CVE-ID: CVE-2026-89856)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt memory or cause a denial of service.

The vulnerability exists due to numeric truncation in the qla2xxx MSI-X queue-count calculation when deriving queue counts from MSI-X vector counts. A remote attacker can cause a zero queue count to be used for queue allocation to corrupt memory or cause a denial of service.

Target mode can also underflow the queue count after decrementing it.


458) Improper locking (CVE-ID: CVE-2026-89857)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause duplicated or dropped commands.

The vulnerability exists due to improper locking in the qla_nvme_ls_reject_iocb() request-ring handling when processing NVMe-FC link-service error responses and purex packets. A remote attacker can send NVMe-FC link-service traffic that triggers concurrent request-ring operations to cause duplicated or dropped commands.


459) Out-of-bounds read (CVE-ID: CVE-2026-89858)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose kernel stack memory to a device.

The vulnerability exists due to an out-of-bounds read in qla2x00_update_fru_versions() when processing BSG requests with an oversized declared image count. A local user can submit a crafted BSG request to disclose kernel stack memory to a device.


460) Race condition (CVE-ID: CVE-2026-89860)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt workqueue state, causing system crashes or a looping worker.

The vulnerability exists due to a race condition in the qla2xxx NVMe abort work handling when multiple aborts are issued for the same command while its abort work item is queued. A remote attacker can trigger repeated aborts for the same command to corrupt workqueue state, causing system crashes or a looping worker.


461) Use-after-free (CVE-ID: CVE-2026-89861)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in qla24xx_report_id_acquisition() in the qla2xxx SCSI driver when a virtual port is concurrently deallocated after it is found in the virtual port list. A remote attacker can trigger the race condition to compromise confidentiality, integrity, and availability.


462) NULL pointer dereference (CVE-ID: CVE-2026-89863)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in qla_chk_edif_rx_sa_delete_pending() when processing a firmware status completion for a command that has already been returned or aborted. A remote attacker can trigger processing of such a status completion to cause a denial of service.

The kernel crash occurs in interrupt context.


463) Out-of-bounds write (CVE-ID: CVE-2026-89864)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to corrupt kernel heap and stack memory.

The vulnerability exists due to improper bounds checking in the qla2x00_write_i2c() and qla2x00_read_i2c() I2C BSG handlers when processing a user-supplied I2C length. A local privileged user can submit a crafted I2C BSG request with an oversized length to corrupt kernel heap and stack memory.

Exploitation requires CAP_SYS_RAWIO.


464) Use of uninitialized resource (CVE-ID: CVE-2026-89865)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and modify device flash contents.

The vulnerability exists due to use of uninitialized memory in the qla2xxx FRU and I2C BSG handlers when processing a user-controlled payload that overrides the transfer length. A local user can send a crafted BSG request to disclose sensitive information and modify device flash contents.


465) Double free (CVE-ID: CVE-2026-89870)

CWE-ID: CWE-415 - Double Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a double free in zoran_exit_video_devices() when unregistering a registered video device during device teardown. A local user can trigger device teardown to cause memory corruption.


466) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-89871)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in the video-i2c driver's streaming functions when a capture-thread startup fails. A local user can invoke streaming operations after a capture-thread startup failure to cause a denial of service.


467) Memory leak (CVE-ID: CVE-2026-89872)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak fwnode references.

The vulnerability exists due to a missing reference release in v4l2_fwnode_parse_link when parsing a link. A local user can trigger link parsing to leak fwnode references.


468) NULL pointer dereference (CVE-ID: CVE-2026-89874)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in v4l2_async_match_notify() in the v4l2-async subsystem when ancillary media link creation fails. A local user can trigger ancillary media link creation failure to cause a denial of service.


469) Integer overflow (CVE-ID: CVE-2026-89876)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger undefined behavior.

The vulnerability exists due to an integer overflow in the tda18250 media driver when exp equals zero. A local user can cause exp to equal zero to trigger undefined behavior.


470) Use-after-free (CVE-ID: CVE-2026-89877)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a use-after-free condition.

The vulnerability exists due to a use-after-free in the saa7164_dev_setup() error path when PCI BAR memory-region allocation fails during device setup. A remote attacker can trigger the affected error path to cause a use-after-free condition.


471) Out-of-bounds read (CVE-ID: CVE-2026-89878)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in s2255_probe() when processing a firmware blob shorter than eight bytes. A local user can supply a firmware blob shorter than eight bytes to read out-of-bounds memory.


472) Out-of-bounds write (CVE-ID: CVE-2026-89879)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to write beyond the destination buffer.

The vulnerability exists due to an out-of-bounds write in the s2255_fillbuff() JPEG/MJPEG frame handling code when processing a device-supplied JPEG frame header. An attacker with physical access can provide a crafted frame header with an oversized jpg_size value to write beyond the destination buffer.


473) Improper resource shutdown or release (CVE-ID: CVE-2026-89880)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper error-path resource cleanup in rtl2832_sdr_start_streaming() when starting streaming after a prior failed streaming attempt. A local user can initiate streaming again after a failed streaming attempt to compromise confidentiality, integrity, and availability.

The out-of-bounds access occurs during URB cleanup when urbs_initialized exceeds MAX_BULK_BUFS.


474) Memory leak (CVE-ID: CVE-2026-89881)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service by leaking DMA resources.

The vulnerability exists due to improper resource cleanup in the rtl2832_sdr driver removal handling when a USB device is disconnected while streaming remains active. A local user can close a file descriptor after the disconnection to cause a denial of service by leaking DMA resources.


475) Improper resource shutdown or release (CVE-ID: CVE-2026-89883)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper resource cleanup in the sunxi-cir driver when probe initialization fails after rc device registration. A local user can trigger a probe failure to compromise confidentiality, integrity, and availability.


476) NULL pointer dereference (CVE-ID: CVE-2026-89884)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a missing null pointer check in the mtk-mdp3 platform driver when initializing the driver before the SCP driver has been bound. A local user can cause the affected driver to initialize before the SCP driver is bound to cause a denial of service.


477) Improper update of reference count (CVE-ID: CVE-2026-89885)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper reference count handling in the mtk-mdp3 mdp_probe() fallback SCP device lookup when the SCP handle lookup fails. A remote attacker can trigger the MDP device probe to compromise confidentiality, integrity, and availability.


478) Memory leak (CVE-ID: CVE-2026-89886)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to missing cleanup of asynchronous notifier connections in isys_notifier_init() when parsing or adding fwnode remote subdevices. A local user can trigger a parsing or addition failure after connections have been added to cause a resource leak.


479) Double free (CVE-ID: CVE-2026-89887)

CWE-ID: CWE-415 - Double Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a kernel panic.

The vulnerability exists due to improper resource lifecycle management in the ov7740_remove() function when removing the ov7740 driver. A local user can trigger driver removal to cause a kernel panic.


480) Use-after-free (CVE-ID: CVE-2026-89888)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code, disclose sensitive information, modify data, or cause a denial of service.

The vulnerability exists due to use-after-free in the ov02a10_check_hwcfg() function of the ov02a10 media I2C driver when handling endpoint configuration. A local user can trigger hardware configuration checking to execute arbitrary code, disclose sensitive information, modify data, or cause a denial of service.


481) Use-after-free (CVE-ID: CVE-2026-89890)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in go7007 ALSA PCM callbacks when a capture PCM remains open during V4L2 device release. A local user can retain an open capture PCM during V4L2 device release to compromise confidentiality, integrity, and availability.


482) Use-after-free (CVE-ID: CVE-2026-89891)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to use-after-free in the em28xx device-list handling during extension closure when disconnecting a dual transport-stream device through the audio-only path. An attacker with physical access can connect a USB device with crafted endpoint descriptors to cause a denial of service.


483) Use-after-free (CVE-ID: CVE-2026-89892)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to trigger a use-after-free.

The vulnerability exists due to improper device list management in the em28xx audio-only extension registration path when connecting and disconnecting a dual-TS board. An attacker with physical access can connect and disconnect a dual-TS board to trigger a use-after-free.

The condition affects audio-only paths on dual-TS boards.


484) Use-after-free (CVE-ID: CVE-2026-89893)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read or modify sensitive information and cause a denial of service.

The vulnerability exists due to a use-after-free in the NetUP CI status work handling in drivers/media/pci/cx23885/cimax2.c when tearing down a NetUP CI device while CI status work is pending or running. A local user can trigger device teardown while the queued status worker can still access freed state to read or modify sensitive information and cause a denial of service.


485) Out-of-bounds write (CVE-ID: CVE-2026-89894)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a heap-based out-of-bounds write.

The vulnerability exists due to a heap-based buffer overflow in cx231xx VBI buffer handling in cx231xx_do_vbi_copy() when changing video geometry while a VBI stream is running. A local user can allocate a small VBI buffer and change the video width or standard to write past the allocated buffer.

Exploitation requires the device to deliver a field-2 VBI payload.


486) Double free (CVE-ID: CVE-2026-89895)

CWE-ID: CWE-415 - Double Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in the cobalt ALSA initialization error cleanup path when initializing cobalt ALSA support. A local user can cause cobalt_alsa_init() to fail after snd_cobalt_card_create() to cause a denial of service.


487) Memory leak (CVE-ID: CVE-2026-89896)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in the V4L2 control handler in cedrus_init_ctrls() when allocation of ctx->ctrls fails. A local user can trigger the allocation failure path to cause a denial of service.


488) Race condition (CVE-ID: CVE-2026-89897)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a race condition in cec_receive_notify() when handling CEC messages concurrently with follower mode changes or release. A remote attacker can send CEC messages during concurrent follower mode changes or release to compromise confidentiality, integrity, and availability.


489) Out-of-bounds write (CVE-ID: CVE-2026-89898)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an out-of-bounds write in the extron_process_received function when processing malformed incoming data. A remote attacker can send malformed incoming data to compromise confidentiality, integrity, and availability.


490) Use-after-free (CVE-ID: CVE-2026-89899)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free race condition in cec_transmit_msg_fh in the CEC subsystem when a blocking transmit wait is interrupted by a signal. A local user can interrupt a blocking transmit wait with a signal to compromise confidentiality, integrity, and availability.


491) Memory leak (CVE-ID: CVE-2026-89900)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper memory release in cec_unregister_adapter() when unregistering a CEC adapter. A local user can trigger CEC adapter unregistration to cause a memory leak.


492) NULL pointer dereference (CVE-ID: CVE-2026-89901)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the Airspy USB driver when closing a streaming device after it has been disconnected. A local user can close the streaming device after disconnection to cause a denial of service.


493) Integer underflow (CVE-ID: CVE-2026-89902)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass a BPF cgroup socket creation policy.

The vulnerability exists due to preempt count underflow in the LoongArch kprobe_singlestep_handler() function when processing an ordinary userspace breakpoint using code 11. A local user can issue a code 11 breakpoint and open a socket from a SIGTRAP handler to bypass a BPF cgroup socket creation policy.

The socket can be attributed to the root cgroup rather than the task's own cgroup.


494) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-89903)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service and corrupt kernel state.

The vulnerability exists due to improper restoration of a stale per-CPU base register in the LoongArch rethook trampoline when a task migrates to another CPU during rethook trampoline handling. A local user can trigger task migration during rethook trampoline handling to cause a denial of service and corrupt kernel state.


495) Out-of-bounds write (CVE-ID: CVE-2026-89904)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the acpi_package_ids[] array when processing a PPTT ACPI table on a LoongArch virtual machine. A remote attacker can trigger the array overflow to cause memory corruption.

The issue can occur on LoongArch virtual machines configured with one core per socket.


496) Improper initialization (CVE-ID: CVE-2026-89908)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper preservation of memslot architecture flags in the LoongArch KVM memory-region handling code when processing a KVM_MR_FLAGS_ONLY memory-region update. A local user can perform a KVM_MR_FLAGS_ONLY update to compromise confidentiality, integrity, and availability.

The issue occurs when guest physical and host virtual address offsets within a PMD differ.


497) Memory leak (CVE-ID: CVE-2026-89909)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to improper cleanup in kvm_loongarch_init() when kvm_init() fails. A local user can trigger a kvm_init() failure to cause a resource leak.


498) Use-after-free (CVE-ID: CVE-2026-89922)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.

The vulnerability exists due to improper synchronization in __import_wp_info() when importing watchpoint data during a concurrent memslot update. A local user can initiate watchpoint data import while a concurrent memslot update occurs to disclose sensitive information, modify data, or cause a denial of service.


499) Memory leak (CVE-ID: CVE-2026-89923)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in KVM s390 vCPU destruction when destroying a vCPU while hardware breakpoints remain armed. A local user can destroy a vCPU with armed hardware breakpoints to cause a denial of service.

The leaked allocations are charged to memory cgroups and can pin dying memory cgroups.


500) Memory leak (CVE-ID: CVE-2026-89924)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the s390 KVM guest debug watchpoint import error path when importing watchpoint data from a KVM_SET_GUEST_DEBUG request. A local user can submit a KVM_SET_GUEST_DEBUG request in which a later watchpoint fails to import to cause a denial of service.

The request can be repeated, leaking up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes per failed request.


501) Memory leak (CVE-ID: CVE-2026-89925)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to missing release of memory in KVM s390 guest debug handling when successfully processing KVM_SET_GUEST_DEBUG requests. A local user can repeatedly issue successful KVM_SET_GUEST_DEBUG requests to cause a denial of service.


502) Numeric Truncation Error (CVE-ID: CVE-2026-89926)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to numeric truncation in the KVM s390 __import_wp_info() function when importing user-supplied hardware breakpoint information. A local user can supply an oversized breakpoint length value to trigger a kernel warning.


503) Integer overflow (CVE-ID: CVE-2026-89927)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an integer overflow in the KVM x86 Hyper-V synthetic timer deadline calculation when programming a synthetic timer with a count value close to U64_MAX. A remote attacker can program a synthetic timer with a crafted count value to cause a denial of service.


504) Race condition (CVE-ID: CVE-2026-89929)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper synchronization of TLB invalidation in KVM nested virtualization INVVPID emulation when a virtual machine is migrated between physical CPUs. A local user can cause L1 to migrate between physical CPUs while emulating INVVPID to compromise confidentiality, integrity, and availability.


505) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-89930)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause stale TLB translations to be used.

The vulnerability exists due to failure to service queued local TLB flush requests in KVM nVMX nested VM-entry handling when a nested VM entry fails after switching to the L2 context. A remote attacker can change L2's VPID and trigger a failed nested VM entry to cause stale TLB translations to be used.


506) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-89931)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause vmcs12 pages to be double-mapped.

The vulnerability exists due to improper state management in KVM nVMX nested VM-Exit handling when emulating a nested VM-Exit. A local user can trigger a nested VM-Exit without the pending request being cleared to cause vmcs12 pages to be double-mapped.

The condition can occur if KVM exits VM-Enter without processing the request before emulating VMLAUNCH or VMRESUME.


507) Improper initialization (CVE-ID: CVE-2026-89932)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose or modify sensitive information, or cause a denial of service.

The vulnerability exists due to improper initialization of last_vpid in KVM nested VMX VPID management when reusing a VPID after an L1 guest transitions from VMXOFF to VMXON and runs an L2 guest. A local user can cause stale TLB entries associated with a previous VPID lifetime to be used to disclose or modify sensitive information, or cause a denial of service.


508) NULL pointer dereference (CVE-ID: CVE-2026-89933)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in dps310_probe() in the DPS310 pressure sensor driver when probing a device enumerated through its ACPI HID. A local user can trigger probing of the affected device to cause a denial of service.


509) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89934)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to prevent the device from autosuspending.

The vulnerability exists due to a runtime PM reference leak in ltrf216a_get_lux() when a sensor data read fails. A local user can trigger a failed sensor data read to prevent the device from autosuspending.


510) Improper resource shutdown or release (CVE-ID: CVE-2026-89936)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leave the Vcc regulator enabled indefinitely.

The vulnerability exists due to improper resource shutdown or release in m62332_set_value() when writing successive non-zero values to a channel before writing zero. A local user can write successive non-zero values to a channel before writing zero to leave the Vcc regulator enabled indefinitely.


511) Unchecked Return Value (CVE-ID: CVE-2026-89937)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an error return in the SGP30 driver sgp_probe() and sgp_remove() functions when IAQ thread creation fails. A local user can cause IAQ thread creation to fail and subsequently trigger device removal to cause a denial of service.


512) Use-after-free (CVE-ID: CVE-2026-89938)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in the Atlas sensor driver's IRQ work handling when a pending irq_work executes after device removal. A local user can cause pending IRQ work to execute after device removal to compromise confidentiality, integrity, and availability.

Exploitation requires an enabled IIO buffer.


513) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89939)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to prevent the device from autosuspending.

The vulnerability exists due to a missing release of a runtime PM reference in atlas_buffer_postenable() when enabling an IIO buffer and interrupt configuration fails. A local user can enable an IIO buffer to prevent the device from autosuspending.


514) Use-after-free (CVE-ID: CVE-2026-89940)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a use-after-free in the iio_dma_fence implementation when a dma fence outlives its associated iio_dmabuf_priv object. A local user can cause a dma fence to access a lock after the associated object has been freed to execute arbitrary code.


515) Use-after-free (CVE-ID: CVE-2026-89941)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in the IIO DMA fence release implementation when releasing an IIO DMA fence. A local user can trigger the release of an IIO DMA fence to compromise confidentiality, integrity, and availability.


516) Use-after-free (CVE-ID: CVE-2026-89942)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in the anonymous IIO buffer release function when releasing an anonymous buffer handle after its underlying IIO device has been removed. A local user can release an anonymous buffer handle holding the last reference to the underlying IIO device to compromise confidentiality, integrity, and availability.


517) Access of Uninitialized Pointer (CVE-ID: CVE-2026-89943)

CWE-ID: CWE-824 - Access of Uninitialized Pointer

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause undefined behavior.

The vulnerability exists due to access of an uninitialized pointer in loongson_card_parse_acpi() when processing the codec-dai-name ACPI property. A remote attacker can trigger processing of a missing or invalid codec-dai-name property to cause undefined behavior.


518) Improper update of reference count (CVE-ID: CVE-2026-89944)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper reference count management in hdac_hda_dev_probe() when ASoC component registration fails during device probing. A local privileged user can cause component registration to fail to cause a denial of service.


519) Race condition (CVE-ID: CVE-2026-89945)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause improper hardware register operations.

The vulnerability exists due to a race condition in the cs35l34 runtime suspend handler when runtime power management suspends the codec while critical fault IRQs remain unmasked. A local user can trigger runtime power management to cause improper hardware register operations.


520) Race condition (CVE-ID: CVE-2026-89946)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect processing of amplifier fault release paths.

The vulnerability exists due to a race condition in the cs35l33 codec driver's runtime suspend and threaded IRQ handling when a threaded IRQ handler executes after runtime suspend has disabled live register access. A local user can cause a threaded IRQ handler to execute during runtime suspend to cause incorrect processing of amplifier fault release paths.

Critical fault IRQs must remain unmasked during runtime power management.


521) Out-of-bounds read (CVE-ID: CVE-2026-89947)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information, modify data, and cause a denial of service.

The vulnerability exists due to an incorrect parent count in the gxbb_32k_clk_sel clock mux when registering the clock mux. A remote attacker can trigger registration of the affected clock mux to disclose sensitive information, modify data, and cause a denial of service.


522) Incomplete cleanup (CVE-ID: CVE-2026-89948)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause bridge loop avoidance claims to remain after mesh interface deletion.

The vulnerability exists due to incomplete cleanup of claims in the batman-adv bridge loop avoidance claim cleanup logic when deleting a mesh interface. A local user can delete a mesh interface to cause bridge loop avoidance claims to remain after mesh interface deletion.


523) Reliance on undefined behavior (CVE-ID: CVE-2026-89949)

CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of unaligned memory access in the batman-adv distributed ARP table IP extraction functions when processing ARP packets with unaligned data in socket buffers. A remote attacker can send an ARP packet to cause a denial of service.

Only hardware without native support for unaligned reads is affected.


524) Reachable assertion (CVE-ID: CVE-2026-89950)

CWE-ID: CWE-617 - Reachable Assertion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to missing skb linearization in batadv_mcast_forw_expand_head() when processing multicast packets via batadv_mcast_forw_mcsend(). A local user can trigger multicast packet forwarding to cause a denial of service.


525) Use-after-free (CVE-ID: CVE-2026-89951)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in batadv_batman_skb_recv() when processing reassembled fragmented packets. A remote attacker can send fragmented packets to compromise confidentiality, integrity, and availability.

Exploitation requires a hard interface to be deleted before fragment reassembly completes.


526) Out-of-bounds read (CVE-ID: CVE-2026-89952)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to read beyond allocated memory.

The vulnerability exists due to an out-of-bounds read in nand_flash_detect_ext_param_page() when parsing an ONFI extended parameter page with invalid section lengths. An attacker with physical access can supply a malformed ONFI extended parameter page to read beyond allocated memory.


527) Memory leak (CVE-ID: CVE-2026-89953)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a memory leak in the mtdoops notification removal handler when a configured backing MTD device is removed and registered again while mtdoops remains loaded. A local privileged user can repeatedly remove and register the configured backing MTD device to exhaust vmalloc memory.

The issue is only exposed when the backing MTD device can disappear and later be registered again; typical static MTD configurations do not expose it.


528) Out-of-bounds read (CVE-ID: CVE-2026-89954)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information, modify data, or cause a denial of service through an out-of-bounds memory access.

The vulnerability exists due to improper bounds checking in the AFS v2 parser when parsing a crafted AFS v2 image. A remote attacker can supply an image with a footer offset or region count that exceeds expected bounds to disclose sensitive information, modify data, or cause a denial of service through an out-of-bounds memory access.


529) NULL pointer dereference (CVE-ID: CVE-2026-89955)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in status_show() when reading the sysfs status attribute during queue probing. A local user can concurrently read the status attribute before queue driver data is set to cause a denial of service.


530) Incorrect Check of Function Return Value (CVE-ID: CVE-2026-89957)

CWE-ID: CWE-253 - Incorrect Check of Function Return Value

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to retain stale hardware access to AP devices removed from the host configuration.

The vulnerability exists due to incorrect handling of the bitmap_andnot() return value in vfio_ap_mdev_hot_unplug_cfg() when the last adapter, domain, or control domain assigned to an mdev is removed. A local user can remove the final assigned AP resource from the host configuration to retain stale hardware access to the unplugged AP devices.


531) NULL pointer dereference (CVE-ID: CVE-2026-89958)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the s390/vfio-ap AP bus configuration callbacks when handling AP bus configuration changes while matrix_mdev->kvm is unset. A local user can trigger the AP bus configuration callbacks to cause a denial of service.


532) Incorrect calculation (CVE-ID: CVE-2026-89959)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise the confidentiality, integrity, and availability of a KVM guest.

The vulnerability exists due to an incorrect bitmap operation in vfio_ap_mdev_cfg_remove when removing control domains from a mediated device. A local user can trigger control-domain removal to compromise the confidentiality, integrity, and availability of a KVM guest.


533) Use-after-free (CVE-ID: CVE-2026-89960)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in the s390 VFIO AP mediated-device KVM assignment handling when executing a PQAP instruction in a guest after a failed conflicting mediated-device assignment and subsequent freeing of the mediated device. A local user can trigger a conflicting mediated-device assignment and execute a PQAP instruction in the guest to compromise confidentiality, integrity, and availability.


534) Incorrect calculation (CVE-ID: CVE-2026-89961)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to incorrect calculation of PFN offsets in vmemmap_populate_compound_pages() when populating compound-page vmemmap mappings. A local user can trigger compound-page vmemmap population to compromise confidentiality, integrity, and availability.


535) Incorrect calculation (CVE-ID: CVE-2026-89962)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause data corruption or crashes.

The vulnerability exists due to incorrect range-merging logic in the powerpc kexec memory-range handling code when merging overlapping memory ranges for a kexec operation. A local privileged user can trigger a kexec operation with overlapping memory ranges to cause data corruption or crashes.


536) NULL pointer dereference (CVE-ID: CVE-2026-89963)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in kexec_extra_fdt_size_ppc64() when calculating extra FDT size during kexec file loading on a platform without reserved memory regions. A local privileged user can invoke kexec file loading to cause a denial of service.


537) Infinite loop (CVE-ID: CVE-2026-89964)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to failure to advance the parsing position in eisa_irq_setup() when processing an invalid eisa_irq_edge kernel command line parameter. A local privileged user can supply an invalid comma-separated IRQ value to cause a denial of service.


538) Out-of-bounds write (CVE-ID: CVE-2026-89965)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in the nvdimm/btt arena I/O path when processing a crafted or foreign arena whose nfree value is below the lane count. A local user can provide a crafted or foreign arena to write past per-lane freelist and rtt array allocations and execute arbitrary code.


539) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-89968)

CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper validation of protocol state in nvmet_tcp_handle_h2c_data_pdu() when processing an unsolicited H2CData PDU before transmitting a requested data transfer (R2T). A remote attacker can send an H2CData PDU for a write command before the R2T is transmitted to cause a denial of service.

The affected subsystem must be configured with allow_any_host.


540) Out-of-bounds write (CVE-ID: CVE-2026-89969)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in nvmet_tcp_try_recv_pdu() when receiving an over-long NVMe/TCP PDU. A remote attacker can send a duplicate ICReq PDU after header digest negotiation to execute arbitrary code.

The attacker-controlled overflow can overwrite the adjacent header and data digest fields before the duplicate ICReq is rejected.


541) Use-after-free (CVE-ID: CVE-2026-89970)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper synchronization of delayed work in the NVMe target authentication submission queue teardown logic when an authentication timeout callback runs during submission queue teardown. A remote attacker can cause the authentication timeout work to race with submission queue teardown to compromise confidentiality, integrity, and availability.


542) Improper input validation (CVE-ID: CVE-2026-89973)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in nvme_tcp_handle_c2h_data() when processing a C2HData PDU for a write command. A remote attacker can send a C2HData PDU in response to a write command to cause a denial of service.

On hosts booted with panic_on_warn, the triggered kernel warning is fatal.


543) Double free (CVE-ID: CVE-2026-89974)

CWE-ID: CWE-415 - Double Free

CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a double free in the nvme-fc controller initialization and cleanup logic when nvme_add_ctrl() fails during controller creation. A remote attacker can trigger the affected error path to compromise confidentiality, integrity, and availability.

The failure is reachable under memory pressure or fault injection.


544) Memory leak (CVE-ID: CVE-2026-89975)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory release in nvmf_parse_options() when parsing malformed DH-CHAP secret options written to /dev/nvme-fabrics. A local user can repeatedly submit malformed dhchap_secret or dhchap_ctrl_secret values to cause a denial of service.

Only systems with CONFIG_NVME_HOST_AUTH enabled are affected. No NVMe-oF target or working transport connection is required.


545) Race condition (CVE-ID: CVE-2026-89979)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause inconsistent PCM state transitions.

The vulnerability exists due to a race condition in ALSA PCM trigger-start handling when concurrently performing non-atomic PCM operations. A local user can concurrently issue a PCM start trigger and non-atomic PCM operations to cause inconsistent PCM state transitions.


546) Race condition (CVE-ID: CVE-2026-89980)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a race condition involving uninitialized locks in the ALSA Harmony driver when a pending interrupt is handled after IRQ registration and before lock initialization. A remote attacker can trigger a pending interrupt during device initialization to compromise confidentiality, integrity, and availability.


547) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-89982)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to missing release of a Device Tree channel node reference in i2c_mux_add_adapter() when adapter registration fails. A local user can trigger an adapter registration failure to cause a memory leak.


548) Use-after-free (CVE-ID: CVE-2026-89983)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the I2C core adapter debugfs directory handling when a write to the new_device sysfs attribute races with adapter removal. A local user can write to the new_device sysfs attribute during adapter removal to cause a denial of service.


549) Improper access control (CVE-ID: CVE-2026-89984)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose kernel addresses.

The vulnerability exists due to improper privilege-level validation in the intel_pmu_lbr_filter() LBR stack filtering function when filtering sampled LBR entries for user-only branch stacks. A local user can request a user-only branch stack through perf to disclose kernel addresses.

The issue affects systems where architectural LBR lacks CPL filtering support.


550) Improper synchronization (CVE-ID: CVE-2026-89986)

CWE-ID: CWE-662 - Improper Synchronization

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper synchronization in alloc_pages_bulk_weighted_interleave() when allocating temporary node weights under an RCU read-side critical section. A local user can trigger the vulnerable allocation while using an MPOL_WEIGHTED_INTERLEAVE memory policy to compromise confidentiality, integrity, and availability.


551) Use-after-free (CVE-ID: CVE-2026-89988)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code, escalate privileges, disclose sensitive information, or cause a denial of service.

The vulnerability exists due to a use-after-free in the kprobe blacklist traversal function __within_kprobe_blacklist() when concurrently checking a kprobe blacklist entry during module unloading. A local user can trigger concurrent blacklist traversal and entry removal to dereference freed memory.

The blacklist traversal can occur in atomic or non-preemptible contexts.


552) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-89989)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of error return values in validate_hash_algo() in IMA appraisal when processing a dentry path that exceeds the buffer. A local user can trigger an extended attribute operation that causes dentry_path() to return an error pointer to cause a denial of service.


553) Use-after-free (CVE-ID: CVE-2026-89990)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in ceph_mds_check_access() when a concurrent MDS session reopen occurs while access is being checked. A remote attacker can trigger concurrent access checking and MDS session reopening to execute arbitrary code.


554) Release of invalid pointer or reference (CVE-ID: CVE-2026-89992)

CWE-ID: CWE-763 - Release of invalid pointer or reference

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an invalid pointer release in the dt_idle_genpd cpuidle power-domain code when freeing an idle power-domain name. A remote attacker can trigger the release of a pointer to the basename rather than the original allocation to compromise confidentiality, integrity, and availability.


555) NULL pointer dereference (CVE-ID: CVE-2026-89993)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a null pointer dereference.

The vulnerability exists due to improper initialization of IRQ data in dw_edma_irq_request() when a shared interrupt is handled before dw_edma_channel_setup() initializes the back pointer. A local user can trigger a shared interrupt during initialization to trigger a null pointer dereference.


556) Use-after-free (CVE-ID: CVE-2026-89994)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the fsl-edma tracing event log output when printing fsl-edma trace log entries after event injection. A local user can inject fsl-edma events and read the trace log to cause a denial of service.


557) Type Confusion (CVE-ID: CVE-2026-89995)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to type confusion in dma_direct_alloc_from_pool() when dma_direct_alloc_pages() uses DMA coherent pool allocations. A remote attacker can trigger DMA page allocation through the affected path to compromise confidentiality, integrity, and availability.


558) Race condition (CVE-ID: CVE-2026-89997)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to a race condition in the device-mapper resume and remove handling when issuing resume and remove ioctls concurrently. A local user can issue resume and remove ioctls concurrently to cause a use-after-free condition.

In the dm-integrity target, the reboot notifier can remain registered after device removal.


559) Race condition (CVE-ID: CVE-2026-89998)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access invalid memory.

The vulnerability exists due to a race condition in the device-mapper table device list handling when processing concurrent table load ioctls. A local user can issue concurrent table load ioctls, causing one operation to succeed while another fails, to access invalid memory.


560) Out-of-bounds read (CVE-ID: CVE-2026-89999)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.

The vulnerability exists due to an out-of-bounds read in wacom_intuos_pro2_bt_irq in the HID Wacom driver when processing undersized Bluetooth reports. A remote attacker can send a crafted undersized Bluetooth report to disclose sensitive information and cause a denial of service.

The peripheral must be paired or spoofed and advertise a matching VID/PID.


561) Out-of-bounds write (CVE-ID: CVE-2026-90000)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information, corrupt memory, or cause a denial of service.

The vulnerability exists due to out-of-bounds read and write operations in the hid-rmi driver when handling undersized RMI reports. A remote attacker can send specially crafted RMI reports to disclose sensitive information, corrupt memory, or cause a denial of service.

A zero-length reply can cause the read loop to run indefinitely with page_mutex held.


562) Race condition (CVE-ID: CVE-2026-90001)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to a race condition in HID BPF struct_ops device reference release when device destruction races with BPF link release. A local user can trigger concurrent device destruction and BPF link release to cause a use-after-free condition.


563) Use-after-free (CVE-ID: CVE-2026-90003)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code, disclose sensitive information, or cause a denial of service.

The vulnerability exists due to a use-after-free in the futex requeue priority-inheritance handling when racing an early waiter wakeup with a priority-inheritance futex requeue. A local user can trigger FUTEX_CMP_REQUEUE_PI operations to access a waiter's stack-allocated futex queue after the waiter returns from the system call.

Exploitation is limited to systems using PREEMPT_RT.


564) Improper resource shutdown or release (CVE-ID: CVE-2026-90007)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leave previously registered interrupt handlers installed.

The vulnerability exists due to incorrect rollback index handling in the pm8001_request_msix() function when handling a request_irq() failure during MSI-X vector registration. A local user can trigger the faulty rollback loop to leave previously registered interrupt handlers installed.


565) Out-of-bounds read (CVE-ID: CVE-2026-90011)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the iSCSI target login payload buffer when processing a crafted login PDU without a terminating null byte. A remote attacker can send a crafted login PDU to disclose sensitive information and cause a denial of service.

Exploitation is reachable through the CHAP authentication path on a portal configured for CHAP.


566) NULL pointer dereference (CVE-ID: CVE-2026-90012)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper DMA mapping cleanup in __spi_map_msg() and spi_unmap_msg() when handling partial DMA mapping failures. A remote attacker can trigger a partial DMA mapping failure to cause a denial of service.


567) Improper resource shutdown or release (CVE-ID: CVE-2026-90015)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause data corruption and leak DMA mappings.

The vulnerability exists due to improper handling of bounce buffers in the xHCI transfer descriptor bounce-buffer cleanup logic when processing sufficiently large fragmented bulk USB transfers that span multiple ring segments. A local user can submit a crafted bulk transfer to cause data corruption and leak DMA mappings.

For IN transfers, unreturned bounce-buffer data can leave a wMaxPacketSize-sized region of the destination buffer containing its previous contents.


568) Out-of-bounds read (CVE-ID: CVE-2026-90017)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in rtw_action_frame_parse() in the rtl8723bs driver when processing a short management action frame. A remote attacker can send a crafted management action frame to cause a denial of service.

The frame can be as short as the 24-byte IEEE 802.11 three-address header.


569) Stack-based buffer overflow (CVE-ID: CVE-2026-90018)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a stack-based buffer overflow in rtw_get_wps_attr() when processing a crafted WPS information element in a wireless management frame. A remote attacker can send a crafted beacon or probe response during scanning to compromise confidentiality, integrity, and availability.


570) NULL pointer dereference (CVE-ID: CVE-2026-90019)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in usb_put_function_instance() when handling an error during UVC function instance allocation. A remote attacker can trigger the error path to cause a denial of service.

The issue occurs before the fd member of the function instance is allocated.


571) Race condition (CVE-ID: CVE-2026-90020)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in gadget_dev_ioctl() when handling ioctl requests concurrently with device binding. A local user can issue ioctl requests during a concurrent bind operation to cause a denial of service.


572) Improper initialization (CVE-ID: CVE-2026-90021)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a kernel warning.

The vulnerability exists due to improper initialization of a work structure in f_midi_alloc() when freeing a MIDI gadget function that was not bound. A local user can free an unbound MIDI gadget function to cause a kernel warning.

The warning occurs in __flush_work because the work function pointer is null.


573) Use-after-free (CVE-ID: CVE-2026-90022)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code, disclose sensitive information, or cause a denial of service.

The vulnerability exists due to use-after-free in the f_midi2 string attribute show path when concurrently reading and writing string attributes. A local user can concurrently access and modify string attributes to execute arbitrary code, disclose sensitive information, or cause a denial of service.


574) NULL pointer dereference (CVE-ID: CVE-2026-90024)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null-pointer dereference in f_midi2_free_ep_reqs() when configuring the MIDI 2.0 gadget through configfs with the block direction set to SNDRV_UMP_DIR_INPUT. A local user can configure the gadget with this block direction to cause a denial of service.

A host must set the alternate setting after the gadget is configured.


575) Out-of-bounds read (CVE-ID: CVE-2026-90025)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the UCSI DisplayPort driver's port altmode array when processing an invalid GET_CURRENT_CAM response from the PPM. A remote attacker can cause the PPM to return an altmode array index above UCSI_MAX_ALTMODES to cause a denial of service.


576) Use-after-free (CVE-ID: CVE-2026-90026)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in the Qualcomm PMIC Type-C PD PHY driver's reset_work handling when pending reset_work executes after device removal frees its associated structure. A local user can trigger the race condition to compromise confidentiality, integrity, and availability.

The race requires the IRQ handler to schedule reset_work immediately before IRQs are disabled.


577) Use-after-free (CVE-ID: CVE-2026-90027)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in the Qualcomm PMIC Type-C port driver when delayed cc_debounce work executes after pmic_typec_port resources are freed. A local user can trigger port shutdown while delayed cc_debounce work is pending to compromise confidentiality, integrity, and availability.


578) Race condition (CVE-ID: CVE-2026-90031)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to trigger a warning that a URB is already active.

The vulnerability exists due to a race condition in the ENE UB6250 USB-storage driver when delayed scan work runs concurrently with card-type probing. An attacker with physical access can cause concurrent access to us->current_urb during device probing to trigger a warning that a URB is already active.


579) Use-after-free (CVE-ID: CVE-2026-90032)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in snd_usbtv_pcm_close() in the usbtv audio driver when closing an ALSA PCM file after USB disconnect. A local user can close a previously opened ALSA PCM file after USB disconnect to compromise confidentiality, integrity, and availability.


580) Out-of-bounds write (CVE-ID: CVE-2026-90033)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in snd_usbmidi_us122l_output() when processing MIDI output for a USB device that declares a bulk endpoint smaller than the expected transfer count. An attacker with physical access can connect a crafted USB device to cause a denial of service.


581) Use of uninitialized resource (CVE-ID: CVE-2026-90034)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in the mdc800 USB driver buffer initialization when receiving shorter messages. An attacker with physical access can send a shorter message to disclose sensitive information.


582) Division by zero (CVE-ID: CVE-2026-90035)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to division by zero in get_estimated_bw() when processing an estimated-bandwidth-change notification from a connected USB4/DPIA tunneling device before a bandwidth-allocation capability-change notification. An attacker with physical access can connect a device that reports an estimated-bandwidth change to cause a denial of service.


583) Use-after-free (CVE-ID: CVE-2026-90036)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the NFSD blocked-lock reaping logic when reaping blocked locks concurrently with client expiration. A remote attacker can cause a client to be freed before nfs4_put_stateowner() dereferences its cl_lock to trigger a use-after-free condition.


584) Use-after-free (CVE-ID: CVE-2026-90037)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in NFSD NFSv4 state management when reaping timed-out close_lru entries concurrently with client expiration. A remote attacker can trigger the use-after-free condition to compromise confidentiality, integrity, and availability.


585) NULL pointer dereference (CVE-ID: CVE-2026-90039)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in NFSD NFSv4 state-revocation and asynchronous COPY walkers when processing unlock filesystem or export operations before NFSD startup completes. A local privileged user can write to the unlock filesystem interface or send an NFSD unlock netlink command to cause a denial of service.

The condition occurs when an NFSD listener has been created but no NFSD thread has started.


586) Use-after-free (CVE-ID: CVE-2026-90041)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a use-after-free in the Sony HID driver's device list handling when handling probe failures for matching controllers. A remote attacker can cause a controller to remain linked in the device list after its driver state is freed to execute arbitrary code.


587) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90042)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of non-linear memory buffers in ceph_fname_to_usr() when processing MDS messages held in vmalloc()-allocated buffers. A remote attacker can cause a message containing encrypted filenames to be processed to cause a denial of service.

The issue can result in kernel oopses, especially on non-x86 platforms.


588) Use-after-free (CVE-ID: CVE-2026-90044)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in ffs_epfile_write_iter() and ffs_epfile_read_iter() when a concurrent cancellation operation runs after an asynchronous I/O operation fails. A local user can submit an asynchronous I/O operation and cancel it concurrently to compromise confidentiality, integrity, and availability.


589) Use-after-free (CVE-ID: CVE-2026-90045)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in the FunctionFS asynchronous I/O handling in drivers/usb/gadget/function/f_fs.c when asynchronous read requests remain pending after the submitting task exits. A local user can queue an asynchronous read request and exit before completion handling finishes to compromise confidentiality, integrity, and availability.


590) Out-of-bounds write (CVE-ID: CVE-2026-90048)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an out-of-bounds write in ni_create_attr_list() in the NTFS3 filesystem driver when processing a crafted loop-mounted NTFS image. A remote attacker can craft an NTFS image containing many nameless minimum-size resident attributes to compromise confidentiality, integrity, and availability.

Exploitation is reached by opening a file on the mounted image and adding an attribute.


591) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90049)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause data corruption.

The vulnerability exists due to improper resource lifetime management in skb_zerocopy() when processing a packet through Open vSwitch's OVS_ACTION_ATTR_USERSPACE path after skb_orphan_frags() fails. A remote attacker can trigger the error path to cause data corruption.


592) Infinite loop (CVE-ID: CVE-2026-90053)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an infinite loop in the HTB packet classifier htb_classify() when processing packets with cyclic inner-class filter selections. A local user can configure cyclic HTB filters and send a packet to cause a denial of service.

Exploitation is reachable through an unprivileged user namespace that provides CAP_NET_ADMIN.


593) Incorrect calculation (CVE-ID: CVE-2026-90054)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt TCP stream data.

The vulnerability exists due to incorrect calculation of the retransmission length in the TCP retransmission path when retransmitting TCP urgent data across multiple segments. A remote attacker can send TCP urgent data that is retransmitted across multiple segments to corrupt TCP stream data.


594) Reliance on undefined behavior (CVE-ID: CVE-2026-90055)

CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger undefined behavior.

The vulnerability exists due to improper initialization of ci_range bit counts in usbatm_atm_init() when processing ATM PVC bind requests. A remote attacker can bind an ATM PVC to trigger undefined behavior.


595) Use of uninitialized resource (CVE-ID: CVE-2026-90056)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use of an uninitialized resource in the FEC Ethernet driver PTP cleanup paths when handling failed device initialization or device removal. A local user can trigger failed device initialization or device removal to cause a denial of service.

PTP initialization is performed only when extended buffer descriptors are available.


596) Use-after-free (CVE-ID: CVE-2026-90057)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free read.

The vulnerability exists due to use-after-free in slip_receive_buf() when racing SLIP receive processing against TTY hangup. A local user can trigger concurrent receive processing and TTY hangup to trigger a use-after-free read.


597) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-90058)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of user-supplied size table values in __qdisc_calculate_pkt_len() when processing a crafted TCA_STAB configuration that amplifies packet length values. A local user can configure a DRR or ETS qdisc with a crafted size table, set a tiny quantum, and send a small packet to cause a denial of service.

The issue requires NET_SCHED and either the DRR or ETS scheduler to be enabled.


598) NULL pointer dereference (CVE-ID: CVE-2026-90060)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the ALSA kcontrol LED state layer when tracking a write-only kcontrol without a get callback. A local user can create a write-only control element without a get callback to cause a denial of service.


599) Incorrect behavior order (CVE-ID: CVE-2026-90062)

CWE-ID: CWE-696 - Incorrect Behavior Order

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an inconsistent state between hardware-offloaded and software rulesets.

The vulnerability exists due to incorrect behavior order in nf_tables commit processing when committing rulesets with hardware flow-rule offload. A local user can commit a ruleset with hardware flow-rule offload to cause an inconsistent state between hardware-offloaded and software rulesets.

The inconsistency can occur if chain blob preparation fails after the hardware ruleset has been offloaded.


600) Integer overflow (CVE-ID: CVE-2026-90063)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a 16-bit gso_segs field overflow.

The vulnerability exists due to improper validation of gso_size in virtio_net_hdr_to_skb when processing TCP packets crafted through an AF_PACKET PACKET_VNET_HDR socket. A local user can submit a TCP packet with a gso_size smaller than TCP_MIN_GSO_SIZE to cause a 16-bit gso_segs field overflow.

The condition applies to TCP packets; UDP GSO permits a gso_size of 1.


601) Memory leak (CVE-ID: CVE-2026-90065)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in IPPROTO_SMC socket initialization when socket creation fails after initialization. A local user can repeatedly create failing IPPROTO_SMC sockets to cause a denial of service.

Exploitation requires the ability to attach a deny-all BPF_CGROUP_INET_SOCK_CREATE program to the user's own cgroup.


602) NULL pointer dereference (CVE-ID: CVE-2026-90066)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper validation of an error pointer in ftrace_direct_multi_init() and ftrace_direct_multi_exit() in samples/ftrace/ftrace-direct-multi-modify.c when unloading the ftrace-direct-multi-modify module after kthread_run() fails. A local privileged user can cause kthread_stop() to receive an error pointer to cause a denial of service.


603) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-90067)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a kernel warning.

The vulnerability exists due to improper validation of banner payload length in the Ceph messenger v2 banner parser when parsing a crafted protocol banner. A remote attacker can send a banner with a zero-length payload to trigger a kernel warning.

The protocol requires banner payloads to contain at least two 64-bit feature fields.


604) Off-by-one (CVE-ID: CVE-2026-90068)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory out of bounds.

The vulnerability exists due to an off-by-one error in snd_soc_dapm_put_enum_double() when writing a second enum channel value. A local user can set the second enum channel value equal to the number of enum items to read one element past the end of the value table.

The affected adav80x control reports two values, and core input validation is disabled by default.


605) Unchecked Return Value (CVE-ID: CVE-2026-90070)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause TPM status checks to complete spuriously.

The vulnerability exists due to an unchecked return value in the st33zp24_status callback when processing failed TPM transport reads. A local user can trigger a TPM status read to cause TPM status checks to complete spuriously.

On I2C transports, this can occur when the register-select write is short or fails.


606) Use-after-free (CVE-ID: CVE-2026-90071)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to failure to restore the skb->dev device pointer in the sch_teql TEQL scheduler when transmitting packets through TEQL slave devices. A local user can cause a packet to retain a stale device pointer after a slave transmission failure.

Exploitation requires a later slave device without a resolved neighbour and deletion of the previous slave while the packet remains queued.


607) Integer overflow (CVE-ID: CVE-2026-90072)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in sfq_init() of the SFQ queueing discipline when initializing SFQ on a device with an MTU that wraps psched_mtu() into the sign bit. A local user can configure a device with a crafted MTU value to cause a denial of service.

Exploitation requires CAP_NET_ADMIN in a user namespace.


608) Integer overflow (CVE-ID: CVE-2026-90073)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in the HHF queuing discipline's hhf_dequeue() function when configuring an HHF qdisc on a device with an oversized MTU. A local user can configure the HHF qdisc to trigger an infinite loop to cause a denial of service.

Exploitation requires CAP_NET_ADMIN in a user namespace and a device whose MTU plus hard-header length wraps psched_mtu() into the sign bit.


609) Integer overflow (CVE-ID: CVE-2026-90074)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to signed integer overflow in the fq_pie queuing discipline when initializing the default quantum from a device MTU. A local privileged user can configure a device with a huge MTU to cause a denial of service.

Exploitation requires CAP_NET_ADMIN in a user namespace and a device whose MTU plus hard header length causes psched_mtu() to wrap into the sign bit.


610) Integer overflow (CVE-ID: CVE-2026-90075)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an integer overflow in the fq_codel queueing discipline initialization when initializing fq_codel on a device whose MTU causes psched_mtu() to wrap into the sign bit. A local privileged user can configure a device with an oversized MTU to cause a denial of service.


611) Integer overflow (CVE-ID: CVE-2026-90076)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in the fq qdisc initialization function fq_init() when initializing an fq qdisc for a device with a huge MTU. A local user can configure a device with an excessively large MTU to cause a denial of service.

Exploitation requires CAP_NET_ADMIN in a user namespace and an MTU plus hard_header_len large enough to make 2 * psched_mtu() wrap.


612) Integer underflow (CVE-ID: CVE-2026-90078)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper length calculation in tcf_skbmod_act() when processing short IP packets at TC ingress. A remote attacker can send a short IP packet to cause a denial of service.

Exploitation requires the skbmod action to process ECN modifications at TC ingress.


613) Race condition (CVE-ID: CVE-2026-90081)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in rds_cong_map_updated() when handling congestion map updates. A local user can race congestion map updates with waiter registration to cause a denial of service.

A sender waiting on a congested port can remain blocked until another congestion update arrives or a signal is delivered, and poll() waiters can miss map-update notifications.


614) NULL pointer dereference (CVE-ID: CVE-2026-90085)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in rvu_dbg_nix_tm_tree_display() when reading the NIX TM tree debugfs path. A local user can read /sys/kernel/debug/octeontx2/nix/tm_tree for a NIX LF whose transmit queues are not set up to cause a denial of service.

The issue is triggered when the SQ context has not been initialized.


615) Improper input validation (CVE-ID: CVE-2026-90088)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in rfcomm_apply_pn() when processing remote parameter negotiation frames. A remote attacker can send a parameter negotiation frame with an MTU value of zero to cause a denial of service.


616) Out-of-bounds read (CVE-ID: CVE-2026-90090)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the Linux kernel btmtksdio_tx_packet() transmit path when transmitting Bluetooth packets over SDIO. A local user can send a packet that causes memory beyond the packet data to be read and sent to the device to disclose sensitive information.


617) Race condition (CVE-ID: CVE-2026-90091)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the L2CAP socket cleanup handler when concurrent L2CAP socket cleanup and channel teardown occur. A local user can trigger concurrent socket cleanup and channel teardown to cause a denial of service.


618) Use-after-free (CVE-ID: CVE-2026-90092)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to a race condition in l2cap_sock_new_connection_cb when handling new L2CAP connections during parent L2CAP channel teardown. A remote attacker can initiate a new L2CAP connection while a parent socket is being torn down to trigger a use-after-free condition.


619) Function Call with Incorrectly Specified Arguments (CVE-ID: CVE-2026-90101)

CWE-ID: CWE-628 - Function Call with Incorrectly Specified Arguments

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an incorrectly specified function argument in the bnxt hardware monitoring event handler when handling hardware monitoring events. A local user can trigger the affected event handler to cause a denial of service.


620) NULL pointer dereference (CVE-ID: CVE-2026-90102)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper cache keying in the NFSv4 pNFS data server cache when processing GETDEVICEINFO data. A remote attacker can supply device information for two device IDs using the same data server address with different major NFS versions to cause a denial of service.


621) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-90103)

CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect buffer size calculation in the NFSv4.2 flexfiles layoutstats encoder when encoding layout statistics for a flexfiles layout. A remote attacker can provide crafted server-controlled filehandle and network-address data to exhaust the send buffer and leave a lock permanently held to cause a denial of service.


622) Memory leak (CVE-ID: CVE-2026-90107)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in smc_llc_flow_stop() when a late duplicate CONFIRM_LINK or ADD_LINK_CONT message arrives before the flow completes. A remote attacker can send a duplicate message during this window to cause a denial of service.


623) Memory leak (CVE-ID: CVE-2026-90108)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a memory leak.

The vulnerability exists due to improper memory management in smc_llc_event_handler() when handling an ADD_LINK request after a CONFIRM_LINK or ADD_LINK_CONT message has been stashed during the SMC_LLC_FLOW_REQ_ADD_LINK state. A remote attacker can send a sequence of LLC messages to cause a memory leak.

The overwritten stashed entry is a kmalloc allocation with no consumer in this flow state.


624) Integer overflow (CVE-ID: CVE-2026-90109)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a 32-bit integer overflow in the gred_enqueue(), bfifo_enqueue(), and plug_enqueue() queue admission functions when calculating queue admission with a backlog exceeding 4 GiB. A local privileged user can attach a qdisc with a queue limit near 4 GiB and enqueue more than 4 GiB of traffic to cause a denial of service.


625) Use of insufficiently random values (CVE-ID: CVE-2026-90110)

CWE-ID: CWE-330 - Use of Insufficiently Random Values

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass IP-keyed ICMP rate limits and infer open UDP ports.

The vulnerability exists due to predictable tree ordering in the inetpeer rate limiting system when processing packets from remote IP addresses. A remote attacker can trigger garbage collection and selectively evict inet_peer entries to bypass IP-keyed ICMP rate limits and infer open UDP ports.

Re-created entries have their rate-limiting token buckets reset to full capacity.


626) Out-of-bounds read (CVE-ID: CVE-2026-90112)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to improper bounds checking in the qlcnic firmware ROM parser and loader when processing a malformed firmware image. A local user can provide a truncated or malformed firmware image to cause an out-of-bounds read.


627) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-90114)

CWE-ID: CWE-195 - Signed to Unsigned Conversion Error

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause unpredictable request return values.

The vulnerability exists due to an incorrect signed-to-unsigned conversion in br_process_vlan_tunnel_info when processing bridge VLAN tunnel range requests. A local user can submit a bridge VLAN tunnel range with descending VLAN IDs to cause unpredictable request return values.


628) NULL pointer dereference (CVE-ID: CVE-2026-90115)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the __xsk_rcv() multi-buffer receive path when allocating buffers for a packet. A local user can supply fill queue entries that are rejected during buffer allocation to cause a denial of service.


629) Memory leak (CVE-ID: CVE-2026-90119)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause resource leaks.

The vulnerability exists due to missing cleanup in snd_ice1712_probe() when a later initialization step fails. A local privileged user can trigger a probe failure to cause resource leaks.


630) Use of Uninitialized Variable (CVE-ID: CVE-2026-90122)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use of an uninitialized variable in visconti_clk_register_gate() when registering a clock gate. A local user can trigger clock gate registration to cause a denial of service.

The issue is exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is enabled.


631) Race condition (CVE-ID: CVE-2026-90124)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause interrupts to be lost.

The vulnerability exists due to a race condition in the Renesas RZ/G2L interrupt controller driver's rzg2l_clear_irq_int() and rzg2l_clear_tint_int() functions when clearing interrupt status bits. A local user can trigger multiple interrupts simultaneously to cause interrupts to be lost.


632) Memory leak (CVE-ID: CVE-2026-90125)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource release in smb2_new_read_req() in the SMB client when handling asynchronous SMB2 read requests after memory registration fails. A local user can issue asynchronous SMB2 read requests during a memory registration failure to cause a denial of service.

Only asynchronous SMB read operations are affected. On hard mounts, replayable failures can repeat the operation without a retransmission-count bound.


633) Memory leak (CVE-ID: CVE-2026-90126)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the pcf8563 RTC driver's CLKOUT clock provider registration when repeatedly binding and unbinding a device. A local privileged user can repeatedly bind and unbind a device or reload the module to cause a denial of service.


634) Memory leak (CVE-ID: CVE-2026-90128)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service through memory resource exhaustion.

The vulnerability exists due to improper resource cleanup in add_direct_chain() in the vdpa/mlx5 memory-region handling code when handling allocation errors while creating a direct memory-region chain. A local user can trigger an allocation error to cause a denial of service through memory resource exhaustion.

Newly allocated direct memory-region entries are kept on a temporary list until the operation succeeds.


635) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-90130)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an initialization failure in the vDPA simulator cleanup path when creating a vDPA simulator and worker creation fails. A local user can trigger vDPA simulator initialization under this failure condition to cause a denial of service.


636) Use-after-free (CVE-ID: CVE-2026-90135)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the alloc_netdev_mqs() reference tracker cleanup when reading ref_tracker debugfs entries after alloc_percpu() or dev_addr_init() fails. A local user can read a ref_tracker debugfs entry to cause a denial of service.


637) Out-of-bounds read (CVE-ID: CVE-2026-90137)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read beyond the bounds of an ACPI package array.

The vulnerability exists due to an out-of-bounds read in the hp-bioscfg password PSWD_ENCODINGS parser when processing a malformed ACPI password encodings package. A local user can trigger parsing of a malformed package to read beyond the bounds of an ACPI package array.


638) Memory leak (CVE-ID: CVE-2026-90138)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a resource leak.

The vulnerability exists due to improper socket error handling in vsock_accept() when accepting a connection after a failed connection attempt on the listener. A remote attacker can perform a failed self-connect and then accept a valid incoming vsock connection to cause a resource leak.

The leak affects virtio and hyperv transports because rejected child sockets are not freed.


639) NULL pointer dereference (CVE-ID: CVE-2026-90139)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in fuse_fill_super_submount when processing an auto-submount after root inode allocation fails under memory pressure. A local user can access an auto-submount to cause a denial of service.


640) Use-after-free (CVE-ID: CVE-2026-90140)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a use-after-free in the cuse module's pending RCU callback handling when unloading the cuse module while a fuse connection release callback remains pending. A local privileged user can close /dev/cuse and unload the cuse module before the callback executes to cause a denial of service.


641) Integer overflow (CVE-ID: CVE-2026-90141)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the FTP helper to configure a data connection with a truncated port or address.

The vulnerability exists due to integer overflow in the ip_vs_ftp_get_addrport() function of the IPVS FTP helper when parsing a crafted FTP PASV or EPSV response. A remote attacker can send a crafted FTP PASV or EPSV response to cause the FTP helper to configure a data connection with a truncated port or address.


642) Improper locking (CVE-ID: CVE-2026-90143)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a kernel warning.

The vulnerability exists due to improper locking in kcm_parse_func_strparser() when executing a KCM strparser BPF program. A local user can invoke BPF map operations from the program to cause a kernel warning.


643) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90147)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to disable and unprepare a clock that was never enabled.

The vulnerability exists due to improper resource lifecycle management in devm_clk_get_optional_enabled_with_rate() when setting a clock rate fails. A local privileged user can invoke the function with a clock rate-setting failure to disable and unprepare a clock that was never enabled.


644) NULL pointer dereference (CVE-ID: CVE-2026-90148)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in nfs4_add_lease() when a lease request races with a delegation return. A local user can trigger the race condition to cause a denial of service.


645) Memory leak (CVE-ID: CVE-2026-90150)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause device resource leaks.

The vulnerability exists due to improper resource cleanup in the pNFS block layout device parsing and cleanup routines when handling child-device parsing failures. A remote attacker can trigger a child-device parsing failure to cause device resource leaks.


646) Use-after-free (CVE-ID: CVE-2026-90151)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free.

The vulnerability exists due to a use-after-free in the NFSv4 callback identifier IDR when an NFSv4.0 callback lookup occurs after a client allocation failure. A remote attacker can trigger an NFSv4.0 callback lookup using the stale callback identifier to trigger a use-after-free.

Exploitation requires an NFSv4.0 client allocation to fail after a callback identifier has been allocated.


647) Memory leak (CVE-ID: CVE-2026-90152)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in ksmbd_session_register() when registering an SMB session and xa_store() fails. A remote attacker can initiate SMB session setup requests that result in failed session registration to cause a denial of service.


648) Incorrect authorization (CVE-ID: CVE-2026-90153)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain unauthorized access.

The vulnerability exists due to improper authorization in smb_check_perm_dacl() in the ksmbd SMB server when processing a crafted DACL during SMB2_CREATE access validation. A remote attacker can submit a crafted DACL containing an access-granting ACE beyond its declared boundary to gain unauthorized access.


649) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-90157)

CWE-ID: CWE-195 - Signed to Unsigned Conversion Error

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a hardened usercopy warning.

The vulnerability exists due to an improper signed-to-unsigned conversion in __cgroup_bpf_run_filter_getsockopt_kern() when a cgroup getsockopt BPF program modifies ctx.optlen after the kernel getsockopt handler has run. A local user can set ctx.optlen to a negative value to trigger a hardened usercopy warning.

The issue affects the kernel-buffer getsockopt path used by TCP_ZEROCOPY_RECEIVE.


650) Deadlock (CVE-ID: CVE-2026-90158)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in nfcon_device() when determining active consoles. A local user can trigger the console device callback to cause a denial of service.


651) Improper locking (CVE-ID: CVE-2026-90159)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to trigger a kernel warning.

The vulnerability exists due to improper locking in bpf_setsockopt() and bpf_getsockopt() when invoking the helpers from cgroup UNIX getname hooks. A local privileged user can call bpf_setsockopt() or bpf_getsockopt() from a BPF program attached to a BPF_CGROUP_UNIX_GETPEERNAME or BPF_CGROUP_UNIX_GETSOCKNAME hook to trigger a kernel warning.


652) Off-by-one (CVE-ID: CVE-2026-90160)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an off-by-one headroom validation error in the lwt_bpf bpf_xmit() path when an LWT_XMIT BPF program modifies skb headroom. A local privileged user can call bpf_skb_change_head() to leave insufficient headroom and cause a denial of service.

On Ethernet, cached hardware-header output requires 16 bytes of headroom although the device hard-header length is 14 bytes.


653) NULL pointer dereference (CVE-ID: CVE-2026-90165)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an invalid pointer dereference in ksmbd_stop_durable_scavenger() when stopping the durable scavenger after its kernel thread fails to start. A local user can cause server reset handling to stop the durable scavenger to cause a denial of service.


654) NULL pointer dereference (CVE-ID: CVE-2026-90166)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in ksmbd_ipc_tree_connect_request() when processing an IPC tree connect request. A remote attacker can send an IPC tree connect request to cause a denial of service.


655) Memory leak (CVE-ID: CVE-2026-90169)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in ksmbd preauthentication session handling when a client disconnects after sending a binding NTLM negotiate request and before sending an authenticate request. A remote attacker can initiate an SMB3.1.1 multichannel binding negotiation and disconnect before authentication completes to cause a denial of service.


656) Out-of-bounds read (CVE-ID: CVE-2026-90170)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory out of bounds.

The vulnerability exists due to an out-of-bounds read in the ksmbd ipc_validate_msg() function when processing undersized IPC responses supplied by the userspace ksmbd daemon. A local user can provide a short IPC response to read memory out of bounds.

The issue is reachable for KSMBD_EVENT_RPC_REQUEST messages.


657) Memory leak (CVE-ID: CVE-2026-90175)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory release in the KSMBD authentication and user-configuration handlers when processing KSMBD login requests. A local user can trigger KSMBD login processing to cause a denial of service.


658) Improper locking (CVE-ID: CVE-2026-90176)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass byte-range lock restrictions.

The vulnerability exists due to improper lock checking in the ksmbd check_lock_range() function when handling one-byte read, write, copychunk, or truncate operations. A remote attacker can issue a one-byte operation that conflicts with an existing byte-range lock to bypass byte-range lock restrictions.


659) Memory leak (CVE-ID: CVE-2026-90178)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a memory leak.

The vulnerability exists due to improper resource release in the coretemp driver when removing a coretemp device on CPUs without package thermal support. A local privileged user can trigger coretemp device removal to cause a memory leak.


660) Use-after-free (CVE-ID: CVE-2026-90180)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the mtip32xx ioctl handlers when an ioctl races with device removal. A local user can issue an ioctl against an already open block device during device removal to trigger a use-after-free condition.

The issue affects both native and compatibility ioctl handlers.


661) Race condition (CVE-ID: CVE-2026-90184)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a race condition in the null_blk configfs attribute store methods when concurrently updating device configuration attributes during device setup. A local privileged user can modify a device configuration attribute during device setup to cause a denial of service.


662) Race condition (CVE-ID: CVE-2026-90185)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a race condition in the null_blk configfs attribute store handlers when concurrently storing configuration attributes through separate configfs file descriptors. A local privileged user can perform concurrent configuration attribute stores to cause a denial of service.


663) NULL pointer dereference (CVE-ID: CVE-2026-90186)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in null_blk shared tag set queue-resize handling when resizing submit_queues or poll_queues through configfs on a device with shared_tags enabled. A local privileged user can resize the per-device queue configuration to cause a denial of service.


664) Memory leak (CVE-ID: CVE-2026-90187)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to missing release of memory in the null_blk zoned device zones array when repeatedly powering a zoned device off and on. A local user can repeatedly power a zoned device off and on to cause a denial of service.


665) Memory leak (CVE-ID: CVE-2026-90188)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in the null_blk module initialization error path when initializing null_blk with shared_tags enabled and device creation fails. A local user can trigger null_blk module initialization under these conditions to cause a denial of service.


666) Use-after-free (CVE-ID: CVE-2026-90189)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a use-after-free in the null_blk err_dev cleanup path when accessing a configfs item that remains reachable after cleanup. A local user can access the reachable configfs item to trigger a use-after-free condition.

Exploitation requires a racing user-created device to be added to the device list before module initialization enters error cleanup.


667) Race condition (CVE-ID: CVE-2026-90189)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause block-device registration to fail.

The vulnerability exists due to a race condition in null_blk initialization when creating and powering on a configfs device during module initialization. A local user can race configfs device creation and power-on operations with module initialization to cause block-device registration to fail.


668) Improper initialization (CVE-ID: CVE-2026-90190)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to improper initialization of a file-scope mutex in the null_blk driver when creating a configfs directory during null_blk initialization. A local user can race a mkdir operation with mutex initialization to trigger a kernel warning.


669) NULL pointer dereference (CVE-ID: CVE-2026-90192)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the qcom_cpucp_mbox_send_data callback when handling a channel-clear notification with null data. A local user can trigger a channel-clear notification to cause a denial of service.

The issue occurs under PREEMPT_RT.


670) Deadlock (CVE-ID: CVE-2026-90193)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in qcom_cpucp_mbox_irq_fn() when handling mailbox interrupts. A local user can trigger mailbox interrupt handling to cause a denial of service.

The issue occurs on systems using PREEMPT_RT, where the channel lock is converted to an rtmutex-based lock.


671) Incomplete cleanup (CVE-ID: CVE-2026-90194)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to consume ACPI device instance IDs.

The vulnerability exists due to incomplete cleanup in the ACPI device registration rollback path when handling a failed device_add() operation. A local user can trigger a device_add() failure to consume ACPI device instance IDs.


672) Incorrect Conversion between Numeric Types (CVE-ID: CVE-2026-90195)

CWE-ID: CWE-681 - Incorrect Conversion between Numeric Types

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect handling of signed kfunc arguments.

The vulnerability exists due to incorrect numeric conversion in the RV64 BPF JIT compiler when processing signed 1-byte and 2-byte kfunc arguments. A local user can invoke a kfunc with signed 1-byte or 2-byte arguments to cause incorrect handling of signed kfunc arguments.


673) Integer overflow (CVE-ID: CVE-2026-90196)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in the SOF topology volume table handling when processing topology mixer control data. A local user can provide topology mixer control data with an oversized maximum value to cause a denial of service.

An inverted minimum and maximum volume range is also invalid.


674) Use-after-free (CVE-ID: CVE-2026-90198)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to a use-after-free in snd_card_do_free() when a managed sound card is unbound while an application retains an open file descriptor. A local user can close the open file descriptor while the managed sound card is being unbound to trigger a use-after-free.


675) Integer overflow (CVE-ID: CVE-2026-90199)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass validation of malformed NTFS attributes.

The vulnerability exists due to an integer overflow in mi_enum_attr() when processing malformed on-disk non-resident NTFS attributes. A local user can supply an attribute with an end virtual cluster number near U64_MAX to bypass validation of malformed NTFS attributes.


676) Integer overflow (CVE-ID: CVE-2026-90200)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in MFT cluster validation in ntfs_init_from_boot() when mounting an NTFS volume with crafted boot-sector MFT cluster numbers. A local user can mount a crafted NTFS volume to cause a denial of service.


677) Use-after-free (CVE-ID: CVE-2026-90201)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a race condition in __page_pool_release_netmem_dma() when page_pool_scrub() runs concurrently with page_pool_put_netmem(). A local user can trigger concurrent page pool destruction and network memory return operations to trigger a use-after-free condition.


678) NULL pointer dereference (CVE-ID: CVE-2026-90202)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the _base_release_memory_pools() function of the mpt3sas driver when releasing PCIe SGL buffers after a partial allocation failure. A local user can trigger memory-pool cleanup after a partial allocation failure to cause a denial of service.


679) Memory corruption (CVE-ID: CVE-2026-90203)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds memory access.

The vulnerability exists due to improper validation of a negative block offset in squashfs_copy_data() when reading a crafted file from a mounted crafted Squashfs filesystem. A local user can read a crafted file with a negative offset to cause an out-of-bounds memory access.

Mounting the crafted Squashfs filesystem requires CAP_SYS_ADMIN.


680) Race condition (CVE-ID: CVE-2026-90207)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the ALSA sequencer MIDI input event handler when closing a rawmidi substream while input events are being processed. A local user can trigger an input event during substream teardown to cause a denial of service.


681) Deadlock (CVE-ID: CVE-2026-90209)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in the s390 debug subsystem's debug area unregistration handling when a debugfs file associated with a debug area is written concurrently with debug area unregistration. A local user can write to an associated debugfs file while debug area unregistration occurs to cause a denial of service.


682) Memory leak (CVE-ID: CVE-2026-90213)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a memory leak.

The vulnerability exists due to improper resource cleanup in the FireWire core build_tree() function when processing an invalid self ID sequence. A remote attacker can cause processing of an invalid self ID sequence to cause a memory leak.


683) Use-after-free (CVE-ID: CVE-2026-90214)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper error handling in xlnx_formatter_pcm_open() in the ASoC Xilinx formatter PCM driver when handling errors during PCM stream initialization. A local user can open a PCM stream that encounters a constraint setup error to trigger a use-after-free condition.

ALSA does not invoke the close callback when opening a stream fails.


684) Memory leak (CVE-ID: CVE-2026-90215)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to prevent a device object from being released.

The vulnerability exists due to improper device reference management in ubi_detach_mtd_dev() when attempting to detach a busy UBI device. A local user can attempt to detach a busy UBI device to prevent a device object from being released.


685) Incomplete cleanup (CVE-ID: CVE-2026-90216)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to leave UBI devices attached after failed module initialization.

The vulnerability exists due to incomplete cleanup in ubi_init_attach() when rolling back initialization after an mtd= parameter specifies an explicit UBI device number. A local privileged user can configure an explicit UBI device number and trigger a later initialization failure to leave UBI devices attached after failed module initialization.


686) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-90218)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to improper handling of an error condition in the RDMA connection manager addr_handler() function when asynchronous address resolution fails to acquire an RDMA device. A local user can initiate asynchronous address resolution for which RDMA device acquisition fails to trigger a kernel warning.


687) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90219)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to missing release of debugfs resources in c4iw_dealloc() when RDMA device registration fails. A local user can trigger a failed RDMA device registration to cause a resource leak.


688) Insertion of Sensitive Information Into Sent Data (CVE-ID: CVE-2026-90220)

CWE-ID: CWE-201 - Insertion of Sensitive Information Into Sent Data

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper sanitization of an embedded variable-length event in bounce_error_event() when reading a bounce event for a queued variable-length event sent to a nonexistent port. A local user can set SNDRV_SEQ_FILTER_BOUNCE, queue a variable-length event, and read the bounce event to disclose sensitive information.

The disclosure consists of eight bytes on 64-bit systems from the client's own pool.


689) Use of uninitialized resource (CVE-ID: CVE-2026-90221)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read uninitialized slab memory.

The vulnerability exists due to improper length validation in the nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() CORE_INIT_RSP parsers when processing a malformed CORE_INIT_RSP packet injected through virtual_ncidev. A local user can inject a malformed response with an inflated number of supported RF interfaces to read uninitialized slab memory.


690) Use-after-free (CVE-ID: CVE-2026-90222)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the PN533 NFC driver send path when command completion races frame transmission. A local user can trigger the race condition to cause a denial of service.


691) Out-of-bounds read (CVE-ID: CVE-2026-90223)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in nfc_llcp_recv_snl() when processing malformed SNL TLVs. A remote attacker can send a malformed SNL frame to perform an out-of-bounds read.

LLCP link activation occurs automatically after NFC-DEP.


692) Use-after-free (CVE-ID: CVE-2026-90224)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a race condition in nci_data_exchange_complete when concurrently closing an NCI device and processing received data. A local user can race device closure with received-data processing to trigger a use-after-free condition.


693) Use-after-free (CVE-ID: CVE-2026-90225)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in nfc_llcp_getsockopt() when racing a getsockopt call with an in-flight bind operation. A local user can invoke getsockopt() while bind() modifies and frees the cached local pointer to trigger a use-after-free condition.


694) Out-of-bounds write (CVE-ID: CVE-2026-90226)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write past a user-supplied buffer.

The vulnerability exists due to improper validation of option-buffer length in nfc_llcp_getsockopt() when handling getsockopt calls with an option length smaller than four bytes. A local user can supply an option buffer with an option length smaller than four bytes to write past a user-supplied buffer.

The issue affects all five supported option names.


695) Missing Authorization (CVE-ID: CVE-2026-90227)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write data despite read-only access restrictions.

The vulnerability exists due to missing authorization in the NVME_IOCTL_SUBMIT_IO ioctl handler when submitting NVMe I/O commands. A local user can invoke the ioctl with a crafted I/O command to write data despite read-only access restrictions.


696) NULL pointer dereference (CVE-ID: CVE-2026-90228)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in nvmet_execute_identify_ns_zns() when processing a host-supplied Identify command with CNS 05h and CSI 02h targeting a file-backed namespace. A remote attacker can send a crafted Identify command targeting a file-backed namespace to cause a denial of service.

The issue is reachable only when CONFIG_BLK_DEV_ZONED is enabled.


697) Use-after-free (CVE-ID: CVE-2026-90229)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the Apple NVMe driver's admin queue during controller removal when a controller fails to initialize and is immediately torn down. A local user can trigger the affected controller removal sequence to cause a denial of service.


698) Out-of-bounds read (CVE-ID: CVE-2026-90230)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read memory beyond an allocated buffer.

The vulnerability exists due to a heap out-of-bounds read in nvmet_auth_negotiate() when processing host-supplied DH-HMAC-CHAP negotiation messages. A remote attacker can send a negotiation message with a truncated transfer length or oversized hash or DH group identifier lists to read memory beyond an allocated buffer.


699) Race condition (CVE-ID: CVE-2026-90235)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger invocation of stale socket callbacks.

The vulnerability exists due to improper synchronization in SUNRPC xprtsock socket callback handling when concurrent socket callback handling occurs during teardown. A remote attacker can race callback processing with socket teardown to trigger invocation of stale socket callbacks.

The issue applies when SUNRPC takes over AF_LOCAL, UDP, or TCP sockets.


700) Use-after-free (CVE-ID: CVE-2026-90241)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause the IOMMU to access freed memory.

The vulnerability exists due to a use-after-free in Intel VT-d scalable-mode context handling when a device probe failure occurs partway through DMA alias processing. A local user can trigger a probe failure after context entries have been programmed to cause the IOMMU to access freed memory.


701) Race condition (CVE-ID: CVE-2026-90243)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause spurious faults or unpredictable behavior.

The vulnerability exists due to a race condition in copied_context_tear_down() in the Intel VT-d IOMMU driver when tearing down copied context entries. A local user can trigger teardown of a copied context entry while its Present bit remains set to cause spurious faults or unpredictable behavior.

On IOMMUs without coherent access to the context table, a zeroed entry may not be visible to hardware when invalidation is submitted.


702) Integer overflow (CVE-ID: CVE-2026-90245)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect overlay viewport register configuration.

The vulnerability exists due to integer overflow in the kyro framebuffer driver's overlay viewport coordinate calculations when processing oversized overlay viewport coordinates. A local user can supply oversized viewport coordinate values to cause incorrect overlay viewport register configuration.


703) Race condition (CVE-ID: CVE-2026-90248)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to silently unlink an active traffic classifier.

The vulnerability exists due to improper ownership tracking in tc_new_tfilter() when handling concurrent traffic-control filter insertions. A local user can race another request to insert a traffic-control filter at the same chain and priority to silently unlink an active traffic classifier.


704) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90249)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper runtime power-management reference handling in the gp2ap002_write_event_config() function when writing duplicate event enable values. A local user can write the same event enable state twice to cause a denial of service.


705) NULL pointer dereference (CVE-ID: CVE-2026-90250)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the cgroup BPF program replacement logic when replacing an attached cgroup BPF program through link_update. A local user can replace an empty attached program with a program that uses per-CPU cgroup storage to cause a denial of service.


706) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-90251)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the kernel to read data beyond the controller response.

The vulnerability exists due to improper validation of an event prefix length in the Bluetooth MSFT read_supported_features() handler when handling an MSFT read supported features response from a Bluetooth controller. A remote attacker can provide a response whose declared event-prefix length exceeds its actual length to cause the kernel to read data beyond the controller response.

The copied data is later used to match incoming vendor events.


707) Memory leak (CVE-ID: CVE-2026-90253)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the Bluetooth MGMT mesh send cancel command handler when a pending mesh send cancel command is cancelled. A local user can cause a pending mesh send cancel command to be cancelled to cause a denial of service.


708) Memory leak (CVE-ID: CVE-2026-90254)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper release of memory in Bluetooth HCI synchronous command queue handling when an advertising timeout expires and a command cannot be queued or a pending entry is canceled. A local user can trigger advertising timeout handling under these conditions to cause a memory leak.


709) Use-after-free (CVE-ID: CVE-2026-90255)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to use-after-free in Bluetooth hci_conn SCO setup handling when queued synchronous setup work accesses a connection after it is freed. A local user can trigger queued SCO setup work that accesses a freed connection to cause a use-after-free condition.

Queued context entries can be canceled before execution, including when the controller is unregistered.


710) Out-of-bounds read (CVE-ID: CVE-2026-90257)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in virtbt_setup_zephyr() when processing a status-only Read Build Information response from a Bluetooth virtio backend. A local user can provide a response containing only a status byte to disclose sensitive information.

Adjacent slab memory bytes may be exposed through the kernel log and the firmware-info debugfs file.


711) Improper handling of exceptional conditions (CVE-ID: CVE-2026-90262)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of read errors in btrfs_read_merkle_tree_page() when reading Merkle tree pages after a transient read failure. A local user can trigger subsequent reads of Merkle tree data to cause a denial of service.


712) Integer underflow (CVE-ID: CVE-2026-90274)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an out-of-bounds memory access.

The vulnerability exists due to an integer underflow in the ETM4x CoreSight trace driver when handling sequencer state transition controls. A local user can configure sequence state controls to trigger an out-of-bounds memory access.

The issue occurs on trace units for which TRCIDR5.NUMSEQSTATE is zero.


713) Improper initialization (CVE-ID: CVE-2026-90275)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the Linux kernel md/raid1 raid1_takeover() function when initiating a RAID1 array takeover. A local user can initiate a RAID1 array takeover to cause a denial of service.


714) Incorrect calculation (CVE-ID: CVE-2026-90279)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect RAID5 bitmap sector mapping.

The vulnerability exists due to improper rounding arithmetic in raid5_bitmap_sector() when processing a write range with a non-power-of-two full RAID5 stripe width. A local user can issue a one-sector write at a full-stripe boundary to cause incorrect RAID5 bitmap sector mapping.


715) NULL pointer dereference (CVE-ID: CVE-2026-90280)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the QMP USB PHY runtime suspend and resume callbacks when runtime power management is re-enabled before the PHY is initialized. A local user can re-enable runtime power management through the sysfs attribute to cause a denial of service.

The issue may also occur during the interval after pm_runtime_enable() and before pm_runtime_forbid().


716) NULL pointer dereference (CVE-ID: CVE-2026-90281)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the Qualcomm SNPS Femto v2 PHY driver's runtime PM callbacks when a runtime suspend callback runs during PHY initialization. A local user can trigger a runtime suspend callback before the PHY instance is ready to cause a denial of service.


717) NULL pointer dereference (CVE-ID: CVE-2026-90282)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the runtime suspend and resume callbacks of the Qualcomm QMP USB legacy PHY driver when runtime power management executes before PHY initialization. A local user can re-enable runtime power management through the sysfs attribute before the PHY is initialized to cause a denial of service.


718) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90283)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause huge page reservations to remain charged.

The vulnerability exists due to improper resource cleanup in the hugetlbfs_fill_super() failure path when initiating a hugetlbfs mount with size or min_size options and root dentry creation fails. A local user can trigger the mount failure path to cause huge page reservations to remain charged.


719) Race condition (CVE-ID: CVE-2026-90284)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the firmware sysfs fallback loader when a userspace helper completes a firmware request after the loading interface is exposed but before the request is added to the pending request list. A local user can write 0 to the loading attribute to cause a denial of service.


720) Race condition (CVE-ID: CVE-2026-90285)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger concurrent flash access operations.

The vulnerability exists due to improper synchronization in qla2x00_sysfs_read_vpd() in the qla2xxx driver when reading VPD data through sysfs while concurrent optrom operations are occurring. A local user can read VPD data through sysfs during concurrent optrom operations to trigger concurrent flash access operations.


721) Race condition (CVE-ID: CVE-2026-90286)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause GPU command submissions to execute out of order.

The vulnerability exists due to improper synchronization in the AMDGPU GFX6 compute queue handling when submitting GPU compute workloads. A local user can submit GPU compute workloads to cause GPU command submissions to execute out of order.

GFX6 compute queues share the command processing path used by graphics queues.


722) Improper resource shutdown or release (CVE-ID: CVE-2026-90287)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak clock and reset resources.

The vulnerability exists due to improper resource shutdown or release in sp_uphy_init() when handling USB PHY initialization failures. A local user can trigger a USB PHY initialization failure to leak clock and reset resources.


723) Improper handling of exceptional conditions (CVE-ID: CVE-2026-90290)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper handling of exceptional conditions in swsusp_arch_suspend() when handling a failure from swsusp_mte_save_tags(). A local privileged user can trigger the hibernation error path to cause a denial of service.


724) Use-after-free (CVE-ID: CVE-2026-90291)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper lifetime management in the kmod dups code when duplicate module requests retain a kmod_dup_req instance across a blocking wait. A local user can issue duplicate module requests while another request is waiting for modprobe completion to trigger a use-after-free condition.


725) Use-after-free (CVE-ID: CVE-2026-90292)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to improper reference counting in the RDMA/siw siw_accept() function when handling a userspace-supplied queue pair that is already in the RTS state. A local user can supply such a queue pair to cause a use-after-free condition.


726) Race condition (CVE-ID: CVE-2026-90293)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a race condition in the iSER target login receive-buffer handling when processing a SCSI command before the final Login Response. A remote attacker can send a SCSI command before receiving the final Login Response to cause a denial of service.


727) Race condition (CVE-ID: CVE-2026-90294)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a race condition in iSER target login-response handling when an initiator submits a SCSI command immediately after receiving the final Login Response. A remote attacker can send a specially timed SCSI command to cause a denial of service.


728) Out-of-bounds write (CVE-ID: CVE-2026-90295)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the imx6q cpufreq driver when probing the driver after it has been unbound. A local user can rebind the driver to cause memory corruption.


729) Memory leak (CVE-ID: CVE-2026-90296)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in the imx6q cpufreq driver when rebinding the driver. A local user can repeatedly rebind the driver to cause a denial of service.


730) NULL pointer dereference (CVE-ID: CVE-2026-90297)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in sun4i_crtc_init() when initializing display layers. A local user can trigger a layer initialization failure to cause a denial of service.


731) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90298)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak device references.

The vulnerability exists due to improper resource release in the sun8i_r40_tcon_tv_set_mux function when configuring the TCON TV multiplexer. A local user can trigger TCON TV multiplexer configuration to leak device references.


732) Use-after-free (CVE-ID: CVE-2026-90302)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the OCFS2 o2net heartbeat callback handling when local-node teardown overlaps heartbeat node-down callback processing. A local user can initiate local-node teardown during heartbeat callback processing to cause a denial of service.


733) Use-after-free (CVE-ID: CVE-2026-90303)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in show_pte() when handling user faults concurrently with munmap() calls. A local user can trigger a user fault while another thread in the same process calls munmap() to cause a denial of service.

Exploitation requires CONFIG_DEBUG_USER=y and the user_debug=31 command-line setting.


734) Out-of-bounds read (CVE-ID: CVE-2026-90307)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the SRP response-processing handlers when processing truncated SRP requests. A remote attacker can send a crafted truncated SRP_CRED_REQ or SRP_AER_REQ to disclose sensitive information.

Exploitation requires an SRP target to advertise a small max_ti_iu_len value during login.


735) Use-after-free (CVE-ID: CVE-2026-90308)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in RDMA/erdma QP handling when AE QP fatal events or iWARP CM paths process QPs concurrently with QP destruction. A local user can cause a QP to be destroyed while AE or CM processing is in progress to cause a denial of service.


736) Use-after-free (CVE-ID: CVE-2026-90309)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the ERDMA completion queue handling when EQ handlers invoke completion or error callbacks after a completion queue has been destroyed. A local user can race completion queue destruction with EQ event processing to cause a denial of service.


737) Use-after-free (CVE-ID: CVE-2026-90313)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an invalid memory access.

The vulnerability exists due to use-after-free in __cgroup_bpf_attach when replacing a cgroup BPF program in multi-attach mode and the attachment fails midway. A local user can perform a failed BPF_F_REPLACE operation and attach another cgroup BPF program to trigger an invalid memory access.

The issue requires an active replaced program with local storage to execute bpf_get_local_storage after the failed attachment.


738) Out-of-bounds read (CVE-ID: CVE-2026-90314)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory out of bounds.

The vulnerability exists due to improper signedness handling in rsc_table_for_each_entry() when processing a firmware resource table. A local user can provide a crafted firmware resource table containing an offset interpreted as negative to read memory out of bounds.


739) Use-after-free (CVE-ID: CVE-2026-90316)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in OMAP DSI interrupt service routine table handling when unregistering interrupts while they are being handled. A local user can unregister interrupts during interrupt handling to trigger a use-after-free condition.


740) Improper resource shutdown or release (CVE-ID: CVE-2026-90318)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a resource leak.

The vulnerability exists due to improper resource release in fat_rebuild_parent() when rebuilding parent inodes through the nostale_ro NFS export path. A remote user can trigger parent inode reconstruction without releasing the buffer head to cause a resource leak.


741) Use-after-free (CVE-ID: CVE-2026-90319)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the RapidIO rio_scan_alloc_net() failure path when handling a rio_add_net() failure. A local user can trigger a subsequent mport unregister path to dereference a dangling mport->net pointer and attempt to free the rio_net object again.


742) Out-of-bounds read (CVE-ID: CVE-2026-90322)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to an invalid node number being used as a heartbeat slot index in the OCFS2 heartbeat subsystem when resetting the local node configuration while heartbeat threads are running. A local user can reset the local node configuration while heartbeat threads are running to read out-of-bounds memory.


743) Use-after-free (CVE-ID: CVE-2026-90325)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a use-after-free in blkcg_activate_policy() when switching I/O schedulers concurrently with blkcg deletion. A local user can race scheduler switching with blkcg deletion to trigger a use-after-free condition.


744) Out-of-bounds write (CVE-ID: CVE-2026-90327)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write up to three bytes beyond a user-supplied buffer.

The vulnerability exists due to an out-of-bounds write in the phonet PEP socket option handler pep_getsockopt() when calling getsockopt() with an optlen smaller than sizeof(int). A local user can invoke getsockopt() with a small optlen to write up to three bytes beyond a user-supplied buffer.


745) Use-after-free (CVE-ID: CVE-2026-90329)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to a use-after-free in HID failed-probe cleanup when a HID report callback runs concurrently with a failed device probe. A local user can cause a HID report to be processed while a device probe fails to trigger a use-after-free.


746) Use-after-free (CVE-ID: CVE-2026-90334)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free.

The vulnerability exists due to use-after-free in tty_cdev_add() when handling a cdev_add() failure. A local user can trigger tty device unregistration after cdev_add() fails to cause a use-after-free.


747) Integer overflow (CVE-ID: CVE-2026-90341)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access memory outside the platform resource.

The vulnerability exists due to integer overflow and insufficient bounds validation in coreboot_table_probe() when processing a malformed coreboot table. A local user can supply a malformed coreboot table to access memory outside the platform resource.


748) Improper input validation (CVE-ID: CVE-2026-90344)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the mac80211 channel switch announcement parser when processing a channel switch announcement that advertises channel zero. A remote attacker can advertise a channel switch to channel zero to cause a denial of service.

The firmware-crash condition applies to Intel devices.


749) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-90348)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper handling of device-memory mappings in ath10k_msa_dump_memory() when collecting an MSA firmware crash dump. A local privileged user can cause firmware crash dump collection to cause a denial of service.


750) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90352)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a resource leak.

The vulnerability exists due to failure to release a resource in the mt7915 PCI probe routine when IRQ vector allocation or primary IRQ request setup fails. A local privileged user can initiate probing of an mt7915 PCI device under an IRQ setup failure condition to cause a resource leak.


751) Use-after-free (CVE-ID: CVE-2026-90353)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in the mt7915 wireless driver's registration error path when main PHY debugfs initialization or coredump registration fails after successful external PHY registration. A local user can exploit the external PHY hardware object being freed while still registered with mac80211 to compromise system confidentiality, integrity, and availability.

The error cleanup calls mt76_unregister_device(), which unregisters only the main hardware object.


752) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90354)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a device reference leak.

The vulnerability exists due to improper resource management in the mt7915_pci_probe HIF2 initialization path when initializing HIF2 on non-WED dual-HIF hardware. A local user can trigger initialization of the mt7915 PCI device to cause a device reference leak.


753) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90357)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt kernel driver state.

The vulnerability exists due to improper resource lifecycle management in the mt7915 TWT flow list when handling a TWT agreement rejected by the MCU. A local user can trigger a rejected TWT agreement to corrupt kernel driver state.

A reused flow slot can remain linked in the TWT list, leaving a dangling entry that is later traversed.


754) Stack-based buffer overflow (CVE-ID: CVE-2026-90358)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to overwrite adjacent stack slots.

The vulnerability exists due to a stack-based buffer overflow in the x86 BPF trampoline register save area when handling a 128-bit scalar function argument. A local user can trigger a BPF trampoline with a 128-bit scalar argument to overwrite adjacent stack slots.


755) Race condition (CVE-ID: CVE-2026-90360)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning during system suspend.

The vulnerability exists due to a race condition involving a non-freezable workqueue in the regulator core when delayed regulator cleanup runs concurrently with system suspend. A local user can cause system suspend to overlap with delayed regulator cleanup to trigger a kernel warning during system suspend.

The cleanup work runs approximately 30 seconds after boot to disable unused regulators via I2C. If the I2C adapter is already suspended, the transfer triggers a -ESHUTDOWN warning in __i2c_transfer().


756) Memory leak (CVE-ID: CVE-2026-90361)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory cleanup in ath11k_service_ready_ext_event() when parsing service-ready extension TLVs. A local user can cause parsing to fail after mac_phy_caps has been allocated to cause a denial of service.


757) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90362)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause the DSI link clock to run without necessary power backing.

The vulnerability exists due to improper power-state management in dsi_link_clk_disable_6g() when disabling DSI link clocks. A local user can trigger the DSI link clock disable path to cause the DSI link clock to run without necessary power backing.


758) Incomplete cleanup (CVE-ID: CVE-2026-90364)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to leave a cpufreq policy notifier registered after ACPI processor driver initialization fails.

The vulnerability exists due to incomplete cleanup in acpi_processor_driver_init() when ACPI processor driver initialization fails after registering the cpufreq policy notifier. A local privileged user can trigger an initialization failure to leave a cpufreq policy notifier registered.


759) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-90366)

CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an incorrect buffer size calculation in the MT7996 beacon update size calculation when processing a beacon update while a CSA countdown is active. A local privileged user can trigger the emission of two bss_bcn_cntdwn_tlv entries to cause a denial of service.

Exploitation requires MBSSID to be enabled and a near-maximum beacon template.


760) Use-after-free (CVE-ID: CVE-2026-90368)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to dereference a stale monitor_vif pointer.

The vulnerability exists due to use-after-free in mt7915_add_interface() when mt76_wcid_alloc() fails during interface addition. A local user can trigger a failed interface addition to dereference a stale monitor_vif pointer.

mac80211 does not call remove_interface() when interface addition fails.


761) Infinite loop (CVE-ID: CVE-2026-90370)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of TLV lengths in mt7996_mcu_get_chip_config when parsing a firmware response during device probe. A local user can provide a firmware response containing a zero-length TLV to cause a denial of service.


762) Integer underflow (CVE-ID: CVE-2026-90372)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-range spatial-stream value to be written to firmware beamforming fields.

The vulnerability exists due to an integer underflow in mt7915_mcu_get_sta_nss when processing a peer VHT/HE MCS map with no supported spatial streams. A remote attacker can advertise a crafted VHT/HE MCS map to cause an out-of-range spatial-stream value to be written to firmware beamforming fields.


763) Race condition (CVE-ID: CVE-2026-90373)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause resource allocation inconsistencies.

The vulnerability exists due to a race condition in the mt7915_remove_interface() function when concurrently removing an interface while allocating wireless client identifiers on another band. A local user can trigger concurrent interface removal and wireless client identifier allocation to cause resource allocation inconsistencies.

The issue occurs on DBDC devices, where two wiphys share one mt76_dev instance.


764) Out-of-bounds read (CVE-ID: CVE-2026-90374)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds memory access.

The vulnerability exists due to improper validation of an array index in the mt7996_mac_fill_rx RX handler when processing a received descriptor with a corrupt or reserved band index. A remote attacker can supply a received descriptor with a corrupt or reserved band index to cause an out-of-bounds memory access.


765) Incorrect calculation (CVE-ID: CVE-2026-90375)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to incorrect non-AQL packet accounting in __mt76_tx_queue_skb() when transmitting frames through a non-setup multi-link operation link. A remote user can transmit a frame using a link different from the station's setup link to cause a denial of service.


766) Memory leak (CVE-ID: CVE-2026-90378)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper memory management in the mt76 SDIO transmit path when tx_prepare_skb() returns an error while processing zero-length frames. A local user can submit a zero-length frame to cause a memory leak.


767) Use-after-free (CVE-ID: CVE-2026-90380)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an invalid memory access.

The vulnerability exists due to a use-after-free in mt76_rx_poll_complete when receive processing races with station removal. A remote attacker can trigger the race condition to trigger an invalid memory access.


768) Reachable assertion (CVE-ID: CVE-2026-90382)

CWE-ID: CWE-617 - Reachable Assertion

CVSSv4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a kernel panic and denial of service.

The vulnerability exists due to a reachable assertion in the mt76x02 receive-processing path when processing a corrupted wireless frame with a receive descriptor length larger than the received buffer. A remote attacker can transmit a corrupted over-the-air frame to cause a kernel panic and denial of service.

Exploitation requires monitor mode with the fcsfail filter enabled and panic_on_warn set.


769) Race condition (CVE-ID: CVE-2026-90383)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an unsafe page-table walk.

The vulnerability exists due to improper synchronization in the GRU TLB miss handler when handling a GRU TLB miss in interrupt context. A local user can trigger a GRU TLB miss to trigger an unsafe page-table walk.


770) Improper initialization (CVE-ID: CVE-2026-90385)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper initialization in the md/raid1 serial pool creation logic when adding a new rdev to an existing RAID1 array with serialize policy enabled. A local privileged user can add a new rdev to a configured RAID1 array to cause a denial of service.


771) Incorrect Bitwise Shift of Integer (CVE-ID: CVE-2026-90386)

CWE-ID: CWE-1335 - Incorrect Bitwise Shift of Integer

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a shift-out-of-bounds condition.

The vulnerability exists due to an incorrect bitwise shift calculation in the DesignWare I3C master DAA handler when ENTDAA assigns no devices on an empty I3C bus. A local user can initiate dynamic address assignment on an empty I3C bus to trigger a shift-out-of-bounds condition.


772) Release of invalid pointer or reference (CVE-ID: CVE-2026-90387)

CWE-ID: CWE-763 - Release of invalid pointer or reference

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to release of an invalid pointer in the swiotlb dynamic-pool allocation and free handling when allocating a decrypted pool from the DMA atomic pool in atomic context with CONFIG_DMA_DIRECT_REMAP enabled. A local user can trigger dynamic swiotlb pool allocation to cause a memory leak.

The atomic pool can use remapped virtual addresses that differ from direct-map addresses.


773) Unchecked Return Value (CVE-ID: CVE-2026-90388)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an IOMMU mapping to be attempted after an allocation failure.

The vulnerability exists due to improper check of an allocation return value in iommu_dma_alloc when executing the non-blocking, non-coherent allocation path. A local user can invoke the affected allocation path during an allocation failure to cause an IOMMU mapping to be attempted after an allocation failure.

The affected path requires CONFIG_DMA_DIRECT_REMAP and non-coherent allocation.


774) Race condition (CVE-ID: CVE-2026-90389)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in MD array suspension handling when concurrent sysfs writes suspend an array. A local user can issue concurrent writes to the suspend_lo and suspend_hi sysfs attributes to cause a denial of service.


775) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-90390)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in the md bitmap backlog_store() function when attempting to set backlog on an array without a write-mostly device. A local user can trigger the error path to cause a denial of service.


776) Infinite loop (CVE-ID: CVE-2026-90391)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in dmirror_fault() in lib/test_hmm.c when handling dmirror read or write ioctl operations after the mirrored mm has exited. A local user can issue dmirror read or write ioctl operations to cause a denial of service.

The loop is reached after a missing device page table entry is encountered.


777) Use-after-free (CVE-ID: CVE-2026-90392)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in bpf_link_show_fdinfo and bpf_link_get_info_by_fd when reading BPF link information while a linked program is concurrently replaced via bpf_link_update. A local user can concurrently replace a linked program and read BPF link information to trigger a use-after-free condition.


778) Use-after-free (CVE-ID: CVE-2026-90393)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a race condition in bpf_netns_link_update_prog when concurrently executing BPF_LINK_UPDATE operations on the same network namespace link. A local user can race program updates to trigger a use-after-free condition.


779) Use-after-free (CVE-ID: CVE-2026-90394)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed driver data.

The vulnerability exists due to use-after-free in the sc2731_charger driver's remove path when queued or running work executes after driver data is released. A local user can cause the driver to be removed while work remains queued or running to access freed driver data.


780) Use-after-free (CVE-ID: CVE-2026-90395)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to access freed power supply state.

The vulnerability exists due to a use-after-free in the isp1704 charger driver's remove path when queued or running work executes during device removal. A local privileged user can cause work scheduled by USB notification or initial VBUS detection to execute after the power supply state is torn down to access freed power supply state.


781) NULL pointer dereference (CVE-ID: CVE-2026-90397)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the Qualcomm SCM driver when processing IRQs or non-atomic SMC calls during driver probe. A local user can trigger the affected probe-time paths to cause a denial of service.


782) Out-of-bounds write (CVE-ID: CVE-2026-90398)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write beyond an allocated buffer.

The vulnerability exists due to an allocation size and pointer stride mismatch in ath11k_wmi_tlv_mac_phy_caps_parse() when processing short firmware TLVs. A local user can cause the kernel to process short firmware TLVs to write beyond an allocated buffer.


783) Out-of-bounds write (CVE-ID: CVE-2026-90399)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an allocation-size and pointer-stride mismatch in ath12k_wmi_mac_phy_caps_parse() when processing short firmware TLVs. A local user can trigger an out-of-bounds write to cause memory corruption.


784) Race condition (CVE-ID: CVE-2026-90400)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a race condition in the md_start_sync() RAID synchronization path when spare configuration changes occur concurrently with normal I/O. A local privileged user can cause spare configuration changes to race with normal I/O to cause a denial of service.

The race can cause rdev_dec_pending() to be called with a NULL pointer.


785) Incomplete cleanup (CVE-ID: CVE-2026-90402)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leave a controller device registered after a sysfs-file creation error.

The vulnerability exists due to incomplete cleanup in mhi_register_controller() when creating the optional trigger_edl sysfs file. A local user can cause sysfs_create_file() to fail during controller registration to leave a controller device registered after an error.


786) Incomplete cleanup (CVE-ID: CVE-2026-90403)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.

The vulnerability exists due to incomplete cleanup caused by an incorrect goto label in the rtl_pci_probe() function when handling an IRQ handler registration failure. A local user can trigger this error path to compromise system confidentiality, integrity, and availability.


787) Use-after-free (CVE-ID: CVE-2026-90404)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the cros_ec_debugfs remove path when an EC panic notification is delivered after the device instance has been removed. A local user can trigger an EC panic notification after device removal to cause a denial of service.

The callback can queue work that accesses released data.


788) Out-of-bounds read (CVE-ID: CVE-2026-90407)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in ath11k_wmi_process_csa_switch_count_event() when processing a firmware CSA switch count event. A local user can provide a crafted firmware event with an unchecked num_vdevs value to read out-of-bounds memory.


789) Use-after-free (CVE-ID: CVE-2026-90410)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the Davinci SPI driver's interrupt handler when processing a late or latched interrupt during device removal. A local user can initiate device removal while such an interrupt is handled to cause a denial of service.


790) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90411)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a DMA mapping resource leak.

The vulnerability exists due to improper resource cleanup in __nvme_fc_init_request() when handling a response IU DMA mapping failure. A local user can trigger request initialization with a response IU DMA mapping failure to cause a DMA mapping resource leak.


791) Out-of-bounds read (CVE-ID: CVE-2026-90413)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in the iSER login PDU handling code when processing a login PDU whose declared data segment length exceeds the received payload length. A remote attacker can send a crafted login PDU with an oversized declared data segment length to read out-of-bounds memory.

The issue can be triggered before authentication.


792) Out-of-bounds read (CVE-ID: CVE-2026-90414)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause an out-of-bounds read and write heap contents beyond the receive descriptor to backing storage.

The vulnerability exists due to missing validation of the declared data segment length in isert_recv_done() when processing iSER/iSCSI PDUs. A remote user can send a PDU that declares a data segment larger than the received data to cause an out-of-bounds read and write heap contents beyond the receive descriptor to backing storage.

Exploitation requires the full feature phase and negotiated parameters that permit unsolicited or immediate data.


793) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90415)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in the RDMA/cxgb4 write_tpt_entry() function when programming a TPT entry. A local user can trigger a failed TPT entry write to cause a denial of service.


794) Out-of-bounds read (CVE-ID: CVE-2026-90416)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the get_param() function of the cc_params debugfs interface when reading a congestion parameter. A local user can read a crafted congestion parameter value through the debugfs interface to disclose sensitive information.

The issue is triggered when the parameter value has bit 31 set.


795) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-90418)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an inconsistent dirty state in nilfs_copy_dirty_pages() when copying dirty DAT folios or pages to the shadow page cache. A local user can trigger the dirty-state mismatch to cause a denial of service.

The condition can occur after metadata corruption causes the filesystem to transition to read-only mode.


796) Out-of-bounds read (CVE-ID: CVE-2026-90419)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to improper input validation in nilfs2 super-root block parsing when processing a malformed filesystem image. A local user can supply a malformed filesystem image to perform an out-of-bounds read.


797) Infinite loop (CVE-ID: CVE-2026-90420)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of terminal errors in nilfs_clean_segments() when the cleaner ioctl encounters repeated -EROFS errors from nilfs_segctor_construct(). A local user can invoke the cleaner ioctl to cause a denial of service.

The issue can occur when the device is remounted read-only after an I/O error.


798) Use-after-free (CVE-ID: CVE-2026-90426)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free race condition in tegra241_cmdqv_remove() and tegra241_cmdqv_isr() when handling an error interrupt while VINTFs are being torn down. A local user can cause an error interrupt to be handled during VINTF teardown to cause a denial of service.


799) Use of Uninitialized Variable (CVE-ID: CVE-2026-90428)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to use of an uninitialized resource in the Tegra241 CMDQV error interrupt handler when handling a latched error interrupt after a kexec. A local privileged user can initiate a kexec while CMDQV is enabled with a latched error to cause a denial of service.


800) Race condition (CVE-ID: CVE-2026-90430)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the Tegra241 CMDQV LVCMDQ initialization and error-handling logic when an error interrupt is handled while an LVCMDQ is being initialized. A local user can cause an LVCMDQ error to be handled during initialization to cause a denial of service.

The condition can occur when an LVCMDQ error is inherited across a kexec.


801) Use-after-free (CVE-ID: CVE-2026-90431)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the remoteproc crash-handler work when crash reporting races with remoteproc deletion. A local user can trigger concurrent crash reporting and remoteproc removal to cause a denial of service.


802) Use-after-free (CVE-ID: CVE-2026-90433)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to improper resource lifetime management in the tiny_spi_irq() interrupt handler when handling a late or latched interrupt during device removal. A local user can cause the interrupt handler to access freed controller memory to cause a use-after-free condition.


803) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90434)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to exhaust buffer-head resources.

The vulnerability exists due to failure to release a buffer-head reference in zisofs_fill_pages() when successfully reading compressed block pointer tables. A local user can cause zisofs_fill_pages() to read compressed block pointer tables to exhaust buffer-head resources.


804) Integer overflow (CVE-ID: CVE-2026-90435)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to integer overflow in the mlx5 RDMA driver's set_user_buf_size() function when processing user-supplied QP buffer parameters. A local user can supply an excessively large rq.wqe_cnt value to cause memory corruption.

The same unchecked shift calculation is also used to compute qp->sq.offset during user QP creation.


805) Use of uninitialized resource (CVE-ID: CVE-2026-92476)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger use of an uninitialized completion.

The vulnerability exists due to use of an uninitialized resource in the Keem Bay OCS AES driver's kmb_ocs_aes_probe() routine when a device interrupt occurs after IRQ registration and before completion initialization. A local user can trigger a device interrupt during this initialization window to trigger use of an uninitialized completion.


806) Improper Null Termination (CVE-ID: CVE-2026-92477)

CWE-ID: CWE-170 - Improper Null Termination

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to improper null termination in ufs_saved_err_write() when handling a write that fills the input buffer. A local user can write input that fills the stack buffer to cause an out-of-bounds read.


807) Use-after-free (CVE-ID: CVE-2026-92481)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a use-after-free in the MediaTek EINT interrupt resource cleanup when unbinding a module. A local privileged user can unbind a MediaTek pinctrl module, leaving a chained interrupt handler referencing freed data, to cause a denial of service.


808) Use-after-free (CVE-ID: CVE-2026-92484)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to use-after-free in the CXL region find_pos_and_ways() function when reporting an error after releasing a switch decoder reference. A local user can cause an error that logs the decoder name after its reference is released to access freed memory.


809) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-92488)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the ERDMA RDMA object destruction functions when a destroy command fails. A local user can destroy an RDMA object after a command failure to cause a denial of service.

A command timeout permanently disables the command queue, preventing retries.


810) Double free (CVE-ID: CVE-2026-92489)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a double-free.

The vulnerability exists due to a double free in xfrm_dev_direct_output() when handling packets dropped by netfilter. A local user can send a packet that is dropped by netfilter to trigger a double-free.


811) Use-after-free (CVE-ID: CVE-2026-92490)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the SCMI driver registration handling in scmi_driver_register() when driver registration fails. A local user can cause a driver registration failure and subsequently trigger request matching or SCMI device creation to trigger a use-after-free condition.


812) Use-after-free (CVE-ID: CVE-2026-92491)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to use-after-free in scmi_protocol_table_register() when a later protocol ID-table entry request fails after earlier requests have been registered. A local user can load a module whose protocol table registration fails to cause a use-after-free condition.


813) Memory leak (CVE-ID: CVE-2026-92494)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a buffer_head reference leak.

The vulnerability exists due to improper resource release in ext4_init_orphan_info() when processing orphan file blocks with an invalid magic value or checksum. A local user can cause ext4_init_orphan_info() to process such orphan file blocks to cause a buffer_head reference leak.


814) Incorrect permission assignment for critical resource (CVE-ID: CVE-2026-92495)

CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain unintended write access to DBR or toggle pages.

The vulnerability exists due to improper permission assignment in bnxt_re_mmap when changing a read-only DBR or toggle page mapping to writable with mprotect. A local user can retain VM_MAYWRITE on the mapping to gain unintended write access to DBR or toggle pages.


815) Out-of-bounds read (CVE-ID: CVE-2026-92496)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in ath11k_wmi_tlv_op_rx() when processing a firmware buffer shorter than a WMI command header. A local user can supply a malformed firmware buffer to read out-of-bounds memory.


816) Out-of-bounds read (CVE-ID: CVE-2026-92497)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause an out-of-bounds read.

The vulnerability exists due to improper bounds checking in ath12k_wmi_op_rx() when processing a firmware buffer that is shorter than a WMI command header. A local privileged user can cause the function to access header data in an undersized firmware buffer to cause an out-of-bounds read.


817) Out-of-bounds read (CVE-ID: CVE-2026-92498)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read beyond the bounds of WMI event buffers.

The vulnerability exists due to an out-of-bounds read in ath6kl WMI event handlers when processing undersized WMI events. A remote attacker can provide a malformed WMI event to read beyond the bounds of event buffers.


818) Race condition (CVE-ID: CVE-2026-92501)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in ext4_buffered_write_iter() when a direct I/O write falls back to buffered I/O while concurrent direct I/O completes. A local user can issue concurrent direct I/O operations to cause a denial of service.

The issue can also occur when non-overlapping direct I/O writes share a large folio and the block size is smaller than the folio size.


819) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-92502)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause data loss.

The vulnerability exists due to improper clearing of stale xarray tags in ext4 writeback handling when clean folios are skipped during writeback. A local privileged user can trigger writeback during a system reboot to cause data loss.

The issue occurs in ext4 data=journal mode while the superblock is being remounted read-only during reboot.


820) Improper resource shutdown or release (CVE-ID: CVE-2026-92504)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to improper resource cleanup in the int3400 thermal driver's ODVP handling when driver probing fails after evaluate_odvp() has created ODVP sysfs files. A local user can trigger a driver probe failure after ODVP evaluation to cause a resource leak.


821) Double free (CVE-ID: CVE-2026-92506)

CWE-ID: CWE-415 - Double Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in scmi_protocol_device_unrequest() when two SCMI drivers for the same protocol unregister concurrently. A local user can trigger concurrent unregistration of the drivers to cause a denial of service.


822) Use-after-free (CVE-ID: CVE-2026-92507)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to potentially trigger a use-after-free.

The vulnerability exists due to use-after-free in ib_dealloc_pd_user() RDMA resource tracking when accessing a protection domain through the netlink path during its destruction. A local user can access a protection domain through the netlink path while it is being destroyed to potentially trigger a use-after-free.


823) Use-after-free (CVE-ID: CVE-2026-92508)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a use-after-free in the RDMA/core ib_free_cq() completion queue destruction function when accessing a completion queue through the netlink path while it is being destroyed. A local user can access a completion queue through netlink during its destruction to trigger a use-after-free condition.


824) Use-after-free (CVE-ID: CVE-2026-92509)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in counter_release() in the RDMA core counter handling when processing netlink access to a counter during its destruction. A local user can access a counter through the netlink path while it is being released to trigger a use-after-free condition.


825) Use-after-free (CVE-ID: CVE-2026-92510)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to a use-after-free in the SRQ resource-tracking lifecycle in ib_destroy_srq_user() when accessing a shared receive queue through the netlink path during destruction. A local user can access a shared receive queue that remains accessible through restrack while its vendor-specific resources are being released to trigger a use-after-free.


826) Use-after-free (CVE-ID: CVE-2026-92511)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a use-after-free in ib_destroy_cq_user() when accessing a completion queue through the netlink path during its destruction. A local user can access a completion queue through netlink while it is being destroyed to trigger a use-after-free condition.


827) Use-after-free (CVE-ID: CVE-2026-92512)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a kernel crash.

The vulnerability exists due to use-after-free in ib_query_qp() when querying a queue pair through the RDMA netlink flow while the queue pair is being destroyed. A local user can send a netlink request to query the queue pair during its destruction to cause a kernel crash.


828) Use-after-free (CVE-ID: CVE-2026-92514)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the ERDMA completion event queue tasklet when removing an ERDMA device. A local user can trigger device removal while a previously scheduled completion event queue tasklet is pending to cause a denial of service.


829) Improper initialization (CVE-ID: CVE-2026-92515)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a kernel warning.

The vulnerability exists due to improper initialization of uniqueness-tracking state in btf_find_struct_field() when processing crafted BTF containing duplicate unique special fields across nested structs. A remote attacker can submit crafted BTF to trigger a kernel warning.

The warning can be triggered before map-creation capability checks.


830) Memory leak (CVE-ID: CVE-2026-92519)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory release in the RISC-V BPF JIT cleanup routine bpf_jit_free() when JIT compilation fails for a later BPF subprogram. A local user can trigger JIT compilation failure for a later BPF subprogram to cause a denial of service.


831) Use-after-free (CVE-ID: CVE-2026-92521)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger use of freed memory.

The vulnerability exists due to a use-after-free in ACPI PCI root handling when processing hot-add failures or root bridge removal. A local user can invoke a later acpi_pci_find_root() lookup to trigger use of freed memory.

The freed root object remains referenced by device->driver_data.


832) Out-of-bounds read (CVE-ID: CVE-2026-92522)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to read out-of-bounds memory.

The vulnerability exists due to improper bounds validation in the ACPI IOAPIC hotplug lookup when parsing MADT and _MAT records. A local privileged user can provide a malformed record with a truncated header, an oversized declared length, or an incomplete IOAPIC body to read out-of-bounds memory.

Only builds with CONFIG_ACPI_HOTPLUG_IOAPIC enabled include the affected code.


833) Out-of-bounds read (CVE-ID: CVE-2026-92523)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to improper input validation in nldev_stat_set_counter_dynamic_doit when processing nested RDMA_NLDEV_ATTR_STAT_HWCOUNTERS netlink attributes. A local user can provide a nested attribute containing a child payload shorter than a u32 to perform an out-of-bounds read.


834) Improper resource shutdown or release (CVE-ID: CVE-2026-92524)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in its_vpe_irq_domain_alloc() when an interrupt allocation fails. A local user can trigger an allocation failure to cause a denial of service.


835) Out-of-bounds read (CVE-ID: CVE-2026-92525)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in copy_data() when processing a user-supplied work queue element. A local user can post a work queue element with an out-of-range cur_sge or oversized num_sge to cause a denial of service.


836) Unchecked Return Value (CVE-ID: CVE-2026-93037)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause improper processing of a request.

The vulnerability exists due to an unchecked return value in the set_txreq_header_ahg() function when initializing an accelerated header generation transmit request. A local user can submit a request for which sdma_txinit_ahg() fails to cause improper processing of a request.


837) Use-after-free (CVE-ID: CVE-2026-93039)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free and double free.

The vulnerability exists due to a stale pointer after reallocation in meson_card_reallocate_links() when handling failure of the second memory reallocation after the first reallocation moves the DAI link array. A local user can cause the second memory reallocation to fail after the first reallocation moves the DAI link array to trigger a use-after-free and double free.


838) Race condition (CVE-ID: CVE-2026-93040)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the DesignWare eDMA channel state handling when pause(), resume(), or issue_pending() evaluates channel state concurrently with interrupt handlers. A local user can invoke DMA channel operations during a concurrent state transition to cause a denial of service.


839) Race condition (CVE-ID: CVE-2026-93041)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the dw-edma abort interrupt handler when aborting a DMA request while queued descriptors are being started. A local user can trigger an abort during the state transition to leave queued descriptors unprocessed and the channel idle.


840) Use-after-free (CVE-ID: CVE-2026-93042)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper descriptor termination in the dw-edma DMA engine driver when terminating DMA transfers. A local user can invoke dmaengine_terminate_sync() during a deferred STOP, allowing a late callback to dereference freed client state to trigger a use-after-free condition.

A pending STOP may remain unresolved until the running transfer generates an interrupt.


841) Improper input validation (CVE-ID: CVE-2026-93045)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to obtain an address below the arena mapping.

The vulnerability exists due to improper input validation in bpf_arena_free_pages() when freeing a scalar arena address below the low 32 bits of the arena base. A local user can free a crafted scalar arena address to obtain an address below the arena mapping.


842) Memory corruption (CVE-ID: CVE-2026-93046)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access memory out of bounds.

The vulnerability exists due to improper bounds checking in software_node_get_reference_args() when handling a reference argument index value of UINT_MAX. A local user can provide an index value of UINT_MAX to access memory out of bounds.


843) Integer underflow (CVE-ID: CVE-2026-93048)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to integer underflow in mtd_add_partition() when processing BLKPG ioctl requests on NAND devices. A local user can pass MTDPART_OFS_RETAIN (-3) as a partition offset to trigger a kernel warning.

Depending on the size calculation, an empty disabled partition can be created.


844) Double free (CVE-ID: CVE-2026-93049)

CWE-ID: CWE-415 - Double Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in mtdswap_add_mtd() cleanup handling when debugfs setup fails after blktrans device registration. A local user can trigger the debugfs failure sequence to cause a denial of service.


845) Use-after-free (CVE-ID: CVE-2026-93050)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in ipoctal_cleanup() when tty cleanup occurs after the associated ipack device has been freed. A local user can close an open tty after device removal to cause a denial of service.


846) NULL pointer dereference (CVE-ID: CVE-2026-93050)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to null pointer dereference in ipoctal_write_tty() when writing to a tty whose transmit buffer has been freed during device removal. A local user can write to an open tty after device removal to cause a denial of service.


847) Use-after-free (CVE-ID: CVE-2026-93050)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the ipoctal driver struct ipoctal lifetime handling when an IP-OCTAL device is removed while a tty session remains active. A local user can issue tty operations during device removal to cause a denial of service.


848) Use-after-free (CVE-ID: CVE-2026-93051)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the Linux kernel ad525x_dpot driver's sysfs attribute handling when removing a device without removing its command sysfs attributes before freeing driver data. A local user can access command sysfs attributes that remain exposed after the driver data is freed to cause a denial of service.

The command sysfs attributes are exposed only for devices supporting the F_CMD_INC feature.


849) Race condition (CVE-ID: CVE-2026-93052)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access message queues using stale cached queue information.

The vulnerability exists due to improper synchronization in the bcm-vk message queue initialization and driver access checks when initializing message queues concurrently with driver access. A local user can race message queue initialization with driver access to access message queues using stale cached queue information.


850) Out-of-bounds write (CVE-ID: CVE-2026-93053)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause an out-of-bounds write.

The vulnerability exists due to improper validation of function-name initial characters in the speakup keyhelp letter_offsets[] handling when processing function names overridden through sysfs. A local privileged user can override a function name with an initial character outside the a-z range to cause an out-of-bounds write.


851) Use-after-free (CVE-ID: CVE-2026-93054)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the __uio_register_device() UIO registration failure path when an opener races with a failed registration after device_add(). A local user can race opening /dev/uioX with a failed device registration to cause a denial of service.


852) Out-of-bounds read (CVE-ID: CVE-2026-93055)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in udf_pc_to_char() when processing malformed UDF symlink data containing a partial pathComponent header. A local user can provide malformed UDF symlink data containing a partial pathComponent header to cause an out-of-bounds read.


853) NULL pointer dereference (CVE-ID: CVE-2026-93056)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the f_uac1_legacy configfs string attribute store handler when writing to the fn_play, fn_cap, or fn_cntl attribute during a memory-allocation failure. A local user can write to an affected configfs attribute while memory allocation fails to cause a denial of service.


854) Buffer Over-read (CVE-ID: CVE-2026-93061)

CWE-ID: CWE-126 - Buffer over-read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in host1x_debug_output() and host1x_debug_cont() when generating debug output longer than 256 bytes. A local user can access affected debugfs output to disclose sensitive information.

Only debugfs files are affected; the printk debug sink ignores the supplied byte count.


855) Division by zero (CVE-ID: CVE-2026-93062)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to division by zero in iwl_dbg_tlv_alloc_fragments when processing firmware monitor configuration data with a zero required size or fragment count. A local user can trigger processing of such configuration data to cause a denial of service.


856) Buffer overflow (CVE-ID: CVE-2026-93063)

CWE-ID: CWE-120 - Buffer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a buffer overflow.

The vulnerability exists due to improper bounds checking in the iwl_mei_handle_sap_rx_cmd function when processing an oversized SAP message. A local user can supply a SAP message whose declared length exceeds the local buffer size to cause a buffer overflow.


857) Off-by-one (CVE-ID: CVE-2026-93064)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an off-by-one error in iwl_mvm_frob_txf_key_iter() when sanitizing TXF keys. A local user can trigger sanitization of a fully matched key to cause memory corruption.


858) Integer overflow (CVE-ID: CVE-2026-93065)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to integer overflow in iwl_fwrt_dump_error_logs when processing firmware that advertises more than 255 PC entries. A local user can trigger processing of firmware advertising more than 255 PC entries to cause a denial of service.


859) Stack-based buffer overflow (CVE-ID: CVE-2026-93067)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a stack-based buffer overflow.

The vulnerability exists due to improper validation of controller-reported AUX byte counts in tc_aux_transfer() and tc_aux_read_data() when handling AUX read transfers. A local user can trigger processing of an AUX read response that reports a byte count larger than requested to cause a stack-based buffer overflow.

The controller-reported byte count can be as high as 255 despite the 16-byte auxrdata stack buffer.


860) Double free (CVE-ID: CVE-2026-93070)

CWE-ID: CWE-415 - Double Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a double free in the Intel IPU6 isys and psys initialization paths when handling MMU initialization or auxiliary-device-addition failures. A local user can trigger error handling after auxiliary device initialization to cause memory corruption.


861) Memory leak (CVE-ID: CVE-2026-93071)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the bcm2835-unicam driver when handling driver initialization failures or device removal. A local privileged user can cause the driver to enter an error or removal path to leak allocated asynchronous subdevice connection resources and cause a denial of service.

The leak was detected after module removal.


862) Use-after-free (CVE-ID: CVE-2026-93072)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to use-after-free in the Renesas IRQC interrupt controller driver when the driver is removed and generic interrupt chip callbacks are subsequently invoked. A local privileged user can remove the driver and trigger a generic interrupt chip callback to cause a denial of service.


863) Race condition (CVE-ID: CVE-2026-93073)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in dax_holder_notify_failure() when fs_put_dax() concurrently clears holder_ops. A local user can trigger the race to dereference a null holder_ops pointer.


864) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-93082)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to failure to release an allocated mailbox channel in mailbox_chan_setup() in the ARM SCMI mailbox transport when requesting an additional P2A receiver mailbox channel after acquiring the primary channel. A local user can trigger a failure in the additional channel request to cause a denial of service.


865) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-93083)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to missing release of a resource after its effective lifetime in mailbox_chan_setup() when requesting an additional unidirectional TX receiver mailbox channel. A local user can initiate mailbox channel setup to cause a denial of service.

The primary mailbox channel remains busy for later probe attempts if the additional channel request fails.


866) Memory leak (CVE-ID: CVE-2026-93084)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak SCMI instance user references.

The vulnerability exists due to improper resource cleanup in the SCMI bus notifier when a protocol driver probe fails after an SCMI handle has been acquired. A local user can trigger a failed protocol-device bind to leak SCMI instance user references.

If a device dependency link cannot be created, a concurrent parent unbind can tear down the SCMI instance while the child retains a handle.


867) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-93085)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause SCMI protocol ID truncation or aliasing.

The vulnerability exists due to improper validation of specified quantities in input in the SCMI device tree parsing paths when processing a malformed 32-bit device tree reg value. A local user can provide an out-of-range protocol ID to cause SCMI protocol ID truncation or aliasing.


868) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-93086)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource lifecycle management in the SCMI channel cleanup routine when cleaning TX/RX channels. A local user can initiate SCMI channel cleanup to cause a denial of service.


869) Improper resource shutdown or release (CVE-ID: CVE-2026-93089)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause resource leaks.

The vulnerability exists due to improper resource shutdown or release in the SCMI transport channel setup error-handling path when an IDR insertion fails after transport channel setup succeeds. A local privileged user can initiate transport channel setup to cause resource leaks.


870) Incomplete cleanup (CVE-ID: CVE-2026-93090)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to incomplete cleanup in the SCMI channel setup error-handling path when SCMI channel setup fails. A local user can cause SCMI channel setup to fail to cause a resource leak.


871) Use-after-free (CVE-ID: CVE-2026-93091)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the ARM SCMI notification subsystem when transport callbacks or late-init work execute during device teardown. A local user can race device teardown with notification processing to cause a denial of service.

Late-init work is queued on the system workqueue.


872) Race condition (CVE-ID: CVE-2026-93092)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a race condition in the SCMI driver.

The vulnerability exists due to improper synchronization in requested-devices notifier handling when a SCMI device is being removed. A local user can cause a requested-devices notifier callback to race with active_protocols IDR teardown to cause a race condition in the SCMI driver.


873) NULL pointer dereference (CVE-ID: CVE-2026-93093)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the ARM SCMI mailbox and SMC transport setup routines when a pending or spurious callback occurs before channel state is fully initialized. A local user can trigger an early transport callback to cause a denial of service.


874) Out-of-bounds write (CVE-ID: CVE-2026-93095)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds write.

The vulnerability exists due to improper validation of catalog thread records in hfsplus_delete_cat() when rebuilding a catalog key from a corrupted HFS+ image. A local user can supply a corrupted HFS+ image with an oversized thread name length to cause an out-of-bounds write.


875) Infinite loop (CVE-ID: CVE-2026-93097)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to an infinite loop in the CXL poison list processing function when processing a device response containing an empty poison payload with the CXL_POISON_FLAG_MORE flag set. An attacker with physical access can cause a CXL device to return a crafted poison response to cause a denial of service.


876) Deadlock (CVE-ID: CVE-2026-93098)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a deadlock in GLINK endpoint destruction when detaching an rpmsg driver. A local privileged user can trigger driver detachment to cause a denial of service.


877) Improper resource shutdown or release (CVE-ID: CVE-2026-93101)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in v4l2_async_unregister_subdev() when disconnecting a susceptible em28xx USB device. An attacker with physical access can disconnect the USB device to cause a denial of service.

The issue occurs when a tvp5150 I2C sub-device is registered through means other than v4l2-async and its asynchronous connection list is empty.


878) Memory leak (CVE-ID: CVE-2026-93102)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the hfi1 init_one() cleanup path when hfi1_init() or hfi1_register_ib_device() fails after RX support allocation. A local user can trigger a late probe failure to cause a denial of service.


879) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-93103)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an allocation failure in hfi1_free_devdata() when allocating a unit ID for an HFI1 device. A local user can cause unit ID allocation to fail to cause a denial of service.

The issue occurs when cleanup runs before the device has been inserted into the unit table.


880) Race condition (CVE-ID: CVE-2026-93107)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service and corrupt data.

The vulnerability exists due to a race condition in the RDMA RXE responder state machine's do_complete function when a queue pair enters the error state while completing a received packet. A remote attacker can send a packet while a disconnect races with receive processing to cause a denial of service and corrupt data.


881) Race condition (CVE-ID: CVE-2026-93108)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper synchronization in the IPoIB module teardown path when unloading the module while RCU callbacks remain pending. A local privileged user can initiate module teardown before queued RCU callbacks complete to cause a denial of service.

The condition can also occur after client registration failure removes already-added devices and queues callbacks.


882) Use-after-free (CVE-ID: CVE-2026-93109)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a failure to wait for queued RCU callbacks in mlx5_ib module teardown when closing a DevX event file or detaching auxiliary driver devices. A local user can close a DevX event file to cause a denial of service.

The issue can also occur during registration error unwinding after driver registration attaches existing devices before failing.


883) Use-after-free (CVE-ID: CVE-2026-93110)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a use-after-free condition in the RDMA core ib_core cleanup routine when unloading the ib_core module after RCU callbacks have been queued. A local privileged user can cause queued callbacks to invoke unloaded module code to cause a denial of service.

Exploitation requires RCU callbacks queued by put_gid_ndev() before module unloading.


884) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-93113)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to improper clock registration in CAMCC_GDSC_CLK in the Qualcomm SC8280XP camera clock controller when unused clocks are shut down. A local user can trigger unused-clock shutdown to trigger a kernel warning.


885) NULL pointer dereference (CVE-ID: CVE-2026-93114)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in san_probe when the Surface ACPI notification driver is force-bound to a device without an ACPI companion. A local user can force-bind the driver to such a device to cause a denial of service.


886) NULL pointer dereference (CVE-ID: CVE-2026-93115)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the mlxbf_pmc_probe() function of the mlxbf-pmc driver when force-binding the driver to a device without an ACPI companion object. A local user can force-bind the driver to such a device to cause a denial of service.


887) Use-after-free (CVE-ID: CVE-2026-93117)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a use-after-free in usb_probe_interface when a USB driver probe runs concurrently with dynamic ID removal. A local user can trigger concurrent USB driver probing and dynamic ID removal to trigger a use-after-free condition.


888) NULL pointer dereference (CVE-ID: CVE-2026-93118)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an unchecked allocator return in the Aspeed UDC driver's ast_udc_probe() function when initializing endpoint buffers after coherent DMA buffer allocation fails. A local privileged user can cause the driver to dereference a null endpoint buffer during probe to cause a denial of service.


889) Stack-based buffer overflow (CVE-ID: CVE-2026-93119)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a stack-based buffer overflow.

The vulnerability exists due to a stack-based buffer overflow in the valid_pin array in ljca_enumerate_gpio() when processing device-provided GPIO descriptors. An attacker with physical access can report a bank_num value exceeding the valid_pin array capacity to cause a stack-based buffer overflow.


890) Out-of-bounds read (CVE-ID: CVE-2026-93120)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in os_desc_qw_sign_show() in the USB gadget configfs implementation when converting a stored signature from UTF-16 to UTF-8. A local user can store a signature that fills the buffer without a NUL terminator and read the configfs attribute to disclose sensitive information.


891) Use of uninitialized resource (CVE-ID: CVE-2026-93121)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause undefined behavior.

The vulnerability exists due to improper cleanup of an uninitialized dma_fence object in ffs_dmabuf_transfer() when handling an endpoint-disabled or request-allocation failure. A local user can initiate a DMA-buffer transfer that encounters either error condition to cause undefined behavior.


892) Race condition (CVE-ID: CVE-2026-93123)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to discard newly written serial data.

The vulnerability exists due to a race condition in the qcom GENI serial DMA transmit completion path when a stale DMA completion is handled after the transmit FIFO is flushed and new data is written. A local user can cause the stale completion to advance the transmit FIFO and discard the new data.

Exploitation requires the hardware DMA transfer to complete before its completion interrupt is handled.


893) Memory leak (CVE-ID: CVE-2026-93126)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak device node references.

The vulnerability exists due to a missing release of a device node reference in the adsp_map_carveout function when calling of_parse_phandle_with_args(). A local user can cause the function to process a device-tree phandle to leak device node references.


894) NULL pointer dereference (CVE-ID: CVE-2026-93128)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the lg-laptop driver's keyboard-backlight LED event notification handling when processing an event notification after keyboard-backlight LED registration fails. A local user can trigger the affected event handling to cause a denial of service.


895) Improper resource shutdown or release (CVE-ID: CVE-2026-93130)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a resource leak.

The vulnerability exists due to improper resource shutdown or release in the dell-wmi-base module initialization routine when module initialization fails. A local privileged user can trigger a module load failure to cause a resource leak.


896) Use-after-free (CVE-ID: CVE-2026-93131)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to a use-after-free race condition in the Dell privacy WMI driver when accessing the features_present field without holding the list mutex. A local user can trigger concurrent access to the field while the associated privacy data is freed to access freed memory.


897) Infinite loop (CVE-ID: CVE-2026-93132)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper loop control in riscv_acpi_add_prt_dep() when processing ACPI PCI routing table entries that trigger an error condition. A local user can trigger an error condition that causes the same entry to be processed repeatedly to cause a denial of service.


898) Access of Uninitialized Pointer (CVE-ID: CVE-2026-93133)

CWE-ID: CWE-824 - Access of Uninitialized Pointer

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use of an uninitialized pointer in riscv_acpi_add_prt_dep() when processing ACPI PRT entries with unresolved source handles. A local user can trigger processing of an ACPI PRT entry with an unresolved source handle to cause a denial of service.


899) Use-after-free (CVE-ID: CVE-2026-93134)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to use-after-free in console_flush_one_record() when emitting records through legacy printing during a console handover. A local user can trigger legacy record emission during a console handover to access freed memory.


900) Memory leak (CVE-ID: CVE-2026-93136)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to improper reference count management in mhi_ep_create_device() when dev_set_name() or device_add() fails during MHI device creation. A local user can trigger a device-creation error to cause a resource leak.


901) Use-after-free (CVE-ID: CVE-2026-93137)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in bpf_find_vma() when a BPF program accesses virtual memory area information for a foreign task. A local user can invoke bpf_find_vma() with a foreign task to trigger a use-after-free condition.

The foreign task must exit concurrently.


902) Race condition (CVE-ID: CVE-2026-93138)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access incompletely initialized vmlinux BTF data.

The vulnerability exists due to a race condition in bpf_get_btf_vmlinux when concurrently invoking the function during first-time vmlinux BTF parsing. A local user can invoke the affected function concurrently to access incompletely initialized vmlinux BTF data.

The race can occur on weakly ordered architectures when CONFIG_DEBUG_INFO_BTF is enabled.


903) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-93140)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a spurious kernel warning.

The vulnerability exists due to improper handling of an exceptional I/O condition in the UDF Logical Volume Integrity Descriptor buffer when marking the buffer dirty after a write I/O error. A local user can remount the filesystem read-write or synchronize it to trigger a spurious kernel warning.


904) Double free (CVE-ID: CVE-2026-93141)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in r8a66597_probe() when usb_add_gadget_udc() fails. A local user can trigger the probe error path to cause a denial of service.


905) Unchecked Return Value (CVE-ID: CVE-2026-93142)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in the rcar_thermal_probe() function when registering a thermal zone during driver probe. A local user can trigger a thermal zone registration failure to cause a denial of service.


906) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-93145)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to failure to release generic power-domain structures in gdsc_unregister() when performing a provider unbind and rebind cycle. A local privileged user can trigger a provider unbind and rebind cycle to cause a denial of service.


907) Race condition (CVE-ID: CVE-2026-93149)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the mac80211_hwsim_stop() pending-frame queue drain when stopping the mac80211_hwsim device. A local user can trigger concurrent TX status handling that removes the final pending frame to cause a denial of service.


908) Race condition (CVE-ID: CVE-2026-93150)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect operations.

The vulnerability exists due to a race condition in the cpuset subsystem's nr_deadline_tasks counter when concurrent scheduler-policy changes and cpuset attachment operations update the counter. A local user can perform concurrent scheduler-policy and cpuset attachment operations to cause incorrect operations.


909) Memory leak (CVE-ID: CVE-2026-93151)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a memory leak.

The vulnerability exists due to failure to release response resources in the nvmet-rdma queue teardown routine when an RDMA connection is forcefully disconnected while I/O operations are in flight. A remote attacker can disconnect an RDMA connection while I/O operations are in flight to cause a memory leak.


910) Race condition (CVE-ID: CVE-2026-93152)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access queue state before its initialization is visible.

The vulnerability exists due to improper synchronization in the Apple NVMe driver's queue enabled-state handling when interrupt or request paths check whether a queue is enabled. A local user can race queue-state checks with queue initialization to access queue state before its initialization is visible.


911) Out-of-bounds read (CVE-ID: CVE-2026-93155)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an out-of-bounds access in the Keem Bay OCS AES driver's register_aes_algs() function when skcipher algorithm registration fails after AEAD algorithm registration. A local privileged user can trigger the registration error path to cause a denial of service.


912) Unchecked Return Value (CVE-ID: CVE-2026-93156)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause hash requests to produce incorrect digest values.

The vulnerability exists due to an unchecked return value in the rk3288 crypto ahash driver's rk_hash_run() function when waiting for the hash engine to become idle after a final DMA transfer. A local user can submit a hash request while the hash engine does not become idle to cause hash requests to produce incorrect digest values.


913) Unchecked Return Value (CVE-ID: CVE-2026-93158)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause crypto request setup failures.

The vulnerability exists due to unchecked return value handling in sa_ul_probe() when security-context DMA pool creation fails. A local user can initiate use of the driver after DMA pool creation fails to cause crypto request setup failures.


914) Incomplete cleanup (CVE-ID: CVE-2026-93159)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to incomplete cleanup in the atmel-sha204a nonblocking RNG path when an asynchronous I2C transfer fails. A local user can make subsequent read attempts after a failed I2C transfer to disclose sensitive information.


915) Key management errors (CVE-ID: CVE-2026-93160)

CWE-ID: CWE-320 - Key Management Errors

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to derive a shared secret using a private key not generated for the current transform context.

The vulnerability exists due to improper cryptographic key management in atmel_ecdh_compute_shared_secret() when processing hardware ECDH shared-secret requests without a cached public key. A local user can submit a hardware ECDH shared-secret request without a cached public key to derive a shared secret using a private key not generated for the current transform context.


916) Sensitive Information in Resource Not Removed Before Reuse (CVE-ID: CVE-2026-93161)

CWE-ID: CWE-226 - Sensitive Information in Resource Not Removed Before Reuse

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive key material.

The vulnerability exists due to failure to clear sensitive information from stack memory in qat_alg_xts_reverse_key() when expanding a forward XTS AES key. A local user can access residual AES key material in stack memory to disclose sensitive key material.


917) Expired pointer dereference (CVE-ID: CVE-2026-93162)

CWE-ID: CWE-825 - Expired pointer dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an expired pointer dereference in the QAT reset worker when an SR-IOV reenable completion wait times out. A local user can trigger a QAT device reset that reaches the timeout to cause memory corruption.


918) Use-after-free (CVE-ID: CVE-2026-93163)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to a use-after-free in the hwrng_register function when handling a hardware random number generator registration failure. A local user can cause registration to fail after the random number generator has been added to the global rng_list and free the associated structure to trigger a use-after-free.


919) Out-of-bounds read (CVE-ID: CVE-2026-93165)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to overread memory.

The vulnerability exists due to an out-of-bounds read in cros_ec_sensorhub_ring_handler() when processing FIFO information responses from EC firmware. A local privileged user can cause the handler to process a response whose length is shorter than expected to overread memory.

The condition can occur when EC firmware reports inconsistent maximum response and sensor-count values.


920) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2026-93167)

CWE-ID: CWE-823 - Use of Out-of-range Pointer Offset

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to incorrect stack offset handling in the C-SKY syscall trace path when tracing system calls with fifth or sixth arguments. A local user can trace a process executing a system call with five or six arguments to cause a denial of service.

The issue is limited to the C-SKY ABIv2 syscall trace path.


921) Race condition (CVE-ID: CVE-2026-93170)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause descriptor corruption or missed DMA completions.

The vulnerability exists due to a race condition in the Xilinx AXIDMA and MCDMA interrupt handlers when handling descriptor-completion interrupts. A local user can queue multiple active descriptors before a completion interrupt occurs to cause descriptor corruption or missed DMA completions.

Exploitation requires descriptors to remain in the active list after completed descriptors are moved to the done list.


922) NULL pointer dereference (CVE-ID: CVE-2026-93172)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in free_area_init_core_hotplug when initializing per-CPU node statistics during memory hotplug. A local privileged user can initiate a memory hotplug operation that encounters a failed per_cpu_nodestats allocation to cause a denial of service.


923) Incorrect behavior order (CVE-ID: CVE-2026-93173)

CWE-ID: CWE-696 - Incorrect Behavior Order

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper execution-context handling in the bpf_prog_free hook of sleepable_lsm_hooks when a BPF program is freed while a sleepable LSM program is attached. A local privileged user can cause a BPF program to be freed to cause a denial of service.


924) Use of uninitialized resource (CVE-ID: CVE-2026-93174)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose stale heap contents.

The vulnerability exists due to incomplete copying of per-CPU map value padding in copy_map_value_long() when processing UAPI LOOKUP_ELEM operations on per-CPU maps. A local user can invoke a UAPI lookup operation on a per-CPU map with a value size that requires padding to disclose stale heap contents.

The issue also affects bpf_iter for per-CPU maps.


925) Out-of-bounds read (CVE-ID: CVE-2026-93177)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in the Vega10 PowerPlay hardware manager when parsing VBIOS-provided voltage dependency tables. A local user can provide voltage table entries containing out-of-range lookup indices to read out-of-bounds memory.


926) Out-of-bounds read (CVE-ID: CVE-2026-93178)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in the SMU7 powerplay voltage lookup handling when processing VBIOS-parsed voltage table entries containing out-of-range voltage indices. A local user can provide VBIOS-parsed table entries with out-of-range voltage indices to perform an out-of-bounds read.


927) Integer overflow (CVE-ID: CVE-2026-93182)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in update_tg_cfs_runnable() in the fair scheduler when processing scheduler runnable-load updates. A local user can run a hackbench workload to cause a denial of service.


928) Improper initialization (CVE-ID: CVE-2026-93183)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization order in lima_device_init() when initializing the Lima device. A local user can trigger creation of an empty Lima VM before its allocation range is configured to cause a denial of service.

The kernel BUG condition is triggered when DRM_DEBUG_MM is enabled.


929) Improper initialization (CVE-ID: CVE-2026-93184)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a system hang.

The vulnerability exists due to improper runtime power management handling in the fsl_audmix probe routine when accessing ALSA control or DAPM paths before the first runtime resume. A local user can access an affected audio control path to cause a system hang.


930) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-93185)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause active timer or work objects to remain after device removal.

The vulnerability exists due to improper cancellation of delayed work in rt700_sdw_remove() when removing an RT700 SoundWire codec after the SoundWire slave becomes unattached while jack work is pending. A local privileged user can cause the remove path to skip cancellation of pending jack work.

Practical reachability depends on SoundWire core remove ordering after an unattached status update.


931) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-93186)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to uncontrolled memory allocation in the CXL mailbox command constructor cxl_mbox_cmd_ctor() when processing CXL_MEM_SEND_COMMAND requests with an oversized output size. A local user can submit a command with a large output size to cause a denial of service.

A system panic requires panic_on_warn=1.


932) Out-of-bounds read (CVE-ID: CVE-2026-93188)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to disclose out-of-bounds data.

The vulnerability exists due to an out-of-bounds read in the Roccat Kone HID driver's profile handling when processing a device-supplied profile index. An attacker with physical access can connect a malicious USB device claiming the Roccat Kone ID and send a switch-profile event or provide a startup profile value during probing to disclose out-of-bounds data.

The out-of-bounds read result is exposed through the actual_dpi sysfs attribute.


933) Use-after-free (CVE-ID: CVE-2026-93189)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to failure to quiesce HID input before freeing objects in hid_hw_stop() in the HID core when a driver probe unwinds after HID input has been enabled while HID reports are in flight. A local user can trigger a failed driver initialization while HID reports are being processed to trigger a use-after-free condition.


934) Stack-based buffer overflow (CVE-ID: CVE-2026-93190)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause memory corruption.

The vulnerability exists due to a stack-based buffer overflow in cros_typec_register_partner_pdos() when processing EC TYPEC_STATUS responses with a source or sink PDO count exceeding PDO_MAX_OBJECTS. A local privileged user can provide a response with an oversized PDO count to cause memory corruption.


935) Incorrect authorization (CVE-ID: CVE-2026-93191)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose messages to an unauthorized receiver.

The vulnerability exists due to improper authorization in smack_msg_queue_msgrcv when processing messages through the pipelined_send optimization for a waiting receiver. A local user can send a message to a queue while an unauthorized target task is waiting to receive it to disclose messages to an unauthorized receiver.


936) Use-after-free (CVE-ID: CVE-2026-93192)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.

The vulnerability exists due to failure to clear a dangling active-job pointer in the Linux kernel V3D driver's BIN, RENDER, TFU, and CSD job execution callbacks when v3d_fence_create() fails during job execution. A local user can exploit the stale queue->active_job reference to compromise system confidentiality, integrity, and availability.

The BIN queue's active-job reference can also be accessed concurrently by v3d_overflow_mem_work().


937) Race condition (CVE-ID: CVE-2026-93203)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt backbone gateway CRC values.

The vulnerability exists due to a race condition in batadv_bla_add_claim() when processing concurrent CLAIM frames for the same client. A remote attacker can send concurrent CLAIM frames to corrupt backbone gateway CRC values.


938) Race condition (CVE-ID: CVE-2026-93204)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to poison an ARP cache.

The vulnerability exists due to a race condition caused by non-atomic MAC address updates in batadv_dat_entry_add() in the batman-adv distributed ARP table when a MAC address is updated concurrently with a reader accessing the entry. A remote attacker can cause a MAC address update to race with a reader to poison an ARP cache.


939) Use-after-free (CVE-ID: CVE-2026-93205)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a use-after-free in the IOPF queue cleanup performed by arm_smmu_device_remove() when removing an Arm SMMU device. A local privileged user can trigger device removal while the event-queue IRQ handler accesses the IOPF queue to cause a denial of service.


940) Incorrect authorization (CVE-ID: CVE-2026-93206)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to disclose PCI configuration-space information.

The vulnerability exists due to improper authorization using the credentials of the calling task rather than the opening process in proc_bus_pci_read() when reading PCI configuration space through procfs. A local privileged user can pass a file descriptor opened with CAP_SYS_ADMIN to an unprivileged process to disclose PCI configuration-space information.


941) Use-after-free (CVE-ID: CVE-2026-93207)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access freed memory.

The vulnerability exists due to a use-after-free condition in svcauth_gss_decode_credbody() when processing malformed RPC GSS credential bodies. A remote attacker can send a malformed RPC GSS credential to access freed memory.

The credential storage is reused across requests, allowing a dangling context-data pointer to be paired with a stale length after request pages are released.


942) Race condition (CVE-ID: CVE-2026-93208)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to prevent slab caches from being released.

The vulnerability exists due to a race condition in KASAN quarantine cache removal when a CPU goes offline after per-CPU cache processing. A local user can trigger cache shrinking or destruction during CPU hotplug activity to prevent slab caches from being released.

Only kernels built with CONFIG_KASAN_GENERIC are affected.


943) Unchecked Return Value (CVE-ID: CVE-2026-93209)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause Bluetooth enable operations to time out.

The vulnerability exists due to improper handling of an allocation failure in the Bluetooth HCI command synchronization functionality when processing a Bluetooth command under memory pressure. A local user can trigger Bluetooth command processing during memory pressure to cause Bluetooth enable operations to time out.


944) NULL pointer dereference (CVE-ID: CVE-2026-93210)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the SMB client DFS cache when processing an invalid target hint. A local user can cause the DFS cache to process an invalid target hint to cause a denial of service.


945) Race condition (CVE-ID: CVE-2026-93211)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in DRC hash table initialization in nfsd_reply_cache_init when the DRC shrinker scans the reply cache before bucket list heads are initialized. A local user can trigger reply-cache initialization concurrently with a shrinker scan to cause a denial of service.

The issue occurs on weakly ordered architectures such as arm64 and ppc.


946) NULL pointer dereference (CVE-ID: CVE-2026-93212)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in nfsd_file_net_dispose() when draining the filecache disposal list during per-network teardown. A local user can trigger per-network teardown while the disposal list contains more than eight entries to cause a denial of service.


947) Out-of-bounds read (CVE-ID: CVE-2026-93213)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in the of_alias_scan() stem parser when parsing a property name that is empty or consists only of digits. A local user can trigger parsing of such a property name to perform an out-of-bounds read.


948) Deadlock (CVE-ID: CVE-2026-93214)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock ordering in usbg_make_tpg() when performing configfs dependency operations across subsystems. A local user can trigger concurrent configfs operations to cause a denial of service.

Exploitation requires a circular lock dependency involving configfs_rmdir().


949) Double free (CVE-ID: CVE-2026-93215)

CWE-ID: CWE-415 - Double Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in cdx_create_res_attr() when sysfs binary file creation fails. A local user can trigger resource attribute creation under this failure condition to cause a denial of service.


950) Incorrect calculation (CVE-ID: CVE-2026-93219)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an incorrect minimum interval calculation in the sun4i clockevent timer driver when processing timer events. A local user can trigger timer events to cause a denial of service.

The issue can leave the next timer event stuck during oneshot, high-resolution, or nohz timer operation.


951) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-93222)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause signal sender identifiers to be incorrectly rewritten.

The vulnerability exists due to improper handling of shared siginfo data in the signal delivery logic when delivering group signals across namespaces. A local user can send a group signal to cause sender identifiers rewritten for one recipient to affect subsequent recipients.


952) Improper update of reference count (CVE-ID: CVE-2026-93223)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a reference count underflow of an Open Firmware node.

The vulnerability exists due to improper reference count management in tegra_vip_channel_of_parse() in the tegra-video VIP driver when parsing endpoint nodes from a malformed device tree. A local user can trigger an endpoint parsing error with a malformed device tree to cause a reference count underflow of an Open Firmware node.


953) Improper update of reference count (CVE-ID: CVE-2026-93224)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the svc_rdma_accept() error-handling path and rpcrdma_rn_unregister() when handling a failed RDMA transport accept. A remote attacker can trigger failed RDMA transport accepts to cause a denial of service.


954) Race condition (CVE-ID: CVE-2026-93226)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a race condition.

The vulnerability exists due to an unsafe iteration of an RCU-protected list in rt6_nh_dump_exceptions() when dumping IPv6 route exceptions while exception entries are concurrently added. A local user can initiate an IPv6 route dump during concurrent route exception insertion to trigger a race condition.


955) Improper input validation (CVE-ID: CVE-2026-93228)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause improper processing of malformed RPC-over-RDMA chunks.

The vulnerability exists due to improper input validation in the xdr_check_write_chunk() function when processing Write or Reply chunks with a zero segment count. A remote attacker can send a malformed Write or Reply chunk with a zero segment count to cause improper processing of malformed RPC-over-RDMA chunks.


956) Race condition (CVE-ID: CVE-2026-93229)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to obtain inconsistent RPC request status information.

The vulnerability exists due to a missing read memory barrier in nfsd_nl_rpc_status_get_dumpit() when reporting RPC request status through a dump operation. A local user can request RPC status information during concurrent request-status updates to obtain inconsistent RPC request status information.

The issue occurs on weakly ordered architectures such as ARM and POWER.


957) Out-of-bounds read (CVE-ID: CVE-2026-93234)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to perform an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in gud_connector_add_tv_mode() when processing TV mode names returned by a GUD device. An attacker with physical access can provide a device response containing a TV mode name without a NUL terminator to perform an out-of-bounds read.


958) Improper initialization (CVE-ID: CVE-2026-93235)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper initialization of post-EOF data in the F2FS file size extension handling when extending a file across an unaligned EOF boundary. A local user can extend a file across an unaligned EOF boundary to disclose sensitive information.

Stale disk data can be exposed after remounting or crash recovery when metadata is persisted before the zeroed data.


959) NULL pointer dereference (CVE-ID: CVE-2026-93236)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in vdec_try_fmt_common() when processing a VIDIOC_TRY_FMT request with an unsupported pixel format on the OUTPUT queue. A local user can submit a crafted VIDIOC_TRY_FMT request to cause a denial of service.

The issue occurs when MPEG2 support has been locally removed and is absent from the platform format table.


960) Use of Uninitialized Variable (CVE-ID: CVE-2026-93238)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause unintended guest hardware queue resets.

The vulnerability exists due to use of an uninitialized bitmap in vfio_ap_mdev_hot_plug_cfg() when processing a hot-plug configuration change that adds only control domains. A local user can modify the hot-plug configuration to add only control domains to cause unintended guest hardware queue resets.


961) Use-after-free (CVE-ID: CVE-2026-93239)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a kernel fault.

The vulnerability exists due to use-after-free in the arm64 show_pte() page-table walk when walking task page tables concurrently with teardown. A local user can cause a task page-table teardown to occur during the walk to cause a kernel fault.

The walk can also derive a lower-level pointer from a parent entry that has been cleared concurrently.


962) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-93240)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to improper execution-context handling in the cgroup v1 memory soft limit reclaim path when soft limit reclaim invokes lru_gen_shrink_lruvec() from kswapd. A local user can configure memory.soft_limit_in_bytes to trigger a kernel warning.


963) Off-by-one (CVE-ID: CVE-2026-93242)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause legitimate firmware responses to be dropped.

The vulnerability exists due to an off-by-one error in __qla_consume_iocb() in the qla2xxx response queue handler when processing response queue IOCBs. A local user can trigger response queue processing to consume an unrelated IOCB and cause legitimate firmware responses to be dropped.


964) Improper initialization (CVE-ID: CVE-2026-93245)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to improper initialization of list heads in AppArmor policy initialization when handling a profile creation failure before initialization completes. A local user can attempt to load a profile that fails during creation to trigger a kernel warning.


965) Race condition (CVE-ID: CVE-2026-93247)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in Bluetooth management discovery state handling when concurrently updating and reading the UUID discovery filter state. A local user can initiate concurrent Bluetooth service discovery operations to cause a denial of service.


966) Use-after-free (CVE-ID: CVE-2026-93250)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a use-after-free in vxlan_mdb_flush() when flushing VXLAN multicast database entries through RTM_DELMDB bulk requests. A local user can create an (S, G) entry before a (*, G) entry and issue a bulk RTM_DELMDB request to cause memory corruption.

The (*, G) entry must be added with NLM_F_REPLACE because adding the source otherwise fails with -EEXIST.


967) Deadlock (CVE-ID: CVE-2026-93252)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock ordering in the OCFS2 ACL initialization and extended attribute handling paths when concurrently performing extended attribute updates and filesystem node-creation operations. A local user can perform concurrent extended attribute updates and mkdir or mknod operations to cause a denial of service.

Exploitation depends on a pending writer on the journal transaction barrier causing the conflicting lock acquisition paths to block.


968) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-93256)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper exception masking in the arm64 hibernation resume code when resuming from hibernation. A local privileged user can resume a hibernated system while exceptions are unmasked to cause a denial of service.

Pseudo-NMI support can permit pseudo-NMI exceptions during the resume process.


969) Reliance on undefined behavior (CVE-ID: CVE-2026-93259)

CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an incorrect inline assembly clobber list in the powerpc interrupt-handling functions call_do_irq() and call_do_softirq() when executing the affected stack-switching calls in CONFIG_PPC_KERNEL_PCREL mode. A local user can trigger the affected interrupt-handling paths to cause a denial of service.

Newer GCC versions can allocate values spanning the calls to r2, exposing register corruption when the called functions modify that register.


970) NULL pointer dereference (CVE-ID: CVE-2026-93261)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a missing null check in __lock_set_class() when register_lock_class() returns NULL. A local user can cause lock class registration to fail to cause a denial of service.

Lock class registration can fail when the lock class pool is exhausted, graph_lock() fails, or key validation fails.


971) Use-after-free (CVE-ID: CVE-2026-93262)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in ppl_do_flush() when processing RAID5 PPL flushes. A local user can cause ppl_io_unit_finished() to free the io object while the loop continues accessing io->pending_flushes to trigger a use-after-free condition.


972) Out-of-bounds read (CVE-ID: CVE-2026-93264)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory registration to be rejected.

The vulnerability exists due to an incorrect chunk length calculation in the EFA RDMA driver's pbl_chunk_list_create function when registering a memory region whose PBL page count is a multiple of 510. A local user can register such a memory region to cause memory registration to be rejected.

The issue can also result in an out-of-bounds access to the chunks array.


973) Improper locking (CVE-ID: CVE-2026-93268)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper lock management in ext4_try_to_expand_extra_isize() when expanding inode extra isize during filesystem mount. A local privileged user can trigger orphan processing during mount to cause a denial of service.

The circular lock dependency involves s_writepages_rwsem, an active jbd2 handle, and xattr_sem.


974) Deadlock (CVE-ID: CVE-2026-93269)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock ordering in ext4_ext_migrate when invoking the ext4 extent migration ioctl. A local user can trigger concurrent inode eviction and writeback operations to cause a denial of service.


975) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-93271)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper range validation in ath11k_dp_rx_h_rate() when processing HT, VHT, or HE frames with a reported MCS above the corresponding mac80211 rate-space maximum. A remote attacker can send a wireless frame with an out-of-range reported MCS value to cause a denial of service.

The affected frame decodes correctly despite its reported MCS value exceeding the corresponding mac80211 rate space.


976) NULL pointer dereference (CVE-ID: CVE-2026-93273)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a missing null check and improper resource release in the tps6594_regulator_probe() multiphase configuration loop when processing multiphase regulator configuration. A local user can trigger the loop with a missing buck device node to cause a denial of service.


977) NULL pointer dereference (CVE-ID: CVE-2026-93274)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in bcm2835_pinctrl_probe() when handling a failed pin controller registration. A local user can trigger a failed pin controller registration to cause a denial of service.


978) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-93275)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to improper resource lifecycle management in the Intel PT perf event stop and start callbacks when group throttling invokes callbacks without update flags. A local user can cause an Intel PT event to be throttled to trigger a kernel warning.

The issue can occur when AUX area sampling is used.


979) Use-after-free (CVE-ID: CVE-2026-93278)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in cvm_oct_rx_shutdown when removing the platform device while a NAPI poll function remains active. A local user can trigger the vulnerable shutdown sequence while a NAPI poll function remains active to cause a denial of service.


980) Use-after-free (CVE-ID: CVE-2026-93279)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to a use-after-free in the Octeon staging Ethernet driver cleanup tasklet, cvm_oct_tx_do_cleanup, when device teardown occurs while the cleanup tasklet remains pending. A local user can trigger device teardown while the cleanup tasklet is pending to cause a use-after-free condition.

The watchdog IRQ handler can schedule the cleanup tasklet.


981) Out-of-bounds read (CVE-ID: CVE-2026-93280)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in the Greybus audio topology parser when parsing a topology blob supplied by a connected module. An attacker with physical access can supply a topology blob with section sizes exceeding the fetched size to read out-of-bounds memory.


982) Out-of-bounds read (CVE-ID: CVE-2026-93281)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in rtw89_mac_check_he_obss_narrow_bw_ru_iter() when processing extended capability information with a length of 10 bytes. A remote attacker can provide an extended capability element that is 10 bytes long to read out-of-bounds memory.


983) Use-after-free (CVE-ID: CVE-2026-93283)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in i3c_master_register_new_i3c_devs() when handling a device_register() failure. A local user can trigger a device registration failure followed by device unregistration to cause a denial of service.


984) NULL pointer dereference (CVE-ID: CVE-2026-93286)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a missing null pointer check in aarp_send_ddp() when sending AppleTalk packets through the LocalTalk fast path on a device without an AppleTalk interface configured. A local user can send an AppleTalk packet to cause a denial of service.


985) Memory corruption (CVE-ID: CVE-2026-93287)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper bounds checking in the i2c-stub driver's stub_xfer function when processing caller-supplied I2C_SMBUS_I2C_BLOCK_DATA transfers. A local user can issue a crafted SMBus block transfer with an oversized length to cause a denial of service.


986) Out-of-bounds read (CVE-ID: CVE-2026-93287)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory out of bounds.

The vulnerability exists due to an out-of-bounds read in the smbus_write tracepoint when processing caller-supplied oversized SMBus block writes. A local user can issue an SMBus block write with an oversized length to read memory out of bounds.


987) Use-after-free (CVE-ID: CVE-2026-93288)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to failure to wait for an RCU grace period in nfnetlink_log per-network state when processing packets concurrently with network namespace teardown. A local user can trigger concurrent packet processing and network namespace teardown to trigger a use-after-free.


988) Deadlock (CVE-ID: CVE-2026-93781)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a deadlock in scsi_eh_lock_door() when allocating a request during SCSI error recovery while all scheduler tags are in use. A local user can trigger SCSI error recovery under these conditions to cause a denial of service.


989) Race condition (CVE-ID: CVE-2026-93782)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write response data to an unrelated userspace object.

The vulnerability exists due to a race condition in vhost-scsi ioctl handling when replacing the memory table while commands are in flight. A local user can submit commands and issue VHOST_SET_MEM_TABLE to write response data to an unrelated userspace object.


990) Out-of-bounds read (CVE-ID: CVE-2026-93783)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read uninitialized memory.

The vulnerability exists due to an out-of-bounds read in rfcomm_recv_frame() when processing truncated Bluetooth RFCOMM frames. A remote attacker can send a truncated Bluetooth RFCOMM frame to read uninitialized memory.

A zero-length frame can cause a length underflow and make skb_tail_pointer() read past the buffer.


991) Out-of-bounds read (CVE-ID: CVE-2026-93784)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of information element buffers in cfg80211_wext_siwgenie() when storing a malformed buffer through SIOCSIWGENIE. A local user can submit a malformed information element buffer and trigger a connection attempt to cause a denial of service.

The issue is triggered when a subsequent SIOCSIWESSID operation initiates connection processing.


992) Numeric Truncation Error (CVE-ID: CVE-2026-93785)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause inconsistent payload length interpretation.

The vulnerability exists due to improper validation of payload length in the cifs.idmap key type when processing oversized preparsed payloads. A local user can provide an oversized preparsed payload to cause inconsistent payload length interpretation.


993) Incorrect permission assignment for critical resource (CVE-ID: CVE-2026-93786)

CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to widen effective permissions on SMB-created objects.

The vulnerability exists due to improper permission assignment in the ksmbd VFS POSIX ACL inheritance handling when creating SMB objects in directories with default POSIX ACLs. A remote user can create an SMB object to widen effective permissions on that object.

Exploitation requires a parent directory with a default POSIX ACL containing a restrictive ACL_MASK entry.


994) Out-of-bounds read (CVE-ID: CVE-2026-93787)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds read.

The vulnerability exists due to improper bounds checking in cifs_filldir() when processing SMB1 TRANS2 directory enumeration responses. A remote attacker can return a directory entry with an oversized FileNameLength to cause an out-of-bounds read.

User interaction is required to list a directory on a CIFS mount served by an attacker-controlled SMB1 server.


995) Reliance on undefined behavior (CVE-ID: CVE-2026-93788)

CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to trigger undefined behavior.

The vulnerability exists due to improper bounds checking in the WGDS table revision index handling when processing WGDS tables reporting an invalid revision value. An attacker with physical access can cause the kernel to process a WGDS table with an invalid revision value to trigger undefined behavior.


996) Integer underflow (CVE-ID: CVE-2026-93789)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a length underflow.

The vulnerability exists due to improper validation of aligned TLV lengths in the iwlwifi firmware parser when processing malformed TLVs in a firmware image. A local user can cause the parser to process a firmware image containing malformed TLVs to cause a length underflow.


997) Out-of-bounds write (CVE-ID: CVE-2026-93790)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write outside the bounds of an array.

The vulnerability exists due to improper array index validation in the iwl_mvm_rx_ba_notif handler when processing compressed block acknowledgment notifications. A local user can trigger processing of a compressed block acknowledgment notification containing an invalid TID to write outside the bounds of an array.

Multi-TID block acknowledgment is not generally in use.


998) Improper Validation of Array Index (CVE-ID: CVE-2026-93791)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds memory access.

The vulnerability exists due to improper validation of an array index in the iwl_mvm_rx_ba_notif function when processing BA notifications from firmware. A local user can trigger processing of a BA notification containing an out-of-range TID to cause an out-of-bounds memory access.


999) Integer underflow (CVE-ID: CVE-2026-93792)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer underflow in the iwl_mvm_report_wakeup_reasons() WoWLAN wakeup-reason packet handling when processing firmware-reported WoWLAN packets with undersized lengths. A local user can trigger processing of a firmware-reported WoWLAN packet with an undersized length to cause a denial of service.


1000) Out-of-bounds read (CVE-ID: CVE-2026-93793)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to improper length validation in TX_CMD response parsing in the iwlwifi mvm driver when processing TX_CMD responses with payloads shorter than the frame_count-dependent status layout. A local user can supply a malformed TX_CMD response to cause an out-of-bounds read.


1001) Race condition (CVE-ID: CVE-2026-93794)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause punched file ranges to be incorrectly reported as allocated data.

The vulnerability exists due to improper synchronization in the SMB client smb3_punch_hole function when punching a hole after a large buffered write. A local user can perform a large buffered write followed by a hole-punch operation to cause punched file ranges to be incorrectly reported as allocated data.


1002) Memory leak (CVE-ID: CVE-2026-93795)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause resource exhaustion.

The vulnerability exists due to improper reference count management in the blkg_create() error path when radix_tree_insert() fails. A local user can trigger a radix_tree_insert() failure during blkcg creation to cause resource exhaustion.

The blkcg group may be marked online despite not being fully inserted.


1003) Use-after-free (CVE-ID: CVE-2026-93796)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to a use-after-free condition in the iwlwifi PCIe RX cleanup routine when RX initialization fails and cleanup or retry paths are invoked. A local user can invoke the affected cleanup or retry paths after a failed RX initialization to access freed memory.


1004) Out-of-bounds read (CVE-ID: CVE-2026-93797)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read memory out of bounds.

The vulnerability exists due to an out-of-bounds read in the iwl_mvm_check_he_obss_narrow_bw_ru_iter function when processing an extended capability information element shorter than 11 bytes. A remote attacker can supply a malformed extended capability information element to read memory out of bounds.


1005) Race condition (CVE-ID: CVE-2026-93798)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause inconsistent relocation-root state.

The vulnerability exists due to improper synchronization in merge_reloc_roots() when merging relocation roots. A local user can trigger relocation-root cleanup to cause inconsistent relocation-root state.

The issue occurs when a root has zero root references in its root item.


1006) Improper Validation of Array Index (CVE-ID: CVE-2026-93799)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds array access.

The vulnerability exists due to improper validation of an array index in the iwl_mvm_window_status_notif BA window status notification handler when processing a BA window status notification. A local user can cause processing of a notification containing an invalid station ID to perform an out-of-bounds array access.

The station ID is extracted as a 5-bit value from the firmware notification and is used to index the fw_id_to_mac_id[] array.


1007) Use-after-free (CVE-ID: CVE-2026-93800)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the btrfs relocation root cleanup logic when handling errors returned by btrfs_update_reloc_root() during relocation. A local user can trigger relocation that encounters an error and unmount the filesystem to cause a denial of service.


1008) Use of Uninitialized Variable (CVE-ID: CVE-2026-93801)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect field values.

The vulnerability exists due to use of uninitialized stack memory in cifs_open_info_data in the SMB client when using affected SMB client operations. A local user can trigger affected SMB client operations to cause incorrect field values.


1009) Out-of-bounds write (CVE-ID: CVE-2026-93802)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in rsi_prepare_beacon() when preparing an oversized beacon frame. A local user can provide an oversized beacon frame to cause a denial of service.


1010) Out-of-bounds read (CVE-ID: CVE-2026-93803)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in libipw_rx() when processing crafted Wi-Fi frames. A remote attacker can send a specially crafted Wi-Fi frame to read out-of-bounds memory.


1011) Race condition (CVE-ID: CVE-2026-93804)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause packets to be transmitted to the driver after it has been told to leave an IBSS.

The vulnerability exists due to a race condition in ieee80211_ibss_disconnect() in mac80211 when disconnecting from an IBSS while transmissions are in flight. A local user can initiate an IBSS disconnect while packets are still being transmitted to cause packets to be transmitted to the driver after it has been told to leave an IBSS.


1012) Out-of-bounds read (CVE-ID: CVE-2026-93805)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to improper frame length validation in the cfg80211_rx_mlme_mgmt() and cfg80211_tx_mlme_mgmt() callbacks when processing truncated MLME management frames. A local user can supply a truncated management frame to read out-of-bounds memory.


1013) Out-of-bounds read (CVE-ID: CVE-2026-93806)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in cfg80211_rx_assoc_resp() in the cfg80211 wireless subsystem when processing a short association response frame. A remote attacker can send a malformed association response frame to read out-of-bounds memory.


1014) Out-of-bounds read (CVE-ID: CVE-2026-93807)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in rsi_hal_load_key() in the rsi wireless driver when processing non-TKIP cipher keys. A local user can provide a non-TKIP cipher key with a shorter key layout to cause an out-of-bounds read.


1015) Out-of-bounds read (CVE-ID: CVE-2026-93808)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause an out-of-bounds read.

The vulnerability exists due to improper length validation in the ALSA USB CAIAQ EP1 reply handling code when processing undersized EP1 replies. An attacker with physical access can provide a malformed EP1 reply to cause an out-of-bounds read.


1016) Double free (CVE-ID: CVE-2026-93810)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a double free.

The vulnerability exists due to a double fput in error handling in cachefiles_create_tmpfile() when the cache does not support read_iter and write_iter. A local user can trigger this error-handling path to cause a double free.


1017) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-93811)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak and an incorrect success result.

The vulnerability exists due to improper exceptional-condition handling in ksmbd_vfs_get_sd_xattr() when validating a decoded security descriptor size. A local user can trigger validation of a security descriptor smaller than struct smb_ntsd to cause a memory leak and an incorrect success result.


1018) Memory leak (CVE-ID: CVE-2026-93811)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper error-path resource cleanup in ksmbd_vfs_get_sd_xattr() when decoding an NT ACL. A local user can trigger an ndr_decode_v4_ntacl() failure to cause a memory leak.


1019) Memory leak (CVE-ID: CVE-2026-93812)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper memory release in ksmbd_vfs_set_sd_xattr when encoding NT ACL data. A remote attacker can cause an encoding operation to return an error after memory allocation to cause a denial of service.


1020) Out-of-bounds read (CVE-ID: CVE-2026-93813)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the Btrfs INODE_REF item handler when processing a crafted Btrfs image. A local user can provide a crafted Btrfs image with an oversized INODE_REF name length to cause a denial of service.


1021) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-93814)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in spi_controller_suspend() when suspending a system while an SPI controller in target mode has an active transfer. A local user can trigger system suspend during an active target-mode SPI transfer to cause a denial of service.


1022) Improper locking (CVE-ID: CVE-2026-93815)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an invalid wait context.

The vulnerability exists due to improper locking in au1000_close() in the au1000 Ethernet driver when stopping the network device. A local user can invoke the affected close operation to trigger an invalid wait context.


1023) Out-of-bounds read (CVE-ID: CVE-2026-93816)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to an out-of-bounds read in the f2fs inline dentry conversion routine when processing a corrupted filesystem image. A local user can provide a corrupted filesystem image containing an overlong inline dentry name to read out-of-bounds memory.


1024) Use-after-free (CVE-ID: CVE-2026-93817)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper lifetime management in event::addr_filter_ranges when address-filter ranges are accessed under RCU. A local user can cause address-filter ranges to be freed while they remain accessible under RCU to trigger a use-after-free condition.


1025) Use-after-free (CVE-ID: CVE-2026-93818)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the PLDA PCIe host controller root bus removal routine when concurrent rescan or hotplug operations are triggered through sysfs. A local user can initiate concurrent sysfs operations to trigger a use-after-free condition and crash the system.


1026) Use-after-free (CVE-ID: CVE-2026-93819)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in the MediaTek PCIe controller driver's root bus removal routine when stopping and removing a root bus concurrently with rescan or hotplug operations triggered via sysfs. A local user can trigger concurrent rescan or hotplug operations via sysfs to cause a denial of service.


1027) Use-after-free (CVE-ID: CVE-2026-93820)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free race condition in Rockchip PCIe host controller root bus removal when rescan or hotplug operations are triggered concurrently via sysfs. A local user can race root bus removal with concurrent rescan or hotplug operations to cause a denial of service.


1028) Race condition (CVE-ID: CVE-2026-93821)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in the Altera PCIe controller driver's root bus removal routine when concurrent rescan or hotplug operations are triggered through sysfs. A local user can trigger concurrent rescan or hotplug operations through sysfs to cause a denial of service.


1029) Use-after-free (CVE-ID: CVE-2026-93822)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a system crash.

The vulnerability exists due to a race condition in PCI iProc root bus removal when concurrently triggering sysfs rescan or hotplug operations. A local user can trigger concurrent sysfs rescan or hotplug operations to cause a system crash.


1030) Resource exhaustion (CVE-ID: CVE-2026-93823)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to uncontrolled resource allocation in the AMDKFD_IOC_GET_DMABUF_INFO ioctl when processing user-supplied metadata buffer sizes. A local user can provide a hostile oversized metadata buffer size to cause a denial of service.

Exploitation requires membership in the render group.


1031) Improper input validation (CVE-ID: CVE-2026-93824)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger exploitable latent bugs.

The vulnerability exists due to improper input validation in the TLS socket option configuration when configuring TLS keys on a socket already in a sockmap. A local user can configure TLS keys on a socket already in a sockmap to trigger exploitable latent bugs.


1032) NULL pointer dereference (CVE-ID: CVE-2026-93825)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a missing null pointer check in spi_get_device_match_data() when processing an SPI device using driver_override without a matching SPI ID entry. A local user can use driver_override without a matching SPI ID entry to cause a denial of service.


1033) Use-after-free (CVE-ID: CVE-2026-93826)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to use-after-free in hidpp_connect_event() when input device registration fails. A local user can trigger a HID++ connection event after input device registration fails to cause a use-after-free condition.


1034) Double free (CVE-ID: CVE-2026-93827)

CWE-ID: CWE-415 - Double Free

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to trigger a double-free.

The vulnerability exists due to a double free in the virtio-fs queue setup and probe cleanup paths when probing a virtio-fs device that advertises more request queues than the transport provides. An attacker with physical access can present a malformed virtio-fs device to cause virtio_find_vqs() to fail during extra queue setup and trigger a double-free.


1035) Integer overflow (CVE-ID: CVE-2026-93828)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an integer overflow in exfat_create_upcase_table() when processing an exFAT volume with an upcase table size of zero. A remote attacker can cause the kernel to process such a volume to trigger an infinite loop.


1036) Race condition (CVE-ID: CVE-2026-93829)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a race condition in cifsd demultiplex thread creation when initializing tcp_ses. A local privileged user can trigger the race during CIFS session creation to cause a denial of service.


1037) Resource exhaustion (CVE-ID: CVE-2026-93830)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper interrupt masking in the XGMAC2 stmmac driver when the DMA runs out of receive descriptors under heavy receive pressure. A remote attacker can generate heavy receive traffic to cause a denial of service.


1038) Unchecked Return Value (CVE-ID: CVE-2026-97407)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access hardware registers while the device state is undefined.

The vulnerability exists due to an unchecked return value in rockchip_pdm_set_fmt() when resuming runtime power management. A local user can request an audio interface format change during a runtime resume failure to access hardware registers while the device state is undefined.


1039) Out-of-bounds read (CVE-ID: CVE-2026-97408)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read beyond the advertised skb payload.

The vulnerability exists due to an out-of-bounds read in l2cap_recv_frame() when processing malformed connectionless L2CAP frames. A remote attacker can send a connectionless frame with an incomplete PSM payload to read beyond the advertised skb payload.

The read can use tailroom bytes as part of the PSM.


1040) Use of uninitialized resource (CVE-ID: CVE-2026-97409)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disable locking correctness validation.

The vulnerability exists due to use of an uninitialized resource in __nvme_fc_abort_outstanding_ios() when error recovery aborts outstanding requests before the I/O tagset is initialized. A local user can trigger an admin request timeout during controller connection to disable locking correctness validation.

The condition occurs while the NVMe over Fibre Channel controller is in the CONNECTING state.


1041) Race condition (CVE-ID: CVE-2026-97410)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt a kernel list.

The vulnerability exists due to improper synchronization in drop_netconsole_target() when removing a configfs target concurrently with cleanup processing after the underlying interface is unregistered. A local user can remove a configfs target while cleanup processing iterates the target cleanup list to corrupt a kernel list.


1042) Infinite loop (CVE-ID: CVE-2026-97411)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper state management in the mal_remove() function of the IBM EMAC MAL driver when removing the affected module after NAPI has not been enabled or has already been disabled. A local privileged user can remove the affected module to cause a denial of service.

The condition can occur when no MACs were registered or when registered MACs were subsequently unregistered.


1043) Use-after-free (CVE-ID: CVE-2026-97412)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to failure to quiesce DMA in the pds_core driver's pdsc_teardown() function when tearing down resources while bus mastering remains enabled. A local user can cause the device to perform DMA after DMA buffers are freed to cause a use-after-free condition.


1044) Integer underflow (CVE-ID: CVE-2026-97413)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds memory access.

The vulnerability exists due to integer underflow in the rtrs-srv process_read and process_write functions when processing a network-supplied RDMA message with usr_len greater than off. A remote attacker can send a crafted RDMA message with usr_len greater than off to cause an out-of-bounds memory access.


1045) NULL pointer dereference (CVE-ID: CVE-2026-97414)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the mt8365_afe_suspend() function of the MediaTek MT8365 AFE PCM driver when handling a suspend operation after register backup buffer allocation fails. A local user can trigger a suspend operation when register backup buffer allocation fails to cause a denial of service.

The runtime-suspend state may be updated even when the suspend operation fails.


1046) Out-of-bounds write (CVE-ID: CVE-2026-97415)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds write.

The vulnerability exists due to improper validation of root reference name lengths in Btrfs ROOT_REF and ROOT_BACKREF item handling when processing malformed Btrfs root reference items. A local user can invoke BTRFS_IOC_GET_SUBVOL_INFO on a filesystem containing a malformed ROOT_BACKREF item to perform an out-of-bounds write.


1047) NULL pointer dereference (CVE-ID: CVE-2026-97416)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in btrfs_may_alloc_data_chunk() when processing corrupted Btrfs metadata during a balance operation. A local user can trigger a Btrfs balance operation on a filesystem whose chunk tree contains a chunk without a corresponding block group to cause a denial of service.

The issue occurs when CONFIG_BTRFS_ASSERT is disabled.


1048) Type conversion (CVE-ID: CVE-2026-97417)

CWE-ID: CWE-704 - Type conversion

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an unaligned memory access.

The vulnerability exists due to an unsafe pointer cast in the tcp_sack() timestamp-only fast path when processing TCP options. A remote attacker can send a TCP packet containing unaligned options to trigger an unaligned memory access.


1049) NULL pointer dereference (CVE-ID: CVE-2026-97418)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in snd_es18xx_mixer when handling control allocation failures. A local user can trigger mixer control creation during an allocation failure to cause a denial of service.


1050) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-97419)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to disclose sensitive information.

The vulnerability exists due to improper network namespace isolation in HSR generic netlink notification handling when broadcasting ring error and node down events. A local privileged user can listen for notifications from HSR devices in other network namespaces in init_net to disclose sensitive information.

The notifications expose the peer node MAC address and slave port interface index.


1051) Out-of-bounds read (CVE-ID: CVE-2026-97420)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to read out-of-bounds memory.

The vulnerability exists due to a missing NUL terminator in the bpf_sysctl_set_new_value helper when replacing a pending sysctl value through a cgroup/sysctl BPF program. A local privileged user can provide a replacement sysctl value without a terminating NUL byte to read out-of-bounds memory.


1052) Integer overflow (CVE-ID: CVE-2026-97421)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect page-size selection.

The vulnerability exists due to integer overflow in ib_umem_find_best_pgsz() in the RDMA/umem subsystem when handling a virtual address and length. A local user can provide values that trigger boundary conditions to cause incorrect page-size selection.

The issue is especially important on 32-bit systems.


1053) Out-of-bounds write (CVE-ID: CVE-2026-97425)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a buffer overflow.

The vulnerability exists due to improper bounds checking in the psp_vbflash sysfs binary attribute when writing vBIOS update data. A local user can write data beyond the maximum vBIOS buffer size to cause a buffer overflow.


1054) Heap-based buffer overflow (CVE-ID: CVE-2026-97427)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a heap-based buffer overflow.

The vulnerability exists due to a heap-based buffer overflow in pp_dpm_set_pp_table() when processing sysfs store writes larger than soft_pp_table_size. A local user can write oversized data through the sysfs store interface to cause a heap-based buffer overflow.


1055) Out-of-bounds read (CVE-ID: CVE-2026-97428)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory out of bounds.

The vulnerability exists due to improper bounds checking in the AMDGPU FRU EEPROM product information parser when parsing truncated or malformed FRU data. A local user can supply truncated or malformed FRU data to read memory out of bounds.


1056) Use-after-free (CVE-ID: CVE-2026-97429)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to a race condition in the drm/amdkfd queue destruction handling when concurrently destroying queues. A local user can initiate concurrent queue destruction to trigger a use-after-free condition.


1057) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-97430)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to queue new commands on the command ring while the xHC is inaccessible.

The vulnerability exists due to an improper check for an inaccessible hardware state in the xHCI command-ring queueing logic when the controller is suspended or resumed. A local user can initiate command queueing while the xHC is inaccessible to queue new commands on the command ring.


1058) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-97434)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause active NAPI instances to be deleted.

The vulnerability exists due to improper resource lifecycle management in the dpaa2-switch device removal path when removing a DPSW device. A local privileged user can trigger the device removal path to cause active NAPI instances to be deleted.

All NAPI instances are attached to the first switch port's net_device but are shared by all switch ports.


1059) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-97435)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to redirect traffic to an unintended port or trigger an out-of-bounds access.

The vulnerability exists due to improper validation of a destination port index in the SJA1105 flower classifier when configuring a redirect action to a switch port on a different switch chip. A local privileged user can configure a redirect action referencing a port from another switch chip to redirect traffic to an unintended port or trigger an out-of-bounds access.


1060) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-97436)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause multiple ports to share a forwarding database.

The vulnerability exists due to improper forwarding database state management in dpaa2_switch_port_set_fdb() when a port leaves a bridge while other ports continue to use the same forwarding database. A local privileged user can change bridge membership to cause multiple ports to share a forwarding database.

The issue occurs when multiple bridges have ports from the same DPSW instance.


1061) Out-of-bounds read (CVE-ID: CVE-2026-97437)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to improper bounds validation in the NTFS3 directory enumeration and index lookup paths when processing crafted NTFS index entries. A local user can provide a crafted NTFS image to cause an out-of-bounds read.


1062) Out-of-bounds read (CVE-ID: CVE-2026-97438)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a slab out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in the NTFS3 index entry processing when processing a malformed NTFS directory index entry during directory lookup. A local user can trigger directory lookup on an entry whose key_size exceeds the bytes available in its NTFS_DE payload to cause a slab out-of-bounds read.


1063) NULL pointer dereference (CVE-ID: CVE-2026-97439)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the ntfs3 extended attribute handler when modifying system.ntfs_attrib and system.dos_attrib on the same file in a corrupted ntfs3 image. A local user can toggle system.ntfs_attrib, overwrite system.dos_attrib, and write to the file to cause a denial of service.


1064) Memory leak (CVE-ID: CVE-2026-97440)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a missing reference release in qrtr_send_resume_tx() when allocation of a QRTR control packet fails. A local user can trigger the allocation failure path to cause a denial of service.


1065) Improper input validation (CVE-ID: CVE-2026-97441)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to improper validation of the mapped BAR size in the AHCI driver when probing an AHCI controller whose HOST_CAP register claims more ports than fit within the mapped BAR region. An attacker with physical access can trigger access to port registers beyond the BAR boundary to cause a denial of service.


1066) Memory corruption (CVE-ID: CVE-2026-97442)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to improper validation of native Wi-Fi header length in ath11k_dp_rx_h_undecap_nwifi() when processing hardware-provided packets using the DP_RX_DECAP_TYPE_NATIVE_WIFI decapsulation type. A remote attacker can provide a packet with a native Wi-Fi header length exceeding the maximum supported length to cause memory corruption.


1067) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-97443)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel warning.

The vulnerability exists due to improper state validation in perf_ftrace_function_unregister() when cleaning up a perf event whose ftrace operations registration failed or was already torn down. A local user can cause perf event cleanup to invoke unregister_ftrace_function() for ftrace operations that are not enabled to trigger a kernel warning.


1068) Out-of-bounds read (CVE-ID: CVE-2026-97444)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds access.

The vulnerability exists due to missing boundary checks in the ACPICA AML parser when parsing ACPI AML input. A local user can supply malformed AML input to cause an out-of-bounds access.


1069) Out-of-bounds read (CVE-ID: CVE-2026-97445)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read beyond the end of a buffer.

The vulnerability exists due to improper buffer validation in acpi_ut_walk_aml_resources() when processing malformed AML resource descriptors. A local user can provide a malformed AML resource descriptor whose length exceeds the remaining buffer size to read beyond the end of a buffer.


1070) NULL pointer dereference (CVE-ID: CVE-2026-97446)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in acpi_ns_custom_package() when processing a firmware-provided _BIX package whose first element is an unresolvable reference. A local user can cause the kernel to process such a package to cause a denial of service.


1071) Use-after-free (CVE-ID: CVE-2026-97448)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper validation of a namespace node in acpi_ns_build_normalized_path() when processing an invalid ACPI namespace node. A local user can cause the function to process an invalid namespace node to trigger a use-after-free condition.


1072) Memory corruption (CVE-ID: CVE-2026-97449)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds access.

The vulnerability exists due to improper restriction of operations within bounds in ACPICA parser functions when parsing package data with invalid package limits. A local user can trigger parsing of package data with invalid package limits to perform an out-of-bounds access.


1073) Type Confusion (CVE-ID: CVE-2026-97450)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access fields of a handler object without validating its type.

The vulnerability exists due to improper type validation in the ACPICA handler-list processing routines when walking handler lists. A local user can cause ACPICA to process a handler object with an invalid type to access fields of a handler object without validating its type.


1074) Integer overflow (CVE-ID: CVE-2026-97451)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an integer overflow in acpi_ex_opcode_3A_1T_1R() when calculating the truncation length for a String or Buffer operand. A local user can trigger the vulnerable operation with values that cause Index + Length to overflow to cause memory corruption.


1075) Improper input validation (CVE-ID: CVE-2026-97452)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of reference classes in acpi_ut_copy_simple_object() when copying local, argument, or debug ACPI reference objects. A local user can cause the function to add a reference to an invalid object pointer to cause a denial of service.


1076) Out-of-bounds read (CVE-ID: CVE-2026-97453)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read beyond the bounds of an ACPI package buffer.

The vulnerability exists due to improper validation of an encoded package length byte count in acpi_ps_get_next_package_length() when parsing ACPI package lengths. A local user can cause the function to process an encoded byte count exceeding the remaining available bytes to read beyond the bounds of an ACPI package buffer.


1077) Out-of-bounds read (CVE-ID: CVE-2026-97454)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read beyond buffer bounds.

The vulnerability exists due to an out-of-bounds read in acpi_ps_get_next_field() when parsing malformed AML field data. A local user can cause malformed AML field data to be parsed to read beyond buffer bounds.


1078) Use-after-free (CVE-ID: CVE-2026-97455)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in acpi_ds_terminate_control_method() when terminating a control method whose return value is a ref_of reference. A local user can cause a control method to return a ref_of reference to trigger a use-after-free condition.

The affected reference can point to a method local variable or argument.


1079) Out-of-bounds read (CVE-ID: CVE-2026-97456)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access memory out of bounds.

The vulnerability exists due to an out-of-bounds read in acpi_ps_parse_loop() when checking for AML_ELSE_OP after skipping a While/If block. A local user can trigger the affected AML parsing condition to access memory out of bounds.


1080) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-97472)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to prevent generation of temporary IPv6 privacy addresses for an IPv6 prefix.

The vulnerability exists due to improper state management in the IPv6 addrconf temporary address management logic when handling router advertisements that deprecate and later restore an IPv6 prefix. A remote attacker can send router advertisements that temporarily deprecate and later restore a prefix to prevent temporary address regeneration.


1081) Memory leak (CVE-ID: CVE-2026-97473)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory release in rapl_add_package_cpuslocked() in the Intel RAPL powercap driver when handling a failed package addition caused by a negative physical package or logical die identifier. A local user can trigger a failed package addition to cause a denial of service.


1082) Use-after-free (CVE-ID: CVE-2026-97475)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to trigger a use-after-free.

The vulnerability exists due to failure to unregister thermal cooling devices in the Tegra SoCTherm driver when the platform driver is removed. A local privileged user can cause the driver to be removed and trigger use of a stale thermal framework reference to trigger a use-after-free.

The stale cooling-device references retain devdata pointers to memory freed during platform-device cleanup.


1083) Missing Authorization (CVE-ID: CVE-2026-97476)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive network and socket information.

The vulnerability exists due to improper access control in the RDS_INFO_* getsockopt handlers when querying RDS information from a separate network namespace. A local user can call getsockopt with RDS_INFO_* options to disclose sensitive network and socket information.

Exploitation requires a fresh user namespace and network namespace.


1084) Improper handling of exceptional conditions (CVE-ID: CVE-2026-97481)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to improper handling of FIFO error interrupts in the 8250 serial driver when the serial interface receives a flood of messages during startup and encounters a FIFO error with no data ready. An attacker with physical access can send a flood of messages to the serial interface during startup to cause a denial of service.


1085) NULL pointer dereference (CVE-ID: CVE-2026-97482)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the goku_irq() interrupt handler when handling an INT_USBRESET event before a gadget driver is bound. An attacker with physical access can trigger an INT_USBRESET event before a gadget driver is bound to cause a denial of service.


1086) Deadlock (CVE-ID: CVE-2026-97483)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of memory allocation flags in USB core root hub control transfer handling when processing root hub control transfers during device-reset handling. A local user can trigger device-reset handling that submits a root hub control transfer to cause a denial of service.

The condition occurs in SCSI error-handler paths involving UAS or the storage driver.


1087) NULL pointer dereference (CVE-ID: CVE-2026-97484)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in status_show_vhci() in drivers/usb/usbip/vhci_sysfs.c when reading VHCI status after a VHCI host controller probe failure. A local user can read the VHCI status sysfs entry to cause a denial of service.


1088) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-97485)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of set_blocksize failures in the OMFS filesystem superblock initialization routine when mounting an OMFS filesystem with a block size larger than PAGE_SIZE. A local user can mount a specially crafted OMFS filesystem to cause a denial of service.


1089) Unchecked Return Value (CVE-ID: CVE-2026-97486)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an unchecked return value in the HPFS superblock mount handler when mounting an HPFS filesystem on a device with a block size greater than the page size. A local privileged user can mount the filesystem to trigger a kernel BUG condition and cause a denial of service.


1090) Unchecked Return Value (CVE-ID: CVE-2026-97487)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an unchecked return value in the JFS superblock initialization function jfs_fill_super when mounting a JFS filesystem with a block size greater than the page size. A local user can mount such a filesystem to cause a denial of service.


1091) Unchecked Return Value (CVE-ID: CVE-2026-97488)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an unchecked return value in qnx4_fill_super when mounting a QNX4 filesystem on a device whose block size causes sb_set_blocksize to fail. A local privileged user can mount the filesystem to trigger a kernel BUG.


1092) Unchecked Return Value (CVE-ID: CVE-2026-97489)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an unchecked return value in the bfs filesystem superblock initialization routine when mounting a BFS file system on a block device with a block size greater than PAGE_SIZE. A local user can mount a BFS file system on such a block device to cause a denial of service.


1093) Unchecked Return Value (CVE-ID: CVE-2026-97490)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of block size configuration failures in the AFFS filesystem mounting code when mounting an AFFS filesystem with a block size greater than PAGE_SIZE. A local user can mount a specially crafted AFFS filesystem to cause a denial of service.


1094) Resource exhaustion (CVE-ID: CVE-2026-97491)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in rds_ib_conn_path_shutdown when tearing down InfiniBand network configurations. A local user can initiate teardown of InfiniBand network configurations to cause a denial of service.


1095) Expired pointer dereference (CVE-ID: CVE-2026-97492)

CWE-ID: CWE-825 - Expired pointer dereference

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leave drivers with dangling pointers.

The vulnerability exists due to improper state cleanup in the mac80211 ieee80211_reconfig NAN reconfiguration failure handling when handling a failed NAN reconfiguration while other interfaces are present. A local user can trigger NAN reconfiguration processing that fails to leave drivers with dangling pointers.

The stale pointers can reference station and link objects.


1096) Out-of-bounds write (CVE-ID: CVE-2026-97494)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the amdgpu PSP firmware-copy routine psp_copy_fw when copying an oversized firmware image into the PSP private buffer. A local user can invoke PSP firmware-loading operations with an oversized firmware image to cause memory corruption.


1097) Out-of-bounds write (CVE-ID: CVE-2026-97495)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform an out-of-bounds write.

The vulnerability exists due to improper bounds checking in the allocate_doorbell function when specifying a doorbell ID for restoration. A local user can provide a doorbell ID that exceeds the maximum number of queues per process to perform an out-of-bounds write.

The specific doorbell ID option is used by CRIU.


1098) Out-of-bounds read (CVE-ID: CVE-2026-97496)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the get_wave_state() function in drm/amdkfd when handling CRIU restore operations through AMDKFD_IOC_RESTORE_PROCESS with H3. A local user can supply crafted MQD control stack size and offset values to disclose sensitive information.

The exposed data can include adjacent GTT or kernel memory, such as other queues' MQDs, ring buffers, and KASLR pointers.


1099) Improper Validation of Array Index (CVE-ID: CVE-2026-97497)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access memory out of bounds.

The vulnerability exists due to improper validation of an array index in the allocate_sdma_queue function when handling a specified SDMA queue identifier during CRIU restoration. A local user can specify an out-of-range SDMA queue identifier to access memory out of bounds.


1100) Out-of-bounds read (CVE-ID: CVE-2026-97500)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds read.

The vulnerability exists due to improper length validation in the rtw89 PHY status information element parser when processing PHY status information elements with unexpected lengths. A remote attacker can cause the parser to process a PHY status information element with an unexpected length to cause an out-of-bounds read.


1101) NULL pointer dereference (CVE-ID: CVE-2026-97502)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the mmc_davinci_irq() handler in the DaVinci MMC host driver when processing read data timeout or data CRC error interrupt status while no data request is present. A local user can trigger the affected interrupt handling condition to cause a denial of service.


1102) Use-after-free (CVE-ID: CVE-2026-97504)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the Lenovo SE10 watchdog driver when platform device addition fails. A local user can trigger platform device initialization to cause a denial of service.

The issue affects systems on which the driver is initialized for a matching Lenovo platform.


1103) Missing Authorization (CVE-ID: CVE-2026-97505)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to missing authorization in the __resource_resize_store() function when writing to a resourceN_resize sysfs attribute. A local user can resize a PCI BAR to cause a denial of service.


1104) NULL pointer dereference (CVE-ID: CVE-2026-97506)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a null-pointer dereference.

The vulnerability exists due to improper handling of an allocation failure in chainup_buffers() in the ixp4xx crypto driver when constructing a buffer descriptor chain for a scatterlist. A local user can submit a crypto request that encounters an allocation failure to trigger a null-pointer dereference.


1105) Unchecked Return Value (CVE-ID: CVE-2026-97507)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an unchecked return value in dm1105_hw_init() when initializing dm1105 hardware after DMA memory allocation fails. A local user can trigger dm1105 hardware initialization to cause a denial of service.


1106) Use-after-free (CVE-ID: CVE-2026-97508)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in the Thunderbolt XDomain request handler when handling a request from a remote host while a domain is stopped. A remote attacker can send a request during domain shutdown to cause a denial of service.


1107) Use-after-free (CVE-ID: CVE-2026-97509)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper reference counting in the Thunderbolt XDomain service lifetime handling when releasing an XDomain service. A local user can trigger service release after the parent XDomain is released to cause a denial of service.


1108) Memory leak (CVE-ID: CVE-2026-97510)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to a missing release of allocated memory in __tb_xdomain_response() when tb_cfg_request() fails to set up a request. A local user can trigger the failed request setup to cause a memory leak.

The issue can occur when the control channel has already been shut down.


1109) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-97512)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause clock and power imbalances.

The vulnerability exists due to incomplete error handling in the Qualcomm QSPI driver's runtime PM suspend and resume functions when a runtime PM operation fails midway. A local user can trigger a failure during a runtime PM suspend or resume operation to cause clock and power imbalances.


1110) Improper locking (CVE-ID: CVE-2026-97514)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger kernel lock validator reports.

The vulnerability exists due to calling sleeping V4L2 control operations while holding a spinlock in the Wave5 decoder's dynamic resolution change handling when processing dynamic resolution changes. A local user can cause the driver to process a dynamic resolution change to trigger kernel lock validator reports.


1111) NULL pointer dereference (CVE-ID: CVE-2026-97516)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in rtw_fw_adaptivity_result() in the rtw88 wireless driver when processing a firmware adaptivity result with an undefined edcca_th configuration. A local user can cause the driver to process a firmware adaptivity result to cause a denial of service.

The issue occurs on devices using the 8821CE chip, which does not define edcca_th in its chip information.


1112) Out-of-bounds read (CVE-ID: CVE-2026-97517)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger an out-of-bounds read.

The vulnerability exists due to improper length validation in nl80211 HE operation element handling when processing a malformed HE operation element in beacon data. A local user can supply a truncated HE operation element to trigger an out-of-bounds read.


1113) Out-of-bounds write (CVE-ID: CVE-2026-97518)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause memory corruption.

The vulnerability exists due to improper validation of duplicate cipher suite entries in cfg80211 wiphy registration when WEXT compatibility code handles SIOCGIWRANGE requests. A local privileged user can register a wiphy with duplicate WEP cipher suite entries and request wireless range information to cause memory corruption.


1114) Insufficient Control Flow Management (CVE-ID: CVE-2026-97520)

CWE-ID: CWE-691 - Insufficient Control Flow Management

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to modify data and cause a denial of service.

The vulnerability exists due to improper control flow management in gfs2_quota_init() when processing quota change entries. A remote attacker can exploit incorrect quota-change iterator progression to modify data and cause a denial of service.

User interaction is required.


1115) Improper locking (CVE-ID: CVE-2026-97521)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a sleeping-function warning from an invalid context.

The vulnerability exists due to improper locking in gfs2_quota_init() when checking duplicate quota_change IDs while holding qd_lock and the quota hash bucket bitlock. A local user can cause duplicate quota_change IDs to be processed during quota initialization to trigger a sleeping-function warning from an invalid context.

The issue occurs on PREEMPT_RT systems because lockref_get_not_dead() may sleep.


1116) Incorrect calculation (CVE-ID: CVE-2026-97522)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect byte accounting.

The vulnerability exists due to improper accounting in __mptcp_subflow_push_pending() when __subflow_push_pending() returns an error. A local user can trigger an error during a pending subflow push to cause incorrect byte accounting.


1117) Race condition (CVE-ID: CVE-2026-97523)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a race condition in the mptcp scheduler when subflow socket states change. A remote attacker can trigger the race condition to cause a denial of service.


1118) Deadlock (CVE-ID: CVE-2026-97524)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper state management in the MPTCP receive path when processing a subflow reset under exceptional error conditions. A remote attacker can trigger the exceptional error condition during MPTCP receive processing to cause a denial of service.


1119) Out-of-bounds read (CVE-ID: CVE-2026-97539)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory out of bounds.

The vulnerability exists due to an out-of-bounds read in xusbatm_bind when binding a USB device through a dynamic ID. A local user can cause an invalid index to be used for USB interface configuration arrays to read memory out of bounds.


1120) Out-of-bounds read (CVE-ID: CVE-2026-97540)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access memory out of bounds.

The vulnerability exists due to improper pointer arithmetic in the pegasus USB network driver probe routine when processing a dynamically configured USB device ID. A local user can trigger calculation of an out-of-bounds index to access memory out of bounds.


1121) Use-after-free (CVE-ID: CVE-2026-97541)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to a use-after-free in the ath9k_htc USB driver when handling a dynamically matched USB device. A local user can cause the driver to dereference a stored usb_device_id pointer after the probe operation has completed to access freed memory.


1122) Unchecked Return Value (CVE-ID: CVE-2026-97542)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause inconsistent in-core data.

The vulnerability exists due to an unchecked return value in xrep_agfl_init_header when walking allocation-group free-list extents during XFS repair. A local user can trigger an error from xagb_bitmap_walk to cause inconsistent in-core data.


1123) Memory leak (CVE-ID: CVE-2026-97543)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper resource release in xchk_dirtree_create_path and xrep_dirtree_create_adoption_path when appending a name to a directory path fails. A local user can trigger a directory-path creation failure to cause a memory leak.


1124) Memory leak (CVE-ID: CVE-2026-97544)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper release of memory in xqcheck_mod_live_ino_dqtrx when a rhashtable insertion fails during XFS quota checking. A local user can trigger a failed rhashtable insertion while XFS quota checking processes a newly allocated dqa object to cause a memory leak.


1125) Improper resource shutdown or release (CVE-ID: CVE-2026-97545)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a locked buffer to be leaked.

The vulnerability exists due to improper resource release in xfs_btree_bload_prep_block when handling an I/O error while writing the delayed-write buffer list to disk. A local user can cause the function to handle an I/O error during the write operation to cause a locked buffer to be leaked.


1126) Infinite loop (CVE-ID: CVE-2026-97546)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of zero-length directory entries in xrep_dir_recover_data when salvaging directory entries. A local user can trigger processing of a directory entry that claims a zero length to cause a denial of service.


1127) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-97547)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause data corruption between reflink-related files.

The vulnerability exists due to improper reflink flag handling in xmi_can_exchange_reflink_flags in XFS exchange-range operations when exchanging full-file ranges with XFS_EXCHMAPS_INO1_WRITTEN requested. A local user can exchange full-file ranges between files with shared extents to cause data corruption between reflink-related files.

Hole and unwritten mappings from the first file can be skipped during the exchange.


1128) Integer underflow (CVE-ID: CVE-2026-97551)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer underflow in XFS parent pointer update handling when processing parent pointer add or replacement updates that grow the attribute fork. A local user can trigger a parent pointer update that grows the attribute fork to cause a denial of service.

Exploitation requires an allocation group with exactly zero available blocks.


1129) Use of Uninitialized Variable (CVE-ID: CVE-2026-97552)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to use of an uninitialized variable in xfs_defer_finish_one() when processing an item-less pending item during an online repair. A local privileged user can trigger processing of an item-less pending item during an online repair to cause a denial of service.

Only kernels built with CONFIG_XFS_ONLINE_REPAIR are affected.


1130) Heap-based buffer overflow (CVE-ID: CVE-2026-97555)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the SMB client DACL owner/group rewrite logic when rewriting an existing DACL containing short SIDs with replacement owner or group SIDs obtained through a cifs.idmap upcall. A remote attacker can cause rewritten access control entries to exceed the allocated buffer to execute arbitrary code.

User interaction is required.


1131) Memory leak (CVE-ID: CVE-2026-97556)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a missing reference count release in cifs_oplock_break() in the SMB client when handling an oplock break after cifs_sb_tlink() fails. A local user can trigger an oplock break that encounters a cifs_sb_tlink() failure to cause a denial of service.

Only SMB mounts using the multiuser option are affected.


1132) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-97557)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper reference count management in cifs_queue_oplock_break() when queueing oplock-break work. A remote attacker can trigger repeated oplock breaks while prior work remains queued to cause a denial of service.

The issue can be triggered when interacting with a slow-responding server.


1133) Out-of-bounds read (CVE-ID: CVE-2026-97560)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds read.

The vulnerability exists due to an incorrect length calculation in smb2_parse_native_symlink() when parsing a share-root relative native symlink. A remote attacker can cause the client to parse a share-root relative native symlink with a crafted target to cause an out-of-bounds read.


1134) Use-after-free (CVE-ID: CVE-2026-97562)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in the SMB client DFS superblock lookup callback when handling DFS automounts during concurrent expiry. A remote attacker can trigger concurrent DFS automount expiry while the superblock is in use to compromise confidentiality, integrity, and availability.

User interaction is required.


1135) Missing Authorization (CVE-ID: CVE-2026-97564)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a root usermodehelper to process unvetted authority-bearing fields.

The vulnerability exists due to missing authorization validation in cifs.idmap key description handling when invoking request_key(2) with a non-NULL callout. A local user can supply a cifs.idmap key description containing authority-bearing fields to cause a root usermodehelper to process unvetted authority-bearing fields.


1136) Use of Uninitialized Variable (CVE-ID: CVE-2026-97568)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect handling of MPTCP backup state.

The vulnerability exists due to use of an uninitialized variable in MPTCP syncookie state handling when copying MPTCP subflow information. A remote attacker can trigger copying of MPTCP subflow information to cause incorrect handling of MPTCP backup state.


1137) Unchecked Return Value (CVE-ID: CVE-2026-97572)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a zeroed DMA address to be handed out.

The vulnerability exists due to an unchecked return value in bnxt_init_nic() when initializing RX rings after an allocation failure. A local user can trigger NIC initialization after RX ring allocation fails to cause a zeroed DMA address to be handed out.


1138) Unchecked Return Value (CVE-ID: CVE-2026-97573)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a loss of confidentiality, integrity, and availability.

The vulnerability exists due to unchecked return value in bnxt_rx_ring_reset() when resetting receive ring buffers after a buffer allocation failure. A remote attacker can trigger the vulnerable receive-ring reset to cause a loss of confidentiality, integrity, and availability.


1139) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-97575)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper validation of tile counts in the V4L2 AV1 frame control validation logic when processing V4L2 AV1 frame controls. A local user can submit a crafted control with excessive tile column or row counts to compromise confidentiality, integrity, and availability.


1140) Out-of-bounds read (CVE-ID: CVE-2026-97576)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an out-of-bounds read in stateless HEVC decoder tile processing when processing a V4L2 HEVC PPS control with excessive tile counts. A local user can submit a crafted HEVC PPS control to compromise confidentiality, integrity, and availability.


1141) Out-of-bounds read (CVE-ID: CVE-2026-97577)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform out-of-bounds memory reads and writes.

The vulnerability exists due to improper bounds checking in rockchip_vpu981_av1_dec_prepare_run() and rockchip_vpu981_av1_dec_set_tile_info() when processing AV1 frames whose claimed tile count exceeds the submitted tile group entry count or the tile descriptor buffer capacity. A local user can submit a crafted AV1 frame with excessive tile dimensions to perform out-of-bounds memory reads and writes.


1142) Out-of-bounds write (CVE-ID: CVE-2026-97578)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an out-of-bounds write in the tile_info DMA descriptor buffer when processing AV1 tile information. A local user can provide AV1 tile information that causes descriptor writes beyond the tile_info buffer to compromise confidentiality, integrity, and availability.


1143) Division by zero (CVE-ID: CVE-2026-97578)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to division by zero in rockchip_vpu981_av1_dec_set_tile_info() when processing AV1 tile information. A local user can provide an AV1 bitstream with zero tile columns to compromise confidentiality, integrity, and availability.


1144) Out-of-bounds write (CVE-ID: CVE-2026-97579)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in vdec_av1_slice_setup_tile() when processing AV1 bitstream tile information. A local user can provide crafted AV1 tile column or row counts to write beyond the mi_col_starts[] or mi_row_starts[] array capacity and execute arbitrary code.


1145) Out-of-bounds write (CVE-ID: CVE-2026-97581)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in prepare_tile_info_buffer() when processing HEVC picture parameter set tile dimensions. A local user can provide tile dimensions exceeding the tile_sizes DMA buffer capacity to cause memory corruption.


1146) Use-after-free (CVE-ID: CVE-2026-97582)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to use-after-free in the gpio-fan alarm work handler when unbinding a GPIO fan device while alarm work is pending. A local user can unbind the device after alarm work has been queued to access freed memory.


1147) Use-after-free (CVE-ID: CVE-2026-97583)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a use-after-free in AFS peer application-data handling when handling an RxRPC callback after an AFS fileserver address-list refresh. A remote attacker can trigger a callback through an RxRPC connection associated with a removed peer to execute arbitrary code.

User interaction is required.


1148) Release of invalid pointer or reference (CVE-ID: CVE-2026-97584)

CWE-ID: CWE-763 - Release of invalid pointer or reference

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an incorrect memory release in afs_lookup_server() when cleaning up a candidate server. A local user can trigger candidate server cleanup to compromise confidentiality, integrity, and availability.


1149) Out-of-bounds read (CVE-ID: CVE-2026-97587)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the RISC-V performance monitoring unit counter mask handling when processing available counter masks on RV32 systems. A local user can trigger performance counter handling that iterates beyond the single unsigned long counter mask to disclose sensitive information.

On RV32 systems, the counter iteration limit is 64 while an unsigned long counter mask has only 32 bits.


1150) Sensitive Information in Resource Not Removed Before Reuse (CVE-ID: CVE-2026-97592)

CWE-ID: CWE-226 - Sensitive Information in Resource Not Removed Before Reuse

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to failure to clear sensitive data from memory in the s390 AES CTR and GCM cryptographic routines when processing cryptographic requests. A local user can process cryptographic requests that leave sensitive data in temporary buffers to disclose sensitive information.


1151) Use-after-free (CVE-ID: CVE-2026-97595)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to use-after-free in mac802154 queued RX frame workers when processing received beacon and MAC-command frames during interface removal. A remote attacker can send MAC-command frames while an interface is removed to cause memory corruption.


1152) Improper Validation of Array Index (CVE-ID: CVE-2026-97596)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an out-of-bounds transition table access.

The vulnerability exists due to improper validation of array indices in IPVS connection template synchronization record processing when processing a crafted IPVS synchronization record containing an invalid template state. A remote attacker can send a crafted IPVS synchronization record with an invalid template state to trigger an out-of-bounds transition table access.

The version 1 synchronization path handles both IPv4 and IPv6 records.


1153) Resource exhaustion (CVE-ID: CVE-2026-97598)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in fib_empty_table() in IPv4 FIB rules when adding an IPv4 rule with automatic table assignment. A local user can populate table IDs and add a table-0 rule to cause a denial of service.

Only the IPv4 automatic table-assignment path is affected.


1154) Double free (CVE-ID: CVE-2026-97599)

CWE-ID: CWE-415 - Double Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in hwsim_update_pib() when concurrent PIB updates occur on the same hwsim PHY. A local user can trigger concurrent PIB updates to cause a denial of service.


1155) Use-after-free (CVE-ID: CVE-2026-97600)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in cc2520_fifop_irqwork handling when removing a cc2520 device. A local privileged user can initiate removal of a cc2520 device while FIFOP interrupts are handled to trigger a use-after-free condition.

The devm-managed FIFOP IRQ can remain active after the driver's removal callback returns.


1156) NULL pointer dereference (CVE-ID: CVE-2026-97601)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the lowpan_newlink function when processing an RTM_NEWLINK request for a TUN device whose link-layer type has been changed to ARPHRD_IEEE802154. A local privileged user can issue an RTM_NEWLINK request to cause a denial of service.


1157) Out-of-bounds write (CVE-ID: CVE-2026-97602)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to an out-of-bounds write caused by stale reassembly metadata in IPv6 fragment reassembly when processing IPv6 fragments after fragment queue teardown. A local user can send crafted IPv6 fragments to escalate privileges.

Exploitation requires unprivileged network namespaces to be available.


1158) Use-after-free (CVE-ID: CVE-2026-97604)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to a use-after-free in vfb colormap cleanup when a concurrent driver unbind occurs while FBIOGETCMAP copies a colormap to userspace. A local user can retain an open framebuffer file reference and invoke FBIOGETCMAP during a driver unbind to disclose sensitive information.


1159) NULL pointer dereference (CVE-ID: CVE-2026-97605)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of failed LZMA decoder allocations in the EROFS LZMA decoder pool resize path when resizing decoder pools. A local user can trigger a decoder-pool resize that encounters an allocation failure to cause a denial of service.

An existing LZMA mount is required.


1160) Memory leak (CVE-ID: CVE-2026-97606)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource release in autofs_fill_super() when creating an autofs root inode. A local user can trigger the root inode creation failure path after a new inode is allocated to cause a denial of service.


1161) Memory leak (CVE-ID: CVE-2026-97607)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a resource leak.

The vulnerability exists due to improper cleanup on an error path in the ifcvf_vdpa_dev_add function when provisioning unsupported device features. A local user can provision unsupported features to cause a resource leak.


1162) Use-after-free (CVE-ID: CVE-2026-97608)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service, disclose sensitive information, or modify data.

The vulnerability exists due to a race condition leading to a use-after-free in the netfilter nf_log logger backends when unregistering logger backends during per-network namespace teardown. A local user can rebind a logger through a sysctl or netlink writer after the prior per-network logger selection has been cleared to cause a denial of service, disclose sensitive information, or modify data.


1163) Use-after-free (CVE-ID: CVE-2026-97611)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code, disclose sensitive information, or cause a denial of service.

The vulnerability exists due to a use-after-free in the Open vSwitch flow table mask array when processing packets during flow table statistics lookup. A local user can trigger concurrent flow table mask array reallocation and packet processing to execute arbitrary code, disclose sensitive information, or cause a denial of service.


1164) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-97612)

CWE-ID: CWE-195 - Signed to Unsigned Conversion Error

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to stale inner protocol state in skb_mpls_pop() when Open vSwitch re-pushes MPLS after all labels have been popped and the packet has been recirculated. A local user can trigger MPLS label push, pop, recirculation, and a subsequent label push to cause memory corruption.


1165) Resource exhaustion (CVE-ID: CVE-2026-97613)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper completion queue sizing in the MANA network driver's RX completion queue when processing receive completions while the queue is full. A remote attacker can cause the receive completion queue to become full while a fence completion is pending to cause a denial of service.

The dropped fence completion can cause the driver to hold the RTNL lock for the timeout duration.


1166) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-97616)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service by exhausting action IDs.

The vulnerability exists due to improper resource release in tcf_action_destroy() in net/sched/act_api.c when processing a batched RTM_NEWACTION request that replaces an existing action and a later action fails to initialize. A local user can submit a crafted batched RTM_NEWACTION request to cause a denial of service by exhausting action IDs.


1167) Race condition (CVE-ID: CVE-2026-97617)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds memory mapping.

The vulnerability exists due to a race condition in ring_buffer_subbuf_order_set() when an mmap operation races a failing sub-buffer order change. A local user can race an mmap of an already mapped CPU with a sub-buffer order change to cause an out-of-bounds memory mapping.


1168) Memory leak (CVE-ID: CVE-2026-97899)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper memory release in query_perf_config_list() when memory reallocation fails. A local user can trigger a performance configuration list query when memory reallocation fails to cause a memory leak.


1169) Infinite loop (CVE-ID: CVE-2026-97900)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper loop control in drm_exec_prepare_array() when processing chained calls that include an empty object array after lock contention. A local user can invoke affected DRM ioctls to cause a denial of service.

This condition affects drivers that prepare separate read and write buffer-object arrays during one locking iteration.


1170) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-97902)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper error handling in thaw_super_locked() when handling nested filesystem thaw operations. A local privileged user can cause bdev_thaw() to retain an elevated filesystem-freeze count after releasing a freeze hold to cause a denial of service.

The condition occurs when a FIFREEZE freeze is nested with bdev_freeze().


1171) Improper initialization (CVE-ID: CVE-2026-97904)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger access to an uninitialized semaphore.

The vulnerability exists due to improper initialization in cpufreq_policy_alloc() when accessing policy sysfs attributes during policy creation. A local user can access a policy sysfs attribute before policy->rwsem is initialized to trigger access to an uninitialized semaphore.


1172) Use of uninitialized resource (CVE-ID: CVE-2026-97905)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to invoke sysfs attribute callbacks on an uninitialized cpufreq policy.

The vulnerability exists due to use of uninitialized memory in the policy->cpus cpumask in cpufreq_policy_alloc() when a cpufreq policy is published to sysfs before initialization completes. A local user can access sysfs attributes during this initialization window to invoke callbacks on the uninitialized policy.

Only systems configured with CONFIG_CPUMASK_OFFSTACK=y are affected by the uninitialized separately allocated bitmap.


1173) Use of Uninitialized Variable (CVE-ID: CVE-2026-97907)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause firmware parsing to fail.

The vulnerability exists due to use of an uninitialized variable in rtlbt_parse_firmware_v2() when parsing firmware format v2 security headers with a zero chip key ID. A local user can trigger parsing of firmware containing a security header to cause firmware parsing to fail.


1174) Use-after-free (CVE-ID: CVE-2026-97908)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the btqcomsmd Bluetooth driver when the command or ACL RPMsg endpoint receives data during device teardown. A remote attacker can trigger delivery of data from WCNSS during device teardown to cause an endpoint callback to dereference an already freed hci_dev.


1175) Use of uninitialized resource (CVE-ID: CVE-2026-97909)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger use of an uninitialized IRQ lock.

The vulnerability exists due to improper initialization in the ASoC STI UniPerif reader initialization routine when a pending shared interrupt is handled before the IRQ lock is initialized. A local user can cause the shared interrupt handler to run during initialization to trigger use of an uninitialized IRQ lock.


1176) Out-of-bounds write (CVE-ID: CVE-2026-97910)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper validation of buffer sizes in sprd_platform_compr_copy() in the ASoC sprd PCM compression driver when handling user-configured compression buffer parameters and write data. A local user can configure oversized compression buffer parameters and write data to overflow fixed IRAM or DDR buffer allocations.

The copy callback can be reached while the stream is in the setup state without starting it.


1177) Out-of-bounds read (CVE-ID: CVE-2026-97915)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to disclose adjacent bytes from a shared tracing buffer.

The vulnerability exists due to an out-of-bounds read in the ivpu firmware log name printing routines when processing a firmware-provided log name that is not NUL-terminated. A local privileged user can cause the firmware log name to be printed to disclose adjacent bytes from the shared tracing buffer.


1178) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-97916)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds memory access.

The vulnerability exists due to a time-of-check to time-of-use race condition in fw_log_print_buffer() in the Intel VPU firmware log handling code when the NPU firmware modifies shared tracing log metadata after validation. A local user can cause the firmware-controlled log header size or log size values to change between validation and use to cause an out-of-bounds memory access.


1179) Out-of-bounds read (CVE-ID: CVE-2026-97917)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory outside the intended buffer.

The vulnerability exists due to an out-of-bounds read in ivpu_to_cpu_addr() when processing IPC messages containing buffer addresses. A local user can cause IPC processing to use an address range that extends beyond the buffer to read memory outside the intended buffer.


1180) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-97920)

CWE-ID: CWE-195 - Signed to Unsigned Conversion Error

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a signed-to-unsigned conversion error in the print_entries() cleanup path when reading the hist file of a trigger while histogram statistics allocation fails. A local user can read the hist file of a trigger with a .percent value to cause a denial of service.

The affected code path is not reachable in mainline while .percent and .graph modifiers are rejected for values.


1181) Memory leak (CVE-ID: CVE-2026-97921)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in __create_val_field() when processing histogram triggers containing unsupported field modifiers. A local user can write a crafted histogram trigger with a disallowed modifier to cause a denial of service.


1182) Memory leak (CVE-ID: CVE-2026-97922)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper memory management in histogram variable reference handling in the tracing subsystem when removing a histogram trigger that references the same variable three or more times. A local user can create a histogram trigger with repeated references to the same variable to cause a memory leak.


1183) Memory leak (CVE-ID: CVE-2026-97923)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper memory management in create_var_ref() in the tracing histogram implementation when initialization of a VAR_REF histogram field fails. A local user can trigger VAR_REF histogram field initialization failure to cause a memory leak.


1184) Improper handling of exceptional conditions (CVE-ID: CVE-2026-97924)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leave a registered trace event in an inconsistent state.

The vulnerability exists due to improper handling of event-removal failures in destroy_user_event() when removing an enabled user event. A local user can attempt to remove an enabled user event to leave a registered trace event in an inconsistent state.


1185) Race condition (CVE-ID: CVE-2026-97925)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a race condition in tick broadcast device handling when a broadcast device is replaced concurrently with tick broadcast operations. A local privileged user can cause a detached clock event device to be armed, triggering a kernel BUG.

The BUG condition occurs when the original broadcast device has a restricted interrupt-affinity mask and the last CPU in that mask goes offline.


1186) Out-of-bounds write (CVE-ID: CVE-2026-97926)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds memory access.

The vulnerability exists due to improper validation of cylinder group metadata in ufs_read_cylinder() when processing a crafted UFS filesystem image. A remote attacker can provide malformed cylinder group metadata to cause an out-of-bounds memory access.

User interaction is required.


1187) NULL pointer dereference (CVE-ID: CVE-2026-97927)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in UFS superblock teardown when mounting a crafted writable UFS filesystem image whose first cylinder group cannot be read. A local user can mount a crafted UFS filesystem image to cause a denial of service.


1188) Use of Uninitialized Variable (CVE-ID: CVE-2026-97929)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to disclose sensitive information.

The vulnerability exists due to use of uninitialized heap data in the i_usx2y_in04_int() interrupt callback when handling a short transfer from a USB device. An attacker with physical access can cause a short transfer to disclose sensitive information.

The uninitialized data is copied to the mmap-accessible ctl_snapshot[] array.


1189) Out-of-bounds read (CVE-ID: CVE-2026-97930)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to read memory beyond the source buffer.

The vulnerability exists due to an out-of-bounds read in the ALSA usbusx2y driver when handling USB interrupt data during initialization. An attacker with physical access can trigger the initialization path to read three bytes past the end of the in04_buf allocation.


1190) Improper privilege management (CVE-ID: CVE-2026-97931)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to improper memory mapping permission handling in the ALSA us122l hwdep mmap callback when using mprotect() on a read-buffer mapping after opening the hwdep node O_RDWR. A local user can upgrade the read-buffer mapping to writable and modify the read_size member to cause memory corruption.

The read VMA remains expandable because pcm_usb_stream uses mremap() after reading read_size.


1191) Out-of-bounds write (CVE-ID: CVE-2026-97936)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in the tracing histogram stacktrace handling when configuring a histogram trigger with the .stacktrace modifier on a non-stacktrace field. A local user can write a crafted histogram trigger configuration to corrupt memory.


1192) Use-after-free (CVE-ID: CVE-2026-97940)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service, disclose sensitive information, or modify information.

The vulnerability exists due to a use-after-free in the IPv6 FIB route iterator walker handling when stopping an IPv6 route iterator while routes are deleted. A local user can trigger a race that leaves a freed walker on the IPv6 FIB walker list to cause a denial of service, disclose sensitive information, or modify information.

The same stop helper is used by /proc/net/ipv6_route and the BPF IPv6 route iterator.


1193) Incorrect calculation (CVE-ID: CVE-2026-97945)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause data loss.

The vulnerability exists due to incorrect preservation of the dirty bit in pmd_modify() when changing memory protections on PMD-mapped transparent huge pages. A local user can use MADV_FREE and change memory protections under memory pressure to cause data loss.

NUMA hinting can also trigger the issue.


1194) Deadlock (CVE-ID: CVE-2026-97948)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to recursive locking in eeh_rmv_device when handling EEH error events. A local user can trigger the affected EEH error-handling path to cause a denial of service.

The issue occurs for errors detected directly on the PHB or when a driver requests a reset but does not provide EEH error handlers.


1195) Deadlock (CVE-ID: CVE-2026-97951)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper command completion in the iSCSI target dataout handler when processing final dataout PDUs for a WRITE command aborted by a LUN reset. A remote user can send remaining dataout PDUs to cause a denial of service.


1196) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-97952)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the sunvdc __send_request() function when a non-ENOTCONN descriptor send trigger fails during disk I/O submission. A local user can submit disk I/O requests that encounter trigger failures to cause a denial of service.


1197) Out-of-bounds write (CVE-ID: CVE-2026-97953)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt the TX ring.

The vulnerability exists due to an out-of-bounds write in the stmmac_tso_xmit() TX descriptor availability check when processing highly fragmented TSO traffic. A remote attacker can trigger transmission of a highly fragmented TSO packet to corrupt the TX ring.


1198) Out-of-bounds read (CVE-ID: CVE-2026-97954)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt the TCP RDS stream.

The vulnerability exists due to an out-of-bounds read in rds_message_map_pages() when transmitting RDS-TCP data on systems with page sizes greater than 8192 bytes. A remote attacker can trigger transmission of the congestion map to corrupt the TCP RDS stream.


1199) Heap-based buffer overflow (CVE-ID: CVE-2026-97957)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a heap-based buffer overflow.

The vulnerability exists due to improper bounds checking in check_mbox_seq_id_and_seg_len() in the hinic driver mailbox receive handler when processing mailbox segments. A local user can send a mailbox segment whose final sequence segment exceeds the remaining receive-buffer space to cause a heap-based buffer overflow.


1200) Infinite loop (CVE-ID: CVE-2026-97958)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of EAGAIN errors in tc_ctl_chain() when processing repeated RTM_GETCHAIN requests without consuming netlink responses. A local user can send repeated RTM_GETCHAIN requests without reading the responses to cause a denial of service.


1201) Memory leak (CVE-ID: CVE-2026-97959)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to a failure to free an emptied route4 bucket in net/sched/cls_route.c route4_change when moving an existing route filter to a different top-level bucket and deleting it. A local user can move an existing route filter to a different top-level bucket and then delete it to cause a memory leak.

The issue requires CONFIG_NET_CLS_ROUTE4, CONFIG_NET_SCH_INGRESS, and CONFIG_NET_CLS_ACT to be enabled.


1202) Operation on a Resource after Expiration or Release (CVE-ID: CVE-2026-97961)

CWE-ID: CWE-672 - Operation on a Resource after Expiration or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt the scheduler callback list.

The vulnerability exists due to unsafe list iteration in perf_pmu_sched_task() when processing perf PMU scheduler callbacks. A local user can invoke PERF_EVENT_IOC_REFRESH on a perf event to corrupt the scheduler callback list.

The issue is triggered when the event limit reaches zero during perf event overflow processing.


1203) Improper initialization (CVE-ID: CVE-2026-97963)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger undefined behavior.

The vulnerability exists due to improper initialization in the stmmac driver's ptp_lock when offloading a TAPRIO schedule while the interface is down. A local user can configure a TAPRIO schedule to trigger undefined behavior.

The issue occurs when the interface has never been opened.


1204) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-97964)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to modify data visible to an AF_PACKET socket.

The vulnerability exists due to failure to ensure a writable skb header in ppp_sync_txmunge() when bridging a received PPP frame to a synchronous tty channel. A remote attacker can send a PPPoE frame that is bridged to a synchronous tty channel to modify data visible to an AF_PACKET socket.

Exploitation requires the frame buffer to be shared with a clone queued to an AF_PACKET socket.


1205) Use of Uninitialized Variable (CVE-ID: CVE-2026-97965)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to disclose uninitialized kernel stack data.

The vulnerability exists due to use of an uninitialized stack variable in vxlan_xmit_one() when transmitting a packet through a VXLAN device using external tunnel information that lacks the IP_TUNNEL_VXLAN_OPT_BIT flag. A local privileged user can transmit such a packet to disclose uninitialized kernel stack data.

The VXLAN device must be configured with both VXLAN_F_COLLECT_METADATA and VXLAN_F_GBP.


1206) Incomplete cleanup (CVE-ID: CVE-2026-97966)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to affect scheduler topology settings for later queue allocations.

The vulnerability exists due to incomplete cleanup of scheduler topology state in the OcteonTX2 PF QoS scheduler queue teardown logic when freeing QoS-allocated scheduler queues. A local user can trigger QoS scheduler hierarchy teardown to affect scheduler topology settings for later queue allocations.

PRIO_ANCHOR and RR_PRIO settings can persist in the shared scheduler pool.


1207) Use-after-free (CVE-ID: CVE-2026-97967)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in corsair-cpro debugfs files when reading debugfs files after a failed probe. A local user can read a stale debugfs file to cause a denial of service.


1208) Use-after-free (CVE-ID: CVE-2026-97968)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the corsair-cpro debugfs files when reading debugfs files after hardware-monitor device registration fails. A local user can read an exposed debugfs file to cause a denial of service.


1209) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-97969)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in msc313e_wdt_settimeout() when setting a watchdog timeout. A local user can set a watchdog timeout to cause a denial of service.


1210) Division by zero (CVE-ID: CVE-2026-97970)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to division by zero in the msc313e watchdog driver's msc313e_wdt_probe function when initializing a watchdog device with a zero clock rate. A local privileged user can trigger watchdog device initialization with a zero clock rate to cause a denial of service.


1211) Memory leak (CVE-ID: CVE-2026-97973)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to leak phylink instances.

The vulnerability exists due to improper resource management in the macb driver probe error path when handling a failed macb_alloc_tieoff() or register_netdev() operation. A local privileged user can trigger a driver probe failure to leak phylink instances.


1212) Out-of-bounds read (CVE-ID: CVE-2026-97976)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to perform an out-of-bounds read.

The vulnerability exists due to improper bounds checking in btintel_pcie_submit_rx_work() when processing RX packets with a packet_len value from rfh_hdr. A local privileged user can provide an oversized packet_len value to perform an out-of-bounds read.


1213) Use-after-free (CVE-ID: CVE-2026-97977)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the Bluetooth USB driver rx_work handler when processing a device disconnect while receive work is running. A local user can trigger a device disconnect while the receive work dereferences freed btusb_data to cause a denial of service.


1214) Use-after-free (CVE-ID: CVE-2026-97978)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a trace event error.

The vulnerability exists due to use-after-free in the Intel Ethernet Controller (ice) driver trace event definitions when printing previously recorded trace events. A local user can trigger an affected trace event to trigger a trace event error.

The affected trace events are ice_rx_dim_work and ice_tx_dim_work.


1215) Memory leak (CVE-ID: CVE-2026-97979)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to improper resource release in the ICE driver's sched_node_ids xarray when cleaning up initialized hardware. A local user can trigger repeated hardware initialization and deinitialization to cause a memory leak.


1216) Resource exhaustion (CVE-ID: CVE-2026-97981)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper NAPI work budget accounting in the Cortina Gemini Ethernet driver's gmac_rx receive loop when processing malformed Ethernet frames. A remote attacker can send a stream of malformed Ethernet frames to cause a denial of service.


1217) Incorrect calculation (CVE-ID: CVE-2026-97982)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect budget accounting in gmac_rx() and gmac_napi_poll() when handling received packets during NAPI polling. A remote attacker can cause an idle poll to report a full budget and remain scheduled to cause a denial of service.


1218) Integer overflow (CVE-ID: CVE-2026-97984)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a kernel warning.

The vulnerability exists due to an integer overflow in IPv6 UDP socket cork handling when sending a large UDP payload with IPv6 path MTU discovery set to IPV6_PMTUDISC_DO or IPV6_PMTUDISC_PROBE over a network device with an unusually large MTU. A local privileged user can configure the device MTU and send a crafted UDP payload to cause a kernel warning.

The issue is limited to UDP sockets; raw IPv6 sockets can send UDP jumbograms.


1219) Infinite loop (CVE-ID: CVE-2026-97985)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the AF_UNIX stream socket out-of-band data handling when processing MSG_PEEK receive operations after skipped out-of-band socket buffers. A local user can send out-of-band data and issue MSG_PEEK receive calls to cause a denial of service.


1220) Use-after-free (CVE-ID: CVE-2026-97986)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to a race condition in virtinput_remove() and virtinput_recv_events() when a virtio input callback runs during input-device unregistration. A local user can cause a callback that passed the ready-state check to access vi->idev after it is freed to trigger a use-after-free.

The lifetime issue is not protected for sleepable callbacks on transports other than PCI and MMIO.


1221) Improper resource shutdown or release (CVE-ID: CVE-2026-97987)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause DMA access to torn-down virtqueues.

The vulnerability exists due to improper resource shutdown in the virtio_input probe error path when handling a failed input device registration. A local user can trigger the failed registration path to cause DMA access to torn-down virtqueues.

The device is marked DRIVER_OK before input device registration is attempted.


1222) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-97990)

CWE-ID: CWE-195 - Signed to Unsigned Conversion Error

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and cause a denial of service.

The vulnerability exists due to improper handling of signed return values in the vdpa_sim_net TX/RX processing path when handling a failed TX pull. A local user can trigger processing of a failed TX pull to disclose sensitive information and cause a denial of service.


1223) Out-of-bounds write (CVE-ID: CVE-2026-97991)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read from and write to out-of-bounds memory.

The vulnerability exists due to improper range validation in vdpasim_blk_check_range() when processing virtio block requests with an out-of-range sector start. A local user can submit a crafted virtio block request to read from and write to out-of-bounds memory.


1224) Use-after-free (CVE-ID: CVE-2026-97992)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the vhost-vdpa configuration eventfd context handling when configuration callbacks run concurrently with configuration call replacement. A local user can inject configuration interrupts while another thread replaces the configuration call file descriptor to cause a denial of service.

Reachability is described for VDUSE parent devices.


1225) Race condition (CVE-ID: CVE-2026-97993)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in vhost_vdpa_set_config_call() when installing a configuration eventfd context. A local user can supply an invalid eventfd descriptor while setting the configuration callback to cause a denial of service.

A configuration interrupt delivered during the error-handling window can pass an error pointer to eventfd_signal().


1226) Out-of-bounds read (CVE-ID: CVE-2026-97994)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory beyond the mapped descriptor ring.

The vulnerability exists due to an out-of-bounds read in the vhost/vdpa VHOST_SET_VRING_NUM handling when configuring a virtual ring queue size larger than the device maximum. A local user can set a queue size exceeding the advertised maximum to read memory beyond the mapped descriptor ring.


1227) Out-of-bounds read (CVE-ID: CVE-2026-97995)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause an out-of-bounds read.

The vulnerability exists due to type confusion in the virtio_console remove_vqs() function when unbinding a device with a control message remaining on the control-out virtqueue. A local privileged user can unbind the device while the control message is queued to cause an out-of-bounds read.


1228) Use-after-free (CVE-ID: CVE-2026-97996)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read freed memory.

The vulnerability exists due to use-after-free in unregister_virtio_device() when unregistering a virtio device. A local user can unbind a virtio device to read freed memory.

The issue affects virtio_mmio, virtio_vdpa, virtio_uml, mlxbf-tmfifo, and virtio_ccw transports.


1229) Race condition (CVE-ID: CVE-2026-97998)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the nfnetlink_log instance destruction handler when concurrently processing a netlink close event and an UNBIND request from sockets using the same port ID. A local user can trigger concurrent instance destruction and unbinding to cause a denial of service.


1230) Use of Uninitialized Variable (CVE-ID: CVE-2026-98001)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to use of uninitialized stack memory in ltc428_clk_provider_setup() when initializing the ltc4282 clock provider. A local privileged user can trigger initialization of the ltc4282 clock provider to cause a denial of service.

The issue is exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is enabled.


1231) Use-after-free (CVE-ID: CVE-2026-98006)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to a use-after-free in the ALSA caiaq USB driver's ep1_in_urb and midi_out_urb handling when processing a command timeout after a submitted URB is unlinked by the dummy HCD driver. A local user can trigger the affected initialization failure to trigger a use-after-free.


1232) Improper Validation of Specified Type of Input (CVE-ID: CVE-2026-98007)

CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper validation of helper argument types in the bpf_loop() nr_loops argument in the BPF verifier when a privileged BPF program passes a pointer value as the iteration count. A local privileged user can submit a privileged BPF program with a pointer-valued iteration count to trigger a verifier warning and kernel panic.

Exploitation requires a kernel configured with panic_on_warn enabled.


1233) NULL pointer dereference (CVE-ID: CVE-2026-98008)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the macb driver cleanup paths when unbinding the driver for a fixed-link device tree configuration without an "mdio" child node. A local privileged user can unbind the driver to cause a denial of service.


1234) Infinite loop (CVE-ID: CVE-2026-98009)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of ETS quantum values in the ETS queuing discipline when configuring an ETS qdisc with crafted quantum values. A local user can configure a crafted ETS qdisc to cause a denial of service.

The issue requires CONFIG_NET_SCH_ETS and CAP_NET_ADMIN; namespace-local capabilities are sufficient.


1235) Resource exhaustion (CVE-ID: CVE-2026-98010)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of DRR quantum values in drr_change_class() when configuring DRR qdisc classes with a low quantum value. A local user can configure a DRR qdisc class with the quantum set to 1 to cause a denial of service.

Exploitation requires CONFIG_NET_SCH_DRR=y and CAP_NET_ADMIN; the capability can be namespace-local through unshare -Urn.


1236) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-98011)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of the quantum value in the HHF queueing discipline when configuring an HHF qdisc with quantum set to 1 and a crafted size table. A local user can configure the qdisc with these values to cause a deficit-refill loop to spin under the qdisc lock and cause a denial of service.

Exploitation requires CONFIG_NET_SCH_HHF=y and CAP_NET_ADMIN in a network namespace.


1237) Improper input validation (CVE-ID: CVE-2026-98012)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the SFQ qdisc change path when processing crafted qdisc configuration. A local user can configure a quantum value of 1 with a crafted size table to cause a denial of service.

The SFQ scheduler must be enabled, and exploitation requires CAP_NET_ADMIN, which can be namespace-local.


1238) Resource exhaustion (CVE-ID: CVE-2026-98013)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of quantum values in fq_pie_change() when changing fq_pie qdisc configuration with a crafted size table. A local user can configure a quantum value of 1 and a crafted size table to cause a denial of service.

Exploitation requires CONFIG_NET_SCH_FQ_PIE to be enabled.


1239) Use-after-free (CVE-ID: CVE-2026-98014)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper cleanup ordering in the mlx5 E-Switch vport disable path when handling firmware-fatal recovery. A local user can trigger a PCI device reset to cause a denial of service.


1240) Use-after-free (CVE-ID: CVE-2026-98015)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to use-after-free in mlx5_eswitch_termtbl_put when two callers concurrently release the same mlx5_termtbl_handle. A local user can invoke concurrent calls on the same handle to access freed memory.


1241) Use-after-free (CVE-ID: CVE-2026-98016)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed memory.

The vulnerability exists due to a use-after-free race in sample_restore_put() when concurrently tearing down TC sample rules sharing the same restore context. A local user can concurrently tear down shared TC sample rules to access freed memory.


1242) Use-after-free (CVE-ID: CVE-2026-98017)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a use-after-free in the Linux kernel traffic-control queueing discipline creation path when processing an RTM_NEWQDISC request with an invalid TCA_RATE attribute after binding a populated shared ingress block. A local user can send a crafted RTM_NEWQDISC request to cause memory corruption.


1243) Use-after-free (CVE-ID: CVE-2026-98018)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a use-after-free in mctp_i3c_probe() when handling concurrent I3C bus removal notifications. A local user can trigger a race between device probing and bus removal to cause memory corruption.


1244) Race condition (CVE-ID: CVE-2026-98020)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in pds_core cmd_regs access handling when a function-level reset occurs concurrently with a devlink firmware update. A local user can trigger a function-level reset during a firmware update to cause a denial of service.


1245) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-98021)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause excessive memory allocation.

The vulnerability exists due to improper validation of a specified quantity in input in the IFLA_TXQLEN netlink attribute when processing netlink requests that specify a transmit queue length. A local user can submit a netlink request with an oversized tx_queue_len value to cause excessive memory allocation.

Exploitation requires network scheduling, veth, user namespace, and network namespace support.


1246) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-98022)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits in netif_change_tx_queue_len() when processing tx queue length changes. A local user can set an oversized tx_queue_len value to cause a denial of service.

User and network namespaces must be enabled.


1247) Use-after-free (CVE-ID: CVE-2026-98023)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to use-after-free in the VXLAN forwarding database entry handling when configuring dynamic FDB entries that reference an FDB nexthop. A local user can configure dynamic entries on VXLAN devices that share an FDB nexthop to cause memory corruption.

The race can occur when an entry is aged while another device adds or deletes an entry associated with the shared FDB nexthop.


1248) Mismatched Memory Management Routines (CVE-ID: CVE-2026-98024)

CWE-ID: CWE-762 - Mismatched Memory Management Routines

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause slab allocator corruption.

The vulnerability exists due to incorrect memory deallocation in ism_alloc_dmb() when handling an error after allocating dmb->cpu_addr with folio_alloc(). A local user can trigger the error exit to cause slab allocator corruption.

The dmb->cpu_addr pointer may be used by future callers after the associated folio has been released.


1249) Heap-based buffer overflow (CVE-ID: CVE-2026-98025)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to corrupt memory.

The vulnerability exists due to a heap-based buffer overflow in the cx82310_rx_fixup function of the cx82310_eth USB network driver when processing a crafted USB network receive URB beginning with the 0xffff reboot sentinel. An attacker with physical access can send a crafted USB network receive URB to corrupt memory.


1250) Use-after-free (CVE-ID: CVE-2026-98026)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free condition.

The vulnerability exists due to improper RCU synchronization in the bridge multicast mglist when deleting port groups concurrently with adjacent multicast-list traversal. A local user can cause a port group to be freed while br_multicast_list_adjacent() traverses the mglist to trigger a use-after-free condition.


1251) Out-of-bounds write (CVE-ID: CVE-2026-98027)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or compromise confidentiality and integrity.

The vulnerability exists due to an out-of-bounds write in the mv88e6xxx_get_rxnfc() policy rule dump handler when processing an ETHTOOL_GRXCLSRLALL request with fewer caller-provided slots than policy rules. A local user can issue a request specifying an insufficient rule count to write beyond the allocated buffer.

Exploitation requires policy rules to have been installed for the targeted port.


1252) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-98028)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in the nfp_net_fs_add() rule replacement logic when reprogramming an existing rule after hardware programming fails. A local user can trigger a failed rule reprogramming operation to cause a denial of service.

The affected ethtool rule-list operation can subsequently return a permanent -EMSGSIZE error because the rule list and rule counter are not resynchronized.


1253) Out-of-bounds write (CVE-ID: CVE-2026-98029)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption or a denial of service.

The vulnerability exists due to missing bounds checking in nfp_net_get_fs_loc() when handling ETHTOOL_GRXCLSRLALL requests with a user-supplied rule count smaller than the number of flow steering rules. A local user can issue a crafted ioctl request to write rule locations beyond the caller-provided buffer.

Exploitation requires flow steering rules to have been installed; a rule count of zero leaves the rule-locations pointer NULL.


1254) Out-of-bounds write (CVE-ID: CVE-2026-98030)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an out-of-bounds write in bcm_sf2_cfp_rule_get_all() in the Broadcom Starfighter 2 DSA driver when processing ETHTOOL_GRXCLSRLALL ioctl requests with a caller-supplied rule count. A local user can request fewer rule slots than installed CFP rules to compromise confidentiality, integrity, and availability.

Exploitation requires CFP rules to have already been installed.


1255) Access of Uninitialized Pointer (CVE-ID: CVE-2026-98031)

CWE-ID: CWE-824 - Access of Uninitialized Pointer

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to access of an uninitialized pointer in remove_nh_grp_entry() when replacing a reduced nexthop group after a listener allocation failure. A local user can trigger removal of a nexthop group entry to cause a denial of service.


1256) Untrusted Pointer Dereference (CVE-ID: CVE-2026-98037)

CWE-ID: CWE-822 - Untrusted Pointer Dereference

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a NULL or stale-memory dereference.

The vulnerability exists due to improper validation of untrusted pointer state in the BPF verifier's type_is_ptr_alloc_obj() predicate when validating a refcount-only local kptr after RCU protection ends. A local user can pass a demoted local kptr to bpf_refcount_acquire() to trigger a NULL or stale-memory dereference.

Fault-protected reads of the demoted pointer remain valid.


1257) Type Confusion (CVE-ID: CVE-2026-98039)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform arbitrary kernel read and write operations.

The vulnerability exists due to improper type validation in map_kptr_match_type() when storing a non-per-CPU pointer in a BPF_KPTR_PERCPU map field. A local user can load a crafted BPF program that stores a plain allocation or referenced kernel pointer in the field to perform arbitrary kernel read and write operations.


1258) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-98041)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to incorrect branch prediction in the BPF verifier's is_branch_taken function when processing 32-bit BPF jump comparisons between pointers and zero. A local user can load a BPF program containing a 32-bit pointer-versus-zero comparison to compromise confidentiality, integrity, and availability.


1259) Improper locking (CVE-ID: CVE-2026-98045)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in the faultable bpf_get_stack() and bpf_get_task_stack() helper prototypes when resolving user-space build IDs from a non-sleepable context. A local user can invoke a faultable stack helper from a non-sleepable kernel context to cause a denial of service.

The task-stack helper can be invoked from a non-sleepable timer callback in a sleepable program.


1260) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-98046)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to install a file descriptor into an interrupted task.

The vulnerability exists due to improper execution-context validation in the bpf_btf_find_by_name_kind() helper prototype when invoking the helper from a non-sleepable BPF timer callback. A local user can invoke the helper from a BPF timer callback to install a file descriptor into an interrupted task.


1261) Incorrect calculation (CVE-ID: CVE-2026-98051)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to initiate a transmission without ensuring that consecutive descriptor slots are available.

The vulnerability exists due to incorrect loop initialization in tx_spb_ring_full() when checking descriptor slot availability for a new transmission. A local user can trigger a transmission after the function repeatedly checks the same descriptor slot instead of consecutive slots.


1262) Use-after-free (CVE-ID: CVE-2026-98052)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to use-after-free in the bcmasp_xmit() transmit descriptor handling when transmitting fragmented SKBs. A local user can transmit a fragmented SKB to cause a use-after-free condition.

The condition requires a descriptor slot to be reused with a stale final-fragment indicator while remaining SKB fragments are still in flight.


1263) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-98054)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak a module reference.

The vulnerability exists due to missing module reference release on error paths in the ASoC Intel AVS strace_open debugfs handler when opening the strace debugfs file. A local user can trigger an error after a module reference is acquired to leak a module reference.

The issue is triggered if the trace FIFO is already initialized or its allocation fails.


1264) Memory leak (CVE-ID: CVE-2026-98055)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in the AVS PCI probe routine when fetching ML capabilities fails or subsequent probe initialization fails. A local user can trigger an AVS PCI device probe failure to cause a denial of service.


1265) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-98056)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity in nvme_scan_ns_list() when processing a reported NVMe namespace identifier list with sparse gaps. A remote attacker can provide a namespace list containing a large sparse namespace identifier gap to cause a denial of service.


1266) Improper input validation (CVE-ID: CVE-2026-98057)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause persistent ring buffer validation to accept an inconsistent sub-buffer count.

The vulnerability exists due to improper input validation in the persistent ring buffer validation code when validating saved persistent ring buffer metadata. A local user can trigger validation of saved metadata with an nr_subbufs value that does not match nr_pages + 1 to cause persistent ring buffer validation to accept an inconsistent sub-buffer count.


1267) NULL pointer dereference (CVE-ID: CVE-2026-98059)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper null pointer handling in the BPF verifier handling of the sched_process_wait tracepoint argument when executing a JITed BPF program that dereferences the argument without a NULL check. A local user can execute a JITed BPF program with an unchecked dereference and trigger a wait for any child to cause a denial of service.

The tracepoint argument can be NULL for wait4(-1) and waitid(P_ALL).


1268) NULL pointer dereference (CVE-ID: CVE-2026-98063)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in btf_var_show() when bpf_snprintf_btf() renders a BTF_KIND_VAR from base vmlinux BTF. A local user can load and run a BPF program that passes the type ID of a BTF_KIND_VAR to bpf_snprintf_btf() to cause a denial of service.


1269) NULL pointer dereference (CVE-ID: CVE-2026-98064)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in btf_modifier_show() when processing a BPF program-supplied const void BTF type. A local user can supply a BPF program with a const void BTF type to bpf_snprintf_btf() to cause a denial of service.


1270) Double free (CVE-ID: CVE-2026-98066)

CWE-ID: CWE-415 - Double Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in the ALSA caiaq driver's audio resource cleanup when handling audio initialization errors. A local user can trigger an audio initialization error after URB resources have been freed to cause a denial of service.


1271) Race condition (CVE-ID: CVE-2026-98068)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a race condition in RDS TCP connection path shutdown handling when connection teardown races with acceptance of a new socket. A remote attacker can trigger concurrent connection teardown and socket acceptance to cause a denial of service.

The affected path can remain in RDS_CONN_DOWN with an established socket and a growing receive queue.


1272) Race condition (CVE-ID: CVE-2026-98069)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper synchronization in rds_conn_shutdown() in the RDS networking subsystem when tearing down an RDS connection path. A remote attacker can race transmission or receive-refill operations with connection teardown to cause a denial of service.

Exploitation occurs on weakly ordered architectures.


1273) Race condition (CVE-ID: CVE-2026-98070)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a race condition in rds_tcp_reset_callbacks() in the RDS TCP transport when concurrent transmit and connection-reset operations access connection state. A remote attacker can trigger concurrent RDS transmission and connection-reset activity to compromise confidentiality, integrity, and availability.


1274) Race condition (CVE-ID: CVE-2026-98071)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause connection state updates to be lost.

The vulnerability exists due to a data race in rds_conn_path_reset() when resetting RDS connection path flags concurrently with atomic flag operations. A local user can trigger concurrent connection reset and transmission operations to cause connection state updates to be lost.


1275) Race condition (CVE-ID: CVE-2026-98072)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory ordering in release_in_xmit() in the RDS networking component when concurrently releasing transmit state and checking for waiters. A local user can trigger a race between waiter registration and transmit-state release to cause a denial of service.

A lost wake-up can leave shutdown workers waiting indefinitely in uninterruptible wait operations.


1276) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-98074)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to leave a physical device in promiscuous mode after bond teardown.

The vulnerability exists due to improper state management in __bond_release_one() when releasing all slaves during bond destruction. A local privileged user can destroy a bond containing active and backup slaves to leave a physical device in promiscuous mode after bond teardown.

The backup slave must be released before the active slave.


1277) Improper input validation (CVE-ID: CVE-2026-98075)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the BPF verifier when loading a BPF program that references the main program as a callback. A local user can load a crafted BPF program using a BPF_PSEUDO_FUNC reference to the main program to cause a denial of service.


1278) Use-after-free (CVE-ID: CVE-2026-98076)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a use-after-free.

The vulnerability exists due to use-after-free in probe-based dynamic event field handling when looking up event fields after removing the first of several attached probes. A local user can create multiple probes for an event, remove the probe that defined its fields, and perform a field lookup to trigger a use-after-free.


1279) Out-of-bounds read (CVE-ID: CVE-2026-98077)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in sip_skip_whitespace() in nf_conntrack_sip when processing a SIP payload containing a recognized header name followed by whitespace at the end of the payload. A remote attacker can send such a crafted SIP payload to trigger an out-of-bounds read.


1280) Function Call with Incorrectly Specified Arguments (CVE-ID: CVE-2026-98078)

CWE-ID: CWE-628 - Function Call with Incorrectly Specified Arguments

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose stale heap data and corrupt connection sequence state.

The vulnerability exists due to incorrect function call argument ordering in the version 1 IPVS synchronization sender when serializing connection sequence data. A remote attacker can send traffic that causes connection sequence data to be synchronized to disclose stale heap data and corrupt connection sequence state.

Only connections with sequence-state flags set are affected.


1281) Operation on a Resource after Expiration or Release (CVE-ID: CVE-2026-98080)

CWE-ID: CWE-672 - Operation on a Resource after Expiration or Release

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause filesystem metadata corruption and force the filesystem read-only.

The vulnerability exists due to improper reloc root creation in the Btrfs qgroup snapshot accounting path when accounting snapshots during block-group relocation. A local user can perform Btrfs operations that account snapshots during relocation to cause filesystem metadata corruption and force the filesystem read-only.

The issue occurs on Btrfs filesystems with quotas enabled.


1282) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-98081)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of exceptional conditions in the btrfs zoned block group cleanup logic when handling a zone-finish operation that fails. A local user can cause a zone-finish operation to fail to cause a denial of service.


1283) Memory leak (CVE-ID: CVE-2026-98082)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource cleanup in the Btrfs ordered extent bioc_list when handling ordered extents after errors. A local user can trigger an error while processing an ordered extent to cause a denial of service.

The leak can occur when RAID extent insertion fails or when an ordered extent encounters an I/O error.


1284) Use-after-free (CVE-ID: CVE-2026-98083)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in Btrfs RAID stripe insertion transaction handling when allocation of a RAID stripe extent fails. A local user can invoke the affected RAID stripe insertion path during this error condition to compromise confidentiality, integrity, and availability.


1285) NULL pointer dereference (CVE-ID: CVE-2026-98086)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the ALSA UMP legacy rawmidi name handling when a UMP packet arrives during endpoint initialization. A local user can trigger processing of a UMP packet during this initialization window to cause a denial of service.


1286) Out-of-bounds read (CVE-ID: CVE-2026-98088)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read.

The vulnerability exists due to improper handling of an invalid NUMA node value in _base_assign_reply_queues() when assigning high IOPS reply queues for a PCI device without NUMA-node affinity. A local user can trigger reply queue assignment to cause an out-of-bounds read.

The issue occurs when dev_to_node() returns NUMA_NO_NODE (-1).


1287) Out-of-bounds read (CVE-ID: CVE-2026-98089)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read out-of-bounds memory.

The vulnerability exists due to an uninitialized transport header offset causing an out-of-bounds read in alb_determine_nd() in the bonding driver when inspecting ICMPv6 headers in IPv6 packets on bonding transmit paths. A remote attacker can send an IPv6 packet that is processed through a bonding transmit path to read out-of-bounds memory.

The affected paths include packets sent through AF_PACKET or raw sockets and forwarded packets.


1288) Use-after-free (CVE-ID: CVE-2026-98090)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the Btrfs active device pointers when handling a failed sprout setup. A local user can trigger a failed sprout setup to cause a denial of service.


1289) Use-after-free (CVE-ID: CVE-2026-98091)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a kernel warning.

The vulnerability exists due to use-after-free in the btrfs device transaction update list when system chunk creation fails while creating the first metadata chunk for a sprout filesystem. A local user can create a sprout filesystem that encounters a system chunk creation failure to cause a kernel warning.


1290) Memory leak (CVE-ID: CVE-2026-98092)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory release in acp6x_pdm_dma_close() when closing PDM DMA audio streams. A local user can repeatedly open and close PDM DMA audio streams to cause a denial of service.


1291) Deadlock (CVE-ID: CVE-2026-98094)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an IRQ-unsafe locking mechanism in the fbtft dirty_lock handling in fbtft_mkdirty() and fbtft_deferred_io() when framebuffer console rendering occurs in hardirq context concurrently with deferred I/O workqueue processing. A local user can trigger concurrent framebuffer console rendering and deferred I/O processing to cause a denial of service.


1292) Incorrect Conversion between Numeric Types (CVE-ID: CVE-2026-98095)

CWE-ID: CWE-681 - Incorrect Conversion between Numeric Types

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper numeric type conversion in tpacket_parse_header() in af_packet when processing a user-provided tpacket_hdr with tp_len larger than INT_MAX. A local user can provide a crafted packet header to cause a denial of service.


1293) Out-of-bounds write (CVE-ID: CVE-2026-98096)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption or a denial of service.

The vulnerability exists due to improper network header offset restoration in the Linux kernel ipv6_srh_rcv() function when processing IPv6 Segment Routing Header packets preceded by another extension header. A remote attacker can send a specially crafted IPv6 packet to cause memory corruption or a denial of service.


1294) Use of uninitialized resource (CVE-ID: CVE-2026-98097)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in TIPC link protocol message construction when sending RESET or ACTIVATE messages. A remote attacker can receive RESET or ACTIVATE messages containing random pad bytes to disclose sensitive information.


1295) NULL pointer dereference (CVE-ID: CVE-2026-98098)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in tipc_named_node_up() when processing node state publications after the local publication limit is reached. A local user can bind a large number of local-scope service addresses to sockets to cause a denial of service.

Subscribers to node or link up/down events may stop receiving notifications.


1296) Race condition (CVE-ID: CVE-2026-98102)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect IPv6 multicast source filtering.

The vulnerability exists due to improper synchronization in ip6_mc_del1_src() when removing active IPv6 multicast source filters concurrently with RCU-protected list traversal. A local user can trigger concurrent source-filter removal and list traversal to cause incorrect IPv6 multicast source filtering.


1297) Deadlock (CVE-ID: CVE-2026-98103)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to recursive locking in ip_check_mc_rcu() when generating IGMPv3 reports while an XFRM policy matches a multicast destination. A local user can trigger IGMPv3 report generation to cause a denial of service.

The affected function is used in packet receive and route lookup RCU fast paths.


1298) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-98104)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to access and modify u32 knodes associated with another tcf_proto instance.

The vulnerability exists due to improper handling of identifier-pool exhaustion in gen_new_htid and u32_init when creating a root hash table after the tp_c handle pool is exhausted. A local privileged user can exhaust the tp_c handle pool and create another u32 proto entry to cause root hash table handle aliasing.

The affected classifier must be enabled.


1299) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-98104)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause duplicate u32 filter handles.

The vulnerability exists due to improper handling of identifier-pool exhaustion in gen_new_kid and u32_change when generating automatic u32 node handles after the node ID pool is exhausted. A local privileged user can add enough u32 filters with automatically generated handles to exhaust the node ID space and cause duplicate handles.

The affected classifier must be enabled and a clsact qdisc must be configured on a device.


1300) Out-of-bounds write (CVE-ID: CVE-2026-98105)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in the oa_tc6 Ethernet driver when processing received data after data-chunk loss caused by receive buffer overflow errors. A remote attacker can cause oversubscribed traffic to trigger an assertion during skb_put.


1301) Out-of-bounds write (CVE-ID: CVE-2026-98107)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds write.

The vulnerability exists due to an out-of-bounds write in the L2CAP ECRED connection handling when connecting a sequence of L2CAP sockets with deferred and non-deferred channels. A local user can initiate the socket connection sequence to write a 16-bit SCID value past the SCID array.


1302) Stack-based buffer overflow (CVE-ID: CVE-2026-98108)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to a stack-based buffer overflow in the Bluetooth L2CAP deferred enhanced credit-based response handling when processing L2CAP LE connection requests. A remote attacker can send specially crafted L2CAP LE connection requests to cause memory corruption.

The issue involves deferred-setup channels and listening parent channels configured for extended flow control.


1303) Race condition (CVE-ID: CVE-2026-98109)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a kernel DEBUG_LOCKS warning.

The vulnerability exists due to a race condition in Bluetooth HCI device registration and Microsoft extension initialization when registering a Bluetooth device marked with an unconfigured-device quirk. A local user can trigger concurrent power-on work processing before the Microsoft extension mutex is initialized to trigger a kernel DEBUG_LOCKS warning.


1304) Out-of-bounds read (CVE-ID: CVE-2026-98110)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause an out-of-bounds read.

The vulnerability exists due to treating a length-bounded value as a NUL-terminated string in btintel firmware ID TLV parsing when processing a received firmware ID TLV without a NUL terminator. An attacker with physical access can provide a firmware ID TLV lacking a NUL terminator to cause an out-of-bounds read.


1305) Out-of-bounds read (CVE-ID: CVE-2026-98111)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read out-of-bounds memory.

The vulnerability exists due to insufficient length validation in btintel_parse_version_tlv() when parsing Bluetooth version TLV responses. A local user can provide a TLV with a value shorter than required for its type to read out-of-bounds memory.


1306) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-98113)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to flood the kernel log.

The vulnerability exists due to missing rate limiting in the ksmbd DACL SID mapping error logging path when processing a DACL containing unmapped SIDs. A remote user can submit a DACL with many structurally valid but unmapped SIDs to flood the kernel log.


1307) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-98114)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incomplete ACL conversion.

The vulnerability exists due to improper error handling in the ksmbd parse_dacl() function when parsing malformed SMB security descriptors. A remote attacker can submit a malformed security descriptor to cause incomplete ACL conversion.


1308) Use-after-free (CVE-ID: CVE-2026-98116)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a use-after-free in ALSA PCM mmap handling when concurrently mapping PCM data during buffer reallocation. A local user can race an mmap operation against buffer reallocation to obtain a stale writable mapping of freed pages and escalate privileges.


1309) NULL pointer dereference (CVE-ID: CVE-2026-98121)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the msc313e watchdog driver's power management callbacks when handling system suspend or resume operations. A local user can trigger the power management callbacks to cause a denial of service.


1310) Use-after-free (CVE-ID: CVE-2026-98122)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in vxlan_mdb_remote_src_del() when processing VXLAN MDB updates containing an all-zeros source address. A local user can submit crafted VXLAN MDB entries to compromise confidentiality, integrity, and availability.

MDB operations are network-namespace scoped and can be performed in a new user and network namespace.


1311) Out-of-bounds read (CVE-ID: CVE-2026-98123)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to read memory out of bounds.

The vulnerability exists due to an out-of-bounds read in sctp_get_asconf_response() when processing a truncated SCTP_PARAM_ERR_CAUSE parameter in an ASCONF-ACK. A remote user can send a crafted ASCONF-ACK containing an error-cause parameter without a complete error header to read memory out of bounds.

The association must have ADD-IP enabled and an outstanding ASCONF request.


1312) Infinite loop (CVE-ID: CVE-2026-98123)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper parameter iteration in sctp_get_asconf_response() when processing a crafted ASCONF-ACK. A remote user can send an ASCONF-ACK containing an odd-length parameter that causes the parameter-processing loop to make no progress and spin in softirq context to cause a denial of service.

The association must have ADD-IP enabled and an outstanding ASCONF request.


1313) Improper Authorization (CVE-ID: CVE-2026-98126)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass file-size limits.

The vulnerability exists due to missing file-size limit validation in smb3_zero_range() when using FALLOC_FL_ZERO_RANGE without FALLOC_FL_KEEP_SIZE on a file on a CIFS mount. A local user can invoke a zero-range operation that extends the end of the file to bypass file-size limits.


1314) Improper input validation (CVE-ID: CVE-2026-98127)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass file-size limits.

The vulnerability exists due to improper validation of the calculated end-of-file size in smb3_insert_range() when handling FALLOC_FL_INSERT_RANGE requests on a CIFS mount. A local user can invoke fallocate with FALLOC_FL_INSERT_RANGE to bypass file-size limits.


1315) Memory leak (CVE-ID: CVE-2026-98128)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a missing reference release in mpi3mr_sas_port_add() when handling an error after acquiring a target device reference. A local user can trigger the error path after a target device reference is acquired to cause a denial of service.

The target device reference is acquired only for SAS_END_DEVICE types.


1316) Memory leak (CVE-ID: CVE-2026-98129)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to leak memory.

The vulnerability exists due to improper resource release in mpi3mr_sas_port_add() when adding an allocated SAS port fails. A local user can trigger SAS port addition failures to leak memory.


1317) NULL pointer dereference (CVE-ID: CVE-2026-98129)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in mpi3mr_sas_port_add() when allocating a SAS port. A local user can trigger SAS port addition when memory allocation fails to cause a denial of service.


1318) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-98130)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free.

The vulnerability exists due to a time-of-check to time-of-use race condition in the SCTP_CMD_TIMER_START handler when processing SCTP timer start commands. A remote attacker can trigger the race condition to trigger a use-after-free.


1319) Out-of-bounds write (CVE-ID: CVE-2026-98142)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in the cirrus-qemu driver's VRAM handling when updating a display plane for a PCI device with an undersized BAR0. A local user can cause a PCI device with a BAR0 smaller than the expected VRAM size to be bound to the driver to cause a denial of service.


1320) Incorrect calculation (CVE-ID: CVE-2026-98151)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to trigger a verifier warning.

The vulnerability exists due to inconsistent synchronization of 32-bit register bounds and pointer offset state in the BPF verifier when verifying speculative pointer arithmetic in an unprivileged BPF program. A local user can load a BPF program that performs bounded scalar arithmetic on a map-value pointer to trigger a verifier warning.

The warning occurs when the verifier evaluates a subsequent register copy along a speculative path.


1321) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-98152)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of resources in the nvmet_rdma_queue_connect function when handling an RDMA connection while pending disconnecting queues exceed the backlog limit. A remote attacker can initiate a connection under this condition to cause a denial of service.


1322) Operation on a Resource after Expiration or Release (CVE-ID: CVE-2026-98154)

CWE-ID: CWE-672 - Operation on a Resource after Expiration or Release

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper cleanup of completed requests in the nvme_rdma_queue_rq function when handling an -EIO error in the NVMe RDMA queue request path. A local user can trigger an -EIO error during queue request processing to compromise confidentiality, integrity, and availability.


1323) Out-of-bounds read (CVE-ID: CVE-2026-98155)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the QAIC response worker when processing a malformed wire message from the device. A local user can send a malformed wire message from the device to cause a denial of service.


1324) Numeric Truncation Error (CVE-ID: CVE-2026-98157)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to numeric truncation and insufficient input validation in the poll_msec sysfs store handler when processing user-supplied polling-delay values. A local user can write a zero value or an oversized value that truncates to zero to cause a denial of service.


1325) Out-of-bounds write (CVE-ID: CVE-2026-98158)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of skb headroom in ppp_async's process_input_packet() when processing a bad-FCS PPP frame followed by a crafted frame. A remote attacker can send malformed PPP frames to cause a denial of service.

When CCP compression is enabled, decompression can read before the skb head.


1326) Out-of-bounds write (CVE-ID: CVE-2026-98159)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to improper bounds checking in the mt7921_load_clc CLC firmware record loader when processing a malformed CLC firmware image. A local user can provide a malformed CLC firmware image to cause memory corruption.


1327) Mismatched Memory Management Routines (CVE-ID: CVE-2026-98160)

CWE-ID: CWE-762 - Mismatched Memory Management Routines

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to mismatched memory management routines in rtw_sdio_if1_init() when handling an initialization failure after allocating HalData. A local user can trigger the initialization error path to cause memory corruption.


1328) Incorrect calculation (CVE-ID: CVE-2026-100070)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose internal network details.

The vulnerability exists due to an incorrect calculation of the Contact-header parsing offset in nf_nat_sip when processing a SIP packet whose NAT address translation changes its length. A remote attacker can send a SIP packet containing subsequent Contact headers to disclose internal network details.

Exploitation requires NAT address translation to shorten the packet.


1329) Memory leak (CVE-ID: CVE-2026-100071)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource cleanup in HSR device setup error handling when receiving frames after an RX handler has been registered and device setup subsequently fails. A remote attacker can send frames during HSR device setup to cause a denial of service.


1330) Incomplete cleanup (CVE-ID: CVE-2026-100075)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect send queue credit accounting.

The vulnerability exists due to incomplete cleanup in the srpt_alloc_rw_ctxs() error unwind path when handling an allocation failure partway through a multi-buffer indirect descriptor. A remote attacker can trigger the error path to cause incorrect send queue credit accounting.


1331) Function Call with Incorrectly Specified Arguments (CVE-ID: CVE-2026-100078)

CWE-ID: CWE-628 - Function Call with Incorrectly Specified Arguments

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an incorrect function argument in the iwlwifi MEI cyclic buffer handling code when sending SAP message payloads. A local user can trigger the vulnerable code path to cause a denial of service.


1332) Improper resource shutdown or release (CVE-ID: CVE-2026-100079)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to prevent UCSI debugfs entries from being created.

The vulnerability exists due to improper resource cleanup in UCSI debugfs entry teardown when unregistering and registering the same UCSI instance across a remoteproc restart. A local user can trigger repeated UCSI instance unregistration and registration to prevent UCSI debugfs entries from being created.


Remediation

Install update from vendor's website.