audit.rawnix.org kernel rawnix.org

Linux 6.18.54

No known CVE is fixed in a later 6.18 release.

Fixed by updating

None.

Not fixed in 6.18 yet

Affects 6.18.54, and no 6.18 release has the fix yet; no 6.18 update helps.

CVESeverityCVSSFixed in mainlinePublishedTitle
CVE-2026-72493CRITICAL9.97.2—net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-31501CRITICAL9.87.0—net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path
CVE-2026-43414CRITICAL9.87.0—scsi: qla2xxx: Completely fix fcport double free
CVE-2026-64067CRITICAL9.87.1—netfs: Fix missing barriers when accessing stream->subrequests locklessly
CVE-2026-64160CRITICAL9.87.1—netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
CVE-2026-72064CRITICAL9.87.2—net: mana: Sync page pool RX frags for CPU
CVE-2026-72477CRITICAL9.87.2—fs/ntfs3: call _ntfs_bad_inode() when failing to rename
CVE-2026-74350CRITICAL9.87.2—ocfs2: validate fast symlink target during inode read
CVE-2026-74723CRITICAL9.87.2—btrfs: lzo: reject inline extents without valid headers
CVE-2026-74752CRITICAL9.87.2—sctp: validate cookie AUTH state before use
CVE-2026-80634CRITICAL9.87.2—netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
CVE-2026-80668CRITICAL9.87.2—netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
CVE-2026-89610CRITICAL9.87.3—ntfs: verify run length exceeding volume boundary
CVE-2026-89611CRITICAL9.87.3—ntfs: validate non-resident attribute offsets
CVE-2026-89654CRITICAL9.87.3—ceph: fix UAF in check_new_map() on session freed during unlock
CVE-2026-89788CRITICAL9.87.3—ksmbd: fix tree connection use-after-free in smb2_tree_connect()
CVE-2026-90104CRITICAL9.87.3—NFSv4.1: zero referring call lists before decoding
CVE-2026-72329CRITICAL9.37.2—net/liquidio: drop cached VF pci_dev LUT
CVE-2026-74568CRITICAL9.37.2—KVM: arm64: vgic: Fix race between LPI release and re-registration
CVE-2026-80693CRITICAL9.37.2—idpf: bound interrupt-vector register fill to the allocated array
CVE-2026-89537CRITICAL9.17.3—SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2
CVE-2026-63941HIGH8.87.1—KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor
CVE-2026-64117HIGH8.87.1—wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
CVE-2026-68470HIGH8.87.2—wifi: mac80211: validate extension-frame layout before RX
CVE-2026-72380HIGH8.87.2—xen/pvcalls: bound backend response req_id before indexing rsp[]
CVE-2026-72423HIGH8.87.2—bpf: Guard conntrack opts error writes
CVE-2026-72497HIGH8.87.2—RDMA/bnxt_re: Add a max slot check for SQ
CVE-2026-72499HIGH8.87.2—RDMA/bnxt_re: Free CQ toggle page after firmware teardown
CVE-2026-74277HIGH8.87.2—iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
CVE-2026-74527HIGH8.87.2—octeontx2-af: Block VFs from clobbering special CGX PKIND state
CVE-2026-74530HIGH8.87.2—Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
CVE-2026-74533HIGH8.87.2—Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero
CVE-2026-74561HIGH8.87.2—nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
CVE-2026-74562HIGH8.87.2—nexthop: take nh->lock for f6i_list walks in replace check and notify
CVE-2026-80692HIGH8.87.2—Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
CVE-2026-80734HIGH8.87.2—btrfs: initialize inode mapping flags for cached inodes
CVE-2026-89513HIGH8.87.3—RISC-V: KVM: Fix PMU event info array size overflow
CVE-2026-89534HIGH8.87.3—svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
CVE-2026-89601HIGH8.87.3—ext2: Fix lost inode updates for IS_SYNC inodes
CVE-2026-89907HIGH8.87.3—LoongArch: KVM: Validate MSI data before routing it to EIOINTC
CVE-2026-90162HIGH8.87.3—ksmbd: defer publishing granted locks to prevent UAF/double-free race
CVE-2026-90256HIGH8.87.3—Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90380HIGH8.87.3—wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90381HIGH8.87.3—wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-93189HIGH8.87.3—HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-98115HIGH8.87.3—ksmbd: safely drain sessions during logoff
CVE-2026-64400HIGH8.67.2—ksmbd: prevent path traversal bypass by restricting caseless retry
CVE-2026-53091HIGH8.47.1—net: pull headers in qdisc_pkt_len_segs_init()
CVE-2026-90347HIGH8.47.3—arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry
CVE-2026-89632HIGH8.2——smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
CVE-2026-31771HIGH8.17.0—Bluetooth: hci_event: move wake reason storage into validated event handlers
CVE-2026-89709HIGH8.17.3—lockd, nfsd: RCU-protect nlmsvc_ops dispatch
CVE-2026-90301HIGH8.17.3—ocfs2: o2hb: quiesce negotiate handlers and timeout work
CVE-2026-93221HIGH8.17.3—nfsd: convert nfsd_net boolean flags to unsigned long flags word
CVE-2026-93282HIGH8.17.3—ksmbd: fix maximum allowed access checks
CVE-2026-80747HIGH8.07.2—drm/amdkfd: Add bounds check for CRAT subtype length
CVE-2025-71074HIGH7.86.19—functionfs: fix the open/removal races
CVE-2026-45991HIGH7.87.1—udf: fix partition descriptor append bookkeeping
CVE-2026-46210HIGH7.87.1—media: iris: fix use-after-free of fmt_src during MBPF check
CVE-2026-46311HIGH7.87.1—drm/amdgpu/userq: fix access to stale wptr mapping
CVE-2026-46330HIGH7.87.0—Revert "net/smc: Introduce TCP ULP support"
CVE-2026-53009HIGH7.87.1—ice: fix double-free of tx_buf skb
CVE-2026-53024HIGH7.87.1—greybus: raw: fix use-after-free if write is called after disconnect
CVE-2026-53025HIGH7.87.1—greybus: raw: fix use-after-free on cdev close
CVE-2026-53401HIGH7.87.2—fbdev: omap2: fix use-after-free in omapfb_mmap
CVE-2026-63858HIGH7.87.1—netfilter: nf_tables: add hook transactions for device deletions
CVE-2026-63879HIGH7.87.1—drm/amdgpu: fix amdgpu_hmm_range_get_pages
CVE-2026-63977HIGH7.87.1—dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work
CVE-2026-64057HIGH7.87.1—afs: Fix the locking used by afs_get_link()
CVE-2026-64123HIGH7.87.1—net: hsr: defer node table free until after RCU readers
CVE-2026-64388HIGH7.87.2—smb/client: fix chown/chgrp with SMB3 POSIX Extensions
CVE-2026-68295HIGH7.87.2—LoongArch: BPF: Zero-extend signed ALU32 div/mod results
CVE-2026-68305HIGH7.87.2—drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers
CVE-2026-68323HIGH7.87.2—tipc: serialize udp bearer replicast list updates
CVE-2026-68382HIGH7.87.2—drm/xe/guc: Hold device ref until queue teardown completes
CVE-2026-68383HIGH7.87.2—drm/xe/guc: Keep scheduler timeline name alive
CVE-2026-68399HIGH7.87.2—bpf: Fix UAF in sock clone early bailouts
CVE-2026-68404HIGH7.87.2—wifi: cfg80211: use wiphy work for socket owner autodisconnect
CVE-2026-72331HIGH7.87.2—accel/amdxdna: Fix VMA access race
CVE-2026-72345HIGH7.87.2—net/mlx5: LAG, Fix off-by-one in single-FDB error rollback
CVE-2026-72404HIGH7.87.2—tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()
CVE-2026-72454HIGH7.87.2—i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
CVE-2026-74260HIGH7.87.2—netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them
CVE-2026-74314HIGH7.87.2—bpf: Cancel special fields on map value recycle
CVE-2026-74317HIGH7.87.2—ixgbe: do not configure xps for XDP queues
CVE-2026-74338HIGH7.87.2—bpf: Reject sleepable BPF_LSM_CGROUP programs at load time
CVE-2026-74354HIGH7.87.2—bpf: Take mmap_lock in zap_pages()
CVE-2026-74367HIGH7.87.2—wifi: ath12k: fix inconsistent arvif state in vdev_create error paths
CVE-2026-74449HIGH7.87.2—drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport
CVE-2026-74529HIGH7.87.2—Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
CVE-2026-74544HIGH7.87.2—net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
CVE-2026-74605HIGH7.87.2—eventfs: Use children field for rcu head and add memory barriers
CVE-2026-74715HIGH7.87.2—bpf: Fix netns reference imbalance in conntrack kfuncs
CVE-2026-74721HIGH7.87.2—accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()
CVE-2026-74733HIGH7.87.2—gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
CVE-2026-74747HIGH7.87.2—ipvs: revalidate ihl to prevent out-of-bounds access
CVE-2026-80579HIGH7.87.2—fbdev: clear fb_info->mode before deleting a videomode
CVE-2026-80580HIGH7.87.2—fbdev: bound mode sysfs output to the sysfs buffer
CVE-2026-89584HIGH7.87.3—block: validate user space vectors during extraction
CVE-2026-89755HIGH7.87.3—mm/migrate_device: clear stale mapping after freeing swapcache
CVE-2026-89764HIGH7.87.3—rust: devres: fix race between concurrent revokers
CVE-2026-89793HIGH7.87.3—ublk: clear VM_MAYWRITE on read-only ublk char device mmap
CVE-2026-89805HIGH7.87.3—drm/pagemap: Fix folio allocation fallback and use-after-put
CVE-2026-90093HIGH7.87.3—Bluetooth: L2CAP: access chan->conn safely in get/setsockopt
CVE-2026-90111HIGH7.87.3—ip6mr: do not clone dst in ip6mr_cache_report()
CVE-2026-90142HIGH7.87.3—virtio_net: Fix resize of the RX ring
CVE-2026-90177HIGH7.87.3—bpf: Check pointer type for all atomic RMW paths
CVE-2026-90217HIGH7.87.3—bpf: Compare iterator types during state pruning
CVE-2026-90237HIGH7.87.3—netfilter: nft_ct: move custom expectation support to helper
CVE-2026-90289HIGH7.87.3—drm/amd/display: Resize MST HDCP per-connector arrays to 32
CVE-2026-90317HIGH7.87.3—bpf: Invalidate RCU pointers after final spin unlock
CVE-2026-90320HIGH7.87.3—ocfs2: validate external xattr entries when reading metadata
CVE-2026-90321HIGH7.87.3—ocfs2: validate inline xattrs during inode block validation
CVE-2026-92485HIGH7.87.3—bpf: Fix WARNING in bpf_tracing_link_release
CVE-2026-93105HIGH7.87.3—esp: do not unref managed frag pages in esp_ssg_unref()
CVE-2026-93122HIGH7.87.3—usb: gadget: uac: validate rate list length before storing
CVE-2026-93125HIGH7.87.3—bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max
CVE-2026-93144HIGH7.87.3—bpf: Reject writes through untrusted BTF pointers
CVE-2026-93148HIGH7.87.3—bpf: Reject MEM_ALLOC BTF accesses past object bounds
CVE-2026-93175HIGH7.87.3—drm/amd/display: Fix dangling pointer in CRTC reset function
CVE-2026-93201HIGH7.87.3—dm-pcache: validate seg_id fields from persistent memory
CVE-2026-90408HIGH7.77.3—wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event()
CVE-2026-52956HIGH7.57.1—libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
CVE-2026-52960HIGH7.57.1—ceph: put folios not suitable for writeback
CVE-2026-64020HIGH7.57.1—nvme-pci: fix dma_vecs leak on p2p memory
CVE-2026-74374HIGH7.57.2—md/raid1,raid10: fix error-path detection with md_cloned_bio()
CVE-2026-74745HIGH7.57.2—eth: bnxt: avoid deadlock when canceling IRQ affinity notifier
CVE-2026-74750HIGH7.57.2—ovpn: defer key slot crypto freeing to workqueue
CVE-2026-80631HIGH7.57.2—btrfs: lzo: reject compressed segment that overflows the compressed input
CVE-2026-90234HIGH7.57.3—NFS: Return a delegation the client fails to record
CVE-2026-90427HIGH7.47.3—iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()
CVE-2026-93260HIGH7.47.3—powerpc/xive: propagate IPI init errors to prevent use-after-free
CVE-2026-74419HIGH7.37.2—accel/amdxdna: Adjust size for copy_to_user()
CVE-2026-80738HIGH7.37.2—bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie
CVE-2026-43042HIGH7.17.0—mpls: add seqcount to protect the platform_label{,s} pair
CVE-2026-52988HIGH7.17.1—netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase
CVE-2026-68103HIGH7.17.2—drm/amdgpu: reject mapping a reserved doorbell to a new queue
CVE-2026-68447HIGH7.17.2—drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
CVE-2026-72397HIGH7.17.2—hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
CVE-2026-72440HIGH7.17.2—md/raid1: fix writes_pending and barrier reference leaks on write failures
CVE-2026-74713HIGH7.17.2—vhost_iotlb: bound map allocation in add_range
CVE-2026-89705HIGH7.17.3—nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths
CVE-2026-90174HIGH7.17.3—ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()
CVE-2026-90401HIGH7.17.3—md: remove REQ_NOWAIT support from raid1/10/456
CVE-2026-93116HIGH7.07.3—platform/x86: asus-wmi: fix resource leaks on probe failure
CVE-2026-93176HIGH7.07.3—drm/amd/display: Fix dangling pointer in plane reset function
CVE-2021-47645MEDIUM5.5——media: staging: media: zoran: calculate the right buffer number for zoran_reap_stat_com
CVE-2025-71306unscored—7.0—ima: Fix stack-out-of-bounds in is_bprm_creds_for_exec()
CVE-2025-71308unscored—7.0—accel/amdxdna: Fix potential NULL pointer dereference in context cleanup
CVE-2025-71313unscored—7.0—PCI: endpoint: Add missing NULL check for alloc_workqueue()
CVE-2026-100072unscored—7.3—ACPI: platform: Use acpi_bus_get_primary_device()
CVE-2026-100073unscored—7.3—ext4: fix transaction overflow during writeback
CVE-2026-23328unscored—7.0—accel/amdxdna: Fix NULL pointer dereference of mgmt_chann
CVE-2026-23374unscored—7.0—blktrace: fix __this_cpu_read/write in preemptible context
CVE-2026-23377unscored—7.0—ice: change XDP RxQ frag_size from DMA write length to xdp.frame_sz
CVE-2026-31710unscored—7.1—smb: client: fix dir separator in SMB1 UNIX mounts
CVE-2026-31777unscored—7.0—ALSA: ctxfi: Check the error for index mapping
CVE-2026-43022unscored—7.0—Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists
CVE-2026-43045unscored—7.0—mshv: Fix error handling in mshv_region_pin
CVE-2026-43053unscored—7.0—xfs: close crash window in attr dabtree inactivation
CVE-2026-43095unscored—7.0—ASoC: SDCA: Fix errors in IRQ cleanup
CVE-2026-43115unscored—7.0—srcu: Use irq_work to start GP in tiny SRCU
CVE-2026-43174unscored—7.0—io_uring/zcrx: fix post open error handling
CVE-2026-43191unscored—7.0—drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35
CVE-2026-43204unscored—7.0—ASoC: qcom: q6asm: drop DSP responses for closed data streams
CVE-2026-43228unscored—7.0—hfs: Replace BUG_ON with error handling for CNID count checks
CVE-2026-43299unscored—7.0—btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()
CVE-2026-43308unscored—7.0—btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()
CVE-2026-43310unscored—7.0—media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC
CVE-2026-43311unscored—7.0—soc/tegra: pmc: Fix unsafe generic_handle_irq() call
CVE-2026-43326unscored—7.0—sched_ext: Fix SCX_KICK_WAIT deadlock by deferring wait to balance callback
CVE-2026-43443unscored—7.0—ASoC: amd: acp-mach-common: Add missing error check for clock acquisition
CVE-2026-45961unscored—7.0—gfs2: fix memory leaks in gfs2_fill_super error path
CVE-2026-46008unscored—7.1—mm/damon/core: fix damos_walk() vs kdamond_fn() exit race
CVE-2026-46017unscored—7.1—mm: fix deferred split queue races during migration
CVE-2026-46032unscored—7.1—KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT
CVE-2026-46147unscored—7.1—KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()
CVE-2026-46153unscored—7.1—8021q: delete cleared egress QoS mappings
CVE-2026-46245unscored—7.0—drm/amd/display: Fix dc_link NULL handling in HPD init
CVE-2026-46298unscored—7.1—pseries/papr-hvpipe: Fix race with interrupt handler
CVE-2026-46302unscored—7.1—selinux: allow multiple opens of /sys/fs/selinux/policy
CVE-2026-52949unscored—7.1—drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure
CVE-2026-52965unscored—7.1—drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure
CVE-2026-53007unscored—7.1—ice: fix potential NULL pointer deref in error path of ice_set_ringparam()
CVE-2026-53008unscored—7.1—ice: fix race condition in TX timestamp ring cleanup
CVE-2026-53017unscored—7.1—f2fs: fix data loss caused by incorrect use of nat_entry flag
CVE-2026-53106unscored—7.1—bpf: Do not allow deleting local storage in NMI
CVE-2026-53108unscored—7.1—powerpc/64s: Fix unmap race with PMD migration entries
CVE-2026-53124unscored—7.1—ublk: reset per-IO canceled flag on each fetch
CVE-2026-53222unscored—7.1—ptp: ocp: fix resource freeing order
CVE-2026-53257unscored—7.1—wifi: cfg80211: enforce HE/EHT cap/oper consistency
CVE-2026-53285unscored—7.1—drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED
CVE-2026-53292unscored—7.1—net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind
CVE-2026-53308unscored—7.1—power: supply: max77705: Free allocated workqueue and fix removal order
CVE-2026-63811unscored—7.2—f2fs: read COW data with the original inode during atomic write
CVE-2026-63983unscored—7.1—net/sched: fix packet loop on netem when duplicate is on
CVE-2026-64013unscored—7.1—ACPI: button: Fix ACPI GPE handler leak during removal
CVE-2026-64019unscored—7.1—nvme-pci: fix dma mapping leak on data setup error
CVE-2026-64040unscored—7.1—cachefiles: Fix error return when vfs_mkdir() fails
CVE-2026-64079unscored—7.1—netfilter: x_tables: allocate hook ops while under mutex
CVE-2026-64146unscored—7.1—erofs: fix metabuf leak in inode xattr initialization
CVE-2026-64154unscored—7.1—drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()
CVE-2026-64159unscored—7.1—netfs: Fix zeropoint update where i_size > remote_i_size
CVE-2026-64212unscored—7.1—wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
CVE-2026-64283unscored—7.2—KVM: guest_memfd: Treat memslot binding offset+size as unsigned values
CVE-2026-64325unscored—7.2—wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon
CVE-2026-64341unscored—7.2—USB: iowarrior: fix use-after-free on disconnect race
CVE-2026-68086unscored———mm/khugepaged: write all dirty file folios when collapsing
CVE-2026-68105unscored—7.2—drm/amdgpu: Fix kernel panic during driver load failure
CVE-2026-68242unscored—7.2—drm/i915/gt: Fix NULL deref on sched_engine alloc failure
CVE-2026-68291unscored—7.2—idpf: fix max_vport related crash on allocation error during init
CVE-2026-68312unscored—7.2—cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
CVE-2026-68375unscored—7.2—bnxt_en: Handle partially initialized auxiliary devices
CVE-2026-68436unscored—7.2—drm/amd/display: use kvzalloc to allocate struct dc
CVE-2026-68441unscored—7.2—net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
CVE-2026-72031unscored—7.2—ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD
CVE-2026-72091unscored—7.2—accel/amdxdna: reject user command submission without a command BO
CVE-2026-72337unscored—7.2—Bluetooth: 6lowpan: avoid untracked enable work
CVE-2026-72370unscored—7.2—iomap: release pages on atomic dio size mismatch
CVE-2026-72377unscored—7.2—afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
CVE-2026-72388unscored—7.2—drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock
CVE-2026-72439unscored—7.2—md/raid10: fix writes_pending leak on write request failures
CVE-2026-74272unscored—7.2—cxl/region: Resolve region deletion races
CVE-2026-74273unscored—7.2—cxl/region: Block region delete during region creation
CVE-2026-74307unscored—7.2—ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
CVE-2026-74336unscored—7.2—wifi: mac80211: bound S1G TIM PVB walk to the TIM element
CVE-2026-74342unscored—7.2—kernfs: link kn to its parent before the LSM init hook
CVE-2026-74368unscored—7.2—wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()
CVE-2026-74373unscored—7.2—md/raid1,raid10: fix bio accounting for split md cloned bios
CVE-2026-74375unscored—7.2—md/raid1,raid10: fix deadlock in read error recovery path
CVE-2026-74466unscored—7.2—s390/zcrypt: Close speculative mem read possibility
CVE-2026-74542unscored—7.2—netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
CVE-2026-74558unscored—7.2—xsk: reclaim invalid Tx descriptors in ZC batch path
CVE-2026-74571unscored—7.2—btrfs: skip global block reserve accounting for rescue mounts
CVE-2026-74716unscored—7.2—accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()
CVE-2026-74729unscored—7.2—soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read
CVE-2026-74732unscored—7.2—drm/amd/display: Check for tg ops in dce110_set_avmute
CVE-2026-74754unscored—7.2—scsi: core: pair EH runtime PM get and put
CVE-2026-80524unscored—7.2—optee: ffa: Add NULL check in optee_ffa_lend_protmem
CVE-2026-80655unscored—7.2—soc: xilinx: Fix race condition in event registration
CVE-2026-80657unscored—7.2—accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer
CVE-2026-80698unscored—7.2—dmaengine: idxd: fix double free of wq, engine, and group structs
CVE-2026-80705unscored—7.2—drm/amd/display: check if dml21_add_phantom_plane() is successful
CVE-2026-80728unscored—7.2—Revert "drm/amdgpu: fix aperture mapping leak"
CVE-2026-80729unscored—7.2—mm/huge_memory: initialise workingset state before folio split
CVE-2026-80785unscored—7.2—fbdev: serialize mode sysfs access with lock_fb_info()
CVE-2026-80786unscored—7.2—fbdev: Wrap user-invoked calls to fb_set_var() in helper
CVE-2026-80866unscored—7.2—tipc: avoid busy looping in tipc_exit_net()
CVE-2026-80884unscored—7.2—ntb: Store original DMA address for future release
CVE-2026-80899unscored—7.2—erofs: remove fscache backend entirely
CVE-2026-89527unscored—7.3—svcrdma: Use svc_xprt_put to free listener on create failure
CVE-2026-89568unscored—7.3—kho: fix size calculation in kho_preserved_memory_reserve()
CVE-2026-89623unscored———HID: mcp2221: stop device IO before hid_hw_stop
CVE-2026-89642unscored—7.3—cifs: call pagecache_isize_extended() in cifs_setsize() when extending
CVE-2026-89673unscored———nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
CVE-2026-89718unscored—7.3—zram: fix out-of-bounds access in writeback_store()
CVE-2026-89772unscored—7.3—btrfs: write-protect folios during data writeback
CVE-2026-89812unscored—7.3—drm/amdgpu: force complete the MES ring fences on reset
CVE-2026-89813unscored—7.3—drm/amdgpu: force complete the KIQ ring fences on reset
CVE-2026-89862unscored—7.3—scsi: qla2xxx: Fix BSG job leak on validate flash image error path
CVE-2026-89866unscored—7.3—media: chips-media: wave5: Resume device before setting EOS flag
CVE-2026-90040unscored—7.3—KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped
CVE-2026-90061unscored—7.3—netfilter: nf_tables: skip double clone set expressions on element insert
CVE-2026-90079unscored—7.3—octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init()
CVE-2026-90082unscored—7.3—net: mana: Cap MSI-X vectors to the device MSI-X table size
CVE-2026-90087unscored—7.3—Bluetooth: do not leak an hci_conn when a second LE connect is rejected
CVE-2026-90095unscored—7.3—fuse: Fix the condition to enable over-io-uring
CVE-2026-90098unscored—7.3—net: sparx5: fix sleep in atomic context in MAC table access
CVE-2026-90099unscored—7.3—net/sched: account classifier filter allocations to memcg
CVE-2026-90105unscored—7.3—vxlan: fix reading neigh ha
CVE-2026-90106unscored—7.3—net: bridge: arp/nd proxy: fix reading neigh ha
CVE-2026-90121unscored—7.3—irqchip/gic-v5: Clear per-CPU IRS data on teardown
CVE-2026-90144unscored—7.3—dpll: fix NULL deref in dpll_device_ops() during teardown race
CVE-2026-90154unscored—7.3—ksmbd: scope session state changes to bound connections
CVE-2026-90155unscored—7.3—ksmbd: detach blocked lock requests before freeing
CVE-2026-90156unscored—7.3—ksmbd: safely discard unregistered deferred locks
CVE-2026-90167unscored—7.3—ksmbd: serialize oplock close with pending break ownership
CVE-2026-90182unscored—7.3—blk-iocost: clear delay state when freeing policy data
CVE-2026-90183unscored—7.3—blk-iolatency: clear delay state when freeing policy data
CVE-2026-90206unscored—7.3—nvmet: fix max_qid race between configfs and controller allocation
CVE-2026-90208unscored—7.3—clocksource/drivers/samsung_pwm: Switch to raw_spinlock_t type
CVE-2026-90211unscored—7.3—bpf, s390: Clear fetch destination on faulting arena atomic
CVE-2026-90242unscored—7.3—iommu/vt-d: Fix iopf_refcount leak on RID domain replacement
CVE-2026-90261unscored—7.3—btrfs: zoned: flush active metadata block group at btree_writepages() start
CVE-2026-90263unscored—7.3—btrfs: check if root is readonly when setting posix acl
CVE-2026-90267unscored—7.3—scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails
CVE-2026-90273unscored—7.3—coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable
CVE-2026-90300unscored—7.3—bpf: Clear buf on error in __bpf_get_task_stack
CVE-2026-90311unscored—7.3—thermal: hwmon: Remove hwmon class device along with its parent
CVE-2026-90315unscored—7.3—PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers
CVE-2026-90323unscored—7.3—ublk: validate auto buf reg before taking uring_cmd
CVE-2026-90330unscored—7.3—HID: logitech-hidpp: Fix FF device cleanup on init failure
CVE-2026-90335unscored—7.3—tty: skip cdev_del() when no cdev is registered
CVE-2026-90336unscored—7.3—serial: core: clear freed pointers on uart_register_driver() failure
CVE-2026-90337unscored—7.3—serial: core: do fallible allocations before the console can be registered
CVE-2026-90345unscored—7.3—wifi: brcmfmac: fix P2P action frame handling without device vif
CVE-2026-90346unscored—7.3—wifi: nl80211: clean up color-change beacon data on errors
CVE-2026-90355unscored—7.3—wifi: mt76: mt7996: clear stale link state on full reset
CVE-2026-90359unscored—7.3—bpf: Reject >8 byte return values on return-reading trampoline paths
CVE-2026-90365unscored—7.3—wifi: mt76: cancel reset and rc work on device unregister
CVE-2026-90409unscored—7.3—drm/panthor: Add vm_bind region with kbo range overlap check
CVE-2026-90412unscored—7.3—nvmet: fix return status of RMI log page on allocation failure
CVE-2026-90417unscored—7.3—RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry()
CVE-2026-90421unscored—7.3—PCI: Fix UAF when probe runs concurrent to dyn ID removal
CVE-2026-92480unscored—7.3—scsi: ufs: core: Validate string descriptors
CVE-2026-92482unscored—7.3—pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip
CVE-2026-92503unscored—7.3—ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find()
CVE-2026-93044unscored—7.3—bpf: Disallow interpreter fallback for arena-related insns
CVE-2026-93047unscored—7.3—drm/v3d: Associate BOs with every job that accesses them
CVE-2026-93081unscored—7.3—firmware: arm_scmi: Fix SCMI device destroy lifetimes
CVE-2026-93096unscored—7.3—cxl/features: Serialize multi-part Get/Set Feature transfers
CVE-2026-93099unscored—7.3—fs/resctrl: Fix UAF from worker threads when domains are removed
CVE-2026-93104unscored—7.3—RDMA/rvt: Return NULL after port allocation failure
CVE-2026-93129unscored—7.3—platform/x86: dell-wmi-base: Fix handling of ultra performance key
CVE-2026-93135unscored—7.3—bpf: Reject programs with inlined helpers if JIT is not available
CVE-2026-93164unscored—7.3—uprobes/x86: Move optimized uprobe from nop5 to nop10
CVE-2026-93168unscored—7.3—dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout
CVE-2026-93179unscored—7.3—drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read
CVE-2026-93181unscored—7.3—perf/x86/intel/uncore: Fix uncore_box ref/unref ordering
CVE-2026-93216unscored—7.3—mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()
CVE-2026-93248unscored—7.3—drm/xe: don't WARN on kernel job timeout when device already wedged
CVE-2026-93251unscored—7.3—ACPI: bus: Introduce acpi_bus_get_primary_device()
CVE-2026-93270unscored—7.3—bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn
CVE-2026-93272unscored—7.3—remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3
CVE-2026-97526unscored—7.3—s390/pai: Support CPU hotplug for PMU PAI
CVE-2026-97532unscored—7.3—scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path
CVE-2026-97537unscored—7.3—scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking
CVE-2026-97538unscored—7.3—hwmon: (asus_rog_ryujin) Validate HID report lengths
CVE-2026-97539unscored—7.3—usb: xusbatm: don't rely on id table pointer arithmetic
CVE-2026-97540unscored—7.3—net: usb: pegasus: don't rely on id table pointer arithmetic
CVE-2026-97541unscored—7.3—wifi: ath9k_htc: don't store usb_device_id
CVE-2026-97554unscored—7.3—smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()
CVE-2026-97561unscored—7.3—smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid
CVE-2026-97563unscored—7.3—smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()
CVE-2026-97928unscored—7.3—drm/amdgpu: skip the VMID 0 flush for VRAM
CVE-2026-97933unscored—7.3—tracing: Take trace_array reference when opening a tracer options file
CVE-2026-97951unscored—7.3—scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands
CVE-2026-97988unscored—7.3—vhost: invalidate vring access on IOTLB transitions
CVE-2026-97989unscored—7.3—vduse: validate virtqueue alignment
CVE-2026-97997unscored—7.3—virtio_ring: fix stale descriptor flags after a failed packed add
CVE-2026-98004unscored—7.3—iommu/riscv: Serialize command queue publishing
CVE-2026-98019unscored—7.3—bpf: mark a NULL call argument precise
CVE-2026-98032unscored—7.3—tracing: Fix subbuf resize races with trace_pipe_raw readers
CVE-2026-98033unscored—7.3—bpf: Preserve inner map identity in callback frames
CVE-2026-98034unscored—7.3—bpf: Mark NULL kptr stores precise
CVE-2026-98038unscored—7.3—bpf: Keep refcount_acquire nullable for borrowed RCU kptrs
CVE-2026-98043unscored—7.3—bpf: Don't infer non-NULL from a pointer with an unbounded offset
CVE-2026-98048unscored—7.3—bpf: don't rewrite bpf_fastcall patterns entered by a jump
CVE-2026-98049unscored—7.3—bpf: zero extend the result of an arena 32-bit cmpxchg
CVE-2026-98057unscored—7.3—ring-buffer: Add checking nr_subbufs to persistent ring buffer validation
CVE-2026-98058unscored—7.3—bpf: Mark syscall helpers as sleepable
CVE-2026-98084unscored—7.3—bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks
CVE-2026-98085unscored—7.3—bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge
CVE-2026-98099unscored—7.3—ipv6: mcast: use rcu_assign_pointer() for __rcu list updates
CVE-2026-98106unscored—7.3—drm/pagemap: Prevent double migration of device pages
CVE-2026-98118unscored—7.3—netfs: Fix readahead synchronisation issues by loading all folios upfront
CVE-2026-98124unscored—7.3—smb/client: invalidate fscache for fallocate range operations
CVE-2026-98125unscored—7.3—smb/client: fix stale page cache in insert/collapse range
CVE-2026-98131unscored—7.3—net: stmmac: fix dma mapping leak in stmmac_tso_xmit()
CVE-2026-98134unscored—7.3—bpf: check_cond_jmp_op(): properly infer if register is null
CVE-2026-98147unscored—7.3—printk: Don't WARN on kthread_run failure.
CVE-2026-98153unscored—7.3—nvme: fix racy access to FDP placement id array
CVE-2026-98161unscored—7.3—nvdimm: pmem: keep PREFLUSH before data writes
CVE-2026-98162unscored—7.3—smb/server: fix tree connection leak in smb2_tree_connect()

Sources

The CVE records of the kernel CVE team, which are updated as fixes are backported; scores from the CVE record where one is published.

Checked 2026-09-27 12:54 UTC rawnix