| audit.rawnix.org | kernel | rawnix.org |
No known CVE is fixed in a later 6.18 release.
None.
Affects 6.18.54, and no 6.18 release has the fix yet; no 6.18 update helps.
| CVE | Severity | CVSS | Fixed in mainline | Published | Title |
|---|---|---|---|---|---|
| CVE-2026-72493 | CRITICAL | 9.9 | 7.2 | — | net: serialize netif_running() check in enqueue_to_backlog() |
| CVE-2026-31501 | CRITICAL | 9.8 | 7.0 | — | net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path |
| CVE-2026-43414 | CRITICAL | 9.8 | 7.0 | — | scsi: qla2xxx: Completely fix fcport double free |
| CVE-2026-64067 | CRITICAL | 9.8 | 7.1 | — | netfs: Fix missing barriers when accessing stream->subrequests locklessly |
| CVE-2026-64160 | CRITICAL | 9.8 | 7.1 | — | netfs: Fix potential for tearing in ->remote_i_size and ->zero_point |
| CVE-2026-72064 | CRITICAL | 9.8 | 7.2 | — | net: mana: Sync page pool RX frags for CPU |
| CVE-2026-72477 | CRITICAL | 9.8 | 7.2 | — | fs/ntfs3: call _ntfs_bad_inode() when failing to rename |
| CVE-2026-74350 | CRITICAL | 9.8 | 7.2 | — | ocfs2: validate fast symlink target during inode read |
| CVE-2026-74723 | CRITICAL | 9.8 | 7.2 | — | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74752 | CRITICAL | 9.8 | 7.2 | — | sctp: validate cookie AUTH state before use |
| CVE-2026-80634 | CRITICAL | 9.8 | 7.2 | — | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
| CVE-2026-80668 | CRITICAL | 9.8 | 7.2 | — | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
| CVE-2026-89610 | CRITICAL | 9.8 | 7.3 | — | ntfs: verify run length exceeding volume boundary |
| CVE-2026-89611 | CRITICAL | 9.8 | 7.3 | — | ntfs: validate non-resident attribute offsets |
| CVE-2026-89654 | CRITICAL | 9.8 | 7.3 | — | ceph: fix UAF in check_new_map() on session freed during unlock |
| CVE-2026-89788 | CRITICAL | 9.8 | 7.3 | — | ksmbd: fix tree connection use-after-free in smb2_tree_connect() |
| CVE-2026-90104 | CRITICAL | 9.8 | 7.3 | — | NFSv4.1: zero referring call lists before decoding |
| CVE-2026-72329 | CRITICAL | 9.3 | 7.2 | — | net/liquidio: drop cached VF pci_dev LUT |
| CVE-2026-74568 | CRITICAL | 9.3 | 7.2 | — | KVM: arm64: vgic: Fix race between LPI release and re-registration |
| CVE-2026-80693 | CRITICAL | 9.3 | 7.2 | — | idpf: bound interrupt-vector register fill to the allocated array |
| CVE-2026-89537 | CRITICAL | 9.1 | 7.3 | — | SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 |
| CVE-2026-63941 | HIGH | 8.8 | 7.1 | — | KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor |
| CVE-2026-64117 | HIGH | 8.8 | 7.1 | — | wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb |
| CVE-2026-68470 | HIGH | 8.8 | 7.2 | — | wifi: mac80211: validate extension-frame layout before RX |
| CVE-2026-72380 | HIGH | 8.8 | 7.2 | — | xen/pvcalls: bound backend response req_id before indexing rsp[] |
| CVE-2026-72423 | HIGH | 8.8 | 7.2 | — | bpf: Guard conntrack opts error writes |
| CVE-2026-72497 | HIGH | 8.8 | 7.2 | — | RDMA/bnxt_re: Add a max slot check for SQ |
| CVE-2026-72499 | HIGH | 8.8 | 7.2 | — | RDMA/bnxt_re: Free CQ toggle page after firmware teardown |
| CVE-2026-74277 | HIGH | 8.8 | 7.2 | — | iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path |
| CVE-2026-74527 | HIGH | 8.8 | 7.2 | — | octeontx2-af: Block VFs from clobbering special CGX PKIND state |
| CVE-2026-74530 | HIGH | 8.8 | 7.2 | — | Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback |
| CVE-2026-74533 | HIGH | 8.8 | 7.2 | — | Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero |
| CVE-2026-74561 | HIGH | 8.8 | 7.2 | — | nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush |
| CVE-2026-74562 | HIGH | 8.8 | 7.2 | — | nexthop: take nh->lock for f6i_list walks in replace check and notify |
| CVE-2026-80692 | HIGH | 8.8 | 7.2 | — | Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks |
| CVE-2026-80734 | HIGH | 8.8 | 7.2 | — | btrfs: initialize inode mapping flags for cached inodes |
| CVE-2026-89513 | HIGH | 8.8 | 7.3 | — | RISC-V: KVM: Fix PMU event info array size overflow |
| CVE-2026-89534 | HIGH | 8.8 | 7.3 | — | svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails |
| CVE-2026-89601 | HIGH | 8.8 | 7.3 | — | ext2: Fix lost inode updates for IS_SYNC inodes |
| CVE-2026-89907 | HIGH | 8.8 | 7.3 | — | LoongArch: KVM: Validate MSI data before routing it to EIOINTC |
| CVE-2026-90162 | HIGH | 8.8 | 7.3 | — | ksmbd: defer publishing granted locks to prevent UAF/double-free race |
| CVE-2026-90256 | HIGH | 8.8 | 7.3 | — | Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind |
| CVE-2026-90380 | HIGH | 8.8 | 7.3 | — | wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete |
| CVE-2026-90381 | HIGH | 8.8 | 7.3 | — | wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() |
| CVE-2026-93189 | HIGH | 8.8 | 7.3 | — | HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
| CVE-2026-98115 | HIGH | 8.8 | 7.3 | — | ksmbd: safely drain sessions during logoff |
| CVE-2026-64400 | HIGH | 8.6 | 7.2 | — | ksmbd: prevent path traversal bypass by restricting caseless retry |
| CVE-2026-53091 | HIGH | 8.4 | 7.1 | — | net: pull headers in qdisc_pkt_len_segs_init() |
| CVE-2026-90347 | HIGH | 8.4 | 7.3 | — | arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry |
| CVE-2026-89632 | HIGH | 8.2 | — | — | smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr() |
| CVE-2026-31771 | HIGH | 8.1 | 7.0 | — | Bluetooth: hci_event: move wake reason storage into validated event handlers |
| CVE-2026-89709 | HIGH | 8.1 | 7.3 | — | lockd, nfsd: RCU-protect nlmsvc_ops dispatch |
| CVE-2026-90301 | HIGH | 8.1 | 7.3 | — | ocfs2: o2hb: quiesce negotiate handlers and timeout work |
| CVE-2026-93221 | HIGH | 8.1 | 7.3 | — | nfsd: convert nfsd_net boolean flags to unsigned long flags word |
| CVE-2026-93282 | HIGH | 8.1 | 7.3 | — | ksmbd: fix maximum allowed access checks |
| CVE-2026-80747 | HIGH | 8.0 | 7.2 | — | drm/amdkfd: Add bounds check for CRAT subtype length |
| CVE-2025-71074 | HIGH | 7.8 | 6.19 | — | functionfs: fix the open/removal races |
| CVE-2026-45991 | HIGH | 7.8 | 7.1 | — | udf: fix partition descriptor append bookkeeping |
| CVE-2026-46210 | HIGH | 7.8 | 7.1 | — | media: iris: fix use-after-free of fmt_src during MBPF check |
| CVE-2026-46311 | HIGH | 7.8 | 7.1 | — | drm/amdgpu/userq: fix access to stale wptr mapping |
| CVE-2026-46330 | HIGH | 7.8 | 7.0 | — | Revert "net/smc: Introduce TCP ULP support" |
| CVE-2026-53009 | HIGH | 7.8 | 7.1 | — | ice: fix double-free of tx_buf skb |
| CVE-2026-53024 | HIGH | 7.8 | 7.1 | — | greybus: raw: fix use-after-free if write is called after disconnect |
| CVE-2026-53025 | HIGH | 7.8 | 7.1 | — | greybus: raw: fix use-after-free on cdev close |
| CVE-2026-53401 | HIGH | 7.8 | 7.2 | — | fbdev: omap2: fix use-after-free in omapfb_mmap |
| CVE-2026-63858 | HIGH | 7.8 | 7.1 | — | netfilter: nf_tables: add hook transactions for device deletions |
| CVE-2026-63879 | HIGH | 7.8 | 7.1 | — | drm/amdgpu: fix amdgpu_hmm_range_get_pages |
| CVE-2026-63977 | HIGH | 7.8 | 7.1 | — | dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work |
| CVE-2026-64057 | HIGH | 7.8 | 7.1 | — | afs: Fix the locking used by afs_get_link() |
| CVE-2026-64123 | HIGH | 7.8 | 7.1 | — | net: hsr: defer node table free until after RCU readers |
| CVE-2026-64388 | HIGH | 7.8 | 7.2 | — | smb/client: fix chown/chgrp with SMB3 POSIX Extensions |
| CVE-2026-68295 | HIGH | 7.8 | 7.2 | — | LoongArch: BPF: Zero-extend signed ALU32 div/mod results |
| CVE-2026-68305 | HIGH | 7.8 | 7.2 | — | drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers |
| CVE-2026-68323 | HIGH | 7.8 | 7.2 | — | tipc: serialize udp bearer replicast list updates |
| CVE-2026-68382 | HIGH | 7.8 | 7.2 | — | drm/xe/guc: Hold device ref until queue teardown completes |
| CVE-2026-68383 | HIGH | 7.8 | 7.2 | — | drm/xe/guc: Keep scheduler timeline name alive |
| CVE-2026-68399 | HIGH | 7.8 | 7.2 | — | bpf: Fix UAF in sock clone early bailouts |
| CVE-2026-68404 | HIGH | 7.8 | 7.2 | — | wifi: cfg80211: use wiphy work for socket owner autodisconnect |
| CVE-2026-72331 | HIGH | 7.8 | 7.2 | — | accel/amdxdna: Fix VMA access race |
| CVE-2026-72345 | HIGH | 7.8 | 7.2 | — | net/mlx5: LAG, Fix off-by-one in single-FDB error rollback |
| CVE-2026-72404 | HIGH | 7.8 | 7.2 | — | tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy() |
| CVE-2026-72454 | HIGH | 7.8 | 7.2 | — | i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev() |
| CVE-2026-74260 | HIGH | 7.8 | 7.2 | — | netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them |
| CVE-2026-74314 | HIGH | 7.8 | 7.2 | — | bpf: Cancel special fields on map value recycle |
| CVE-2026-74317 | HIGH | 7.8 | 7.2 | — | ixgbe: do not configure xps for XDP queues |
| CVE-2026-74338 | HIGH | 7.8 | 7.2 | — | bpf: Reject sleepable BPF_LSM_CGROUP programs at load time |
| CVE-2026-74354 | HIGH | 7.8 | 7.2 | — | bpf: Take mmap_lock in zap_pages() |
| CVE-2026-74367 | HIGH | 7.8 | 7.2 | — | wifi: ath12k: fix inconsistent arvif state in vdev_create error paths |
| CVE-2026-74449 | HIGH | 7.8 | 7.2 | — | drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport |
| CVE-2026-74529 | HIGH | 7.8 | 7.2 | — | Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback |
| CVE-2026-74544 | HIGH | 7.8 | 7.2 | — | net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds |
| CVE-2026-74605 | HIGH | 7.8 | 7.2 | — | eventfs: Use children field for rcu head and add memory barriers |
| CVE-2026-74715 | HIGH | 7.8 | 7.2 | — | bpf: Fix netns reference imbalance in conntrack kfuncs |
| CVE-2026-74721 | HIGH | 7.8 | 7.2 | — | accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() |
| CVE-2026-74733 | HIGH | 7.8 | 7.2 | — | gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock |
| CVE-2026-74747 | HIGH | 7.8 | 7.2 | — | ipvs: revalidate ihl to prevent out-of-bounds access |
| CVE-2026-80579 | HIGH | 7.8 | 7.2 | — | fbdev: clear fb_info->mode before deleting a videomode |
| CVE-2026-80580 | HIGH | 7.8 | 7.2 | — | fbdev: bound mode sysfs output to the sysfs buffer |
| CVE-2026-89584 | HIGH | 7.8 | 7.3 | — | block: validate user space vectors during extraction |
| CVE-2026-89755 | HIGH | 7.8 | 7.3 | — | mm/migrate_device: clear stale mapping after freeing swapcache |
| CVE-2026-89764 | HIGH | 7.8 | 7.3 | — | rust: devres: fix race between concurrent revokers |
| CVE-2026-89793 | HIGH | 7.8 | 7.3 | — | ublk: clear VM_MAYWRITE on read-only ublk char device mmap |
| CVE-2026-89805 | HIGH | 7.8 | 7.3 | — | drm/pagemap: Fix folio allocation fallback and use-after-put |
| CVE-2026-90093 | HIGH | 7.8 | 7.3 | — | Bluetooth: L2CAP: access chan->conn safely in get/setsockopt |
| CVE-2026-90111 | HIGH | 7.8 | 7.3 | — | ip6mr: do not clone dst in ip6mr_cache_report() |
| CVE-2026-90142 | HIGH | 7.8 | 7.3 | — | virtio_net: Fix resize of the RX ring |
| CVE-2026-90177 | HIGH | 7.8 | 7.3 | — | bpf: Check pointer type for all atomic RMW paths |
| CVE-2026-90217 | HIGH | 7.8 | 7.3 | — | bpf: Compare iterator types during state pruning |
| CVE-2026-90237 | HIGH | 7.8 | 7.3 | — | netfilter: nft_ct: move custom expectation support to helper |
| CVE-2026-90289 | HIGH | 7.8 | 7.3 | — | drm/amd/display: Resize MST HDCP per-connector arrays to 32 |
| CVE-2026-90317 | HIGH | 7.8 | 7.3 | — | bpf: Invalidate RCU pointers after final spin unlock |
| CVE-2026-90320 | HIGH | 7.8 | 7.3 | — | ocfs2: validate external xattr entries when reading metadata |
| CVE-2026-90321 | HIGH | 7.8 | 7.3 | — | ocfs2: validate inline xattrs during inode block validation |
| CVE-2026-92485 | HIGH | 7.8 | 7.3 | — | bpf: Fix WARNING in bpf_tracing_link_release |
| CVE-2026-93105 | HIGH | 7.8 | 7.3 | — | esp: do not unref managed frag pages in esp_ssg_unref() |
| CVE-2026-93122 | HIGH | 7.8 | 7.3 | — | usb: gadget: uac: validate rate list length before storing |
| CVE-2026-93125 | HIGH | 7.8 | 7.3 | — | bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max |
| CVE-2026-93144 | HIGH | 7.8 | 7.3 | — | bpf: Reject writes through untrusted BTF pointers |
| CVE-2026-93148 | HIGH | 7.8 | 7.3 | — | bpf: Reject MEM_ALLOC BTF accesses past object bounds |
| CVE-2026-93175 | HIGH | 7.8 | 7.3 | — | drm/amd/display: Fix dangling pointer in CRTC reset function |
| CVE-2026-93201 | HIGH | 7.8 | 7.3 | — | dm-pcache: validate seg_id fields from persistent memory |
| CVE-2026-90408 | HIGH | 7.7 | 7.3 | — | wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event() |
| CVE-2026-52956 | HIGH | 7.5 | 7.1 | — | libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() |
| CVE-2026-52960 | HIGH | 7.5 | 7.1 | — | ceph: put folios not suitable for writeback |
| CVE-2026-64020 | HIGH | 7.5 | 7.1 | — | nvme-pci: fix dma_vecs leak on p2p memory |
| CVE-2026-74374 | HIGH | 7.5 | 7.2 | — | md/raid1,raid10: fix error-path detection with md_cloned_bio() |
| CVE-2026-74745 | HIGH | 7.5 | 7.2 | — | eth: bnxt: avoid deadlock when canceling IRQ affinity notifier |
| CVE-2026-74750 | HIGH | 7.5 | 7.2 | — | ovpn: defer key slot crypto freeing to workqueue |
| CVE-2026-80631 | HIGH | 7.5 | 7.2 | — | btrfs: lzo: reject compressed segment that overflows the compressed input |
| CVE-2026-90234 | HIGH | 7.5 | 7.3 | — | NFS: Return a delegation the client fails to record |
| CVE-2026-90427 | HIGH | 7.4 | 7.3 | — | iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() |
| CVE-2026-93260 | HIGH | 7.4 | 7.3 | — | powerpc/xive: propagate IPI init errors to prevent use-after-free |
| CVE-2026-74419 | HIGH | 7.3 | 7.2 | — | accel/amdxdna: Adjust size for copy_to_user() |
| CVE-2026-80738 | HIGH | 7.3 | 7.2 | — | bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie |
| CVE-2026-43042 | HIGH | 7.1 | 7.0 | — | mpls: add seqcount to protect the platform_label{,s} pair |
| CVE-2026-52988 | HIGH | 7.1 | 7.1 | — | netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase |
| CVE-2026-68103 | HIGH | 7.1 | 7.2 | — | drm/amdgpu: reject mapping a reserved doorbell to a new queue |
| CVE-2026-68447 | HIGH | 7.1 | 7.2 | — | drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size |
| CVE-2026-72397 | HIGH | 7.1 | 7.2 | — | hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid() |
| CVE-2026-72440 | HIGH | 7.1 | 7.2 | — | md/raid1: fix writes_pending and barrier reference leaks on write failures |
| CVE-2026-74713 | HIGH | 7.1 | 7.2 | — | vhost_iotlb: bound map allocation in add_range |
| CVE-2026-89705 | HIGH | 7.1 | 7.3 | — | nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths |
| CVE-2026-90174 | HIGH | 7.1 | 7.3 | — | ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user() |
| CVE-2026-90401 | HIGH | 7.1 | 7.3 | — | md: remove REQ_NOWAIT support from raid1/10/456 |
| CVE-2026-93116 | HIGH | 7.0 | 7.3 | — | platform/x86: asus-wmi: fix resource leaks on probe failure |
| CVE-2026-93176 | HIGH | 7.0 | 7.3 | — | drm/amd/display: Fix dangling pointer in plane reset function |
| CVE-2021-47645 | MEDIUM | 5.5 | — | — | media: staging: media: zoran: calculate the right buffer number for zoran_reap_stat_com |
| CVE-2025-71306 | unscored | — | 7.0 | — | ima: Fix stack-out-of-bounds in is_bprm_creds_for_exec() |
| CVE-2025-71308 | unscored | — | 7.0 | — | accel/amdxdna: Fix potential NULL pointer dereference in context cleanup |
| CVE-2025-71313 | unscored | — | 7.0 | — | PCI: endpoint: Add missing NULL check for alloc_workqueue() |
| CVE-2026-100072 | unscored | — | 7.3 | — | ACPI: platform: Use acpi_bus_get_primary_device() |
| CVE-2026-100073 | unscored | — | 7.3 | — | ext4: fix transaction overflow during writeback |
| CVE-2026-23328 | unscored | — | 7.0 | — | accel/amdxdna: Fix NULL pointer dereference of mgmt_chann |
| CVE-2026-23374 | unscored | — | 7.0 | — | blktrace: fix __this_cpu_read/write in preemptible context |
| CVE-2026-23377 | unscored | — | 7.0 | — | ice: change XDP RxQ frag_size from DMA write length to xdp.frame_sz |
| CVE-2026-31710 | unscored | — | 7.1 | — | smb: client: fix dir separator in SMB1 UNIX mounts |
| CVE-2026-31777 | unscored | — | 7.0 | — | ALSA: ctxfi: Check the error for index mapping |
| CVE-2026-43022 | unscored | — | 7.0 | — | Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists |
| CVE-2026-43045 | unscored | — | 7.0 | — | mshv: Fix error handling in mshv_region_pin |
| CVE-2026-43053 | unscored | — | 7.0 | — | xfs: close crash window in attr dabtree inactivation |
| CVE-2026-43095 | unscored | — | 7.0 | — | ASoC: SDCA: Fix errors in IRQ cleanup |
| CVE-2026-43115 | unscored | — | 7.0 | — | srcu: Use irq_work to start GP in tiny SRCU |
| CVE-2026-43174 | unscored | — | 7.0 | — | io_uring/zcrx: fix post open error handling |
| CVE-2026-43191 | unscored | — | 7.0 | — | drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 |
| CVE-2026-43204 | unscored | — | 7.0 | — | ASoC: qcom: q6asm: drop DSP responses for closed data streams |
| CVE-2026-43228 | unscored | — | 7.0 | — | hfs: Replace BUG_ON with error handling for CNID count checks |
| CVE-2026-43299 | unscored | — | 7.0 | — | btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() |
| CVE-2026-43308 | unscored | — | 7.0 | — | btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() |
| CVE-2026-43310 | unscored | — | 7.0 | — | media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC |
| CVE-2026-43311 | unscored | — | 7.0 | — | soc/tegra: pmc: Fix unsafe generic_handle_irq() call |
| CVE-2026-43326 | unscored | — | 7.0 | — | sched_ext: Fix SCX_KICK_WAIT deadlock by deferring wait to balance callback |
| CVE-2026-43443 | unscored | — | 7.0 | — | ASoC: amd: acp-mach-common: Add missing error check for clock acquisition |
| CVE-2026-45961 | unscored | — | 7.0 | — | gfs2: fix memory leaks in gfs2_fill_super error path |
| CVE-2026-46008 | unscored | — | 7.1 | — | mm/damon/core: fix damos_walk() vs kdamond_fn() exit race |
| CVE-2026-46017 | unscored | — | 7.1 | — | mm: fix deferred split queue races during migration |
| CVE-2026-46032 | unscored | — | 7.1 | — | KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT |
| CVE-2026-46147 | unscored | — | 7.1 | — | KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() |
| CVE-2026-46153 | unscored | — | 7.1 | — | 8021q: delete cleared egress QoS mappings |
| CVE-2026-46245 | unscored | — | 7.0 | — | drm/amd/display: Fix dc_link NULL handling in HPD init |
| CVE-2026-46298 | unscored | — | 7.1 | — | pseries/papr-hvpipe: Fix race with interrupt handler |
| CVE-2026-46302 | unscored | — | 7.1 | — | selinux: allow multiple opens of /sys/fs/selinux/policy |
| CVE-2026-52949 | unscored | — | 7.1 | — | drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure |
| CVE-2026-52965 | unscored | — | 7.1 | — | drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure |
| CVE-2026-53007 | unscored | — | 7.1 | — | ice: fix potential NULL pointer deref in error path of ice_set_ringparam() |
| CVE-2026-53008 | unscored | — | 7.1 | — | ice: fix race condition in TX timestamp ring cleanup |
| CVE-2026-53017 | unscored | — | 7.1 | — | f2fs: fix data loss caused by incorrect use of nat_entry flag |
| CVE-2026-53106 | unscored | — | 7.1 | — | bpf: Do not allow deleting local storage in NMI |
| CVE-2026-53108 | unscored | — | 7.1 | — | powerpc/64s: Fix unmap race with PMD migration entries |
| CVE-2026-53124 | unscored | — | 7.1 | — | ublk: reset per-IO canceled flag on each fetch |
| CVE-2026-53222 | unscored | — | 7.1 | — | ptp: ocp: fix resource freeing order |
| CVE-2026-53257 | unscored | — | 7.1 | — | wifi: cfg80211: enforce HE/EHT cap/oper consistency |
| CVE-2026-53285 | unscored | — | 7.1 | — | drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED |
| CVE-2026-53292 | unscored | — | 7.1 | — | net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind |
| CVE-2026-53308 | unscored | — | 7.1 | — | power: supply: max77705: Free allocated workqueue and fix removal order |
| CVE-2026-63811 | unscored | — | 7.2 | — | f2fs: read COW data with the original inode during atomic write |
| CVE-2026-63983 | unscored | — | 7.1 | — | net/sched: fix packet loop on netem when duplicate is on |
| CVE-2026-64013 | unscored | — | 7.1 | — | ACPI: button: Fix ACPI GPE handler leak during removal |
| CVE-2026-64019 | unscored | — | 7.1 | — | nvme-pci: fix dma mapping leak on data setup error |
| CVE-2026-64040 | unscored | — | 7.1 | — | cachefiles: Fix error return when vfs_mkdir() fails |
| CVE-2026-64079 | unscored | — | 7.1 | — | netfilter: x_tables: allocate hook ops while under mutex |
| CVE-2026-64146 | unscored | — | 7.1 | — | erofs: fix metabuf leak in inode xattr initialization |
| CVE-2026-64154 | unscored | — | 7.1 | — | drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() |
| CVE-2026-64159 | unscored | — | 7.1 | — | netfs: Fix zeropoint update where i_size > remote_i_size |
| CVE-2026-64212 | unscored | — | 7.1 | — | wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it |
| CVE-2026-64283 | unscored | — | 7.2 | — | KVM: guest_memfd: Treat memslot binding offset+size as unsigned values |
| CVE-2026-64325 | unscored | — | 7.2 | — | wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon |
| CVE-2026-64341 | unscored | — | 7.2 | — | USB: iowarrior: fix use-after-free on disconnect race |
| CVE-2026-68086 | unscored | — | — | — | mm/khugepaged: write all dirty file folios when collapsing |
| CVE-2026-68105 | unscored | — | 7.2 | — | drm/amdgpu: Fix kernel panic during driver load failure |
| CVE-2026-68242 | unscored | — | 7.2 | — | drm/i915/gt: Fix NULL deref on sched_engine alloc failure |
| CVE-2026-68291 | unscored | — | 7.2 | — | idpf: fix max_vport related crash on allocation error during init |
| CVE-2026-68312 | unscored | — | 7.2 | — | cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths |
| CVE-2026-68375 | unscored | — | 7.2 | — | bnxt_en: Handle partially initialized auxiliary devices |
| CVE-2026-68436 | unscored | — | 7.2 | — | drm/amd/display: use kvzalloc to allocate struct dc |
| CVE-2026-68441 | unscored | — | 7.2 | — | net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains |
| CVE-2026-72031 | unscored | — | 7.2 | — | ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD |
| CVE-2026-72091 | unscored | — | 7.2 | — | accel/amdxdna: reject user command submission without a command BO |
| CVE-2026-72337 | unscored | — | 7.2 | — | Bluetooth: 6lowpan: avoid untracked enable work |
| CVE-2026-72370 | unscored | — | 7.2 | — | iomap: release pages on atomic dio size mismatch |
| CVE-2026-72377 | unscored | — | 7.2 | — | afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints |
| CVE-2026-72388 | unscored | — | 7.2 | — | drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock |
| CVE-2026-72439 | unscored | — | 7.2 | — | md/raid10: fix writes_pending leak on write request failures |
| CVE-2026-74272 | unscored | — | 7.2 | — | cxl/region: Resolve region deletion races |
| CVE-2026-74273 | unscored | — | 7.2 | — | cxl/region: Block region delete during region creation |
| CVE-2026-74307 | unscored | — | 7.2 | — | ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT |
| CVE-2026-74336 | unscored | — | 7.2 | — | wifi: mac80211: bound S1G TIM PVB walk to the TIM element |
| CVE-2026-74342 | unscored | — | 7.2 | — | kernfs: link kn to its parent before the LSM init hook |
| CVE-2026-74368 | unscored | — | 7.2 | — | wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic() |
| CVE-2026-74373 | unscored | — | 7.2 | — | md/raid1,raid10: fix bio accounting for split md cloned bios |
| CVE-2026-74375 | unscored | — | 7.2 | — | md/raid1,raid10: fix deadlock in read error recovery path |
| CVE-2026-74466 | unscored | — | 7.2 | — | s390/zcrypt: Close speculative mem read possibility |
| CVE-2026-74542 | unscored | — | 7.2 | — | netfs: Fix folio_queue ENOMEM in writeback by adding a mempool |
| CVE-2026-74558 | unscored | — | 7.2 | — | xsk: reclaim invalid Tx descriptors in ZC batch path |
| CVE-2026-74571 | unscored | — | 7.2 | — | btrfs: skip global block reserve accounting for rescue mounts |
| CVE-2026-74716 | unscored | — | 7.2 | — | accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages() |
| CVE-2026-74729 | unscored | — | 7.2 | — | soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read |
| CVE-2026-74732 | unscored | — | 7.2 | — | drm/amd/display: Check for tg ops in dce110_set_avmute |
| CVE-2026-74754 | unscored | — | 7.2 | — | scsi: core: pair EH runtime PM get and put |
| CVE-2026-80524 | unscored | — | 7.2 | — | optee: ffa: Add NULL check in optee_ffa_lend_protmem |
| CVE-2026-80655 | unscored | — | 7.2 | — | soc: xilinx: Fix race condition in event registration |
| CVE-2026-80657 | unscored | — | 7.2 | — | accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer |
| CVE-2026-80698 | unscored | — | 7.2 | — | dmaengine: idxd: fix double free of wq, engine, and group structs |
| CVE-2026-80705 | unscored | — | 7.2 | — | drm/amd/display: check if dml21_add_phantom_plane() is successful |
| CVE-2026-80728 | unscored | — | 7.2 | — | Revert "drm/amdgpu: fix aperture mapping leak" |
| CVE-2026-80729 | unscored | — | 7.2 | — | mm/huge_memory: initialise workingset state before folio split |
| CVE-2026-80785 | unscored | — | 7.2 | — | fbdev: serialize mode sysfs access with lock_fb_info() |
| CVE-2026-80786 | unscored | — | 7.2 | — | fbdev: Wrap user-invoked calls to fb_set_var() in helper |
| CVE-2026-80866 | unscored | — | 7.2 | — | tipc: avoid busy looping in tipc_exit_net() |
| CVE-2026-80884 | unscored | — | 7.2 | — | ntb: Store original DMA address for future release |
| CVE-2026-80899 | unscored | — | 7.2 | — | erofs: remove fscache backend entirely |
| CVE-2026-89527 | unscored | — | 7.3 | — | svcrdma: Use svc_xprt_put to free listener on create failure |
| CVE-2026-89568 | unscored | — | 7.3 | — | kho: fix size calculation in kho_preserved_memory_reserve() |
| CVE-2026-89623 | unscored | — | — | — | HID: mcp2221: stop device IO before hid_hw_stop |
| CVE-2026-89642 | unscored | — | 7.3 | — | cifs: call pagecache_isize_extended() in cifs_setsize() when extending |
| CVE-2026-89673 | unscored | — | — | — | nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo |
| CVE-2026-89718 | unscored | — | 7.3 | — | zram: fix out-of-bounds access in writeback_store() |
| CVE-2026-89772 | unscored | — | 7.3 | — | btrfs: write-protect folios during data writeback |
| CVE-2026-89812 | unscored | — | 7.3 | — | drm/amdgpu: force complete the MES ring fences on reset |
| CVE-2026-89813 | unscored | — | 7.3 | — | drm/amdgpu: force complete the KIQ ring fences on reset |
| CVE-2026-89862 | unscored | — | 7.3 | — | scsi: qla2xxx: Fix BSG job leak on validate flash image error path |
| CVE-2026-89866 | unscored | — | 7.3 | — | media: chips-media: wave5: Resume device before setting EOS flag |
| CVE-2026-90040 | unscored | — | 7.3 | — | KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped |
| CVE-2026-90061 | unscored | — | 7.3 | — | netfilter: nf_tables: skip double clone set expressions on element insert |
| CVE-2026-90079 | unscored | — | 7.3 | — | octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init() |
| CVE-2026-90082 | unscored | — | 7.3 | — | net: mana: Cap MSI-X vectors to the device MSI-X table size |
| CVE-2026-90087 | unscored | — | 7.3 | — | Bluetooth: do not leak an hci_conn when a second LE connect is rejected |
| CVE-2026-90095 | unscored | — | 7.3 | — | fuse: Fix the condition to enable over-io-uring |
| CVE-2026-90098 | unscored | — | 7.3 | — | net: sparx5: fix sleep in atomic context in MAC table access |
| CVE-2026-90099 | unscored | — | 7.3 | — | net/sched: account classifier filter allocations to memcg |
| CVE-2026-90105 | unscored | — | 7.3 | — | vxlan: fix reading neigh ha |
| CVE-2026-90106 | unscored | — | 7.3 | — | net: bridge: arp/nd proxy: fix reading neigh ha |
| CVE-2026-90121 | unscored | — | 7.3 | — | irqchip/gic-v5: Clear per-CPU IRS data on teardown |
| CVE-2026-90144 | unscored | — | 7.3 | — | dpll: fix NULL deref in dpll_device_ops() during teardown race |
| CVE-2026-90154 | unscored | — | 7.3 | — | ksmbd: scope session state changes to bound connections |
| CVE-2026-90155 | unscored | — | 7.3 | — | ksmbd: detach blocked lock requests before freeing |
| CVE-2026-90156 | unscored | — | 7.3 | — | ksmbd: safely discard unregistered deferred locks |
| CVE-2026-90167 | unscored | — | 7.3 | — | ksmbd: serialize oplock close with pending break ownership |
| CVE-2026-90182 | unscored | — | 7.3 | — | blk-iocost: clear delay state when freeing policy data |
| CVE-2026-90183 | unscored | — | 7.3 | — | blk-iolatency: clear delay state when freeing policy data |
| CVE-2026-90206 | unscored | — | 7.3 | — | nvmet: fix max_qid race between configfs and controller allocation |
| CVE-2026-90208 | unscored | — | 7.3 | — | clocksource/drivers/samsung_pwm: Switch to raw_spinlock_t type |
| CVE-2026-90211 | unscored | — | 7.3 | — | bpf, s390: Clear fetch destination on faulting arena atomic |
| CVE-2026-90242 | unscored | — | 7.3 | — | iommu/vt-d: Fix iopf_refcount leak on RID domain replacement |
| CVE-2026-90261 | unscored | — | 7.3 | — | btrfs: zoned: flush active metadata block group at btree_writepages() start |
| CVE-2026-90263 | unscored | — | 7.3 | — | btrfs: check if root is readonly when setting posix acl |
| CVE-2026-90267 | unscored | — | 7.3 | — | scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails |
| CVE-2026-90273 | unscored | — | 7.3 | — | coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable |
| CVE-2026-90300 | unscored | — | 7.3 | — | bpf: Clear buf on error in __bpf_get_task_stack |
| CVE-2026-90311 | unscored | — | 7.3 | — | thermal: hwmon: Remove hwmon class device along with its parent |
| CVE-2026-90315 | unscored | — | 7.3 | — | PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers |
| CVE-2026-90323 | unscored | — | 7.3 | — | ublk: validate auto buf reg before taking uring_cmd |
| CVE-2026-90330 | unscored | — | 7.3 | — | HID: logitech-hidpp: Fix FF device cleanup on init failure |
| CVE-2026-90335 | unscored | — | 7.3 | — | tty: skip cdev_del() when no cdev is registered |
| CVE-2026-90336 | unscored | — | 7.3 | — | serial: core: clear freed pointers on uart_register_driver() failure |
| CVE-2026-90337 | unscored | — | 7.3 | — | serial: core: do fallible allocations before the console can be registered |
| CVE-2026-90345 | unscored | — | 7.3 | — | wifi: brcmfmac: fix P2P action frame handling without device vif |
| CVE-2026-90346 | unscored | — | 7.3 | — | wifi: nl80211: clean up color-change beacon data on errors |
| CVE-2026-90355 | unscored | — | 7.3 | — | wifi: mt76: mt7996: clear stale link state on full reset |
| CVE-2026-90359 | unscored | — | 7.3 | — | bpf: Reject >8 byte return values on return-reading trampoline paths |
| CVE-2026-90365 | unscored | — | 7.3 | — | wifi: mt76: cancel reset and rc work on device unregister |
| CVE-2026-90409 | unscored | — | 7.3 | — | drm/panthor: Add vm_bind region with kbo range overlap check |
| CVE-2026-90412 | unscored | — | 7.3 | — | nvmet: fix return status of RMI log page on allocation failure |
| CVE-2026-90417 | unscored | — | 7.3 | — | RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry() |
| CVE-2026-90421 | unscored | — | 7.3 | — | PCI: Fix UAF when probe runs concurrent to dyn ID removal |
| CVE-2026-92480 | unscored | — | 7.3 | — | scsi: ufs: core: Validate string descriptors |
| CVE-2026-92482 | unscored | — | 7.3 | — | pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip |
| CVE-2026-92503 | unscored | — | 7.3 | — | ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find() |
| CVE-2026-93044 | unscored | — | 7.3 | — | bpf: Disallow interpreter fallback for arena-related insns |
| CVE-2026-93047 | unscored | — | 7.3 | — | drm/v3d: Associate BOs with every job that accesses them |
| CVE-2026-93081 | unscored | — | 7.3 | — | firmware: arm_scmi: Fix SCMI device destroy lifetimes |
| CVE-2026-93096 | unscored | — | 7.3 | — | cxl/features: Serialize multi-part Get/Set Feature transfers |
| CVE-2026-93099 | unscored | — | 7.3 | — | fs/resctrl: Fix UAF from worker threads when domains are removed |
| CVE-2026-93104 | unscored | — | 7.3 | — | RDMA/rvt: Return NULL after port allocation failure |
| CVE-2026-93129 | unscored | — | 7.3 | — | platform/x86: dell-wmi-base: Fix handling of ultra performance key |
| CVE-2026-93135 | unscored | — | 7.3 | — | bpf: Reject programs with inlined helpers if JIT is not available |
| CVE-2026-93164 | unscored | — | 7.3 | — | uprobes/x86: Move optimized uprobe from nop5 to nop10 |
| CVE-2026-93168 | unscored | — | 7.3 | — | dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout |
| CVE-2026-93179 | unscored | — | 7.3 | — | drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read |
| CVE-2026-93181 | unscored | — | 7.3 | — | perf/x86/intel/uncore: Fix uncore_box ref/unref ordering |
| CVE-2026-93216 | unscored | — | 7.3 | — | mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() |
| CVE-2026-93248 | unscored | — | 7.3 | — | drm/xe: don't WARN on kernel job timeout when device already wedged |
| CVE-2026-93251 | unscored | — | 7.3 | — | ACPI: bus: Introduce acpi_bus_get_primary_device() |
| CVE-2026-93270 | unscored | — | 7.3 | — | bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn |
| CVE-2026-93272 | unscored | — | 7.3 | — | remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 |
| CVE-2026-97526 | unscored | — | 7.3 | — | s390/pai: Support CPU hotplug for PMU PAI |
| CVE-2026-97532 | unscored | — | 7.3 | — | scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path |
| CVE-2026-97537 | unscored | — | 7.3 | — | scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking |
| CVE-2026-97538 | unscored | — | 7.3 | — | hwmon: (asus_rog_ryujin) Validate HID report lengths |
| CVE-2026-97539 | unscored | — | 7.3 | — | usb: xusbatm: don't rely on id table pointer arithmetic |
| CVE-2026-97540 | unscored | — | 7.3 | — | net: usb: pegasus: don't rely on id table pointer arithmetic |
| CVE-2026-97541 | unscored | — | 7.3 | — | wifi: ath9k_htc: don't store usb_device_id |
| CVE-2026-97554 | unscored | — | 7.3 | — | smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr() |
| CVE-2026-97561 | unscored | — | 7.3 | — | smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid |
| CVE-2026-97563 | unscored | — | 7.3 | — | smb: client: reject out-of-bounds DataOffset in CIFSSMBRead() |
| CVE-2026-97928 | unscored | — | 7.3 | — | drm/amdgpu: skip the VMID 0 flush for VRAM |
| CVE-2026-97933 | unscored | — | 7.3 | — | tracing: Take trace_array reference when opening a tracer options file |
| CVE-2026-97951 | unscored | — | 7.3 | — | scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands |
| CVE-2026-97988 | unscored | — | 7.3 | — | vhost: invalidate vring access on IOTLB transitions |
| CVE-2026-97989 | unscored | — | 7.3 | — | vduse: validate virtqueue alignment |
| CVE-2026-97997 | unscored | — | 7.3 | — | virtio_ring: fix stale descriptor flags after a failed packed add |
| CVE-2026-98004 | unscored | — | 7.3 | — | iommu/riscv: Serialize command queue publishing |
| CVE-2026-98019 | unscored | — | 7.3 | — | bpf: mark a NULL call argument precise |
| CVE-2026-98032 | unscored | — | 7.3 | — | tracing: Fix subbuf resize races with trace_pipe_raw readers |
| CVE-2026-98033 | unscored | — | 7.3 | — | bpf: Preserve inner map identity in callback frames |
| CVE-2026-98034 | unscored | — | 7.3 | — | bpf: Mark NULL kptr stores precise |
| CVE-2026-98038 | unscored | — | 7.3 | — | bpf: Keep refcount_acquire nullable for borrowed RCU kptrs |
| CVE-2026-98043 | unscored | — | 7.3 | — | bpf: Don't infer non-NULL from a pointer with an unbounded offset |
| CVE-2026-98048 | unscored | — | 7.3 | — | bpf: don't rewrite bpf_fastcall patterns entered by a jump |
| CVE-2026-98049 | unscored | — | 7.3 | — | bpf: zero extend the result of an arena 32-bit cmpxchg |
| CVE-2026-98057 | unscored | — | 7.3 | — | ring-buffer: Add checking nr_subbufs to persistent ring buffer validation |
| CVE-2026-98058 | unscored | — | 7.3 | — | bpf: Mark syscall helpers as sleepable |
| CVE-2026-98084 | unscored | — | 7.3 | — | bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks |
| CVE-2026-98085 | unscored | — | 7.3 | — | bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge |
| CVE-2026-98099 | unscored | — | 7.3 | — | ipv6: mcast: use rcu_assign_pointer() for __rcu list updates |
| CVE-2026-98106 | unscored | — | 7.3 | — | drm/pagemap: Prevent double migration of device pages |
| CVE-2026-98118 | unscored | — | 7.3 | — | netfs: Fix readahead synchronisation issues by loading all folios upfront |
| CVE-2026-98124 | unscored | — | 7.3 | — | smb/client: invalidate fscache for fallocate range operations |
| CVE-2026-98125 | unscored | — | 7.3 | — | smb/client: fix stale page cache in insert/collapse range |
| CVE-2026-98131 | unscored | — | 7.3 | — | net: stmmac: fix dma mapping leak in stmmac_tso_xmit() |
| CVE-2026-98134 | unscored | — | 7.3 | — | bpf: check_cond_jmp_op(): properly infer if register is null |
| CVE-2026-98147 | unscored | — | 7.3 | — | printk: Don't WARN on kthread_run failure. |
| CVE-2026-98153 | unscored | — | 7.3 | — | nvme: fix racy access to FDP placement id array |
| CVE-2026-98161 | unscored | — | 7.3 | — | nvdimm: pmem: keep PREFLUSH before data writes |
| CVE-2026-98162 | unscored | — | 7.3 | — | smb/server: fix tree connection leak in smb2_tree_connect() |
The CVE records of the kernel CVE team, which are updated as fixes are backported; scores from the CVE record where one is published.
| Checked 2026-09-27 12:54 UTC | rawnix |