7.0

CVSS3.1

CVE-2026-43124 - pstore: ram_core: fix incorrect success return when vmap() fails

In the Linux kernel, the following vulnerability has been resolved: pstore: ram_core: fix incorrect success return when vmap() fails In persistent_ram_vmap(), vmap() may return NULL on failure. If offset is non-zero, adding offset_in_page(start) causes the function to return a non-NULL pointer e…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 5:45 a.m.

7.5

CVSS3.1

CVE-2026-43245 - ntfs: ->d_compare() must not block

In the Linux kernel, the following vulnerability has been resolved: ntfs: ->d_compare() must not block ... so don't use __getname() there. Switch it (and ntfs_d_hash(), while we are at it) to kmalloc(PATH_MAX, GFP_NOWAIT). Yes, ntfs_d_hash() almost certainly can do with smaller allocations, but…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:41 p.m.

8.8

CVSS3.1

CVE-2026-43110 - wifi: brcmfmac: validate bsscfg indices in IF events

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg indices in IF events brcmf_fweh_handle_if_event() validates the firmware-provided interface index before it touches drvr->iflist[], but it still uses the raw bsscfgidx field as an array index witho…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:40 p.m.

7.8

CVSS3.1

CVE-2026-43111 - HID: roccat: fix use-after-free in roccat_report_event

In the Linux kernel, the following vulnerability has been resolved: HID: roccat: fix use-after-free in roccat_report_event roccat_report_event() iterates over the device->readers list without holding the readers_lock. This allows a concurrent roccat_release() to remove and free a reader while it'…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:40 p.m.

5.5

CVSS3.1

CVE-2026-43240 - x86/kexec: add a sanity check on previous kernel's ima kexec buffer

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: add a sanity check on previous kernel's ima kexec buffer When the second-stage kernel is booted via kexec with a limiting command line such as "mem=<size>", the physical range that contains the carried over IMA measure…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4 a.m.

7.0

CVSS3.1

CVE-2026-43077 - crypto: algif_aead - Fix minimum RX size check for decryption

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for decryption The check for the minimum receive buffer size did not take the tag size into account during decryption. Fix this by adding the required extra length.

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 3:15 a.m.

7.0

CVSS3.1

CVE-2026-43163 - md/bitmap: fix GPF in write_page caused by resize race

In the Linux kernel, the following vulnerability has been resolved: md/bitmap: fix GPF in write_page caused by resize race A General Protection Fault occurs in write_page() during array resize: RIP: 0010:write_page+0x22b/0x3c0 [md_mod] This is a use-after-free race between bitmap_daemon_work() a…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 3:45 a.m.

7.5

CVSS3.1

CVE-2026-43203 - atm: fore200e: fix use-after-free in tasklets during device removal

In the Linux kernel, the following vulnerability has been resolved: atm: fore200e: fix use-after-free in tasklets during device removal When the PCA-200E or SBA-200E adapter is being detached, the fore200e is deallocated. However, the tx_tasklet or rx_tasklet may still be running or pending, lead…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:41 p.m.

0.0

CVE-2026-43149 - net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in uhdlc_memclean()

In the Linux kernel, the following vulnerability has been resolved: net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in uhdlc_memclean() The priv->rx_buffer and priv->tx_buffer are alloc'd together as contiguous buffers in uhdlc_init() but freed as two buffers in uhdlc_memclean(). Change the clean…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4 a.m.

5.5

CVSS3.1

CVE-2026-43097 - PCI: hv: Fix double ida_free in hv_pci_probe error path

In the Linux kernel, the following vulnerability has been resolved: PCI: hv: Fix double ida_free in hv_pci_probe error path If hv_pci_probe() fails after storing the domain number in hbus->bridge->domain_nr, there is a call to free this domain_nr via pci_bus_release_emul_domain_nr(), however, dur…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4:45 a.m.
Total resulsts: 349182
Page 102 of 34,919
Β« previous page Β» next page
Filters