7.5

CVSS3.1

CVE-2026-43031 - net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets

In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets When a TX packet spans multiple buffer descriptors (scatter-gather), axienet_free_tx_chain sums the per-BD actual length from descriptor status into a caller-providโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:46 a.m.

8.8

CVSS3.1

CVE-2026-43018 - Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt hci_conn lookup and field access must be covered by hdev lock in hci_le_remote_conn_param_req_evt, otherwise it's possible it is freed concurrently. Extโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:46 a.m.

7.8

CVSS3.1

CVE-2026-31742 - vt: discard stale unicode buffer on alt screen exit after resize

In the Linux kernel, the following vulnerability has been resolved: vt: discard stale unicode buffer on alt screen exit after resize When enter_alt_screen() saves vc_uni_lines into vc_saved_uni_lines and sets vc_uni_lines to NULL, a subsequent console resize via vc_do_resize() skips reallocating โ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.8

CVSS3.1

CVE-2026-31735 - iommupt: Fix short gather if the unmap goes into a large mapping

In the Linux kernel, the following vulnerability has been resolved: iommupt: Fix short gather if the unmap goes into a large mapping unmap has the odd behavior that it can unmap more than requested if the ending point lands within the middle of a large or contiguous IOPTE. In this case the gatheโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.8

CVSS3.1

CVE-2026-31773 - Bluetooth: SMP: derive legacy responder STK authentication from MITM state

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: derive legacy responder STK authentication from MITM state The legacy responder path in smp_random() currently labels the stored STK as authenticated whenever pending_sec_level is BT_SECURITY_HIGH. That reflects wโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

7.8

CVSS3.1

CVE-2026-31768 - iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() Add a DMA-safe buffer and use it for spi_read() instead of a stack memory. All SPI buffers must be DMA-safe. Since we only need up to 3 bytes, we just use a u8[] insteaโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

7.1

CVSS3.1

CVE-2026-31766 - drm/amdgpu: validate doorbell_offset in user queue creation

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate doorbell_offset in user queue creation amdgpu_userq_get_doorbell_index() passes the user-provided doorbell_offset to amdgpu_doorbell_index_on_bar() without bounds checking. An arbitrarily large doorbell_offseโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.1

CVSS3.1

CVE-2026-31779 - wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() The memcpy function assumes the dynamic array notif->matches is at least as large as the number of bytes to copy. Otherwise, results->matchesโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.1

CVSS3.1

CVE-2026-43051 - HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports without sufficient bounds checking. A maliciously crafted short report can trigger an out-of-bounds readโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:46 a.m.

7.8

CVSS3.1

CVE-2026-43047 - HID: multitouch: Check to ensure report responses match the request

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possible for a malicious (or clumsy) device to respond to a specific report's feature request using a completely different report ID. This can cause confuโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:46 a.m.
Total resulsts: 348401
Page 102 of 34,841
ยซ previous page ยป next page
Filters