5.5

CVSS3.1

CVE-2026-31634 - rxrpc: fix reference count leak in rxrpc_server_keyring()

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix reference count leak in rxrpc_server_keyring() This patch fixes a reference count leak in rxrpc_server_keyring() by checking if rx->securities is already set.

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:30 p.m.

9.8

CVSS3.1

CVE-2026-31633 - rxrpc: Fix integer overflow in rxgk_verify_response()

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response(), there's a potential integer overflow due to rounding up token_len before checking it, thereby allowing the length check to be bypassed. Fix this by…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:30 p.m.

8.2

CVSS3.1

CVE-2026-31631 - rxrpc: Fix buffer overread in rxgk_do_verify_authenticator()

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce.

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:30 p.m.

7.8

CVSS3.1

CVE-2026-31630 - rxrpc: proc: size address buffers for %pISpc output

In the Linux kernel, the following vulnerability has been resolved: rxrpc: proc: size address buffers for %pISpc output The AF_RXRPC procfs helpers format local and remote socket addresses into fixed 50-byte stack buffers with "%pISpc". That is too small for the longest current-tree IPv6-with-po…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:30 p.m.

8.8

CVSS3.1

CVE-2026-31629 - nfc: llcp: add missing return after LLCP_CLOSED checks

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc_llcp_sock_put() but fails to return. E…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:36 p.m.

5.5

CVSS3.1

CVE-2026-31628 - x86/CPU: Fix FPDSS on Zen1

In the Linux kernel, the following vulnerability has been resolved: x86/CPU: Fix FPDSS on Zen1 Zen1's hardware divider can leave, under certain circumstances, partial results from previous operations. Those results can be leaked by another, attacker thread. Fix that with a chicken bit.

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:40 p.m.

5.5

CVSS3.1

CVE-2026-31625 - HID: alps: fix NULL pointer dereference in alps_raw_event()

In the Linux kernel, the following vulnerability has been resolved: HID: alps: fix NULL pointer dereference in alps_raw_event() Commit ecfa6f34492c ("HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them") attempted to fix up the HID drivers that had missed the previous fix that w…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 9:14 p.m.

7.0

CVSS3.1

CVE-2026-31624 - HID: core: clamp report_size in s32ton() to avoid undefined shift

In the Linux kernel, the following vulnerability has been resolved: HID: core: clamp report_size in s32ton() to avoid undefined shift s32ton() shifts by n-1 where n is the field's report_size, a value that comes directly from a HID device. The HID parser bounds report_size only to <= 256, so a b…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 1:57 p.m.

7.0

CVSS3.1

CVE-2026-31623 - net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()

In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() A malicious USB device claiming to be a CDC Phonet modem can overflow the skb_shared_info->frags[] array by sending an unbounded sequence of full-page bulk transfers…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 1:57 p.m.

8.8

CVSS3.1

CVE-2026-31622 - NFC: digital: Bounds check NFC-A cascade depth in SDD response handler

In the Linux kernel, the following vulnerability has been resolved: NFC: digital: Bounds check NFC-A cascade depth in SDD response handler The NFC-A anti-collision cascade in digital_in_recv_sdd_res() appends 3 or 4 bytes to target->nfcid1 on each round, but the number of cascade rounds is contro…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 2:16 p.m.
Total resulsts: 347405
Page 110 of 34,741
Β« previous page Β» next page
Filters