5.5

CVSS3.1

CVE-2026-23436 - net: shaper: protect from late creation of hierarchy

In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect from late creation of hierarchy We look up a netdev during prep of Netlink ops (pre- callbacks) and take a ref to it. Then later in the body of the callback we take its lock or RCU which are the actual protec…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

7.0

CVSS3.1

CVE-2026-31403 - NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd

In the Linux kernel, the following vulnerability has been resolved: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd The /proc/fs/nfs/exports proc entry is created at module init and persists for the module's lifetime. exports_proc_open() captures the caller's current network …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.5

CVSS3.1

CVE-2026-31400 - sunrpc: fix cache_request leak in cache_release

In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix cache_request leak in cache_release When a reader's file descriptor is closed while in the middle of reading a cache_request (rp->offset != 0), cache_release() decrements the request's readers count but never checks w…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

7.0

CVSS3.1

CVE-2026-31398 - mm/rmap: fix incorrect pte restoration for lazyfree folios

In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix incorrect pte restoration for lazyfree folios We batch unmap anonymous lazyfree folios by folio_unmap_pte_batch. If the batch has a mix of writable and non-writable bits, we may end up setting the entire batch writa…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

0.0

CVE-2026-31397 - mm/huge_memory: fix use of NULL folio in move_pages_huge_pmd()

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages_huge_pmd() move_pages_huge_pmd() handles UFFDIO_MOVE for both normal THPs and huge zero pages. For the huge zero page path, src_folio is explicitly set to NULL, and is used as …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

7.0

CVSS3.1

CVE-2026-31394 - mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations

In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations ieee80211_chan_bw_change() iterates all stations and accesses link->reserved.oper via sta->sdata->link[link_id]. For stations on AP_VLAN interfaces (e.g. 4addr …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

0.0

CVE-2026-23468 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace can pass an arbitrary number of BO list entries via the bo_number field. Although the previous multiplication overflow check prevents out-of-bounds al…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

7.0

CVSS3.1

CVE-2026-23461 - Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user After commit ab4eedb790ca ("Bluetooth: L2CAP: Fix corrupted list in hci_chan_del"), l2cap_conn_del() uses conn->lock to protect access to conn->users. However, l2cap_r…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

7.0

CVSS3.1

CVE-2026-23451 - bonding: prevent potential infinite loop in bond_header_parse()

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. Add new "const struct net_device *dev"…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

7.0

CVSS3.1

CVE-2026-23447 - net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check

In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against the total skb length…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.
Total resulsts: 343194
Page 121 of 34,320
Β« previous page Β» next page
Filters