7.5

CVSS3.1

CVE-2026-31635 - rxrpc: fix oversized RESPONSE authenticator length check

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length check rxgk_verify_response() decodes auth_len from the packet and is supposed to verify that it fits in the remaining bytes. The existing check is inverted, so oversized RESPONSE…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:30 p.m.

8.8

CVSS3.1

CVE-2026-31629 - nfc: llcp: add missing return after LLCP_CLOSED checks

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc_llcp_sock_put() but fails to return. E…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:36 p.m.

5.5

CVSS3.1

CVE-2026-31621 - bnge: return after auxiliary_device_uninit() in error path

In the Linux kernel, the following vulnerability has been resolved: bnge: return after auxiliary_device_uninit() in error path When auxiliary_device_add() fails, the error block calls auxiliary_device_uninit() but does not return. The uninit drops the last reference and synchronously runs bnge_a…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 2:05 p.m.

4.6

CVSS3.1

CVE-2026-31620 - ALSA: usx2y: us144mkii: fix NULL deref on missing interface 0

In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: us144mkii: fix NULL deref on missing interface 0 A malicious USB device with the TASCAM US-144MKII device id can have a configuration containing bInterfaceNumber=1 but no interface 0. USB configuration descriptors a…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 2:11 p.m.

5.5

CVSS3.1

CVE-2026-31592 - KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock Take and hold kvm->lock for before checking sev_guest() in sev_mem_enc_register_region(), as sev_guest() isn't stable unless kvm->lock is held (or KVM can gu…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 8:33 p.m.

5.5

CVSS3.1

CVE-2026-31591 - KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish Lock all vCPUs when synchronizing and encrypting VMSAs for SNP guests, as allowing userspace to manipulate and/or run a vCPU while its state is being synchron…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 8:34 p.m.

9.8

CVSS3.1

CVE-2026-31589 - mm: call ->free_folio() directly in folio_unmap_invalidate()

In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_invalidate() We can only call filemap_free_folio() if we have a reference to (or hold a lock on) the mapping. Otherwise, we've already removed the folio from the mapping so it no l…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 8:40 p.m.

7.8

CVSS3.1

CVE-2026-31586 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()

In the Linux kernel, the following vulnerability has been resolved: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() cgwb_release_workfn() calls css_put(wb->blkcg_css) and then later accesses wb->blkcg_css again via blkcg_unpin_online(). If css_put() drops the last reference, the blkc…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 8:45 p.m.

5.5

CVSS3.1

CVE-2026-31573 - media: verisilicon: Fix kernel panic due to __initconst misuse

In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: Fix kernel panic due to __initconst misuse Fix a kernel panic when probing the driver as a module: Unable to handle kernel paging request at virtual address ffffd9c18eb05000 of_find_matching_node_and_ma…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:29 p.m.

4.7

CVSS3.1

CVE-2026-31572 - i2c: designware: amdisp: Fix resume-probe race condition issue

In the Linux kernel, the following vulnerability has been resolved: i2c: designware: amdisp: Fix resume-probe race condition issue Identified resume-probe race condition in kernel v7.0 with the commit 38fa29b01a6a ("i2c: designware: Combine the init functions"),but this issue existed from the beg…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:33 p.m.
Total resulsts: 347632
Page 133 of 34,764
Β« previous page Β» next page
Filters