5.5

CVSS3.1

CVE-2026-23300 - net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop When a standalone IPv6 nexthop object is created with a loopback device (e.g., "ip -6 nexthop add id 100 dev lo"), fib6_nh_init() misclassifies it as a reject …

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:50 a.m.

5.5

CVSS3.1

CVE-2026-23313 - i40e: Fix preempt count leak in napi poll tracepoint

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix preempt count leak in napi poll tracepoint Using get_cpu() in the tracepoint assignment causes an obvious preempt count leak because nothing invokes put_cpu() to undo it: softirq: huh, entered softirq 3 NET_RX with p…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 26, 2026, 12:16 p.m.

5.5

CVSS3.1

CVE-2026-23351 - netfilter: nft_set_pipapo: split gc into unlink and reclaim phase

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: split gc into unlink and reclaim phase Yiming Qian reports Use-after-free in the pipapo set type: Under a large number of expired elements, commit-time GC can run for a very long time in a non-preem…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.

5.5

CVSS3.1

CVE-2026-23315 - wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211()

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() Check frame length before accessing the mgmt fields in mt76_connac2_mac_write_txwi_80211 in order to avoid a possible oob access. [fix check to also cove…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.

5.5

CVSS3.1

CVE-2026-23352 - x86/efi: defer freeing of boot services memory

In the Linux kernel, the following vulnerability has been resolved: x86/efi: defer freeing of boot services memory efi_free_boot_services() frees memory occupied by EFI_BOOT_SERVICES_CODE and EFI_BOOT_SERVICES_DATA using memblock_free_late(). There are two issue with that: memblock_free_late() s…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 26, 2026, 12:16 p.m.

5.5

CVSS3.1

CVE-2026-23385 - netfilter: nf_tables: clone set on flush only

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: clone set on flush only Syzbot with fault injection triggered a failing memory allocation with GFP_KERNEL which results in a WARN splat: iter.err WARNING: net/netfilter/nf_tables_api.c:845 at nft_map_deacti…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:48 a.m.

5.5

CVSS3.1

CVE-2026-23343 - xdp: produce a warning when calculated tailroom is negative

In the Linux kernel, the following vulnerability has been resolved: xdp: produce a warning when calculated tailroom is negative Many ethernet drivers report xdp Rx queue frag size as being the same as DMA write size. However, the only user of this field, namely bpf_xdp_frags_increase_tail(), clea…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.

9.8

CVSS3.1

CVE-2026-26831 -

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequa…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:58 p.m.

0.0

CVE-2026-23378 - net/sched: act_ife: Fix metalist update behavior

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: Fix metalist update behavior Whenever an ife action replace changes the metalist, instead of replacing the old data on the metalist, the current ife code is appending the new metadata. Aside from being innapro…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.

5.5

CVSS3.1

CVE-2026-23368 - net: phy: register phy led_triggers during probe to avoid AB-BA deadlock

In the Linux kernel, the following vulnerability has been resolved: net: phy: register phy led_triggers during probe to avoid AB-BA deadlock There is an AB-BA deadlock when both LEDS_TRIGGER_NETDEV and LED_TRIGGER_PHY are enabled: [ 1362.049207] [<8054e4b8>] led_trigger_register+0x5c/0x1fc …

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.
Total resulsts: 341475
Page 155 of 34,148
Β« previous page Β» next page
Filters