7.8

CVSS3.1

CVE-2026-23194 - rust_binder: correctly handle FDA objects of length zero

In the Linux kernel, the following vulnerability has been resolved: rust_binder: correctly handle FDA objects of length zero Fix a bug where an empty FDA (fd array) object with 0 fds would cause an out-of-bounds error. The previous implementation used `skip == 0` to mean "this is a pointer fixup"…

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 12:15 p.m.

5.5

CVSS3.1

CVE-2026-23188 - net: usb: r8152: fix resume reset deadlock

In the Linux kernel, the following vulnerability has been resolved: net: usb: r8152: fix resume reset deadlock rtl8152 can trigger device reset during reset which potentially can result in a deadlock: **** DPM device timeout after 10 seconds; 15 seconds until panic **** Call Trace: <TASK> sc…

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 6:15 p.m.

7.8

CVSS3.1

CVE-2026-23192 - linkwatch: use __dev_put() in callers to prevent UAF

In the Linux kernel, the following vulnerability has been resolved: linkwatch: use __dev_put() in callers to prevent UAF After linkwatch_do_dev() calls __dev_put() to release the linkwatch reference, the device refcount may drop to 1. At this point, netdev_run_todo() can proceed (since linkwatch_…

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 12:45 a.m.

5.5

CVSS3.1

CVE-2026-23165 - sfc: fix deadlock in RSS config read

In the Linux kernel, the following vulnerability has been resolved: sfc: fix deadlock in RSS config read Since cited commit, core locks the net_device's rss_lock when handling ethtool -x command, so driver's implementation should not lock it again. Remove the latter.

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 6:15 p.m.

5.5

CVSS3.1

CVE-2026-23196 - HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer

In the Linux kernel, the following vulnerability has been resolved: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer Add DMA buffer readiness check before reading DMA buffer to avoid unexpected NULL pointer accessing.

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 12:15 p.m.

5.5

CVSS3.1

CVE-2026-23202 - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer

In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer The curr_xfer field is read by the IRQ handler without holding the lock to check if a transfer is in progress. When clearing curr_xfer in the combined sequence…

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 12:15 p.m.

7

CVSS3.1

CVE-2026-23195 - cgroup/dmem: avoid pool UAF

In the Linux kernel, the following vulnerability has been resolved: cgroup/dmem: avoid pool UAF An UAF issue was observed: BUG: KASAN: slab-use-after-free in page_counter_uncharge+0x65/0x150 Write of size 8 at addr ffff888106715440 by task insmod/527 CPU: 4 UID: 0 PID: 527 Comm: insmod 6.19.…

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 12:45 a.m.

7.8

CVSS3.1

CVE-2026-23191 - ALSA: aloop: Fix racy access at PCM trigger

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix racy access at PCM trigger The PCM trigger callback of aloop driver tries to check the PCM state and stop the stream of the tied substream in the corresponding cable. Since both check and stop operations are perf…

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 8:30 p.m.

5.5

CVSS3.1

CVE-2026-23190 - ASoC: amd: fix memory leak in acp3x pdm dma ops

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: fix memory leak in acp3x pdm dma ops

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 7:30 p.m.

7.8

CVSS3.1

CVE-2026-23184 - binder: fix UAF in binder_netlink_report()

In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF in binder_netlink_report() Oneway transactions sent to frozen targets via binder_proc_transaction() return a BR_TRANSACTION_PENDING_FROZEN error but they are still treated as successful since the target is expecte…

πŸ“… Published: Feb. 14, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 12:45 a.m.
Total resulsts: 349182
Page 1639 of 34,919
Β« previous page Β» next page
Filters