5.5

CVSS3.1

CVE-2026-31722 - usb: gadget: f_rndis: Fix net_device lifecycle with device_move

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Fix net_device lifecycle with device_move The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbi…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 8:55 p.m.

8.8

CVSS3.1

CVE-2026-31709 - smb: client: validate the whole DACL before rewriting it in cifsacl

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and id_mode_to_cifs_acl() derive a DACL pointer from a server-supplied dacloffset and then use the incoming ACL to rebuild the chmod/chown secur…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4:35 a.m.

5.5

CVSS3.1

CVE-2026-31714 - f2fs: fix to avoid memory leak in f2fs_rename()

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid memory leak in f2fs_rename() syzbot reported a f2fs bug as below: BUG: memory leak unreferenced object 0xffff888127f70830 (size 16): comm "syz.0.23", pid 6144, jiffies 4294943712 hex dump (first 16 bytes):…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 9:12 p.m.

7.8

CVSS3.1

CVE-2026-31696 - rxrpc: Fix missing validation of ticket length in non-XDR key preparsing

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix missing validation of ticket length in non-XDR key preparsing In rxrpc_preparse(), there are two paths for parsing key payloads: the XDR path (for large payloads) and the non-XDR path (for payloads <= 28 bytes). While …

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 7:17 p.m.

7.0

CVSS3.1

CVE-2026-43027 - netfilter: nf_conntrack_helper: pass helper to expect cleanup

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_helper: pass helper to expect cleanup nf_conntrack_helper_unregister() calls nf_ct_expect_iterate_destroy() to remove expectations belonging to the helper being unregistered. However, it passes NULL instea…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 2, 2026, 10:15 a.m.

5.5

CVSS3.1

CVE-2026-43022 - Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources. C…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 2:53 p.m.

7.0

CVSS3.1

CVE-2026-31756 - usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop()

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop() dwc2_gadget_exit_clock_gating() internally calls call_gadget() macro, which expects hsotg->lock to be held since it does spin_unlock/spin_lock around the g…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 4:45 p.m.

7.8

CVSS3.1

CVE-2026-31731 - thermal: core: Address thermal zone removal races with resume

In the Linux kernel, the following vulnerability has been resolved: thermal: core: Address thermal zone removal races with resume Since thermal_zone_pm_complete() and thermal_zone_device_resume() re-initialize the poll_queue delayed work for the given thermal zone, the cancel_delayed_work_sync() …

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 5:30 p.m.

4.7

CVSS3.1

CVE-2026-31728 - usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop A race condition between gether_disconnect() and eth_stop() leads to a NULL pointer dereference. Specifically, if eth_stop() is triggered concurrently while ge…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4:16 p.m.

5.5

CVSS3.1

CVE-2026-31724 - usb: gadget: f_eem: Fix net_device lifecycle with device_move

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_eem: Fix net_device lifecycle with device_move The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbind…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 5 p.m.
Total resulsts: 349182
Page 164 of 34,919
Β« previous page Β» next page
Filters