7

CVSS3.1

CVE-2026-23013 - net: octeon_ep_vf: fix free_irq dev_id mismatch in IRQ rollback

In the Linux kernel, the following vulnerability has been resolved: net: octeon_ep_vf: fix free_irq dev_id mismatch in IRQ rollback octep_vf_request_irqs() requests MSI-X queue IRQs with dev_id set to ioq_vector. If request_irq() fails part-way, the rollback loop calls free_irq() with dev_id set …

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 9:45 p.m.

5.5

CVSS3.1

CVE-2025-71163 - dmaengine: idxd: fix device leaks on compat bind and unbind

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind and unbind Make sure to drop the reference taken when looking up the idxd device as part of the compat bind and unbind sysfs interface.

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:10 p.m.

5.5

CVSS3.1

CVE-2026-23011 - ipv4: ip_gre: make ipgre_header() robust

In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to commit db5b4e39c4e6 ("ip6_gre: make ip6gre_header() robust") Over the years, syzbot found many ways to crash the kernel in ipgre_header() [1]. This involves team or bonding dri…

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3 a.m.

7.8

CVSS3.1

CVE-2025-71162 - dmaengine: tegra-adma: Fix use-after-free

In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-after-free bug exists in the Tegra ADMA driver when audio streams are terminated, particularly during XRUN conditions. The issue occurs when the DMA buffer is freed by tegra_adma_te…

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:12 p.m.

4.7

CVSS3.1

CVE-2026-23004 - dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()

In the Linux kernel, the following vulnerability has been resolved: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() syzbot was able to crash the kernel in rt6_uncached_list_flush_dev() in an interesting way [1] Crash happens in list_del_init()/INIT_LIST_HEAD() while writing …

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 7:30 a.m.

5.5

CVSS3.1

CVE-2026-23007 - block: zero non-PI portion of auto integrity buffer

In the Linux kernel, the following vulnerability has been resolved: block: zero non-PI portion of auto integrity buffer The auto-generated integrity buffer for writes needs to be fully initialized before being passed to the underlying block device, otherwise the uninitialized memory can be read b…

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3 a.m.

7.8

CVSS3.1

CVE-2026-23001 - macvlan: fix possible UAF in macvlan_forward_source()

In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source() Add RCU protection on (struct macvlan_source_entry)->vlan. Whenever macvlan_hash_del_source() is called, we must clear entry->vlan pointer before RCU grace period starts. Th…

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3 a.m.

7.8

CVSS3.1

CVE-2026-23012 - mm/damon/core: remove call_control in inactive contexts

In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: remove call_control in inactive contexts If damon_call() is executed against a DAMON context that is not running, the function returns error while keeping the damon_call_control object linked to the context's call_…

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3 a.m.

5.5

CVSS3.1

CVE-2026-23002 - lib/buildid: use __kernel_read() for sleepable context

In the Linux kernel, the following vulnerability has been resolved: lib/buildid: use __kernel_read() for sleepable context Prevent a "BUG: unable to handle kernel NULL pointer dereference in filemap_read_folio". For the sleepable context, convert freader to use __kernel_read() instead of direct …

πŸ“… Published: Jan. 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3:15 p.m.

5.3

CVSS3.1

CVE-2026-0593 - WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscribe…

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscr…

πŸ“… Published: Jan. 24, 2026, 4:25 p.m. πŸ”„ Last Modified: April 15, 2026, 9:45 p.m.
Total resulsts: 346710
Page 1709 of 34,671
Β« previous page Β» next page
Filters