5.5

CVSS3.1

CVE-2026-22979 - net: fix memory leak in skb_segment_list for GRO packets

In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list() is called during packet forwarding, it handles packets that were aggregated by the GRO engine. Historically, the segmentation logic in skb_segment_…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2025-69908 -

An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript resource.

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:42 p.m.

7.8

CVSS3.1

CVE-2026-22995 - ublk: fix use-after-free in ublk_partition_scan_work

In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_work A race condition exists between the async partition scan work and device teardown that can lead to a use-after-free of ub->ub_disk: 1. ublk_ctrl_start_dev() schedules partitio…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3:15 p.m.

5.5

CVSS3.1

CVE-2026-22991 - libceph: make free_choose_arg_map() resilient to partial allocation

In the Linux kernel, the following vulnerability has been resolved: libceph: make free_choose_arg_map() resilient to partial allocation free_choose_arg_map() may dereference a NULL pointer if its caller fails after a partial allocation. For example, in decode_choose_args(), if allocation of arg_…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3:15 p.m.

7.1

CVSS3.1

CVE-2026-22984 - libceph: prevent potential out-of-bounds reads in handle_auth_done()

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in handle_auth_done() Perform an explicit bounds check on payload_len to avoid a possible out-of-bounds access in the callout. [ idryomov: changelog ]

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3:15 p.m.

3.3

CVSS3.1

CVE-2026-22978 - wifi: avoid kernel-infoleak from struct iw_point

In the Linux kernel, the following vulnerability has been resolved: wifi: avoid kernel-infoleak from struct iw_point struct iw_point has a 32bit hole on 64bit arches. struct iw_point { void __user *pointer; /* Pointer to the data (in user space) */ __u16 length; /* n…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3:15 p.m.

5.5

CVSS3.1

CVE-2026-22994 - bpf: Fix reference count leak in bpf_prog_test_run_xdp()

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reference count leak in bpf_prog_test_run_xdp() syzbot is reporting unregister_netdevice: waiting for sit0 to become free. Usage count = 2 problem. A debug printk() patch found that a refcount is obtained at xdp_conv…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 7 p.m.

5.5

CVSS3.1

CVE-2026-22988 - arp: do not assume dev_hard_header() does not change skb->head

In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not change skb->head arp_create() is the only dev_hard_header() caller making assumption about skb->head being unchanged. A recent commit broke this assumption. Initialize @arp pointer …

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 7 p.m.

5.5

CVSS3.1

CVE-2026-22982 - net: mscc: ocelot: Fix crash when adding interface under a lag

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix crash when adding interface under a lag Commit 15faa1f67ab4 ("lan966x: Fix crash when adding interface under a lag") fixed a similar issue in the lan966x driver caused by a NULL pointer dereference. The oce…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 7 p.m.

5.5

CVSS3.1

CVE-2026-22993 - idpf: Fix RSS LUT NULL ptr issue after soft reset

In the Linux kernel, the following vulnerability has been resolved: idpf: Fix RSS LUT NULL ptr issue after soft reset During soft reset, the RSS LUT is freed and not restored unless the interface is up. If an ethtool command that accesses the rss lut is attempted immediately after reset, it will …

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 9:45 p.m.
Total resulsts: 346572
Page 1728 of 34,658
Β« previous page Β» next page
Filters