7.0

CVSS3.1

CVE-2026-23441 - net/mlx5e: Prevent concurrent access to IPSec ASO context

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Prevent concurrent access to IPSec ASO context The query or updating IPSec offload object is through Access ASO WQE. The driver uses a single mlx5e_ipsec_aso struct for each PF, which contains a shared DMA-mapped conte…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:53 p.m.

7.0

CVSS3.1

CVE-2026-23461 - Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user After commit ab4eedb790ca ("Bluetooth: L2CAP: Fix corrupted list in hci_chan_del"), l2cap_conn_del() uses conn->lock to protect access to conn->users. However, l2cap_r…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:53 p.m.

5.5

CVSS3.1

CVE-2026-23465 - btrfs: log new dentries when logging parent dir of a conflicting inode

In the Linux kernel, the following vulnerability has been resolved: btrfs: log new dentries when logging parent dir of a conflicting inode If we log the parent directory of a conflicting inode, we are not logging the new dentries of the directory, so when we finish we have the parent directory's …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.5

CVSS3.1

CVE-2026-23463 - soc: fsl: qbman: fix race condition in qman_destroy_fq

In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: fix race condition in qman_destroy_fq When QMAN_FQ_FLAG_DYNAMIC_FQID is set, there's a race condition between fq_table[fq->idx] state and freeing/allocating from the pool and WARN_ON(fq_table[fq->idx]) in qman_cr…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:53 p.m.

4.7

CVSS3.1

CVE-2026-23440 - net/mlx5e: Fix race condition during IPSec ESN update

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race condition during IPSec ESN update In IPSec full offload mode, the device reports an ESN (Extended Sequence Number) wrap event to the driver. The driver validates this event by querying the IPSec ASO and checki…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:53 p.m.

7.0

CVSS3.1

CVE-2026-23451 - bonding: prevent potential infinite loop in bond_header_parse()

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. Add new "const struct net_device *dev"…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:53 p.m.

5.5

CVSS3.1

CVE-2026-23418 - drm/xe/reg_sr: Fix leak on xa_store failure

In the Linux kernel, the following vulnerability has been resolved: drm/xe/reg_sr: Fix leak on xa_store failure Free the newly allocated entry when xa_store() fails to avoid a memory leak on the error path. v2: use goto fail_free. (Bala) (cherry picked from commit 6bc6fec71ac45f52db609af4e62bdb…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:54 p.m.

7.0

CVSS3.1

CVE-2026-23452 - PM: runtime: Fix a race condition related to device removal

In the Linux kernel, the following vulnerability has been resolved: PM: runtime: Fix a race condition related to device removal The following code in pm_runtime_work() may dereference the dev->parent pointer after the parent device has been freed: /* Maybe the parent is now able to suspend. */ …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:53 p.m.

7.0

CVSS3.1

CVE-2026-31402 - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operation responses. This size was calculated based on OPEN response…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:53 p.m.

7.0

CVSS3.1

CVE-2026-23455 - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the protocol discriminator byte before passing i…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:53 p.m.
Total resulsts: 343996
Page 195 of 34,400
Β« previous page Β» next page
Filters