7.0

CVSS3.1

CVE-2026-23452 - PM: runtime: Fix a race condition related to device removal

In the Linux kernel, the following vulnerability has been resolved: PM: runtime: Fix a race condition related to device removal The following code in pm_runtime_work() may dereference the dev->parent pointer after the parent device has been freed: /* Maybe the parent is now able to suspend. */ …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

7.0

CVSS3.1

CVE-2026-31402 - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operation responses. This size was calculated based on OPEN response…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.

7.0

CVSS3.1

CVE-2026-23455 - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the protocol discriminator byte before passing i…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-23474 - mtd: Avoid boot crash in RedBoot partition table parser

In the Linux kernel, the following vulnerability has been resolved: mtd: Avoid boot crash in RedBoot partition table parser Given CONFIG_FORTIFY_SOURCE=y and a recent compiler, commit 439a1bcac648 ("fortify: Use __builtin_dynamic_object_size() when available") produces the warning below and an oo…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-23431 - spi: amlogic-spisg: Fix memory leak in aml_spisg_probe()

In the Linux kernel, the following vulnerability has been resolved: spi: amlogic-spisg: Fix memory leak in aml_spisg_probe() In aml_spisg_probe(), ctlr is allocated by spi_alloc_target()/spi_alloc_host(), but fails to call spi_controller_put() in several error paths. This leads to a memory leak w…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

5.5

CVSS3.1

CVE-2026-23475 - spi: fix statistics allocation

In the Linux kernel, the following vulnerability has been resolved: spi: fix statistics allocation The controller per-cpu statistics is not allocated until after the controller has been registered with driver core, which leaves a window where accessing the sysfs attributes can trigger a NULL-poin…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

6.4

CVSS3.1

CVE-2026-23456 - netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checking that len bytes remain in the buffer. …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2025-59710 - Remote Code Execution via Unrestricted DLL Loading in Biztalk360

An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the serv…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 6, 2026, 9:23 p.m.

0.0

CVE-2026-23425 - KVM: arm64: Fix ID register initialization for non-protected pKVM guests

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix ID register initialization for non-protected pKVM guests In protected mode, the hypervisor maintains a separate instance of the `kvm` structure for each VM. For non-protected VMs, this structure is initialized fro…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:54 a.m.

0.0

CVE-2026-23435 - perf/x86: Move event pointer setup earlier in x86_pmu_enable()

In the Linux kernel, the following vulnerability has been resolved: perf/x86: Move event pointer setup earlier in x86_pmu_enable() A production AMD EPYC system crashed with a NULL pointer dereference in the PMU NMI handler: BUG: kernel NULL pointer dereference, address: 0000000000000198 RIP:…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.
Total resulsts: 342650
Page 61 of 34,265
Β« previous page Β» next page
Filters