0.0

CVE-2026-43046 - btrfs: reject root items with drop_progress and zero drop_level

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject root items with drop_progress and zero drop_level [BUG] When recovering relocation at mount time, merge_reloc_root() and btrfs_drop_snapshot() both use BUG_ON(level == 0) to guard against an impossible state: a non-…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43045 - mshv: Fix error handling in mshv_region_pin

In the Linux kernel, the following vulnerability has been resolved: mshv: Fix error handling in mshv_region_pin The current error handling has two issues: First, pin_user_pages_fast() can return a short pin count (less than requested but greater than zero) when it cannot pin all requested pages.…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43043 - crypto: af-alg - fix NULL pointer dereference in scatterwalk

In the Linux kernel, the following vulnerability has been resolved: crypto: af-alg - fix NULL pointer dereference in scatterwalk The AF_ALG interface fails to unmark the end of a Scatter/Gather List (SGL) when chaining a new af_alg_tsgl structure. If a sendmsg() fills an SGL exactly to MAX_SGL_EN…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43041 - net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak __radix_tree_create() allocates and links intermediate nodes into the tree one by one. If a subsequent allocation fails, the already-linked nodes remain in…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43040 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an in…

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak When processing Router Advertisements with user options the kernel builds an RTM_NEWNDUSEROPT netlink message. The ndusero…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43036 - net: use skb_header_pointer() for TCPv4 GSO frag_off check

In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_off check Syzbot reported a KMSAN uninit-value warning in gso_features_check() called from netif_skb_features() [1]. gso_features_check() reads iph->frag_off to decide whether to …

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43035 - net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak When building netlink messages, tc_chain_fill_node() never initializes the tcm_info field of struct tcmsg. Since the allocation is…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43034 - bnxt_en: set backing store type from query type

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: set backing store type from query type bnxt_hwrm_func_backing_store_qcaps_v2() stores resp->type from the firmware response in ctxm->type and later uses that value to index fixed backing-store metadata arrays such as ctx…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43032 - NFC: pn533: bound the UART receive buffer

In the Linux kernel, the following vulnerability has been resolved: NFC: pn533: bound the UART receive buffer pn532_receive_buf() appends every incoming byte to dev->recv_skb and only resets the buffer after pn532_uart_rx_is_frame() recognizes a complete frame. A continuous stream of bytes withou…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43027 - netfilter: nf_conntrack_helper: pass helper to expect cleanup

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_helper: pass helper to expect cleanup nf_conntrack_helper_unregister() calls nf_ct_expect_iterate_destroy() to remove expectations belonging to the helper being unregistered. However, it passes NULL instea…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.
Total resulsts: 348200
Page 61 of 34,820
Β« previous page Β» next page
Filters