4.7

CVSS3.1

CVE-2026-31399 - nvdimm/bus: Fix potential use after free in asynchronous initialization

In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchronous initialization Dingisoul with KASAN reports a use after free if device_add() fails in nd_async_device_register(). Commit b6eae0f61db2 ("libnvdimm: Hold reference on parent…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.

7.0

CVSS3.1

CVE-2026-31394 - mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations

In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations ieee80211_chan_bw_change() iterates all stations and accesses link->reserved.oper via sta->sdata->link[link_id]. For stations on AP_VLAN interfaces (e.g. 4addr …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.

5.8

CVSS3.1

CVE-2026-31392 - smb: client: fix krb5 mount with username option

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option Customer reported that some of their krb5 mounts were failing against a single server as the client was trying to mount the shares with wrong credentials. It turned out the client…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 6, 2026, 9:23 p.m.

5.5

CVSS3.1

CVE-2026-23472 - serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN

In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN uart_write_room() and uart_write() behave inconsistently when xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were never properly initialized): - uart_w…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

7.0

CVSS3.1

CVE-2026-23451 - bonding: prevent potential infinite loop in bond_header_parse()

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. Add new "const struct net_device *dev"…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

5.5

CVSS3.1

CVE-2026-23448 - net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check

In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE entries fit within the skb. The first check correctly accounts for ndpoffset: if ((ndpoffset + …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

7.0

CVSS3.1

CVE-2026-23447 - net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check

In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against the total skb length…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

5.5

CVSS3.1

CVE-2026-23434 - mtd: rawnand: serialize lock/unlock against other NAND operations

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: serialize lock/unlock against other NAND operations nand_lock() and nand_unlock() call into chip->ops.lock_area/unlock_area without holding the NAND device lock. On controllers that implement SET_FEATURES via multip…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

5.5

CVSS3.1

CVE-2026-23419 - net/rds: Fix circular locking dependency in rds_tcp_tune

In the Linux kernel, the following vulnerability has been resolved: net/rds: Fix circular locking dependency in rds_tcp_tune syzbot reported a circular locking dependency in rds_tcp_tune() where sk_net_refcnt_upgrade() is called while holding the socket lock: ====================================…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:55 a.m.

4.7

CVSS3.1

CVE-2026-31389 - spi: fix use-after-free on controller registration failure

In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of dr…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.
Total resulsts: 342654
Page 64 of 34,266
Β« previous page Β» next page
Filters