4.7

CVSS3.1

CVE-2026-31389 - spi: fix use-after-free on controller registration failure

In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of dr…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

5.5

CVSS3.1

CVE-2026-31390 - drm/xe: Fix memory leak in xe_vm_madvise_ioctl

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() validation fails, jump to the new free_vmas cleanup label to properly free the allocated resources. This ensures proper cleanup in this error path. (ch…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

5.5

CVSS3.1

CVE-2026-23473 - io_uring/poll: fix multishot recv missing EOF on wakeup race

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix multishot recv missing EOF on wakeup race When a socket send and shutdown() happen back-to-back, both fire wake-ups before the receiver's task_work has a chance to run. The first wake gets poll ownership (poll_…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-23432 - mshv: Fix use-after-free in mshv_map_user_memory error path

In the Linux kernel, the following vulnerability has been resolved: mshv: Fix use-after-free in mshv_map_user_memory error path In the error path of mshv_map_user_memory(), calling vfree() directly on the region leaves the MMU notifier registered. When userspace later unmaps the memory, the notif…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-23453 - net: ti: icssg-prueth: Fix memory leak in XDP_DROP for non-zero-copy mode

In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: Fix memory leak in XDP_DROP for non-zero-copy mode Page recycling was removed from the XDP_DROP path in emac_run_xdp() to avoid conflicts with AF_XDP zero-copy mode, which uses xsk_buff_free() instead. How…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-23426 - drm/logicvc: Fix device node reference leak in logicvc_drm_config_parse()

In the Linux kernel, the following vulnerability has been resolved: drm/logicvc: Fix device node reference leak in logicvc_drm_config_parse() The logicvc_drm_config_parse() function calls of_get_child_by_name() to find the "layers" node but fails to release the reference, leading to a device node…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:54 a.m.

0.0

CVE-2026-23429 - iommu/sva: Fix crash in iommu_sva_unbind_device()

In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Fix crash in iommu_sva_unbind_device() domain->mm->iommu_mm can be freed by iommu_domain_free(): iommu_domain_free() mmdrop() __mmdrop() mm_pasid_drop() After iommu_domain_free() returns, accessing …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:54 a.m.

7.0

CVSS3.1

CVE-2026-31401 - HID: bpf: prevent buffer overflow in hid_hw_request

In the Linux kernel, the following vulnerability has been resolved: HID: bpf: prevent buffer overflow in hid_hw_request right now the returned value is considered to be always valid. However, when playing with HID-BPF, the return value can be arbitrary big, because it's the return value of dispat…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.

7.0

CVSS3.1

CVE-2026-23454 - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_destroy_channel() where hwc->caller_ctx is freed before the HWC's Completion Queue (CQ) and Event Qu…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-31396 - net: macb: fix use-after-free access to PTP clock

In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock PTP clock is registered on every opening of the interface and destroyed on every closing. However it may be accessed via get_ts_info ethtool call which is possible while the inte…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.
Total resulsts: 342654
Page 65 of 34,266
Β« previous page Β» next page
Filters