0.0

CVE-2026-23429 - iommu/sva: Fix crash in iommu_sva_unbind_device()

In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Fix crash in iommu_sva_unbind_device() domain->mm->iommu_mm can be freed by iommu_domain_free(): iommu_domain_free() mmdrop() __mmdrop() mm_pasid_drop() After iommu_domain_free() returns, accessing …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:54 a.m.

7.0

CVSS3.1

CVE-2026-31401 - HID: bpf: prevent buffer overflow in hid_hw_request

In the Linux kernel, the following vulnerability has been resolved: HID: bpf: prevent buffer overflow in hid_hw_request right now the returned value is considered to be always valid. However, when playing with HID-BPF, the return value can be arbitrary big, because it's the return value of dispat…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.

7.0

CVSS3.1

CVE-2026-23454 - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_destroy_channel() where hwc->caller_ctx is freed before the HWC's Completion Queue (CQ) and Event Qu…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-31396 - net: macb: fix use-after-free access to PTP clock

In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock PTP clock is registered on every opening of the interface and destroyed on every closing. However it may be accessed via get_ts_info ethtool call which is possible while the inte…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.

5.5

CVSS3.1

CVE-2026-23418 - drm/xe/reg_sr: Fix leak on xa_store failure

In the Linux kernel, the following vulnerability has been resolved: drm/xe/reg_sr: Fix leak on xa_store failure Free the newly allocated entry when xa_store() fails to avoid a memory leak on the error path. v2: use goto fail_free. (Bala) (cherry picked from commit 6bc6fec71ac45f52db609af4e62bdb…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:55 a.m.

5.5

CVSS3.1

CVE-2026-23439 - udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n

In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n When CONFIG_IPV6 is disabled, the udp_sock_create6() function returns 0 (success) without actually creating a socket. Callers such as fou_create() then proc…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

9.6

CVSS3.1

CVE-2026-28373 -

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 6, 2026, 9:23 p.m.

0.0

CVE-2026-23422 - dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler

In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler Commit 31a7a0bbeb00 ("dpaa2-switch: add bounds check for if_id in IRQ handler") introduces a range check for if_id to avoid an out-of-bounds access. If an…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:54 a.m.

0.0

CVE-2026-23469 - drm/imagination: Synchronize interrupts before suspending the GPU

In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Synchronize interrupts before suspending the GPU The runtime PM suspend callback doesn't know whether the IRQ handler is in progress on a different CPU core and doesn't wait for it to finish. Depending on timing…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-23438 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: guard flow control update with global_tx_fc in buffer switching mvpp2_bm_switch_buffers() unconditionally calls mvpp2_bm_pool_update_priv_fc() when switching between per-cpu and shared buffer pool modes. This function…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:16 p.m.
Total resulsts: 342658
Page 66 of 34,266
Β« previous page Β» next page
Filters