0.0

CVE-2026-23453 - net: ti: icssg-prueth: Fix memory leak in XDP_DROP for non-zero-copy mode

In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: Fix memory leak in XDP_DROP for non-zero-copy mode Page recycling was removed from the XDP_DROP path in emac_run_xdp() to avoid conflicts with AF_XDP zero-copy mode, which uses xsk_buff_free() instead. How…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

7.0

CVSS3.1

CVE-2026-23451 - bonding: prevent potential infinite loop in bond_header_parse()

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. Add new "const struct net_device *dev"…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

7.0

CVSS3.1

CVE-2026-23447 - net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check

In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against the total skb length…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

0.0

CVE-2026-23443 - ACPI: processor: Fix previous acpi_processor_errata_piix4() fix

In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()"), device pointers may be dereferenced after dropping refer…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

5.5

CVSS3.1

CVE-2026-23466 - drm/xe: Open-code GGTT MMIO access protection

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Open-code GGTT MMIO access protection GGTT MMIO access is currently protected by hotplug (drm_dev_enter), which works correctly when the driver loads successfully and is later unbound or unloaded. However, if driver load …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.5

CVSS3.1

CVE-2026-23449 - net/sched: teql: Fix double-free in teql_master_xmit

In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: Fix double-free in teql_master_xmit Whenever a TEQL devices has a lockless Qdisc as root, qdisc_reset should be called using the seq_lock to avoid racing with the datapath. Failure to do so may cause crashes like…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

0.0

CVE-2026-23433 - arm_mpam: Fix null pointer dereference when restoring bandwidth counters

In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Fix null pointer dereference when restoring bandwidth counters When an MSC supporting memory bandwidth monitoring is brought offline and then online, mpam_restore_mbwu_state() calls __ris_msmon_read() via ipi to restore…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

7.0

CVSS3.1

CVE-2026-23458 - netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() stores a conntrack pointer in cb->data for the netlink dump callback ctnetlink_exp_ct_dump_table(), but drops the conntrack reference imm…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

0.0

CVE-2026-23459 - ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS

In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats() was assuming tunnels were only using …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 p.m.

0.0

CVE-2025-59709 - Directory Traversal Allowing Super User File Read in Biztalk360

An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 6, 2026, 9:23 p.m.
Total resulsts: 342692
Page 67 of 34,270
Β« previous page Β» next page
Filters