7.1

CVSS3.1

CVE-2026-31697 - crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed When retrieving the ID for the CPU, don't attempt to copy the ID blob to userspace if the firmware command failed. If the failure was due to an invalid lenโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

7.5

CVSS3.1

CVE-2026-43031 - net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets

In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets When a TX packet spans multiple buffer descriptors (scatter-gather), axienet_free_tx_chain sums the per-BD actual length from descriptor status into a caller-providโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:46 a.m.

8.8

CVSS3.1

CVE-2026-43018 - Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt hci_conn lookup and field access must be covered by hdev lock in hci_le_remote_conn_param_req_evt, otherwise it's possible it is freed concurrently. Extโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:46 a.m.

7.8

CVSS3.1

CVE-2026-31742 - vt: discard stale unicode buffer on alt screen exit after resize

In the Linux kernel, the following vulnerability has been resolved: vt: discard stale unicode buffer on alt screen exit after resize When enter_alt_screen() saves vc_uni_lines into vc_saved_uni_lines and sets vc_uni_lines to NULL, a subsequent console resize via vc_do_resize() skips reallocating โ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.8

CVSS3.1

CVE-2026-31735 - iommupt: Fix short gather if the unmap goes into a large mapping

In the Linux kernel, the following vulnerability has been resolved: iommupt: Fix short gather if the unmap goes into a large mapping unmap has the odd behavior that it can unmap more than requested if the ending point lands within the middle of a large or contiguous IOPTE. In this case the gatheโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.8

CVSS3.1

CVE-2026-31773 - Bluetooth: SMP: derive legacy responder STK authentication from MITM state

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: derive legacy responder STK authentication from MITM state The legacy responder path in smp_random() currently labels the stored STK as authenticated whenever pending_sec_level is BT_SECURITY_HIGH. That reflects wโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

7.8

CVSS3.1

CVE-2026-31768 - iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() Add a DMA-safe buffer and use it for spi_read() instead of a stack memory. All SPI buffers must be DMA-safe. Since we only need up to 3 bytes, we just use a u8[] insteaโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

7.1

CVSS3.1

CVE-2026-31766 - drm/amdgpu: validate doorbell_offset in user queue creation

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate doorbell_offset in user queue creation amdgpu_userq_get_doorbell_index() passes the user-provided doorbell_offset to amdgpu_doorbell_index_on_bar() without bounds checking. An arbitrarily large doorbell_offseโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.1

CVSS3.1

CVE-2026-31779 - wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() The memcpy function assumes the dynamic array notif->matches is at least as large as the number of bytes to copy. Otherwise, results->matchesโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.1

CVSS3.1

CVE-2026-43051 - HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports without sufficient bounds checking. A maliciously crafted short report can trigger an out-of-bounds readโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 3, 2026, 5:46 a.m.
Total resulsts: 348202
Page 82 of 34,821
ยซ previous page ยป next page
Filters