8.1

CVSS3.1

CVE-2026-43134 - Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ This adds a check for encryption key size upon receiving L2CAP_LE_CONN_REQ which is required by L2CAP/LE/CFC/BV-15-C which expects L2CAP_CR_LE_BAD_KEY_SIZE.

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:40 p.m.

0.0

CVE-2026-43141 - ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut

In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut Number of MW LUTs depends on NTB configuration and can be set to zero, in such scenario rounddown_pow_of_two will cause undefined behaviour and should not be performed. …

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 4 p.m.

0.0

CVE-2026-43131 - drm/amd/pm: Fix null pointer dereference issue

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Fix null pointer dereference issue If SMU is disabled, during RAS initialization, there will be null pointer dereference issue here.

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 5:30 p.m.

5.5

CVSS3.1

CVE-2026-43123 - fbcon: check return value of con2fb_acquire_newinfo()

In the Linux kernel, the following vulnerability has been resolved: fbcon: check return value of con2fb_acquire_newinfo() If fbcon_open() fails when called from con2fb_acquire_newinfo() then info->fbcon_par pointer remains NULL which is later dereferenced. Add check for return value of the funct…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 3:15 a.m.

7.0

CVSS3.1

CVE-2025-71273 - wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band() Simplify the code by using device managed memory allocations. This also fixes a memory leak in rtw_register_hw(). The supported bands were not freed in the error path. …

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 2:15 a.m.

0.0

CVE-2026-43162 - media: tegra-video: Fix memory leak in __tegra_channel_try_format()

In the Linux kernel, the following vulnerability has been resolved: media: tegra-video: Fix memory leak in __tegra_channel_try_format() The state object allocated by __v4l2_subdev_state_alloc() must be freed with __v4l2_subdev_state_free() when it is no longer needed. In __tegra_channel_try_form…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 5:45 a.m.

5.5

CVSS3.1

CVE-2025-71271 - hfsplus: ensure sb->s_fs_info is always cleaned up

In the Linux kernel, the following vulnerability has been resolved: hfsplus: ensure sb->s_fs_info is always cleaned up When hfsplus was converted to the new mount api a bug was introduced by changing the allocation pattern of sb->s_fs_info. If setup_bdev_super() fails after a new superblock has b…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4:15 a.m.

0.0

CVE-2026-43221 - ipmi: ipmb: initialise event handler read bytes

In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: initialise event handler read bytes IPMB doesn't use i2c reads, but the handler needs to set a value. Otherwise an i2c read will return an uninitialised value from the bus driver.

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 3:45 a.m.

7.0

CVSS3.1

CVE-2026-43272 - ring-buffer: Fix possible dereference of uninitialized pointer

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix possible dereference of uninitialized pointer There is a pointer head_page in rb_meta_validate_events() which is not initialized at the beginning of a function. This pointer can be dereferenced if there is a fail…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4:15 p.m.

7.0

CVSS3.1

CVE-2026-43171 - EFI/CPER: don't dump the entire memory region

In the Linux kernel, the following vulnerability has been resolved: EFI/CPER: don't dump the entire memory region The current logic at cper_print_fw_err() doesn't check if the error record length is big enough to handle offset. On a bad firmware, if the ofset is above the actual record, length -=…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 3 a.m.
Total resulsts: 349182
Page 84 of 34,919
Β« previous page Β» next page
Filters