5.5

CVSS3.1

CVE-2026-23303 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds

In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled, cifs_set_cifscreds() logs the key payload and exposes the plaintext username and password. Remove the debug log to avoid exposing c…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

5.5

CVSS3.1

CVE-2026-23299 - Bluetooth: purge error queues in socket destructors

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors When TX timestamping is enabled via SO_TIMESTAMPING, SKBs may be queued into sk_error_queue and will stay there until consumed. If userspace never gets to read the timestamps, o…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

5.5

CVSS3.1

CVE-2026-23298 - can: ucan: Fix infinite loop from zero-length messages

In the Linux kernel, the following vulnerability has been resolved: can: ucan: Fix infinite loop from zero-length messages If a broken ucan device gets a message with the message length field set to 0, then the driver will loop for forever in ucan_read_bulk_callback(), hanging the system. If the…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

5.5

CVSS3.1

CVE-2026-23296 - scsi: core: Fix refcount leak for tagset_refcnt

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix refcount leak for tagset_refcnt This leak will cause a hang when tearing down the SCSI host. For example, iscsid hangs with the following call trace: [130120.652718] scsi_alloc_sdev: Allocation failure during SCS…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

5.5

CVSS3.1

CVE-2026-23293 - net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled

In the Linux kernel, the following vulnerability has been resolved: net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never initialized because inet6_init() exits before ndisc_init() is called which initializes it. If an …

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

5.5

CVSS3.1

CVE-2026-23292 - scsi: target: Fix recursive locking in __configfs_open_file()

In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix recursive locking in __configfs_open_file() In flush_write_buffer, &p->frag_sem is acquired and then the loaded store function is called, which, here, is target_core_item_dbroot_store(). This function called fi…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

0.0

CVE-2026-23291 - nfc: pn533: properly drop the usb interface reference on disconnect

In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: properly drop the usb interface reference on disconnect When the device is disconnected from the driver, there is a "dangling" reference count on the usb interface that was grabbed in the probe callback. Fix this up …

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

5.5

CVSS3.1

CVE-2026-23290 - net: usb: pegasus: validate USB endpoints

In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: validate USB endpoints The pegasus driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

7.8

CVSS3.1

CVE-2026-23288 - accel/amdxdna: Fix out-of-bounds memset in command slot handling

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix out-of-bounds memset in command slot handling The remaining space in a command slot may be smaller than the size of the command header. Clearing the command header with memset() before verifying the available s…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

5.5

CVSS3.1

CVE-2026-23287 - irqchip/sifive-plic: Fix frozen interrupt due to affinity setting

In the Linux kernel, the following vulnerability has been resolved: irqchip/sifive-plic: Fix frozen interrupt due to affinity setting PLIC ignores interrupt completion message for disabled interrupt, explained by the specification: The PLIC signals it has completed executing an interrupt han…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.
Total resulsts: 349182
Page 931 of 34,919
Β« previous page Β» next page
Filters