0.0

CVE-2026-43105 - drm/vc4: Fix memory leak of BO array in hang state

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Fix memory leak of BO array in hang state The hang state's BO array is allocated separately with kzalloc() in vc4_save_hang_state() but never freed in vc4_free_hang_state(). Add the missing kfree() for the BO array befor…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4:45 a.m.

7.8

CVSS3.1

CVE-2026-43248 - vhost: move vdpa group bound check to vhost_vdpa

In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be as…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:41 p.m.

7.0

CVSS3.1

CVE-2026-43089 - xfrm_user: fix info leak in build_mapping()

In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_mapping() struct xfrm_usersa_id has a one-byte padding hole after the proto field, which ends up never getting set to zero before copying out to userspace. Fix that up by zeroing out the whole s…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4 a.m.

7.5

CVSS3.1

CVE-2026-43194 - net: consume xmit errors of GSO frames

In the Linux kernel, the following vulnerability has been resolved: net: consume xmit errors of GSO frames udpgro_frglist.sh and udpgro_bench.sh are the flakiest tests currently in NIPA. They fail in the same exact way, TCP GRO test stalls occasionally and the test gets killed after 10min. These…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:41 p.m.

0.0

CVE-2026-43220 - iommu/amd: serialize sequence allocation under concurrent TLB invalidations

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: serialize sequence allocation under concurrent TLB invalidations With concurrent TLB invalidations, completion wait randomly gets timed out because cmd_sem_val was incremented outside the IOMMU spinlock, allowing CMD_C…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 3:45 a.m.

7.1

CVSS3.1

CVE-2026-43166 - erofs: fix interlaced plain identification for encoded extents

In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced plain identification for encoded extents Only plain data whose start position and on-disk physical length are both aligned to the block size should be classified as interlaced plain extents. Otherwise, it mu…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:40 p.m.

0.0

CVE-2026-43103 - net: lapbether: handle NETDEV_PRE_TYPE_CHANGE

In the Linux kernel, the following vulnerability has been resolved: net: lapbether: handle NETDEV_PRE_TYPE_CHANGE lapbeth_data_transmit() expects the underlying device type to be ARPHRD_ETHER. Returning NOTIFY_BAD from lapbeth_device_event() makes sure bonding driver can not break this expectati…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 4 a.m.

7.0

CVSS3.1

CVE-2026-43161 - iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode PCIe endpoints with ATS enabled and passed through to userspace (e.g., QEMU, DPDK) can hard-lock the host when their link drops, either by surpri…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 3:45 a.m.

5.5

CVSS3.1

CVE-2026-43090 - xfrm: fix refcount leak in xfrm_migrate_policy_find

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix refcount leak in xfrm_migrate_policy_find syzkaller reported a memory leak in xfrm_policy_alloc: BUG: memory leak unreferenced object 0xffff888114d79000 (size 1024): comm "syz.1.17", pid 931 ... xfrm_po…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 1:08 p.m.

5.5

CVSS3.1

CVE-2026-43107 - xfrm: account XFRMA_IF_ID in aevent size calculation

In the Linux kernel, the following vulnerability has been resolved: xfrm: account XFRMA_IF_ID in aevent size calculation xfrm_get_ae() allocates the reply skb with xfrm_aevent_msgsize(), then build_aevent() appends attributes including XFRMA_IF_ID when x->if_id is set. xfrm_aevent_msgsize() does…

πŸ“… Published: May 6, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 2:30 a.m.
Total resulsts: 349182
Page 95 of 34,919
Β« previous page Β» next page
Filters