5.5

CVSS3.1

CVE-2026-23060 - crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec authencesn assumes an ESP/ESN-formatted AAD. When assoclen is shorter than the minimum expected length, crypto_authenc_esn_decrypt() can advance past th…

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 11:45 p.m.

7.1

CVSS3.1

CVE-2026-23099 - bonding: limit BOND_MODE_8023AD to Ethernet devices

In the Linux kernel, the following vulnerability has been resolved: bonding: limit BOND_MODE_8023AD to Ethernet devices BOND_MODE_8023AD makes sense for ARPHRD_ETHER only. syzbot reported: BUG: KASAN: global-out-of-bounds in __hw_addr_create net/core/dev_addr_lists.c:63 [inline] BUG: KASAN: g…

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 11:45 p.m.

5.5

CVSS3.1

CVE-2026-23104 - ice: fix devlink reload call trace

In the Linux kernel, the following vulnerability has been resolved: ice: fix devlink reload call trace Commit 4da71a77fc3b ("ice: read internal temperature sensor") introduced internal temperature sensor reading via HWMON. ice_hwmon_init() was added to ice_init_feature() and ice_hwmon_exit() was …

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 11:45 p.m.

7.8

CVSS3.1

CVE-2026-23066 - rxrpc: Fix recvmsg() unconditional requeue

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recvmsg() unconditional requeue If rxrpc_recvmsg() fails because MSG_DONTWAIT was specified but the call at the front of the recvmsg queue already has its mutex locked, it requeues the call - whether or not the call is…

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 7 a.m.

4.7

CVSS3.1

CVE-2026-23101 - leds: led-class: Only Add LED to leds_list when it is fully ready

In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it is fully ready Before this change the LED was added to leds_list before led_init_core() gets called adding it the list before led_classdev.set_brightness_work gets initialized. …

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 6:30 p.m.

5.5

CVSS3.1

CVE-2026-23093 - ksmbd: smbd: fix dma_unmap_sg() nents

In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbd: fix dma_unmap_sg() nents The dma_unmap_sg() functions should be called with the same nents as the dma_map_sg(), not the value the map function returned.

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2 p.m.

7.8

CVSS3.1

CVE-2026-23068 - spi: spi-sprd-adi: Fix double free in probe error path

In the Linux kernel, the following vulnerability has been resolved: spi: spi-sprd-adi: Fix double free in probe error path The driver currently uses spi_alloc_host() to allocate the controller but registers it using devm_spi_register_controller(). If devm_register_restart_handler() fails, the co…

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2 p.m.

7.0

CVSS3.1

CVE-2026-23046 - virtio_net: fix device mismatch in devm_kzalloc/devm_kfree

In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix device mismatch in devm_kzalloc/devm_kfree Initial rss_hdr allocation uses virtio_device->device, but virtnet_set_queues() frees using net_device->device. This device mismatch causing below devres warning [ 3788.…

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:15 p.m.

5.5

CVSS3.1

CVE-2026-23043 - btrfs: fix NULL pointer dereference in do_abort_log_replay()

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix NULL pointer dereference in do_abort_log_replay() Coverity reported a NULL pointer dereference issue (CID 1666756) in do_abort_log_replay(). When btrfs_alloc_path() fails in replay_one_buffer(), wc->subvol_path is NULL…

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:15 p.m.

7.8

CVSS3.1

CVE-2026-23077 - mm/vma: fix anon_vma UAF on mremap() faulted, unfaulted merge

In the Linux kernel, the following vulnerability has been resolved: mm/vma: fix anon_vma UAF on mremap() faulted, unfaulted merge Patch series "mm/vma: fix anon_vma UAF on mremap() faulted, unfaulted merge", v2. Commit 879bca0a2c4f ("mm/vma: fix incorrectly disallowed anonymous VMA merges") intr…

πŸ“… Published: Feb. 4, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 7 a.m.
Total resulsts: 349182
Page 1817 of 34,919
Β« previous page Β» next page
Filters