7.0

CVSS3.1

CVE-2026-23031 - can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak

In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak In gs_can_open(), the URBs for USB-in transfers are allocated, added to the parent->rx_submitted anchor and submitted. In the complete callback gs_usb_receive_bulk_…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 8:57 a.m.

0.0

CVE-2026-23028 - LoongArch: KVM: Fix kvm_device leak in kvm_ipi_destroy()

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix kvm_device leak in kvm_ipi_destroy() In kvm_ioctl_create_device(), kvm_device has allocated memory, kvm_device->destroy() seems to be supposed to free its kvm_device struct, but kvm_ipi_destroy() is not curren…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 1 a.m.

5.5

CVSS3.1

CVE-2025-71189 - dmaengine: dw: dmamux: fix OF node leak on route allocation failure

In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route allocation failure Make sure to drop the reference taken to the DMA master OF node also on late route allocation failures.

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 6:38 p.m.

5.5

CVSS3.1

CVE-2025-71186 - dmaengine: stm32: dmamux: fix device leak on route allocation

In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent …

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 6:43 p.m.

7.0

CVSS3.1

CVE-2026-23035 - net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv mlx5e_priv is an unstable structure that can be memset(0) if profile attaching fails. Pass netdev to mlx5e_destroy_netdev() to guarantee it will work on a valid netd…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

0.0

CVE-2026-23029 - LoongArch: KVM: Fix kvm_device leak in kvm_eiointc_destroy()

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix kvm_device leak in kvm_eiointc_destroy() In kvm_ioctl_create_device(), kvm_device has allocated memory, kvm_device->destroy() seems to be supposed to free its kvm_device struct, but kvm_eiointc_destroy() is no…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 1 a.m.

5.5

CVSS3.1

CVE-2025-71184 - btrfs: fix NULL dereference on root when tracing inode eviction

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix NULL dereference on root when tracing inode eviction When evicting an inode the first thing we do is to setup tracing for it, which implies fetching the root's id. But in btrfs_evict_inode() the root might be NULL, as …

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 6:55 p.m.

5.5

CVSS3.1

CVE-2025-71183 - btrfs: always detect conflicting inodes when logging inode refs

In the Linux kernel, the following vulnerability has been resolved: btrfs: always detect conflicting inodes when logging inode refs After rename exchanging (either with the rename exchange operation or regular renames in multiple non-atomic steps) two inodes and at least one of them is a director…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 7:16 p.m.

5.5

CVSS3.1

CVE-2026-23018 - btrfs: release path before initializing extent tree in btrfs_read_locked_inode()

In the Linux kernel, the following vulnerability has been resolved: btrfs: release path before initializing extent tree in btrfs_read_locked_inode() In btrfs_read_locked_inode() we are calling btrfs_init_file_extent_tree() while holding a path with a read locked leaf from a subvolume tree, and bt…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 8 p.m.

5.5

CVSS3.1

CVE-2026-23036 - btrfs: release path before iget_failed() in btrfs_read_locked_inode()

In the Linux kernel, the following vulnerability has been resolved: btrfs: release path before iget_failed() in btrfs_read_locked_inode() In btrfs_read_locked_inode() if we fail to lookup the inode, we jump to the 'out' label with a path that has a read locked leaf and then we call iget_failed().…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 1 a.m.
Total resulsts: 349182
Page 1874 of 34,919
Β« previous page Β» next page
Filters