linux package
kernel
pkg:linux/kernel
Vulnerabilities (16,579)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-98374 | — | >= 5.11.0, < 5.15.222 | 5.15.222 | Oct 7, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() When tcp_send_synack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcp_rtx_queue_u | ||
| CVE-2026-98373 | — | >= 6.0.0, < 6.12.112 | 6.12.112 | Oct 7, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: preserve mremap address delta when skipping page tables move_hugetlb_page_tables() optimizes mremap() by advancing to the last entry in the page table when the source page table does not exist, eith | ||
| CVE-2026-98372 | — | >= 6.14.0, < 6.18.54 | 6.18.54 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() iptfs_skb_reset_frag_walk() advances to the fragment containing @offset with an unbounded loop: while (offset >= walk->past + walk->frags[walk->f | ||
| CVE-2026-98371 | — | >= 6.14.0, < 6.18.54 | 6.18.54 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short inner tot_len When the start of an inner packet is split across two outer packets such that fewer than 4 bytes land at the end of the first one, __input_process | ||
| CVE-2026-98370 | — | >= 5.10.0, < 5.10.271 | 5.10.271 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi | ||
| CVE-2026-98369 | Hig | 7.8 | < 5.15.222 | 5.15.222 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): WARNING: suspicious RCU usage in ip6_pkt_drop i | |
| CVE-2026-98368 | Hig | 7.8 | >= 6.0.0, < 6.1.189 | 6.1.189 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutating skb frags On the out-of-place output path (esp->inplace == false) ESP rewrites the skb frag array: esp_output_head() appends a trailer frag and esp_output_t | |
| CVE-2026-98367 | Hig | 7.8 | >= 5.3.0, < 5.10.271 | 5.10.271 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did. Otherwise if siw_qp_modif | |
| CVE-2026-98366 | Hig | 7.8 | >= 6.5.0, < 6.6.158 | 6.6.158 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: validate access flags before swapping the MR's PD rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument: if (flags & IB_MR_REREG_PD) { rxe_put(old | |
| CVE-2026-98365 | Cri | 9.8 | >= 4.8.0, < 6.6.158 | 6.6.158 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: if (iova | |
| CVE-2026-98364 | Hig | 7.8 | >= 2.6.25, < 7.2.8 | 7.2.8 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: hold net_device reference under RCU in bundle creation xfrm_bundle_create() and xfrm_create_dummy_bundle() read dst->dev into a local pointer without taking a device reference, then pass it to xfrm_fill_d | |
| CVE-2026-98363 | — | >= 4.4.0, < 5.10.271 | 5.10.271 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds | ||
| CVE-2026-98362 | — | >= 4.4.0, < 5.10.271 | 5.10.271 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large | ||
| CVE-2026-98361 | Hig | 7.8 | >= 6.16.0, < 6.18.54 | 6.18.54 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages") dropped the access permission test from rxe_check_pagefault() and left only H | |
| CVE-2026-98360 | Hig | 7.0 | >= 5.18.0, < 6.1.189 | 6.1.189 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds rxe_get_mcg() publishes a newly allocated multicast group in rxe->mcg_tree before programming the backing Ethernet multicast address with r | |
| CVE-2026-98359 | Hig | 7.0 | >= 4.14.0, < 6.1.189 | 6.1.189 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Reject unregistering netdevs in ib_get_eth_speed ib_device_get_netdev() intentionally returns a referenced net_device even when it is unregistering, so matching and cleanup callers can still find the | |
| CVE-2026-98358 | — | >= 4.5.0, < 5.10.271 | 5.10.271 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: IB/iser: reject a remote invalidation of an unregistered direction A write command whose data is sent entirely as immediate data is not registered. iser_reg_mem_fastreg() takes the DMA key path and leaves rdma | ||
| CVE-2026-98357 | Hig | 8.1 | >= 3.10.0, < 5.10.271 | 5.10.271 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: wait for deferred control PDU completions before releasing the connection isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and ISTATE_SEND_TEXTRSP completions off to isert_comp_wq an | |
| CVE-2026-98356 | — | >= 6.14.0, < 6.18.54 | 6.18.54 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB handler later calls queue_work() on the NULL pointer. | ||
| CVE-2026-98355 | — | >= 6.1.0, < 7.2.8 | 7.2.8 | Oct 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: guard against null kobj name In the client, if `init_path()` errors, the callee tries to clean up with `rtrs_clt_close_conns()`. However, this can lead to calling the event tracing code with `clt_pat |
- CVE-2026-98374Oct 7, 2026affected >= 5.11.0, < 5.15.222fixed 5.15.222
In the Linux kernel, the following vulnerability has been resolved: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() When tcp_send_synack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcp_rtx_queue_u
- CVE-2026-98373Oct 7, 2026affected >= 6.0.0, < 6.12.112fixed 6.12.112
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: preserve mremap address delta when skipping page tables move_hugetlb_page_tables() optimizes mremap() by advancing to the last entry in the page table when the source page table does not exist, eith
- CVE-2026-98372Oct 6, 2026affected >= 6.14.0, < 6.18.54fixed 6.18.54
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() iptfs_skb_reset_frag_walk() advances to the fragment containing @offset with an unbounded loop: while (offset >= walk->past + walk->frags[walk->f
- CVE-2026-98371Oct 6, 2026affected >= 6.14.0, < 6.18.54fixed 6.18.54
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short inner tot_len When the start of an inner packet is split across two outer packets such that fewer than 4 bytes land at the end of the first one, __input_process
- CVE-2026-98370Oct 6, 2026affected >= 5.10.0, < 5.10.271fixed 5.10.271
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi
- affected < 5.15.222fixed 5.15.222
In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): WARNING: suspicious RCU usage in ip6_pkt_drop i
- affected >= 6.0.0, < 6.1.189fixed 6.1.189
In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutating skb frags On the out-of-place output path (esp->inplace == false) ESP rewrites the skb frag array: esp_output_head() appends a trailer frag and esp_output_t
- affected >= 5.3.0, < 5.10.271fixed 5.10.271
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did. Otherwise if siw_qp_modif
- affected >= 6.5.0, < 6.6.158fixed 6.6.158
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: validate access flags before swapping the MR's PD rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument: if (flags & IB_MR_REREG_PD) { rxe_put(old
- affected >= 4.8.0, < 6.6.158fixed 6.6.158
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: if (iova
- affected >= 2.6.25, < 7.2.8fixed 7.2.8
In the Linux kernel, the following vulnerability has been resolved: xfrm: hold net_device reference under RCU in bundle creation xfrm_bundle_create() and xfrm_create_dummy_bundle() read dst->dev into a local pointer without taking a device reference, then pass it to xfrm_fill_d
- CVE-2026-98363Oct 6, 2026affected >= 4.4.0, < 5.10.271fixed 5.10.271
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds
- CVE-2026-98362Oct 6, 2026affected >= 4.4.0, < 5.10.271fixed 5.10.271
In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large
- affected >= 6.16.0, < 6.18.54fixed 6.18.54
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages") dropped the access permission test from rxe_check_pagefault() and left only H
- affected >= 5.18.0, < 6.1.189fixed 6.1.189
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds rxe_get_mcg() publishes a newly allocated multicast group in rxe->mcg_tree before programming the backing Ethernet multicast address with r
- affected >= 4.14.0, < 6.1.189fixed 6.1.189
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Reject unregistering netdevs in ib_get_eth_speed ib_device_get_netdev() intentionally returns a referenced net_device even when it is unregistering, so matching and cleanup callers can still find the
- CVE-2026-98358Oct 6, 2026affected >= 4.5.0, < 5.10.271fixed 5.10.271
In the Linux kernel, the following vulnerability has been resolved: IB/iser: reject a remote invalidation of an unregistered direction A write command whose data is sent entirely as immediate data is not registered. iser_reg_mem_fastreg() takes the DMA key path and leaves rdma
- affected >= 3.10.0, < 5.10.271fixed 5.10.271
In the Linux kernel, the following vulnerability has been resolved: IB/isert: wait for deferred control PDU completions before releasing the connection isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and ISTATE_SEND_TEXTRSP completions off to isert_comp_wq an
- CVE-2026-98356Oct 6, 2026affected >= 6.14.0, < 6.18.54fixed 6.18.54
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB handler later calls queue_work() on the NULL pointer.
- CVE-2026-98355Oct 6, 2026affected >= 6.1.0, < 7.2.8fixed 7.2.8
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: guard against null kobj name In the client, if `init_path()` errors, the callee tries to clean up with `rtrs_clt_close_conns()`. However, this can lead to calling the event tracing code with `clt_pat
Page 1 of 829