VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2026-92511HigSep 17, 2026
    affected >= 4.16.0, < 6.1.188fixed 6.1.188

    In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_cq_user() When accessing a CQ via the netlink path the only synchronization mechanism for the said CQ is rdma_restrack_get(). Currently, rdma_restrack_del()

  • CVE-2026-92510HigSep 17, 2026
    affected >= 5.13.0, < 6.1.188fixed 6.1.188

    In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_srq_user() When accessing a SRQ via the netlink path the only synchronization mechanism for the said SRQ is rdma_restrack_get(). Currently, rdma_restrack_de

  • CVE-2026-92509Sep 17, 2026
    affected >= 5.3.0, < 6.1.188fixed 6.1.188

    In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in counter_release() When accessing a counter via the netlink path the only synchronization mechanism for the said counter is rdma_restrack_get(). Currently, rdma_restrac

  • CVE-2026-92508HigSep 17, 2026
    affected >= 5.10.0, < 5.15.221fixed 5.15.221

    In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_cq() When accessing a CQ via the netlink path the only synchronization mechanism for the said CQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invo

  • CVE-2026-92507HigSep 17, 2026
    affected >= 5.10.0, < 6.1.188fixed 6.1.188

    In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_dealloc_pd_user() When accessing a PD via the netlink path the only synchronization mechanism for the said PD is rdma_restrack_get(). Currently, rdma_restrack_del()

  • CVE-2026-92506Sep 17, 2026
    affected >= 6.3.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix requested device removal race scmi_protocol_device_unrequest() drops scmi_requested_devices_mtx while notifying listeners but continues to retain the per-protocol list head. When two SCM

  • CVE-2026-92505Sep 17, 2026
    affected >= 6.17.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix undefined behavior in devid_write debugfs function When for_each_pci_segment() loop completes without finding a matching segment, the pci_seg pointer is not NULL but points to an invalid memory l

  • CVE-2026-92504HigSep 17, 2026
    affected >= 5.8.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int3400: clean up ODVP on probe failures evaluate_odvp() creates per-ODVP sysfs files before the thermal zone and later probe resources are registered. The current unwind path only calls cleanup

  • CVE-2026-92503Sep 17, 2026
    affected >= 6.10.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find() Syzbot/stress-ng reported an ABBA deadlock in ext4 when exercising concurrent xattr workloads (using the ea_inode mount/format option). The deadlock occ

  • CVE-2026-92502Sep 17, 2026
    affected >= 6.2.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: ext4: clear stale xarray tags on folios skipped during writeback In data=journal mode, the writeback thread can hit the WARN_ON_ONCE(sb_rdonly(sb)) in ext4_journal_check_start() while the superblock is being re

  • CVE-2026-92501Sep 17, 2026
    affected >= 5.5.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: ext4: drain in-flight DIO before buffered write fallback generic/746 started failing intermittently on ext3 (no-extent inodes). The test triggers 'Page cache invalidation failure on direct I/O' warnings and sub

  • CVE-2026-92500Sep 17, 2026
    affected >= 3.8.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: ext4: use fsdata to track inline data write state and fix race Instead of checking the live inode state (ext4_has_inline_data(inode) and ext4_test_inode_state(inode, EXT4_STATE_MAY_INLINE_DATA)) in the write_en

  • CVE-2026-92499Sep 17, 2026
    affected >= 2.6.19, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: ext4: validate readdir offset before accessing dirent A corrupted directory can trigger the following KASAN report when ext4_readdir() resumes from an invalid position: BUG: KASAN: use-after-free in __ext4_c

  • CVE-2026-92498Sep 17, 2026
    affected >= 3.2.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: avoid buffer overreads in WMI event handlers The following WMI event handlers currently read from the event buffer without first verifying that the message was large enough to hold the expected ev

  • CVE-2026-92497Sep 17, 2026
    affected >= 6.3.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could resul

  • CVE-2026-92496Sep 17, 2026
    affected >= 5.6.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() Currently, in ath11k_wmi_tlv_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This cou

  • CVE-2026-92495Sep 17, 2026
    affected >= 6.6.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap bnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap flags, but a read-only mapping can still retain VM_MAYWRITE. nd later be upgraded wi

  • CVE-2026-92494Sep 17, 2026
    affected >= 5.15.0, < 5.15.221fixed 5.15.221

    In the Linux kernel, the following vulnerability has been resolved: ext4: fix buffer_head leak in ext4_init_orphan_info ext4_init_orphan_info() reads orphan file blocks with ext4_bread() and stores the returned buffer_head in oi->of_binfo[i].ob_bh. If ext4_bread() succeeds but

  • CVE-2026-92493Sep 17, 2026
    affected >= 6.1.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active The crash issue may occur when modprobe amd_pstate_ut on intel platform. amd_pstate_ut: 1 amd_pstate_ut_acpi_cpc_valid success!

  • CVE-2026-92492Sep 17, 2026
    affected >= 7.1.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks cpufreq_cpu_get() returns NULL when no cpufreq policy is associated with the requested CPU, for example because the CPU is offline or the polic

Page 10 of 789