linux package
kernel
pkg:linux/kernel
Vulnerabilities (15,762)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-92491 | — | >= 6.9.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Roll back partial protocol table registration scmi_protocol_table_register() can leave earlier requests registered when a later entry in the same ID table fails. Each request retains a point | ||
| CVE-2026-92490 | — | >= 6.3.0, < 6.6.157 | 6.6.157 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unrequest devices if driver registration fails scmi_driver_register() requests protocol devices before registering the driver. If driver_register() fails, those requests remain in the global | ||
| CVE-2026-92489 | Cri | 9.8 | < 6.6.157 | 6.6.157 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless fr | |
| CVE-2026-92488 | Hig | 7.0 | >= 6.0.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destroy command fails erdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and erdma_destroy_ah() returned early when erdma_post_cmd_wait() failed, leaking the | |
| CVE-2026-92487 | — | >= 7.2.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix valid_size extension over a shared writable mapping When a shared writable mapping has its valid_size extended by a buffered write or a page fault, exfat zeroes the page-cache gap below the new valid | ||
| CVE-2026-92486 | — | >= 6.18.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix CFI mismatch in task work callback BPF subprograms use the bpf_callback_t ABI, but task work invokes the callback through a three-argument function pointer. This trips kCFI. Store and invoke the callb | ||
| CVE-2026-92485 | Hig | 7.8 | >= 6.7.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The trampoline could be corrupted by the blindly 'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier. 1. A fexit attached to a tail_call_reachable prog. 'tr->flags' | |
| CVE-2026-92484 | — | < 6.6.157 | 6.6.157 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix use-after-free in find_pos_and_ways() error path The error path releases its reference to a switch decoder before logging an error that includes the decoder name. If the released reference is th | ||
| CVE-2026-92483 | — | >= 7.0.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: liveupdate: Remember FLB retrieve() status LUO keeps track of successful retrieve attempts on an FLB. It does so to avoid multiple retrievals of the same FLB. Multiple retrievals cause problems because once the | ||
| CVE-2026-92482 | — | >= 4.1.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip The gpio_chip is allocated with device-managed memory but registered with the non-managed gpiochip_add_data(). This was harmless while the drivers w | ||
| CVE-2026-92481 | — | >= 4.18.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind mtk_eint_do_init() creates an IRQ domain, populates it with a mapping for every EINT line and installs a chained handler on the parent interrupt, but none of the | ||
| CVE-2026-92480 | — | >= 5.4.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate string descriptors The string descriptor length includes a two-byte header while the UTF-16 payload starts after it. utf16s_to_utf8s() expects a count of UTF-16 code units, not bytes. | ||
| CVE-2026-92479 | — | >= 6.19.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags The single-doorbell completion path can call ufshcd_compl_one_cqe() with a NULL CQE. If no command is associated with the completion tag, the wa | ||
| CVE-2026-92478 | — | >= 7.1.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate connected lane counts The connected lane count is used by TX equalization code to index arrays sized by UFS_MAX_LANES. Reject zero and out-of-range RX or TX lane counts before they can | ||
| CVE-2026-92477 | — | >= 5.16.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: debugfs: Reserve space for a string terminator ufs_saved_err_write() copies user input into a zero-initialized stack buffer and passes it to kstrtoint(). A write that fills the entire buffer overwrit | ||
| CVE-2026-92476 | — | >= 5.11.0, < 5.15.221 | 5.15.221 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Initialize completion before requesting IRQ kmb_ocs_aes_probe() requests the device IRQ before initializing irq_completion. Once the handler is registered it can run immediately, and ocs_aes_i | ||
| CVE-2026-90435 | Hig | 7.8 | >= 3.11.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix integer overflow of user QP buffer size set_user_buf_size() computes the QP buffer size by left-shifting the user-supplied rq.wqe_cnt and rq.wqe_shift values as signed integers. A sufficiently la | |
| CVE-2026-90434 | — | >= 2.6.33, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: isofs: release zisofs block pointer buffer head zisofs_fill_pages() reads the compressed block pointer table. The error paths release the current buffer_head, the loop also releases the old buffer_head when it | ||
| CVE-2026-90433 | — | >= 2.6.39, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: oc-tiny: switch to managed controller allocation The controller is allocated with the non-managed spi_alloc_host() while the interrupt is registered with devm_request_irq(). During removal, spi_bitbang_st | ||
| CVE-2026-90432 | — | >= 7.1.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Abort directly from the hardlockup handler scx_hardlockup() defers the abort to an irq_work because exit claiming used to take scx_sched_lock and couldn't run from NMI. The deferral is now unnecessar |
- CVE-2026-92491Sep 17, 2026affected >= 6.9.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Roll back partial protocol table registration scmi_protocol_table_register() can leave earlier requests registered when a later entry in the same ID table fails. Each request retains a point
- CVE-2026-92490Sep 17, 2026affected >= 6.3.0, < 6.6.157fixed 6.6.157
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unrequest devices if driver registration fails scmi_driver_register() requests protocol devices before registering the driver. If driver_register() fails, those requests remain in the global
- affected < 6.6.157fixed 6.6.157
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless fr
- affected >= 6.0.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destroy command fails erdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and erdma_destroy_ah() returned early when erdma_post_cmd_wait() failed, leaking the
- CVE-2026-92487Sep 17, 2026affected >= 7.2.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: exfat: fix valid_size extension over a shared writable mapping When a shared writable mapping has its valid_size extended by a buffered write or a page fault, exfat zeroes the page-cache gap below the new valid
- CVE-2026-92486Sep 17, 2026affected >= 6.18.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix CFI mismatch in task work callback BPF subprograms use the bpf_callback_t ABI, but task work invokes the callback through a three-argument function pointer. This trips kCFI. Store and invoke the callb
- affected >= 6.7.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The trampoline could be corrupted by the blindly 'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier. 1. A fexit attached to a tail_call_reachable prog. 'tr->flags'
- CVE-2026-92484Sep 17, 2026affected < 6.6.157fixed 6.6.157
In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix use-after-free in find_pos_and_ways() error path The error path releases its reference to a switch decoder before logging an error that includes the decoder name. If the released reference is th
- CVE-2026-92483Sep 17, 2026affected >= 7.0.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: liveupdate: Remember FLB retrieve() status LUO keeps track of successful retrieve attempts on an FLB. It does so to avoid multiple retrievals of the same FLB. Multiple retrievals cause problems because once the
- CVE-2026-92482Sep 17, 2026affected >= 4.1.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip The gpio_chip is allocated with device-managed memory but registered with the non-managed gpiochip_add_data(). This was harmless while the drivers w
- CVE-2026-92481Sep 17, 2026affected >= 4.18.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind mtk_eint_do_init() creates an IRQ domain, populates it with a mapping for every EINT line and installs a chained handler on the parent interrupt, but none of the
- CVE-2026-92480Sep 17, 2026affected >= 5.4.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate string descriptors The string descriptor length includes a two-byte header while the UTF-16 payload starts after it. utf16s_to_utf8s() expects a count of UTF-16 code units, not bytes.
- CVE-2026-92479Sep 17, 2026affected >= 6.19.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags The single-doorbell completion path can call ufshcd_compl_one_cqe() with a NULL CQE. If no command is associated with the completion tag, the wa
- CVE-2026-92478Sep 17, 2026affected >= 7.1.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate connected lane counts The connected lane count is used by TX equalization code to index arrays sized by UFS_MAX_LANES. Reject zero and out-of-range RX or TX lane counts before they can
- CVE-2026-92477Sep 17, 2026affected >= 5.16.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: debugfs: Reserve space for a string terminator ufs_saved_err_write() copies user input into a zero-initialized stack buffer and passes it to kstrtoint(). A write that fills the entire buffer overwrit
- CVE-2026-92476Sep 17, 2026affected >= 5.11.0, < 5.15.221fixed 5.15.221
In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Initialize completion before requesting IRQ kmb_ocs_aes_probe() requests the device IRQ before initializing irq_completion. Once the handler is registered it can run immediately, and ocs_aes_i
- affected >= 3.11.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix integer overflow of user QP buffer size set_user_buf_size() computes the QP buffer size by left-shifting the user-supplied rq.wqe_cnt and rq.wqe_shift values as signed integers. A sufficiently la
- CVE-2026-90434Sep 17, 2026affected >= 2.6.33, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: isofs: release zisofs block pointer buffer head zisofs_fill_pages() reads the compressed block pointer table. The error paths release the current buffer_head, the loop also releases the old buffer_head when it
- CVE-2026-90433Sep 17, 2026affected >= 2.6.39, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: spi: oc-tiny: switch to managed controller allocation The controller is allocated with the non-managed spi_alloc_host() while the interrupt is registered with devm_request_irq(). During removal, spi_bitbang_st
- CVE-2026-90432Sep 17, 2026affected >= 7.1.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Abort directly from the hardlockup handler scx_hardlockup() defers the abort to an irq_work because exit claiming used to take scx_sched_lock and couldn't run from NMI. The deferral is now unnecessar
Page 11 of 789