VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,254)

  • CVE-2026-64014Jul 19, 2026
    affected >= 2.6.34, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size nexio_read_data() pulls data_len and x_len from a packed __be16 header in the device's interrupt packet and then walks packet->data[0..x_len

  • CVE-2026-64013Jul 19, 2026
    affected >= 6.15.0, < 7.0.12fixed 7.0.12

    In the Linux kernel, the following vulnerability has been resolved: ACPI: button: Fix ACPI GPE handler leak during removal Commit a7e23ec17fee ("ACPI: button: Install notifier for system events as well") changed the ACPI notify handler type for ACPI buttons to ACPI_ALL_NOTIFY,

  • CVE-2026-64012Jul 19, 2026
    affected >= 2.6.39, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked When sfb has children (eg qfq qdisc) whose peek() callback is qdisc_peek_dequeued(), we could get a kernel panic. When the pare

  • CVE-2026-64011HigJul 19, 2026
    affected >= 3.11.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: Fix use-after-free in llcp_sock_release() llcp_sock_release() unconditionally unlinks the socket from the local sockets list. However, if the socket is still in connecting state, it is on the connec

  • CVE-2026-64010HigJul 19, 2026
    affected >= 3.6.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() A race condition exists in the NFC LLCP connection state machine where the connection acceptance packet (CC) can be processed concurrently with socket re

  • CVE-2026-64009HigJul 19, 2026
    affected >= 2.6.22, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: xfrm: Check for underflow in xfrm_state_mtu Leo Lin reported OOB write issue in esp component: xfrm_state_mtu() returns u32 but performs its arithmetic in unsigned modulo-2^32 space using an attacker-influ

  • CVE-2026-64008HigJul 19, 2026
    affected >= 6.18.0, < 6.18.35fixed 6.18.35

    In the Linux kernel, the following vulnerability has been resolved: accel/rocket: fix UAF via dangling GEM handle in create_bo rocket_ioctl_create_bo() inserts a GEM handle into the file's IDR via drm_gem_handle_create() early on, then performs several operations that can fail

  • CVE-2026-64007CriJul 19, 2026
    affected >= 3.12.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inet_proto_csum_replace4() on the caller-s

  • CVE-2026-64006Jul 19, 2026
    affected >= 5.6.0, < 6.6.143fixed 6.6.143

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix dst corruption in same register operation For lshift and rshift, the shift operations are performed in a loop over 32-bit words. The loop calculates the shifted value and write it to d

  • CVE-2026-64005HigJul 19, 2026
    affected >= 4.11.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: net/smc: Do not re-initialize smc hashtables INIT_HLIST_HEAD(&smc_v*_hashinfo.ht) are called after smc_nl_init(), proto_register() and sock_register(). This can lead to smc_v*_hashinfo.ht being reset even thoug

  • CVE-2026-64004HigJul 19, 2026
    affected >= 3.4.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix locking in .getsockopt Mirror iucv_sock_setsockopt() and wrap the whole switch in lock_sock()/release_sock(). The pre-existing SO_MSGLIMIT-only lock becomes redundant and is removed. Any AF_IUCV

  • CVE-2026-64003HigJul 19, 2026
    affected >= 6.5.0, < 6.6.143fixed 6.6.143

    In the Linux kernel, the following vulnerability has been resolved: scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues While a SCSI host is in a recovery state, scsi_mq_requeue_cmd() will not set the requeue list for a requeued command to be kicked in

  • CVE-2026-64002HigJul 19, 2026
    affected >= 3.16.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl

  • CVE-2026-64001Jul 19, 2026
    affected >= 2.6.17, < 6.12.93fixed 6.12.93

    In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix setup list UAF on proc write error snd_pcm_oss_proc_write() links a newly allocated setup entry into the OSS setup list before duplicating the task name. If the task-name allocation fails, t

  • CVE-2026-64000CriJul 19, 2026
    affected >= 5.16.0, < 6.1.176fixed 6.1.176

    In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the entire TLV header is linearized before access by adding sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this, a trunc

  • CVE-2026-63999Jul 19, 2026
    affected >= 6.15.0, < 6.18.35fixed 6.18.35

    In the Linux kernel, the following vulnerability has been resolved: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure rss_prepare_get() allocates the indirection table and hash key buffer via rss_get_data_alloc(), then calls ops->get_rxfh() to populate them. If ge

  • CVE-2026-63998Jul 19, 2026
    affected >= 6.11.0, < 6.18.35fixed 6.18.35

    In the Linux kernel, the following vulnerability has been resolved: ethtool: module: call ethnl_ops_complete() on module flash errors When validate() fails we are skipping over ethnl_ops_complete() even tho we already called ethnl_ops_begin().

  • CVE-2026-63997Jul 19, 2026
    affected >= 6.11.0, < 6.12.93fixed 6.12.93

    In the Linux kernel, the following vulnerability has been resolved: ethtool: module: avoid leaking a netdev ref on module flash errors module_flash_fw_schedule() is missing undo for setting the "in_progress" flag and taking the netdev reference. Delay taking these, the device c

  • CVE-2026-63996HigJul 19, 2026
    affected >= 6.11.0, < 6.12.93fixed 6.12.93

    In the Linux kernel, the following vulnerability has been resolved: ethtool: cmis: require exact CDB reply length Malicious SFP module could respond with rpl_len longer than what cmis_cdb_process_reply() expected, leading to OOB writes. Malicious HW is a bit theoretical but som

  • CVE-2026-63995HigJul 19, 2026
    affected >= 6.11.0, < 6.12.93fixed 6.12.93

    In the Linux kernel, the following vulnerability has been resolved: ethtool: cmis: validate start_cmd_payload_size from module The CMIS firmware update code reads start_cmd_payload_size from the module's FW Management Features CDB reply and uses it directly as the byte count fo

Page 110 of 713