VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2026-90431Sep 17, 2026
    affected >= 3.7.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: remoteproc: Prevent crash handling to race with rproc_del() There's no synchronization between rproc_crash_handler_work() and rproc_del(), as such it's possible for a driver to be removed while crash-handler wo

  • CVE-2026-90430Sep 17, 2026
    affected >= 6.12.0, < 6.12.111fixed 6.12.111

    In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized tegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to the vintf->lvcmdqs[] array, before tegra241_vcmdq_alloc_smmu

  • CVE-2026-90429HigSep 17, 2026
    affected >= 6.17.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init A user VINTF is torn down by tegra241_cmdqv_deinit_vintf(), which runs from the destroy callback and from the init-failure unwind in the al

  • CVE-2026-90428Sep 17, 2026
    affected >= 6.12.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs __tegra241_cmdqv_probe() requests the error IRQ before it has allocated the cmdqv->vintfs array and set cmdqv->num_vintfs. A CMDQV left

  • CVE-2026-90427HigSep 17, 2026
    affected >= 6.12.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() __tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger tegra241_cmdqv, which frees the original @smmu once it rel

  • CVE-2026-90426Sep 17, 2026
    affected >= 6.12.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq(). Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An

  • CVE-2026-90425HigSep 17, 2026
    affected >= 6.17.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID tegra241_vintf_init_vsid() maps a guest vSID to a single physical Stream ID taken from master->streams[0], and only warns when the device does not

  • CVE-2026-90424Sep 17, 2026
    affected >= 6.12.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path tegra241_cmdqv_init_structures() allocates VINTF0 with kzalloc_obj(), inits it, and preallocates its logical VCMDQs. Two of its error paths leak.

  • CVE-2026-90423HigSep 17, 2026
    affected >= 6.15.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix UAF in ODP init error-handling path rxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before calling rxe_odp_init_pages(). If rxe_odp_init_pages() fails, rxe_odp_mr_init_user() releases um

  • CVE-2026-90422Sep 17, 2026
    affected >= 6.2.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path When mtk_clk_register_pllfhs function fails to register a PLL, it unregisters all PLLs and cleans up itself in its error path before ret

  • CVE-2026-90421Sep 17, 2026
    affected >= 2.6.30, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: PCI: Fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only guaranteed to be valid when dynids.lock is held, as remove_id_store() can free the node. Thus, make a copy in pci_match_device(). A

  • CVE-2026-90420Sep 17, 2026
    affected >= 2.6.30, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix infinite loop in nilfs_clean_segments() syzbot reported a hung task in nilfs_transaction_begin(). This occurs because the cleaner ioctl falls into an infinite loop if nilfs_segctor_construct() repea

  • CVE-2026-90419HigSep 17, 2026
    affected >= 2.6.30, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of-bounds read in super root block parsing super-root inode metadata size is trusted before nilfs_read_inode_common(). Reject super-root inode sizes whose computed on-disk footprint exceeds

  • CVE-2026-90418Sep 17, 2026
    affected >= 3.10.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch Syzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(), which copies dirty DAT file folios/pages to its shadow page cache. Th

  • CVE-2026-90417Sep 17, 2026
    affected >= 4.8.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry() When the device is in the fatal error state, write_tpt_entry() returns -EIO before handing the caller's preallocated skb to the transmit path;

  • CVE-2026-90416Sep 17, 2026
    affected >= 4.14.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs get_param() reads a congestion parameter as a u32 but formats it with the signed "%d" into an 11-byte stack buffer. A value with bit 31 set, such as

  • CVE-2026-90415Sep 17, 2026
    affected >= 3.5.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: free STAG index when TPT entry write fails write_tpt_entry() allocates a new STAG index with c4iw_get_resource() and bumps stats.stag.cur before programming the entry. When write_adapter_mem() fail

  • CVE-2026-90414CriSep 17, 2026
    affected >= 3.10.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was received isert_recv_done() hands each received PDU to the opcode handlers without ever looking at wc->byte_len, the number of bytes the HCA actually placed in

  • CVE-2026-90413CriSep 17, 2026
    affected >= 3.10.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data than was received isert_login_recv_done() records how many bytes the HCA actually placed in the login buffer, but nothing compares that against the length the log

  • CVE-2026-90412Sep 17, 2026
    affected >= 6.13.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: nvmet: fix return status of RMI log page on allocation failure nvmet_execute_get_log_page_rmi() leaves 'status' holding NVME_SC_SUCCESS (set by the successful nvmet_req_find_ns() call) when the kzalloc() for th

Page 12 of 789