VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,255)

  • CVE-2026-53366HigJul 16, 2026
    affected >= 6.0.0, < 6.1.178fixed 6.1.178

    In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen

  • CVE-2026-53365MedJul 13, 2026
    affected >= 6.7.0, < 6.12.97fixed 6.12.97

    In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb sends When a large message is fragmented into multiple skbs, the zerocopy uarg is only allocated and attached to the last skb in the loop. Non-final skbs carr

  • CVE-2026-53364MedJul 13, 2026
    affected >= 6.17.0, < 6.18.35fixed 6.18.35

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but returns 0 without freeing it when neither pa_sync_term nor big_sync_term flags a

  • CVE-2026-53363CriJul 10, 2026
    affected >= 6.14.0, < 6.18.36fixed 6.18.36

    In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket buffer to another but fails to propagate the SKBFL_SHARED_FRAG flag. This is the

  • CVE-2026-53362HigKEVJul 4, 2026
    affected >= 6.0.0, < 6.1.177fixed 6.1.177

    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen

  • CVE-2026-53361HigJul 4, 2026
    affected < 6.1.183fixed 6.1.183

    In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2

  • CVE-2026-53360HigJul 4, 2026
    affected >= 6.10.0, < 6.12.93fixed 6.12.93

    In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things like Page State Chan

  • CVE-2026-53359HigJul 4, 2026
    affected >= 2.6.36, < 6.1.177fixed 6.1.177

    In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and comp

  • CVE-2026-53358HigJul 2, 2026
    affected >= 3.4.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock. cleanup_listen() runs under the parent sk_l

  • CVE-2026-53357HigJul 2, 2026
    affected >= 5.7.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returning, so the returned s

  • CVE-2026-53356HigJul 1, 2026
    affected >= 5.7.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset sg_page() returns struct page pointer not (void *) so the scaling of pread/pwrite is wrong for phys BO and wrong parts of BO would be accessed if non-zero offs

  • CVE-2026-53355CriJul 1, 2026
    affected >= 4.11.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. It uses NULL pointers to distinguish resources that

  • CVE-2026-53354HigJul 1, 2026
    affected >= 3.7.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm CPUs A number of CPUs developed by Arm suffer from errata whereby a broadcast TLBI;DSB sequence may complete before the global observation of writes which are

  • CVE-2026-53353MedJul 1, 2026
    affected >= 3.17.0, < 6.6.143fixed 6.6.143

    In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syzbot reported the warning [0] in hsr_addr_is_self(), whose assumption is simply wrong. hsr->self_node is cleared in hsr_del_self_node(), which is called from hs

  • CVE-2026-53352MedJul 1, 2026
    affected >= 3.0.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() When a multi-threaded process receives a stop signal (e.g., SIGSTOP), do_signal_stop() sets JOBCTL_STOP_PENDING and JOBCTL_STOP_CONSUME on all

  • CVE-2026-53351MedJul 1, 2026
    affected >= 7.0.0, < 7.0.13fixed 7.0.13

    In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI Fixes a warning while dumping core: [54983.546369][ C7] WARNING: [!note_name] fs/binfmt_elf.c:1771 at elf_core_dump+0x910/0xf68, CPU#7: abort01/31982

  • CVE-2026-53350MedJul 1, 2026
    affected >= 5.16.0, < 6.1.176fixed 6.1.176

    In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_control_remove() check that the priv pointer is not NULL before attempting to cleanup what it points to. When cs_dsp creates a con

  • CVE-2026-53349MedJul 1, 2026
    affected >= 2.6.20, < 6.1.176fixed 6.1.176

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister NAT helpers such as nf_nat_h323 store a raw pointer to module text in exp->expectfn (e.g. ip_nat_q931_expect). nf_ct_helper_expectfn_un

  • CVE-2026-53348MedJul 1, 2026
    affected >= 6.19.0, < 7.0.13fixed 7.0.13

    In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions sdca_dev_unregister_functions() iterates over all SDCA function descriptors and calls sdca_dev_unregister() on each func_dev without che

  • CVE-2026-53347MedJul 1, 2026
    affected >= 6.4.0, < 6.6.143fixed 6.6.143

    In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu driver built with disabled KMS, leading to access of uninitialized data on driver removal/unbinding a

Page 123 of 713