VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2026-90411Sep 17, 2026
    affected >= 4.10.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request __nvme_fc_init_request() maps cmd_iu and then rsp_iu for DMA. If the rsp_iu mapping fails, the original code only recorded the error and fell

  • CVE-2026-90410Sep 17, 2026
    affected >= 3.14.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: spi: davinci: switch to managed controller allocation The controller is allocated with the non-managed spi_alloc_host() while the interrupt is registered with devm_request_threaded_irq(). During removal, spi_b

  • CVE-2026-90409Sep 17, 2026
    affected >= 6.10.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Add vm_bind region with kbo range overlap check When a VM is created, caller has to specify the range of the address space carve-out set aside for mapping kernel BO's. That means vm_bind mappings o

  • CVE-2026-90408HigSep 17, 2026
    affected >= 6.3.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event() There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so the parse infrastructure does not enforce a minimum length

  • CVE-2026-90407HigSep 17, 2026
    affected >= 5.6.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so the parse infrastructure does not enforce a minimum length

  • CVE-2026-90406Sep 17, 2026
    affected >= 6.15.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: media: qcom: iris: handle runtime PM resume failure in core deinit Check the return value of pm_runtime_resume_and_get() in iris_core_deinit(). If runtime PM resume fails, skip hardware power-off operations bu

  • CVE-2026-90405Sep 17, 2026
    affected >= 7.1.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: media: stm32: dcmi: fix some error handling bugs in probe() There are a few issues here: 1) After we assign: chan = dma_request_chan(&pdev->dev, "tx"); Then the error paths need to clean up before r

  • CVE-2026-90404Sep 17, 2026
    affected >= 6.3.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_debugfs: Unregister panic notifier cros_ec_debugfs_probe() registers notifier_panic with the EC panic notifier chain. The remove path tears down debugfs and the console log, but leaves

  • CVE-2026-90403HigSep 17, 2026
    affected >= 2.6.38, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: pci: fix error path in rtl_pci_probe() In the last error path in rtl_pci_probe(), the cleanup functions are skipped due to a wrong goto label. Moreover, the successful call to rtl_init_rfkill(),

  • CVE-2026-90402HigSep 17, 2026
    affected >= 6.10.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix controller cleanup on EDL sysfs failure mhi_register_controller() adds the controller device before creating the optional trigger_edl sysfs file. If sysfs_create_file() fails, the error path

  • CVE-2026-90401HigSep 17, 2026
    affected >= 5.17.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: md: remove REQ_NOWAIT support from raid1/10/456 REQ_NOWAIT support in md personalities that can block internally is fundamentally incomplete. While reads can avoid some blocking paths, write requests can still

  • CVE-2026-90400Sep 17, 2026
    affected >= 6.7.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: md: recheck spare changes before starting sync remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended. md_start_syn

  • CVE-2026-90399HigSep 17, 2026
    affected >= 6.3.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Currently, in ath12k_wmi_mac_phy_caps_parse(), kzalloc() sizes the mac_phy_caps buffer as tot_phy_id * len, where len is clamped to min(firmware_len, si

  • CVE-2026-90398HigSep 17, 2026
    affected >= 5.6.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix stride mismatch in mac_phy_caps_parse() Currently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the mac_phy_caps buffer as tot_phy_id * len, where len is clamped to min(firmware_len

  • CVE-2026-90397Sep 17, 2026
    affected >= 6.3.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published In qcom_scm_probe(), devm_request_threaded_irq() is called before smp_store_release(&__scm, scm). Two paths can dereference __s

  • CVE-2026-90396Sep 17, 2026
    affected >= 6.17.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: block: fix dio leak on metadata mapping error A failed integrity mapping holds a dio reference, so we need to go through the full bio ending in case there were previously submitted bio's in the sequence.

  • CVE-2026-90395Sep 17, 2026
    affected >= 2.6.37, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: power: supply: isp1704_charger: cancel work on remove The USB notifier and initial VBUS detection can schedule isp->work. The remove path unregisters the notifier and power supply, but does not wait for queued

  • CVE-2026-90394Sep 17, 2026
    affected >= 5.0.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: power: supply: sc2731_charger: cancel work on remove The USB notifier and initial charger detection can schedule info->work. The remove path unregisters the notifier, but does not cancel queued or running work

  • CVE-2026-90393Sep 17, 2026
    affected >= 5.8.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF in bpf_netns_link_update_prog In bpf_netns_link_update_prog, the checks for old_prog and prog type are currently performed locklessly before acquiring netns_bpf_mutex. This creates a race

  • CVE-2026-90392HigSep 17, 2026
    affected >= 5.7.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF when reading bpf link info In bpf_link_show_fdinfo and bpf_link_get_info_by_fd, link->prog is accessed without holding any locks. If the prog is concurrently replaced via bpf_link_update,

Page 13 of 789