VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2026-90391Sep 17, 2026
    affected >= 5.8.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone dmirror_fault() is called from the dmirror_read() and dmirror_write() retry loops after dmirror_do_read() or dmirror_do_write() finds a missing de

  • CVE-2026-90390Sep 17, 2026
    affected >= 6.7.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: md/bitmap: resume array on backlog_store() error path backlog_store() suspends the array before checking whether a write-mostly device exists. If no such device exists, the error path only unlocks reconfig_mute

  • CVE-2026-90389Sep 17, 2026
    affected >= 5.8.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: md: scope memalloc_noio to allocation critical sections Storing a memalloc_noio_save() token in mddev->noio_flags lets one task save the token and another task restore it. With concurrent suspend sysfs writes,

  • CVE-2026-90388HigSep 17, 2026
    affected >= 5.9.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Check atomic pool allocation result directly The non-blocking, non-coherent allocation path uses dma_alloc_from_pool(), which returns the allocated page and fills cpu_addr only on success. Do not re

  • CVE-2026-90387HigSep 17, 2026
    affected >= 6.6.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: swiotlb: Preserve allocation virtual address for dynamic pools swiotlb_alloc_tlb() can allocate from the DMA atomic pool when a decrypted pool is needed from atomic context. With CONFIG_DMA_DIRECT_REMAP, the at

  • CVE-2026-90386Sep 17, 2026
    affected >= 5.0.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices On an empty bus ENTDAA assigns nothing, so cmd->rx_len (the count of addresses left unassigned) equals master->maxdevs. The GENMASK() index master

  • CVE-2026-90385Sep 17, 2026
    affected >= 5.6.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: md/raid1: create serial pool adding rdev to array with serialize_policy=1 The following bug has been observed with kernel 7.1.3 after adding a new rdev to an existing RAID1 array with serialize_policy enabled:

  • CVE-2026-90384Sep 17, 2026
    affected >= 6.19.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: iomap: release the folio batch on iomap callback failures A sashiko review of an unrelated patch points out that the folio batch mechanism used for iomap zero range fails to release the batch in a couple error

  • CVE-2026-90383HigSep 17, 2026
    affected >= 2.6.27, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: misc: sgi-gru: remove interrupt-context page-table walks The GRU TLB miss handler walks a process's page tables without holding page-table locks or a reference to the mapped page. It also uses a kernel page-tab

  • CVE-2026-90382Sep 17, 2026
    affected >= 4.16.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length The MPDU length in the rx descriptor comes from the hardware. In monitor mode with the fcsfail filter enabled, the hardware passes up corrupted f

  • CVE-2026-90381HigSep 17, 2026
    affected >= 6.14.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() When performing channel switches on different radios within a short timeframe, channel contexts with different bands ca

  • CVE-2026-90380HigSep 17, 2026
    affected >= 6.7.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete A use-after-free issue occurs in mt76_rx_poll_complete due to a race condition. The STA has already been removed, but the rx_status still had a po

  • CVE-2026-90379HigSep 17, 2026
    affected >= 4.16.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash When an AER error occurs and the bus is hung, the register reads return 0xFFFFFFFF, causing the DMA queue state to be corrupted and resul

  • CVE-2026-90378Sep 17, 2026
    affected >= 5.12.0, < 5.15.221fixed 5.15.221

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt792x: Fix memory leak in SDIO TX path When tx_prepare_skb() returns an error in the SDIO TX path, the skb is not freed, leading to a memory leak. This can occur when zero-length frames (such as WN

  • CVE-2026-90377Sep 17, 2026
    affected >= 6.18.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix RX data queuing of RRO 3.0 For RRO 3.0, RX data released from a RRO data queue should be put to the indicator queue. The frames are processed and completed in the context of the indicator queue

  • CVE-2026-90376Sep 17, 2026
    affected < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP Problem: MCU command timeout while the firmware state is normal, and the firmware keeps showing the error log "ERROR!! NO PAUSE...". Root cause: If the MLD

  • CVE-2026-90375Sep 17, 2026
    affected >= 5.10.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix non-AQL packet accounting for MLO stations __mt76_tx_queue_skb() overrides the wcid passed by the driver with sta->drv_priv, so the wcid might incorrectly be changed after TX, causing wcid->non_

  • CVE-2026-90374Sep 17, 2026
    affected >= 6.2.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] band_idx comes from a 2-bit descriptor field (0-3) and was used directly to index dev->mt76.phys[] (size __MT_MAX_BAND == 3) and dereference

  • CVE-2026-90373Sep 17, 2026
    affected >= 6.12.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear mt7915_remove_interface() cleared the wcid mask bit with no lock held and before clearing the RCU wcid pointer. The mask is a non-atomic R

  • CVE-2026-90372HigSep 17, 2026
    affected >= 5.8.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss If a peer's VHT/HE MCS map has no supported spatial stream (all fields 0x3), the loop exits with nss == 0 and the function returned (u8)-1 (255)

Page 14 of 789