VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,255)

  • CVE-2026-52966MedJun 24, 2026
    affected >= 6.18.32, < 6.18.33fixed 6.18.33

    In the Linux kernel, the following vulnerability has been resolved: drm: Replace old pointer to new idr Commit 5e28b7b94408 introduced a logical error by failing to replace the newly generated IDR pointer to old id's pointer at the correct location within the "change handle" lo

  • CVE-2026-52965MedJun 24, 2026
    affected >= 6.13.0, < 7.0.10fixed 7.0.10

    In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure When ttm_tt_swapout() fails, the current code calls ttm_resource_add_bulk_move() followed by ttm_resource_move_to_lru_tail() to restore the res

  • CVE-2026-52964MedJun 24, 2026
    affected >= 6.5.0, < 6.6.141fixed 6.6.141

    In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans The USB MIDI 2.0 endpoint parser has the same descriptor walking pattern as the legacy MIDI parser. It validates bLength against bNumGrpTrmBlock before

  • CVE-2026-52963MedJun 24, 2026
    affected >= 5.7.0, < 5.10.258fixed 5.10.258

    In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI endpoint descriptor scans snd_usbmidi_get_ms_info() validates the internal MIDIStreaming endpoint descriptor size before using baAssocJackID[], but the descriptor walker can still re

  • CVE-2026-52962HigJun 24, 2026
    affected >= 5.3.0, < 5.10.258fixed 5.10.258

    In the Linux kernel, the following vulnerability has been resolved: ceph: fix a buffer leak in __ceph_setxattr() The old_blob in __ceph_setxattr() can store ci->i_xattrs.prealloc_blob value during the retry. However, it is never called the ceph_buffer_put() for the old_blob obj

  • CVE-2026-52961MedJun 24, 2026
    affected >= 6.0.0, < 6.12.91fixed 6.12.91

    In the Linux kernel, the following vulnerability has been resolved: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size The generic/642 test-case can reproduce the kernel crash: [40243.605254] ------------[ cut here ]------------ [40243.605956] kernel BUG at

  • CVE-2026-52960HigJun 24, 2026
    affected >= 6.15.0, < 7.0.10fixed 7.0.10

    In the Linux kernel, the following vulnerability has been resolved: ceph: put folios not suitable for writeback The batch holds references to the folios (see `filemap_get_folios`, `folio_batch_release`), so we need to `folio_put` the folios we remove. Tested on v6.18.

  • CVE-2026-52959HigJun 24, 2026
    affected >= 6.14.0, < 6.18.33fixed 6.18.33

    In the Linux kernel, the following vulnerability has been resolved: virt: sev-guest: Do not use host-controlled page order in cleanup path When issuing an extended guest request (SVM_VMGEXIT_EXT_GUEST_REQUEST), get_ext_report() allocates a buffer to retrieve a certificate blob

  • CVE-2026-52958CriJun 24, 2026
    affected >= 5.3.0, < 5.10.258fixed 5.10.258

    In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The cep

  • CVE-2026-52957HigJun 24, 2026
    affected >= 4.13.0, < 5.10.258fixed 5.10.258

    In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential null-ptr-deref in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an array of

  • CVE-2026-52956HigJun 24, 2026
    affected >= 4.10.0, < 7.0.10fixed 7.0.10

    In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct is accessed. This ha

  • CVE-2026-52955CriJun 24, 2026
    affected >= 2.6.34, < 5.10.258fixed 5.10.258

    In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algorithm. If the values in the

  • CVE-2026-52954HigJun 24, 2026
    affected >= 4.13.0, < 5.10.258fixed 5.10.258

    In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally contain choose_args

  • CVE-2026-52953HigJun 24, 2026
    affected >= 6.6.0, < 6.18.33fixed 6.18.33

    In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix oops due to out of scope access Below oops triggers when kill QEMU process: Oops: general protection fault, probably for non-canonical address 0x7fffffff844eaaa7: 0000 [#1] SMP NOPTI Call T

  • CVE-2026-52952HigJun 24, 2026
    affected >= 7.0.0, < 7.0.10fixed 7.0.10

    In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset In __iommu_group_set_domain_internal(), concurrent domain attachments are rejected when any device in the group is recovering. This is necess

  • CVE-2026-52951HigJun 24, 2026
    affected >= 6.8.0, < 6.12.91fixed 6.12.91

    In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: handle empty bo and UAF races There look to be some nasty races here when triggering the invalidate_mappings hook: 1) We do xe_bo_alloc() followed by the attach, before the actual full bo in

  • CVE-2026-52950HigJun 24, 2026
    affected >= 6.18.0, < 6.18.33fixed 6.18.33

    In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry doesn't work here, since bo will be freed on error, leading to UAF. However, now that we do the alloc & init before the attach, we can now combine this as one unit

  • CVE-2026-52949MedJun 24, 2026
    affected >= 6.15.0, < 7.0.10fixed 7.0.10

    In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure Apply the same fix as b2ed01e7ad ("drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure") to the ttm_bo_shrink() path. Move del_bu

  • CVE-2026-52948MedJun 24, 2026
    affected >= 2.6.29, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzkaller, a persistent `schedule_timeout: wrong timeout value` warning was observed, accompanied by SMBus controller state machine cor

  • CVE-2026-52947HigJun 24, 2026
    affected >= 4.7.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove In qrtr_port_remove(), the socket reference count is decremented via __sock_put() before the port is removed from the qrtr_ports XArray a

Page 143 of 713