VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,255)

  • CVE-2026-52946HigJun 24, 2026
    affected >= 2.6.12, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in send_sigio() and send_sigurg() when a process group receives a signal. When FASYNC

  • CVE-2026-52945HigJun 24, 2026
    affected >= 5.15.186, < 5.15.201fixed 5.15.201

    In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" This reverts commit 933466fc50a8e4eb167acbd0d8ec96a078462e9c which is commit db9ae3b6b43c79b1ba87eea849fd65efa05b4b2e upstream. We have had three independent pr

  • CVE-2026-52944MedJun 24, 2026
    affected >= 5.15.0, < 6.6.143fixed 6.6.143

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE FSCTL_SET_SPARSE in fsctl_set_sparse() modifies the file's sparse attribute and saves it through xattr without any permission

  • CVE-2026-52943HigJun 24, 2026
    affected >= 4.7.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy the old skb_shared_info header into a new buffer via memcpy(), which incl

  • CVE-2026-52942HigJun 24, 2026
    affected >= 2.6.36, < 5.10.261fixed 5.10.261

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback path of dump_mac_header() guards the MAC header access only with "skb->mac_header != skb->network_header", without checking skb_mac_

  • CVE-2026-52941MedJun 24, 2026
    affected >= 5.16.0, < 6.1.175fixed 6.1.175

    In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint The smc_msg_event tracepoint class, shared by smc_tx_sendmsg and smc_rx_recvmsg, unconditionally dereferences smc->conn.lnk: __string(name, s

  • CVE-2026-52940MedJun 24, 2026
    affected >= 6.17.0, < 6.18.36fixed 6.18.36

    In the Linux kernel, the following vulnerability has been resolved: tun: zero the whole vnet header in tun_put_user() tun_put_user() declares an on-stack struct virtio_net_hdr_v1_hash_tunnel without zeroing it. For a non-tunnel skb, virtio_net_hdr_tnl_from_skb() only initialize

  • CVE-2026-52939MedJun 24, 2026
    affected >= 2.6.37, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion rds_ib_xmit_atomic() always programs a masked atomic opcode (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD

  • CVE-2026-52938MedJun 24, 2026
    affected >= 7.0.0, < 7.0.14fixed 7.0.14

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereference in bpf_sk_storage_clone and diag paths bpf_selem_unlink_nofail() sets SDATA(selem)->smap to NULL before removing the selem from the storage hlist. A concurrent RCU reader in bp

  • CVE-2026-52937MedJun 24, 2026
    affected >= 5.12.0, < 6.18.34fixed 6.18.34

    In the Linux kernel, the following vulnerability has been resolved: tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR In the SIOCGIFHWADDR path, tap_ioctl() copies 16 bytes of an uninitialised on-stack struct sockaddr_storage to userspace via ifr_hwaddr, but netif_get_mac_a

  • CVE-2026-52936MedJun 24, 2026
    affected >= 4.2.0, < 6.6.141fixed 6.6.141

    In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock with mutex jent_kcapi_random() serializes the shared jitterentropy state, but it currently holds a spinlock across the jent_read_entropy() call. That path perf

  • CVE-2026-52935HigJun 24, 2026
    affected >= 5.6.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial send espintcp keeps a single in-flight transmit in ctx->partial. Before building a new sk_msg, espintcp_sendmsg() first tries to flush that state through espi

  • CVE-2026-52934HigJun 24, 2026
    affected >= 3.13.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets batadv_tvlv_container_ogm_append() builds a TVLV packet section from the tvlv.container_list. The total size of this section is computed by batadv_tvlv_container_

  • CVE-2026-52933HigJun 24, 2026
    affected >= 6.1.0, < 6.1.175fixed 6.1.175

    In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath: if (unlikely(atomic_r

  • CVE-2026-52932HigJun 24, 2026
    affected >= 6.15.0, < 6.18.35fixed 6.18.35

    In the Linux kernel, the following vulnerability has been resolved: xfrm: ipcomp: Free destination pages on acomp errors Move the out_free_req label up by a couple of lines so that the allocated dst SG list gets freed on error as well as success.

  • CVE-2026-52931CriJun 24, 2026
    affected >= 4.8.0, < 5.10.258fixed 5.10.258

    In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and batadv_tp_stop() are only valid for tp_vars in the BATADV_TP_SENDER role. When called with a BATADV_TP_RECEIVER role, it proceeds t

  • CVE-2026-52930MedJun 24, 2026
    affected >= 3.1.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch updates shm_destroy_orphaned() walks the shm idr under shm_ids(ns).rwsem, but that does not serialize all fields tested by shm_may_destroy(). In particular, sh

  • CVE-2026-52929HigJun 24, 2026
    affected >= 4.15.0, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream state When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and then lowers outcnt. That leaves removed stream metadata behind, so a later re-add ca

  • CVE-2026-52928MedJun 24, 2026
    affected >= 5.15.0, < 5.15.211fixed 5.15.211

    In the Linux kernel, the following vulnerability has been resolved: af_unix: Reject SIOCATMARK on non-stream sockets SIOCATMARK reports whether the receive queue is at the urgent mark for MSG_OOB. In AF_UNIX, MSG_OOB is supported only for SOCK_STREAM sockets. SOCK_DGRAM and SO

  • CVE-2026-52927HigJun 24, 2026
    affected >= 2.6.34, < 5.10.259fixed 5.10.259

    In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_from_user Luxiao Xu says: The function compat_mtw_from_user() converts ebtables extensions from 32-bit user structures to kernel native structures. However, it

Page 144 of 713