VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2026-90351Sep 17, 2026
    affected >= 6.8.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed If the WED attach for the primary PCIe function fails, the probe path still attached wed_hif2 for the secondary function, leaving the d

  • CVE-2026-90350Sep 17, 2026
    affected >= 6.15.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: reject out-of-range link ids in mt76_vif_link() mt76_vif_link() indexes mvif->link[] without validating link_id, but callers pass mvif->deflink_id / msta->deflink_id, which hold IEEE80211_LINK_UNSPE

  • CVE-2026-90349Sep 17, 2026
    affected >= 6.18.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx() When mac80211 leaves the link unspecified, mt7996_tx() substitutes the primary link id of the station or vif. That value is IEEE80211_LINK_

  • CVE-2026-90348Sep 17, 2026
    affected >= 5.5.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump On WCN3990/SNOC the MSA region is mapped with devm_memremap(MEMREMAP_WT). On arm64 such a mapping is not Normal-cacheable, so unaligned accesses to it are

  • CVE-2026-90347HigSep 17, 2026
    affected >= 4.8.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry Commit e057b9477232 ("arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates") attempted to resolve a long-standing issue with syscall

  • CVE-2026-90346Sep 17, 2026
    affected >= 5.16.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: clean up color-change beacon data on errors nl80211_color_change() calls nl80211_parse_beacon() for the beacon_next template, which can allocate params.beacon_next.mbssid_ies and .rnr_ies. A pars

  • CVE-2026-90345Sep 17, 2026
    affected >= 3.9.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix P2P action frame handling without device vif Some P2P action frame paths assume the P2P device vif is always available. That is not true when userspace sends non-P2P public action frames thr

  • CVE-2026-90344Sep 17, 2026
    affected >= 6.9.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: disconnect on CSA to channel 0 The refactor for the CSA parsing erroneously equates channel zero and no information present, leading it to ignore a CSA on an AP that advertises a switch to that

  • CVE-2026-90343HigSep 17, 2026
    affected >= 5.0.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: stop PMSR before P2P and NAN teardown PMSR request teardown must abort active measurements while the wireless_dev is still present in the driver. cfg80211_leave_locked() and cfg80211_stop_pd() a

  • CVE-2026-90342Sep 17, 2026
    affected >= 7.0.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock deadlock on arena lock failure Reported by the Sashiko AI review. arena_vm_fault() returns VM_FAULT_RETRY when it can't take arena->spinlock, but it never took mmap_lock. The fault path assu

  • CVE-2026-90341HigSep 17, 2026
    affected >= 4.12.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: firmware: coreboot: Validate table bounds The existing coreboot_table_populate() bounds checks limit individual entries to the mapped length. However, coreboot_table_probe() replaces the platform resource leng

  • CVE-2026-90340Sep 17, 2026
    affected >= 7.2.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: pinctrl: generic: free maps on pinctrl_generic_to_map() failure pinctrl_generic_to_map() parses DT configuration and allocates pinctrl maps via pinctrl_utils_reserve_map(). If subsequent steps (such as pinctrl

  • CVE-2026-90339Sep 17, 2026
    affected >= 7.2.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: powerpc/syscall: Fix syscall skip handling for seccomp and ptrace After enabling GENERIC_ENTRY on PowerPC, syscall_enter_from_user_mode() returns -1 as a sentinel to signal that seccomp or ptrace has intercepte

  • CVE-2026-90338Sep 17, 2026
    affected >= 6.15.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: keep console clock enabled for atomic writes pl011_console_write_atomic() runs from nbcon atomic context, where sleeping is not allowed. It calls clk_enable(), which takes the common-clk ena

  • CVE-2026-90337Sep 17, 2026
    affected >= 3.17.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: serial: core: do fallible allocations before the console can be registered serial_core_add_one_port() allocates uport->tty_groups after uart_configure_port(), which may register the console. If the allocation f

  • CVE-2026-90336Sep 17, 2026
    affected >= 2.6.12, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: serial: core: clear freed pointers on uart_register_driver() failure uart_register_driver() leaves drv->state pointing to freed memory when tty_alloc_driver() fails. If tty_register_driver() fails, drv->tty_dri

  • CVE-2026-90335Sep 17, 2026
    affected >= 4.3.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: tty: skip cdev_del() when no cdev is registered TTY device registration can fail before a cdev is allocated. Serial core keeps the port so setserial can still use it, and later removal passes the NULL cdev slot

  • CVE-2026-90334Sep 17, 2026
    affected >= 4.3.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: tty: clear cdev pointer after cdev_add() failure tty_cdev_add() drops the cdev reference when cdev_add() fails, but leaves driver->cdevs[index] pointing to freed memory. tty_unregister_device() later passes tha

  • CVE-2026-90333Sep 17, 2026
    affected >= 5.7.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: dm-integrity: replace forgeable discard filler with a keyed sector marker The discard-block check in dm_integrity_rw_tag() treats a stored tag of all 0xf6 bytes (DISCARD_FILLER) as proof a block was discarded a

  • CVE-2026-90332HigSep 17, 2026
    affected >= 7.0.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Flush cached MSI write before unmapping the iATU The MSI-X path already flushes any posted MSI-X write before tearing down its iATU mapping. That was added by commit c22533c66cca ("PCI: dwc: ep: F

Page 16 of 789