linux package
kernel
pkg:linux/kernel
Vulnerabilities (16,370)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-98154 | Hig | 7.0 | >= 5.12.0, < 5.15.222 | 5.15.222 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix -EIO cleanup order in queue_rq On -EIO, the RDMA queue_rq path reports a host path error and then still cleans up the command and unmaps the SQE DMA. The path error helper completes the request, | |
| CVE-2026-98153 | — | >= 6.16.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix racy access to FDP placement id array nvme_query_fdp_info() is called per-path and therefore prone to races. It populates head->nr_plids/head->plids for fdp registration. But nothing protects that pa | ||
| CVE-2026-98152 | Med | 5.5 | < 6.12.111 | 6.12.111 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix queue leak when connect backlog is exceeded When pending disconnecting queues exceed the backlog limit, the connect path only drops the device reference and leaks the newly allocated queue and i | |
| CVE-2026-98151 | — | >= 6.8.0, < 6.12.111 | 6.12.111 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic Take the following unprivileged program as an example: r0 = bpf_map_lookup_elem(...) /* PTR_TO_MAP_VALUE, offset 0 */ ... 14: r0 += r1 / | ||
| CVE-2026-98150 | Hig | 7.0 | >= 7.0.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix BPF_F_CPU validation for sparse CPU IDs BPF_F_CPU stores the target CPU ID in the upper 32 bits of the map operation flags. bpf_map_check_op_flags() currently compares that ID with num_possible_cpus(), | |
| CVE-2026-98149 | — | >= 7.0.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix percpu map update indexing with sparse CPU IDs Per-CPU array, hash, and cgroup storage map updates without BPF_F_CPU or BPF_F_ALL_CPUS use a value buffer whose per-CPU slots are packed in possible-CPU | ||
| CVE-2026-98148 | — | >= 5.13.0, < 6.18.53 | 6.18.53 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate GUD_ROTATION_0 is present in supported rotations The rotation argument to drm_plane_create_rotation_property() is set to DRM_MODE_ROTATE_0, and the device reported rotation bitmask is used as | ||
| CVE-2026-98147 | — | >= 6.12.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: printk: Don't WARN on kthread_run failure. Since __kthread_create_on_node() returns -EINTR upon SIGKILL, we should not use WARN_ON() in order to catch kthread_run() failure. | ||
| CVE-2026-98146 | — | >= 6.14.0, < 6.18.53 | 6.18.53 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain struct amdxdna_cmd_chain contains a flexible array annotated with __counted_by(command_count). Since the structure is stored in shared AMDXDNA_BO | ||
| CVE-2026-98145 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject a command chain that carries no commands A chain whose command_count is zero passes the payload length check, because struct_size(payload, data, 0) is just the header. The fill loop then d | ||
| CVE-2026-98144 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: put the chained BO when its mapping fails amdxdna_cmd_set_error() looks up the first BO of a command chain, which takes a reference, and drops it at the end of the function. The mapping of that B | ||
| CVE-2026-98143 | Hig | 7.8 | >= 6.19.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Don't read the U65 rounding mode as a storage mode Bits 15:14 of NPU_SET_{IFM,OFM}_PRECISION select the activation storage mode on U85 only. On U65 the same field holds the rounding mode, and the | |
| CVE-2026-98142 | — | >= 5.2.0, < 6.6.158 | 6.6.158 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/cirrus-qemu: Validate BAR0 size during probe The `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate framebuffer sizes. However, during PCI probe, the driver mapped BAR0 without verifying t | ||
| CVE-2026-98141 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: propagate reparse index insertion failure update_reparse_data() ignores the return value of set_reparse_index(). When index insertion fails, the code removes the just-written reparse data as cleanup but s | ||
| CVE-2026-98140 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: fix kmap_local leak in write_mft_record_nolock() error paths write_mft_record_nolock() maps the MFT record folio with kmap_local_folio(), but the pre_write_mst_fixup() and bio_add_folio() failure paths ju | ||
| CVE-2026-98139 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: only count successfully cleared runs when freeing clusters ntfs_cluster_free_from_rl_nolock() adds a run's length to nr_freed whenever the error bookkeeping condition is false, which includes cases where | ||
| CVE-2026-98138 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: do not mark the volume clean in sync_fs when errors were recorded ntfs_put_super() and the remount-read-only path both clear the dirty bit only when NVolErrors(vol) is false. ntfs_sync_fs() clears it unco | ||
| CVE-2026-98137 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: treat any nonzero dio zero-range return as an error ntfs_dio_zero_range() returns either 0 or a negative errno from blkdev_issue_zeroout(); it never returns a positive value. The zeroing failure check in | ||
| CVE-2026-98136 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound $AttrDef table walk to the loaded table size ntfs_attr_find_in_attrdef() walks the in-memory $AttrDef table, but the loop condition bounds only the start of each entry, not the whole entry: for (a | ||
| CVE-2026-98135 | — | >= 7.1.0, < 7.2.7 | 7.2.7 | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid sectors_per_cluster in the boot sector is_boot_sector_ntfs() checks the boot sector's sectors_per_cluster field with a range test that rejects 0x81..0xf3 but accepts 0 and other non-power-o |
- affected >= 5.12.0, < 5.15.222fixed 5.15.222
In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix -EIO cleanup order in queue_rq On -EIO, the RDMA queue_rq path reports a host path error and then still cleans up the command and unmaps the SQE DMA. The path error helper completes the request,
- CVE-2026-98153Sep 25, 2026affected >= 6.16.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: nvme: fix racy access to FDP placement id array nvme_query_fdp_info() is called per-path and therefore prone to races. It populates head->nr_plids/head->plids for fdp registration. But nothing protects that pa
- affected < 6.12.111fixed 6.12.111
In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix queue leak when connect backlog is exceeded When pending disconnecting queues exceed the backlog limit, the connect path only drops the device reference and leaks the newly allocated queue and i
- CVE-2026-98151Sep 25, 2026affected >= 6.8.0, < 6.12.111fixed 6.12.111
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic Take the following unprivileged program as an example: r0 = bpf_map_lookup_elem(...) /* PTR_TO_MAP_VALUE, offset 0 */ ... 14: r0 += r1 /
- affected >= 7.0.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix BPF_F_CPU validation for sparse CPU IDs BPF_F_CPU stores the target CPU ID in the upper 32 bits of the map operation flags. bpf_map_check_op_flags() currently compares that ID with num_possible_cpus(),
- CVE-2026-98149Sep 25, 2026affected >= 7.0.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix percpu map update indexing with sparse CPU IDs Per-CPU array, hash, and cgroup storage map updates without BPF_F_CPU or BPF_F_ALL_CPUS use a value buffer whose per-CPU slots are packed in possible-CPU
- CVE-2026-98148Sep 25, 2026affected >= 5.13.0, < 6.18.53fixed 6.18.53
In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate GUD_ROTATION_0 is present in supported rotations The rotation argument to drm_plane_create_rotation_property() is set to DRM_MODE_ROTATE_0, and the device reported rotation bitmask is used as
- CVE-2026-98147Sep 25, 2026affected >= 6.12.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: printk: Don't WARN on kthread_run failure. Since __kthread_create_on_node() returns -EINTR upon SIGKILL, we should not use WARN_ON() in order to catch kthread_run() failure.
- CVE-2026-98146Sep 25, 2026affected >= 6.14.0, < 6.18.53fixed 6.18.53
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain struct amdxdna_cmd_chain contains a flexible array annotated with __counted_by(command_count). Since the structure is stored in shared AMDXDNA_BO
- CVE-2026-98145Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject a command chain that carries no commands A chain whose command_count is zero passes the payload length check, because struct_size(payload, data, 0) is just the header. The fill loop then d
- CVE-2026-98144Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: put the chained BO when its mapping fails amdxdna_cmd_set_error() looks up the first BO of a command chain, which takes a reference, and drops it at the end of the function. The mapping of that B
- affected >= 6.19.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Don't read the U65 rounding mode as a storage mode Bits 15:14 of NPU_SET_{IFM,OFM}_PRECISION select the activation storage mode on U85 only. On U65 the same field holds the rounding mode, and the
- CVE-2026-98142Sep 25, 2026affected >= 5.2.0, < 6.6.158fixed 6.6.158
In the Linux kernel, the following vulnerability has been resolved: drm/cirrus-qemu: Validate BAR0 size during probe The `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate framebuffer sizes. However, during PCI probe, the driver mapped BAR0 without verifying t
- CVE-2026-98141Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: ntfs: propagate reparse index insertion failure update_reparse_data() ignores the return value of set_reparse_index(). When index insertion fails, the code removes the just-written reparse data as cleanup but s
- CVE-2026-98140Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix kmap_local leak in write_mft_record_nolock() error paths write_mft_record_nolock() maps the MFT record folio with kmap_local_folio(), but the pre_write_mst_fixup() and bio_add_folio() failure paths ju
- CVE-2026-98139Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: ntfs: only count successfully cleared runs when freeing clusters ntfs_cluster_free_from_rl_nolock() adds a run's length to nr_freed whenever the error bookkeeping condition is false, which includes cases where
- CVE-2026-98138Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: ntfs: do not mark the volume clean in sync_fs when errors were recorded ntfs_put_super() and the remount-read-only path both clear the dirty bit only when NVolErrors(vol) is false. ntfs_sync_fs() clears it unco
- CVE-2026-98137Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: ntfs: treat any nonzero dio zero-range return as an error ntfs_dio_zero_range() returns either 0 or a negative errno from blkdev_issue_zeroout(); it never returns a positive value. The zeroing failure check in
- CVE-2026-98136Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: ntfs: bound $AttrDef table walk to the loaded table size ntfs_attr_find_in_attrdef() walks the in-memory $AttrDef table, but the loop condition bounds only the start of each entry, not the whole entry: for (a
- CVE-2026-98135Sep 25, 2026affected >= 7.1.0, < 7.2.7fixed 7.2.7
In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid sectors_per_cluster in the boot sector is_boot_sector_ntfs() checks the boot sector's sectors_per_cluster field with a range test that rejects 0x81..0xf3 but accepts 0 and other non-power-o
Page 2 of 819