linux package
kernel
pkg:linux/kernel
Vulnerabilities (15,762)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-93144 | Hig | 7.8 | >= 6.2.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject writes through untrusted BTF pointers check_ptr_to_btf_access() lets program-type btf_struct_access callbacks validate writes before the default BTF access path rejects non-read accesses. That bypas | |
| CVE-2026-93143 | — | >= 6.17.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() ipu7_resume() calls pm_runtime_get_sync() before resuming the device. If the runtime PM resume fails, the usage count remains incremented, but | ||
| CVE-2026-93142 | — | >= 5.9.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/rcar: Fix error checking in probe() This code accidentally calls thermal_zone_device_enable() before checking whether thermal_zone_device_register_with_trips() failed. Move the call until later | ||
| CVE-2026-93141 | — | >= 3.17.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: r8a66597: avoid double free of ep0_req in probe error path If usb_add_gadget_udc() fails, r8a66597_probe() jumps to err_add_udc and frees ep0_req, then falls through to clean_up2 where ep0_req is f | ||
| CVE-2026-93140 | — | >= 3.3.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: udf: Mark LVID buffer as uptodate before marking it dirty When an I/O error occurs while writing the Logical Volume Integrity Descriptor (LVID) buffer to the block device, the block layer's completion handler ( | ||
| CVE-2026-93139 | — | >= 7.2.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC The loop iterated only AMDGPU_MAX_MES_PIPES times, leaving entries uninitialized for multi-XCC GPUs. This causes null pointer dereferences when a | ||
| CVE-2026-93138 | Hig | 7.8 | >= 5.5.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux bpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the bpf_verifier_lock, but publishes the result through a plain store and re-checks it through a p | |
| CVE-2026-93137 | Hig | 7.8 | >= 5.17.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free on mm_struct in bpf_find_vma() bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without holding a reference on the mm. On a foreign task, a concurrent exit_mm() can free the | |
| CVE-2026-93136 | — | >= 5.19.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation mhi_ep_create_device() takes one device reference for the UL channel and another for the DL channel after allocating the transfer | ||
| CVE-2026-93135 | — | >= 6.10.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject programs with inlined helpers if JIT is not available When an architecture (such as LoongArch, ARM64, and RISC-V) implements bpf_jit_inlines_helper_call(), the verifier skips rewriting the helper ca | ||
| CVE-2026-93134 | — | >= 6.12.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: printk: Fix possible console use-after-free When emitting a record via legacy printing, it is possible that a handover to another legacy printing context occurs. When a context has performed a handover, the con | ||
| CVE-2026-93133 | — | >= 6.12.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() In riscv_acpi_add_prt_dep(), the acpi_get_handle() call can fail which would leave link_handle uninitialized. Fix it by checking the acp | ||
| CVE-2026-93132 | — | >= 6.12.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling The loop in riscv_acpi_add_prt_dep() includes error conditions that are handled in a dubious - if not outright wrong - way, by continuining the loop (whi | ||
| CVE-2026-93131 | — | >= 5.14.0, < 5.15.221 | 5.15.221 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-privacy: Fix race condition Accessing priv->features_present needs to happen with the list mutex being held, otherwise priv can be freed at any moment. | ||
| CVE-2026-93130 | — | >= 5.14.0, < 5.15.221 | 5.15.221 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix resource leak on module load failure We need to properly clean up the SMBIOS request and the privacy driver when the module load fails. | ||
| CVE-2026-93129 | — | >= 5.16.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix handling of ultra performance key The commit message of commit 5fbd827eb9c2 ("platform/x86: dell-wmi: Recognise or support new switches") states that the ultra performance key c | ||
| CVE-2026-93128 | — | >= 5.15.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: lg-laptop: Fix LED resource handling The event notification callback might access kbd_backlight even when it was not successfully registered with the LED subsystem. The same happens inside acpi_re | ||
| CVE-2026-93127 | Hig | 7.8 | >= 7.0.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Drop scalar id on sign-extending narrowing stack fills When a spilled scalar is filled back with a sign-extending narrowing load (BPF_MEMSX), check_stack_read_fixed_off() copies the spilled register includ | |
| CVE-2026-93126 | — | >= 6.3.0, < 6.6.157 | 6.6.157 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_q6v5_adsp: Fix reference leak for device node When calling of_parse_phandle_with_args(), the caller is responsible to call of_node_put() to release the reference of device node. In adsp_map_car | ||
| CVE-2026-93125 | Hig | 7.8 | >= 6.1.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max check_kfunc_args() detects a kfunc argument named rdonly_buf_size or rdwr_buf_size and stores reg->var_off.value into meta->r0_size, a u64, a |
- affected >= 6.2.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject writes through untrusted BTF pointers check_ptr_to_btf_access() lets program-type btf_struct_access callbacks validate writes before the default BTF access path rejects non-read accesses. That bypas
- CVE-2026-93143Sep 17, 2026affected >= 6.17.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() ipu7_resume() calls pm_runtime_get_sync() before resuming the device. If the runtime PM resume fails, the usage count remains incremented, but
- CVE-2026-93142Sep 17, 2026affected >= 5.9.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/rcar: Fix error checking in probe() This code accidentally calls thermal_zone_device_enable() before checking whether thermal_zone_device_register_with_trips() failed. Move the call until later
- CVE-2026-93141Sep 17, 2026affected >= 3.17.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: r8a66597: avoid double free of ep0_req in probe error path If usb_add_gadget_udc() fails, r8a66597_probe() jumps to err_add_udc and frees ep0_req, then falls through to clean_up2 where ep0_req is f
- CVE-2026-93140Sep 17, 2026affected >= 3.3.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: udf: Mark LVID buffer as uptodate before marking it dirty When an I/O error occurs while writing the Logical Volume Integrity Descriptor (LVID) buffer to the block device, the block layer's completion handler (
- CVE-2026-93139Sep 17, 2026affected >= 7.2.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC The loop iterated only AMDGPU_MAX_MES_PIPES times, leaving entries uninitialized for multi-XCC GPUs. This causes null pointer dereferences when a
- affected >= 5.5.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux bpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the bpf_verifier_lock, but publishes the result through a plain store and re-checks it through a p
- affected >= 5.17.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free on mm_struct in bpf_find_vma() bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without holding a reference on the mm. On a foreign task, a concurrent exit_mm() can free the
- CVE-2026-93136Sep 17, 2026affected >= 5.19.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation mhi_ep_create_device() takes one device reference for the UL channel and another for the DL channel after allocating the transfer
- CVE-2026-93135Sep 17, 2026affected >= 6.10.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject programs with inlined helpers if JIT is not available When an architecture (such as LoongArch, ARM64, and RISC-V) implements bpf_jit_inlines_helper_call(), the verifier skips rewriting the helper ca
- CVE-2026-93134Sep 17, 2026affected >= 6.12.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: printk: Fix possible console use-after-free When emitting a record via legacy printing, it is possible that a handover to another legacy printing context occurs. When a context has performed a handover, the con
- CVE-2026-93133Sep 17, 2026affected >= 6.12.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() In riscv_acpi_add_prt_dep(), the acpi_get_handle() call can fail which would leave link_handle uninitialized. Fix it by checking the acp
- CVE-2026-93132Sep 17, 2026affected >= 6.12.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling The loop in riscv_acpi_add_prt_dep() includes error conditions that are handled in a dubious - if not outright wrong - way, by continuining the loop (whi
- CVE-2026-93131Sep 17, 2026affected >= 5.14.0, < 5.15.221fixed 5.15.221
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-privacy: Fix race condition Accessing priv->features_present needs to happen with the list mutex being held, otherwise priv can be freed at any moment.
- CVE-2026-93130Sep 17, 2026affected >= 5.14.0, < 5.15.221fixed 5.15.221
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix resource leak on module load failure We need to properly clean up the SMBIOS request and the privacy driver when the module load fails.
- CVE-2026-93129Sep 17, 2026affected >= 5.16.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix handling of ultra performance key The commit message of commit 5fbd827eb9c2 ("platform/x86: dell-wmi: Recognise or support new switches") states that the ultra performance key c
- CVE-2026-93128Sep 17, 2026affected >= 5.15.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: platform/x86: lg-laptop: Fix LED resource handling The event notification callback might access kbd_backlight even when it was not successfully registered with the LED subsystem. The same happens inside acpi_re
- affected >= 7.0.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: bpf: Drop scalar id on sign-extending narrowing stack fills When a spilled scalar is filled back with a sign-extending narrowing load (BPF_MEMSX), check_stack_read_fixed_off() copies the spilled register includ
- CVE-2026-93126Sep 17, 2026affected >= 6.3.0, < 6.6.157fixed 6.6.157
In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_q6v5_adsp: Fix reference leak for device node When calling of_parse_phandle_with_args(), the caller is responsible to call of_node_put() to release the reference of device node. In adsp_map_car
- affected >= 6.1.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max check_kfunc_args() detects a kfunc argument named rdonly_buf_size or rdwr_buf_size and stores reg->var_off.value into meta->r0_size, a u64, a
Page 4 of 789