linux package
kernel
pkg:linux/kernel
Vulnerabilities (15,762)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-93124 | — | >= 7.1.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wireless: Fail probe when there is no ACPI match Every platform driver can be forced to match a device that does not match its list of device IDs because of device_match_driver_override(), so | ||
| CVE-2026-93123 | — | >= 6.3.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: do not advance stale DMA completions The qcom GENI serial DMA TX completion path advances the transmit fifo by the number of bytes recorded in port->tx_remaining. If uart_flush_buffer() runs | ||
| CVE-2026-93122 | Hig | 7.8 | >= 5.18.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uac: validate rate list length before storing UAC1 and UAC2 configfs rate-list attributes parse a comma-separated list of sampling rates and store each parsed value in fixed-size arrays. The arrays | |
| CVE-2026-93121 | Hig | 7.0 | >= 6.9.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths The error paths for endpoint-disabled (ESHUTDOWN) and request-allocation failure (ENOMEM) in ffs_dmabuf_transfer() jump to err_fence_put | |
| CVE-2026-93120 | — | >= 4.13.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qw_sign os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input length to utf16s_to_utf8s(), but that argument counts UTF-16 code units while OS_STRING_ | ||
| CVE-2026-93119 | — | >= 6.7.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: ljca: bound bank_num in ljca_enumerate_gpio() ljca_enumerate_gpio() reads desc->bank_num from the device and loops valid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[] holds only LJCA_MAX_G | ||
| CVE-2026-93118 | — | >= 6.0.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: check endpoint DMA allocation ast_udc_probe() allocates a coherent DMA buffer used as the backing store for endpoint buffers. ast_udc_init_ep() derives per-endpoint buffer pointers from | ||
| CVE-2026-93117 | — | >= 2.6.33, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only guaranteed to be valid when usb_dynids_lock is held, as remove_id_store can free the node. Thus, make a copy in usb_probe_interface | ||
| CVE-2026-93116 | Hig | 7.0 | >= 5.17.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: fix resource leaks on probe failure During driver initialization in asus_wmi_add(), various subsystems are registered sequentially. However, the error path labels are out of order relati | |
| CVE-2026-93115 | — | >= 5.11.0, < 5.15.221 | 5.15.221 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL Every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), so pl | ||
| CVE-2026-93114 | — | >= 5.14.0, < 5.15.221 | 5.15.221 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/surface: acpi-notify: Check ACPI companion before use Since every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), pl | ||
| CVE-2026-93113 | — | >= 6.8.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK With the introduction of sync_state support in the clk and pmdomain subsystems, the following warning happens when the unused clocks are shutdown in camcc-sc | ||
| CVE-2026-93112 | Hig | 7.1 | >= 6.15.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Require a BPF cpumask for bpf_cpumask_populate() bpf_cpumask_populate() writes to its destination with bitmap_copy(), but the destination is typed as struct cpumask *. That allows the verifier to accept bo | |
| CVE-2026-93111 | Hig | 7.8 | >= 7.2.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark tracing_multi trampolines as ftrace managed Since tracing_multi link does not set ftrace_managed, it would fail to release the tracing_multi link when attaching tracing_multi link and then attaching f | |
| CVE-2026-93110 | — | >= 5.2.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Wait for RCU callbacks before unloading ib_core put_gid_ndev() is queued with call_rcu() and implemented in ib_core. Stopping the workqueues does not drain callbacks already queued, so RCU could invo | ||
| CVE-2026-93109 | — | >= 5.6.0, < 5.15.221 | 5.15.221 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Drain RCU callbacks during module teardown devx_free_subscription() can remain queued after the last DevX event file drops its module reference or an auxiliary driver detaches its devices. mlx5_ib ca | ||
| CVE-2026-93108 | — | >= 3.6.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/ipoib: Drain RCU callbacks during module teardown IPoIB reclamation completions can be signaled from inside an RCU callback. Teardown can wake before the callback returns and unload ib_ipoib while its code | ||
| CVE-2026-93107 | Hig | 8.2 | >= 6.4.0, < 6.6.157 | 6.6.157 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state When do_complete() finds the QP in the error state it returns RESPST_CHK_RESOURCE. Before commit 49dc9c1f0c7e ("RDMA/rxe: Cle | |
| CVE-2026-93106 | — | >= 6.16.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: crash_dump: release keyring reference at the correct time restore_dm_crypt_keys_to_thread_keyring() gets a reference to the user keyring before restoring the saved dm-crypt keys. The same keyring reference is | ||
| CVE-2026-93105 | Hig | 7.8 | >= 4.11.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: esp: do not unref managed frag pages in esp_ssg_unref() esp_ssg_unref() releases the page references held on the source scatterlist after the AEAD operation completes. It calls skb_page_unref() on every frag p |
- CVE-2026-93124Sep 17, 2026affected >= 7.1.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wireless: Fail probe when there is no ACPI match Every platform driver can be forced to match a device that does not match its list of device IDs because of device_match_driver_override(), so
- CVE-2026-93123Sep 17, 2026affected >= 6.3.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: do not advance stale DMA completions The qcom GENI serial DMA TX completion path advances the transmit fifo by the number of bytes recorded in port->tx_remaining. If uart_flush_buffer() runs
- affected >= 5.18.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uac: validate rate list length before storing UAC1 and UAC2 configfs rate-list attributes parse a comma-separated list of sampling rates and store each parsed value in fixed-size arrays. The arrays
- affected >= 6.9.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths The error paths for endpoint-disabled (ESHUTDOWN) and request-allocation failure (ENOMEM) in ffs_dmabuf_transfer() jump to err_fence_put
- CVE-2026-93120Sep 17, 2026affected >= 4.13.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qw_sign os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input length to utf16s_to_utf8s(), but that argument counts UTF-16 code units while OS_STRING_
- CVE-2026-93119Sep 17, 2026affected >= 6.7.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: usb: ljca: bound bank_num in ljca_enumerate_gpio() ljca_enumerate_gpio() reads desc->bank_num from the device and loops valid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[] holds only LJCA_MAX_G
- CVE-2026-93118Sep 17, 2026affected >= 6.0.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: check endpoint DMA allocation ast_udc_probe() allocates a coherent DMA buffer used as the backing store for endpoint buffers. ast_udc_init_ep() derives per-endpoint buffer pointers from
- CVE-2026-93117Sep 17, 2026affected >= 2.6.33, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: usb: fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only guaranteed to be valid when usb_dynids_lock is held, as remove_id_store can free the node. Thus, make a copy in usb_probe_interface
- affected >= 5.17.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: fix resource leaks on probe failure During driver initialization in asus_wmi_add(), various subsystems are registered sequentially. However, the error path labels are out of order relati
- CVE-2026-93115Sep 17, 2026affected >= 5.11.0, < 5.15.221fixed 5.15.221
In the Linux kernel, the following vulnerability has been resolved: platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL Every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), so pl
- CVE-2026-93114Sep 17, 2026affected >= 5.14.0, < 5.15.221fixed 5.15.221
In the Linux kernel, the following vulnerability has been resolved: platform/surface: acpi-notify: Check ACPI companion before use Since every platform driver can be forced to match a device that doesn't match its list of device IDs because of device_match_driver_override(), pl
- CVE-2026-93113Sep 17, 2026affected >= 6.8.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK With the introduction of sync_state support in the clk and pmdomain subsystems, the following warning happens when the unused clocks are shutdown in camcc-sc
- affected >= 6.15.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: bpf: Require a BPF cpumask for bpf_cpumask_populate() bpf_cpumask_populate() writes to its destination with bitmap_copy(), but the destination is typed as struct cpumask *. That allows the verifier to accept bo
- affected >= 7.2.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: bpf: Mark tracing_multi trampolines as ftrace managed Since tracing_multi link does not set ftrace_managed, it would fail to release the tracing_multi link when attaching tracing_multi link and then attaching f
- CVE-2026-93110Sep 17, 2026affected >= 5.2.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Wait for RCU callbacks before unloading ib_core put_gid_ndev() is queued with call_rcu() and implemented in ib_core. Stopping the workqueues does not drain callbacks already queued, so RCU could invo
- CVE-2026-93109Sep 17, 2026affected >= 5.6.0, < 5.15.221fixed 5.15.221
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Drain RCU callbacks during module teardown devx_free_subscription() can remain queued after the last DevX event file drops its module reference or an auxiliary driver detaches its devices. mlx5_ib ca
- CVE-2026-93108Sep 17, 2026affected >= 3.6.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: RDMA/ipoib: Drain RCU callbacks during module teardown IPoIB reclamation completions can be signaled from inside an RCU callback. Teardown can wake before the callback returns and unload ib_ipoib while its code
- affected >= 6.4.0, < 6.6.157fixed 6.6.157
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state When do_complete() finds the QP in the error state it returns RESPST_CHK_RESOURCE. Before commit 49dc9c1f0c7e ("RDMA/rxe: Cle
- CVE-2026-93106Sep 17, 2026affected >= 6.16.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: crash_dump: release keyring reference at the correct time restore_dm_crypt_keys_to_thread_keyring() gets a reference to the user keyring before restoring the saved dm-crypt keys. The same keyring reference is
- affected >= 4.11.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: esp: do not unref managed frag pages in esp_ssg_unref() esp_ssg_unref() releases the page references held on the source scatterlist after the AEAD operation completes. It calls skb_page_unref() on every frag p
Page 5 of 789