VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2026-93104Sep 17, 2026
    affected >= 4.6.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: RDMA/rvt: Return NULL after port allocation failure rvt_alloc_device() deallocates the IB device when its port array cannot be allocated but then returns the pointer to the released allocation. Callers treat an

  • CVE-2026-93103Sep 17, 2026
    affected >= 5.2.0, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Preserve unit 0 on allocation failure hfi1_free_devdata() assumes that the device was inserted into the unit table and unconditionally erases dd->unit. If xa_alloc_irq() fails, the zero-initialized u

  • CVE-2026-93102Sep 17, 2026
    affected >= 5.8.0, < 5.15.221fixed 5.15.221

    In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Free RX data on late probe failure hfi1_init_dd() allocates the shared AIP/VNIC RX support before returning. If hfi1_init() or hfi1_register_ib_device() later fails, init_one() tears down the device

  • CVE-2026-93101Sep 17, 2026
    affected >= 6.6.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: media: v4l2-async: Unregister sub-device if asc_list is empty When my em28xx USB device that uses the i2c tvp5150 driver is disconnected, it crashes. The cause is that the tvp5150 i2c module uses v4l2_async, b

  • CVE-2026-93100Sep 17, 2026
    affected >= 5.6.0, < 6.18.52fixed 6.18.52

    In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Prevent use-after-free in rdtgroup_kn_put() A struct rdtgroup is reference counted via rdtgroup::waitcount. Callers that need the structure to remain valid across a sleep (while waiting on acquiring

  • CVE-2026-93099Sep 17, 2026
    affected >= 4.14.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix UAF from worker threads when domains are removed The mbm_handle_overflow() and cqm_handle_limbo() workers read event counters and may sleep while doing so. They are scheduled via delayed_work em

  • CVE-2026-93098Sep 17, 2026
    affected < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: fix deadlock in endpoint destroy during driver detach During driver detach, the device core holds the device mutex throughout the driver's remove callback chain. When the rpmsg endpoint is destro

  • CVE-2026-93097Sep 17, 2026
    affected >= 6.4.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Break poison list loop on an empty payload A device that returns count == 0 with CXL_POISON_FLAG_MORE set on every iteration never advances nr_records, so the max_errors guard never trips and the do/w

  • CVE-2026-93096Sep 17, 2026
    affected >= 6.15.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: cxl/features: Serialize multi-part Get/Set Feature transfers A Get or Set Feature payload larger than the mailbox payload size is split into several mailbox commands. mbox_mutex only serializes individual mailb

  • CVE-2026-93095HigSep 17, 2026
    affected >= 2.6.12, < 5.10.270fixed 5.10.270

    In the Linux kernel, the following vulnerability has been resolved: hfsplus: validate thread record before delete key rebuild hfsplus_delete_cat() is called with str == NULL when the last open reference to an unlinked HFS+ hardlink backing inode is closed. In that case, the fun

  • CVE-2026-93094Sep 17, 2026
    affected >= 7.0.0, < 7.2.6fixed 7.2.6

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix dp_link_peer dangling references on AP vdev rollback ath12k_mac_vdev_create() for an AP vdev creates the bss self-peer via ath12k_peer_create(), which finishes by calling ath12k_dp_link_peer_a

  • CVE-2026-93093Sep 17, 2026
    affected >= 5.7.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Publish channel state before callbacks Transport setup can enable callbacks before the setup routine returns. mailbox_chan_setup() registers the mailbox client with mbox_request_channel(), a

  • CVE-2026-93092Sep 17, 2026
    affected >= 6.3.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unregister device notifier before IDR teardown The requested-devices notifier looks up protocol fwnodes from the active_protocols IDR. During remove, unregister the notifier before releasing

  • CVE-2026-93091Sep 17, 2026
    affected >= 5.15.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Quiesce notifications before teardown scmi_notification_exit() clears and releases the notification instance, but transport callbacks can still deliver incoming notifications until the TX/RX

  • CVE-2026-93090Sep 17, 2026
    affected >= 6.3.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Clean up channels on setup failure scmi_channels_setup() can fail after the common BASE channel or earlier protocol channels have already been registered in the TX/RX IDRs. Route this failu

  • CVE-2026-93089Sep 17, 2026
    affected >= 6.3.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Free transport channel on IDR failure If transport channel setup succeeds but the following IDR insertion fails, the error path destroys the transport device and frees the channel info witho

  • CVE-2026-93086Sep 17, 2026
    affected >= 6.3.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Avoid IDR updates while cleaning channels scmi_cleanup_channels() walks the TX/RX channel IDRs with idr_for_each() to free transport resources and destroy the dedicated transport devices bef

  • CVE-2026-93085Sep 17, 2026
    affected >= 6.3.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Reject out of range DT protocol IDs SCMI protocol IDs carried in message headers are limited by MSG_PROTOCOL_ID_MASK. The DT parsing paths noticed protocol IDs outside that range, but only l

  • CVE-2026-93084Sep 17, 2026
    affected >= 6.3.0, < 6.6.157fixed 6.6.157

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Drop handle on protocol bind failures The SCMI bus notifier acquires an SCMI handle when the driver core emits BUS_NOTIFY_BIND_DRIVER, before invoking the protocol driver probe callback. The

  • CVE-2026-93083Sep 17, 2026
    affected >= 6.4.0, < 6.12.110fixed 6.12.110

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind TX receiver mailbox setup failure mailbox_chan_setup() can request an additional unidirectional TX receiver channel after successfully acquiring the primary channel. If that second re

Page 6 of 789