linux package
kernel
pkg:linux/kernel
Vulnerabilities (15,762)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-93062 | — | >= 5.5.0, < 6.6.157 | 6.6.157 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments Make sure we don't end-up with a num_frags = 0 situation. For that, check that the required size is not 0 and put a checker on num_fr | ||
| CVE-2026-93061 | — | >= 3.10.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Avoid stack over-read in debug output helpers host1x_debug_output() and host1x_debug_cont() used vsnprintf(), which returns the length the formatted string would have reached with an unbounded buff | ||
| CVE-2026-93060 | — | >= 7.2.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points to freed memory. Preserve the error code before freeing the memory to | ||
| CVE-2026-93059 | — | >= 6.17.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix task_struct reference leak in recover_worker get_pid_task() increments the task reference count, but the corresponding put_task_struct() was missing in the else branch, leaking a reference on every | ||
| CVE-2026-93058 | — | >= 5.15.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Only fini scheduler after successful init msm_ringbuffer_new() destroys a partially initialized ring through msm_ringbuffer_destroy() when an allocation or scheduler setup step fails. If drm_sched_ini | ||
| CVE-2026-93057 | — | >= 7.1.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context TX EQTR may run while devfreq gear scaling has quiesced the UFS tagset. In that context, functions ufshcd_tx_eqtr(), __ufshcd_tx_eqtr() | ||
| CVE-2026-93056 | — | >= 3.18.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: remove broken string configfs attributes The UAC1_STR_ATTRIBUTE macro defines configfs show/store handlers for the fn_play, fn_cap, and fn_cntl string options. The store function con | ||
| CVE-2026-93055 | — | >= 2.6.12, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: UDF symlink pathComponent header OOB read udf_symlink_filler() can enter udf_pc_to_char() with a partial pathComponent header. Validate that enough input remains for a complete pathComponent header before acce | ||
| CVE-2026-93054 | Hig | 7.0 | >= 4.18.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: uio: Fix stale info pointer in failed registration path After device_add(), the UIO device is visible to userspace and /dev/uioX can be opened. If a later setup step fails, __uio_register_device() unwinds the d | |
| CVE-2026-93053 | — | >= 2.6.37, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: speakup: keyhelp: guard letter_offsets possible out-of-range indexing help_init() builds letter_offsets[] by using the first byte of each function name as an index via `(start & 31) - 1`. If function_names are | ||
| CVE-2026-93052 | — | >= 5.12.0, < 5.15.221 | 5.15.221 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: misc: bcm-vk: Use acquire/release for msgq_inited bcm_vk_sync_msgq() fills the message queue information and then sets msgq_inited. Readers call bcm_vk_drv_access_ok() before accessing the message queues and th | ||
| CVE-2026-93051 | — | >= 2.6.33, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: misc: ad525x_dpot: use driver core groups for sysfs files ad_dpot_probe() creates per-RDAC sysfs files manually and then optionally creates the command sysfs group. This leaves probe responsible for rolling bac | ||
| CVE-2026-93050 | — | >= 3.8.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove Three issues arise when the device is removed while a tty session is still active: 1. UAF of struct ipoctal: the remove callback | ||
| CVE-2026-93049 | — | >= 4.14.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: mtdswap: Avoid freeing registered blktrans device twice In mtdswap_add_mtd(), debugfs setup failure after successful blktrans registration can free mbd_dev twice. add_mtd_blktrans_dev() initializes the bl | ||
| CVE-2026-93048 | — | >= 3.2.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() mtd_add_partition() does not reject the special offset value MTDPART_OFS_RETAIN (-3), which leads to a WARN_ON in add_mtd_device() when called through | ||
| CVE-2026-93047 | — | >= 5.3.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Associate BOs with every job that accesses them A submission can expand into a chain of jobs (e.g. bin + render + cache clean). Implicit synchronization in v3d_submit_lock_reservations() is gated on ea | ||
| CVE-2026-93046 | Hig | 7.0 | < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: software node: Fix software_node_get_reference_args() with index -1 The bounds check for the index passed to software_node_get_reference_args() was failing when passed UINT_MAX, this in turn would lead to an ou | |
| CVE-2026-93045 | Hig | 7.8 | >= 6.9.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_arena_free_pages() accepts scalar arena addresses. The runtime masks the address to the low 32 bits and reconstructs a full user address from the arena base befo | |
| CVE-2026-93044 | — | >= 6.9.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for arena-related insns Since the interpreter does not support the arena-related insns, interpreter fallback should not be allowed for these insns in core.c::__bpf_prog_select | ||
| CVE-2026-93043 | — | >= 6.19.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for gotox insn The interpreter does not recognize the BPF_JMP|BPF_JA|BPF_X insn, which is used for insn_array map. Thereafter, it would hit the BUG_ON() in ___bpf_prog_run() a |
- CVE-2026-93062Sep 17, 2026affected >= 5.5.0, < 6.6.157fixed 6.6.157
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments Make sure we don't end-up with a num_frags = 0 situation. For that, check that the required size is not 0 and put a checker on num_fr
- CVE-2026-93061Sep 17, 2026affected >= 3.10.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Avoid stack over-read in debug output helpers host1x_debug_output() and host1x_debug_cont() used vsnprintf(), which returns the length the formatted string would have reached with an unbounded buff
- CVE-2026-93060Sep 17, 2026affected >= 7.2.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points to freed memory. Preserve the error code before freeing the memory to
- CVE-2026-93059Sep 17, 2026affected >= 6.17.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix task_struct reference leak in recover_worker get_pid_task() increments the task reference count, but the corresponding put_task_struct() was missing in the else branch, leaking a reference on every
- CVE-2026-93058Sep 17, 2026affected >= 5.15.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Only fini scheduler after successful init msm_ringbuffer_new() destroys a partially initialized ring through msm_ringbuffer_destroy() when an allocation or scheduler setup step fails. If drm_sched_ini
- CVE-2026-93057Sep 17, 2026affected >= 7.1.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context TX EQTR may run while devfreq gear scaling has quiesced the UFS tagset. In that context, functions ufshcd_tx_eqtr(), __ufshcd_tx_eqtr()
- CVE-2026-93056Sep 17, 2026affected >= 3.18.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: remove broken string configfs attributes The UAC1_STR_ATTRIBUTE macro defines configfs show/store handlers for the fn_play, fn_cap, and fn_cntl string options. The store function con
- CVE-2026-93055Sep 17, 2026affected >= 2.6.12, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: UDF symlink pathComponent header OOB read udf_symlink_filler() can enter udf_pc_to_char() with a partial pathComponent header. Validate that enough input remains for a complete pathComponent header before acce
- affected >= 4.18.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: uio: Fix stale info pointer in failed registration path After device_add(), the UIO device is visible to userspace and /dev/uioX can be opened. If a later setup step fails, __uio_register_device() unwinds the d
- CVE-2026-93053Sep 17, 2026affected >= 2.6.37, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: speakup: keyhelp: guard letter_offsets possible out-of-range indexing help_init() builds letter_offsets[] by using the first byte of each function name as an index via `(start & 31) - 1`. If function_names are
- CVE-2026-93052Sep 17, 2026affected >= 5.12.0, < 5.15.221fixed 5.15.221
In the Linux kernel, the following vulnerability has been resolved: misc: bcm-vk: Use acquire/release for msgq_inited bcm_vk_sync_msgq() fills the message queue information and then sets msgq_inited. Readers call bcm_vk_drv_access_ok() before accessing the message queues and th
- CVE-2026-93051Sep 17, 2026affected >= 2.6.33, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: misc: ad525x_dpot: use driver core groups for sysfs files ad_dpot_probe() creates per-RDAC sysfs files manually and then optionally creates the command sysfs group. This leaves probe responsible for rolling bac
- CVE-2026-93050Sep 17, 2026affected >= 3.8.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove Three issues arise when the device is removed while a tty session is still active: 1. UAF of struct ipoctal: the remove callback
- CVE-2026-93049Sep 17, 2026affected >= 4.14.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: mtd: mtdswap: Avoid freeing registered blktrans device twice In mtdswap_add_mtd(), debugfs setup failure after successful blktrans registration can free mbd_dev twice. add_mtd_blktrans_dev() initializes the bl
- CVE-2026-93048Sep 17, 2026affected >= 3.2.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() mtd_add_partition() does not reject the special offset value MTDPART_OFS_RETAIN (-3), which leads to a WARN_ON in add_mtd_device() when called through
- CVE-2026-93047Sep 17, 2026affected >= 5.3.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Associate BOs with every job that accesses them A submission can expand into a chain of jobs (e.g. bin + render + cache clean). Implicit synchronization in v3d_submit_lock_reservations() is gated on ea
- affected < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: software node: Fix software_node_get_reference_args() with index -1 The bounds check for the index passed to software_node_get_reference_args() was failing when passed UINT_MAX, this in turn would lead to an ou
- affected >= 6.9.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_arena_free_pages() accepts scalar arena addresses. The runtime masks the address to the low 32 bits and reconstructs a full user address from the arena base befo
- CVE-2026-93044Sep 17, 2026affected >= 6.9.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for arena-related insns Since the interpreter does not support the arena-related insns, interpreter fallback should not be allowed for these insns in core.c::__bpf_prog_select
- CVE-2026-93043Sep 17, 2026affected >= 6.19.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for gotox insn The interpreter does not recognize the BPF_JMP|BPF_JA|BPF_X insn, which is used for insn_array map. Thereafter, it would hit the BUG_ON() in ___bpf_prog_run() a
Page 8 of 789