linux package
kernel
pkg:linux/kernel
Vulnerabilities (15,762)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-93042 | Hig | 8.8 | >= 5.3.0, < 6.6.157 | 6.6.157 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors without callbacks The DMA Engine client documentation says in the "Terminate APIs" section of Documentation/driver-api/dmaengine/client.rst: "No callback functions | |
| CVE-2026-93041 | — | >= 5.3.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize abort state updates dw_edma_abort_interrupt() drops vc.lock before changing request and status. issue_pending() can acquire the lock in that small window, observe the old busy stat | ||
| CVE-2026-93040 | — | >= 5.3.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize channel state checks pause() and resume() read and update channel state without holding vc.lock, while the interrupt handlers update the same state under it. Take the same lock aro | ||
| CVE-2026-93039 | Hig | 7.4 | >= 4.19.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: Keep link pointers valid on realloc failure meson_card_reallocate_links() grows the DAI link and private data arrays with two consecutive krealloc() calls and updates the owner pointers only after | |
| CVE-2026-93038 | — | >= 7.2.0, < 7.2.6 | 7.2.6 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: dac: ad5686: missing NULL check on match data Verify that chip_info pointer is not NULL. If a user binds the driver using driver_override via sysfs with a device name not present in the id_table or of_matc | ||
| CVE-2026-93037 | Hig | 7.8 | >= 4.14.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() fails, it returns before initializing tx->txreq. However, set_txreq_head | |
| CVE-2026-92525 | Hig | 7.1 | >= 4.8.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] For a user QP, qp->sq.queue is a ring the application writes directly, so rxe_post_send() takes the is_user branch and only schedules send_task | |
| CVE-2026-92524 | — | >= 4.14.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() When its_irq_gic_domain_alloc() fails, the following its_vpe_irq_domain_free() fails to invoke its_vep_teardown() for the corresponding interrupt, | ||
| CVE-2026-92523 | — | >= 5.16.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic counter attribute length RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is a nested attribute whose children are consumed directly with nla_get_u32(). The top-level policy validates only the conta | ||
| CVE-2026-92522 | Hig | 7.3 | >= 4.0.0, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after on | |
| CVE-2026-92521 | — | >= 2.6.28, < 5.10.270 | 5.10.270 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root acpi_pci_root_add() assigns the freshly allocated root to device->driver_data before dmar_device_add() and pci_acpi_scan_root(). Both failur | ||
| CVE-2026-92520 | — | >= 6.6.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Zero queue and stack outputs on lock failure Queue and stack pop/peek helpers accept an uninitialized output buffer because the verifier expects the helper to initialize it. The empty-map error path clears | ||
| CVE-2026-92519 | — | >= 6.6.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix memory leak in bpf_jit_free When bpf_int_jit_compile() is called for subprograms, it returns early during the first pass (!prog->is_func || extra_pass is false), keeping ctx->offset alive for th | ||
| CVE-2026-92518 | Hig | 7.8 | >= 6.12.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi instruction during setup. Including it again in the tailcall jump offset caus | |
| CVE-2026-92517 | — | >= 6.18.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf, riscv: Fix extable handling for arena load_acquire emit_atomic_ld_st() returns 1 to have build_body() skip the zext after a sub-word load_acquire. The caller does "ret = ret ?: add_exception_handler(...)", | ||
| CVE-2026-92516 | — | >= 6.15.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix offset warn check for bpf_res_spin_lock Sashiko pointed out correctly that the case statement for BPF_RES_SPIN_LOCK incorrectly checks offset for BPF_SPIN_LOCK. Fix it by checking res_spin_lock_off ins | ||
| CVE-2026-92515 | — | >= 6.11.0, < 6.12.110 | 6.12.110 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve unique-field state across nested structs btf_find_struct_field() initializes a fresh seen mask for every recursive descent. Unique special fields in different levels of the same aggregate therefor | ||
| CVE-2026-92514 | — | >= 6.0.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Fix CEQ tasklet use-after-free on removal Each CEQ interrupt handler only schedules eqc->tasklet. The tasklet calls erdma_ceq_completion_handler(), which reads the DMA-coherent EQ ring through get_n | ||
| CVE-2026-92513 | — | >= 6.15.0, < 6.18.52 | 6.18.52 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial table insertion mana_table_store_ud_qp() publishes a QP at its send-queue id before inserting the receive-queue id, dropping the XArray lock between the two xa_in | ||
| CVE-2026-92512 | — | >= 5.15.0, < 6.1.188 | 6.1.188 | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix use after free in ib_query_qp() When querying a QP via the netlink flow the only synchronization mechanism for the said QP is rdma_restrack_get(), meanwhile during the QP destroy path rdma_restra |
- affected >= 5.3.0, < 6.6.157fixed 6.6.157
In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors without callbacks The DMA Engine client documentation says in the "Terminate APIs" section of Documentation/driver-api/dmaengine/client.rst: "No callback functions
- CVE-2026-93041Sep 17, 2026affected >= 5.3.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize abort state updates dw_edma_abort_interrupt() drops vc.lock before changing request and status. issue_pending() can acquire the lock in that small window, observe the old busy stat
- CVE-2026-93040Sep 17, 2026affected >= 5.3.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize channel state checks pause() and resume() read and update channel state without holding vc.lock, while the interrupt handlers update the same state under it. Take the same lock aro
- affected >= 4.19.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: Keep link pointers valid on realloc failure meson_card_reallocate_links() grows the DAI link and private data arrays with two consecutive krealloc() calls and updates the owner pointers only after
- CVE-2026-93038Sep 17, 2026affected >= 7.2.0, < 7.2.6fixed 7.2.6
In the Linux kernel, the following vulnerability has been resolved: iio: dac: ad5686: missing NULL check on match data Verify that chip_info pointer is not NULL. If a user binds the driver using driver_override via sysfs with a device name not present in the id_table or of_matc
- affected >= 4.14.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() fails, it returns before initializing tx->txreq. However, set_txreq_head
- affected >= 4.8.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] For a user QP, qp->sq.queue is a ring the application writes directly, so rxe_post_send() takes the is_user branch and only schedules send_task
- CVE-2026-92524Sep 17, 2026affected >= 4.14.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() When its_irq_gic_domain_alloc() fails, the following its_vpe_irq_domain_free() fails to invoke its_vep_teardown() for the corresponding interrupt,
- CVE-2026-92523Sep 17, 2026affected >= 5.16.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic counter attribute length RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is a nested attribute whose children are consumed directly with nla_get_u32(). The top-level policy validates only the conta
- affected >= 4.0.0, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after on
- CVE-2026-92521Sep 17, 2026affected >= 2.6.28, < 5.10.270fixed 5.10.270
In the Linux kernel, the following vulnerability has been resolved: ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root acpi_pci_root_add() assigns the freshly allocated root to device->driver_data before dmar_device_add() and pci_acpi_scan_root(). Both failur
- CVE-2026-92520Sep 17, 2026affected >= 6.6.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: bpf: Zero queue and stack outputs on lock failure Queue and stack pop/peek helpers accept an uninitialized output buffer because the verifier expects the helper to initialize it. The empty-map error path clears
- CVE-2026-92519Sep 17, 2026affected >= 6.6.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix memory leak in bpf_jit_free When bpf_int_jit_compile() is called for subprograms, it returns early during the first pass (!prog->is_func || extra_pass is false), keeping ctx->offset alive for th
- affected >= 6.12.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi instruction during setup. Including it again in the tailcall jump offset caus
- CVE-2026-92517Sep 17, 2026affected >= 6.18.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: bpf, riscv: Fix extable handling for arena load_acquire emit_atomic_ld_st() returns 1 to have build_body() skip the zext after a sub-word load_acquire. The caller does "ret = ret ?: add_exception_handler(...)",
- CVE-2026-92516Sep 17, 2026affected >= 6.15.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix offset warn check for bpf_res_spin_lock Sashiko pointed out correctly that the case statement for BPF_RES_SPIN_LOCK incorrectly checks offset for BPF_SPIN_LOCK. Fix it by checking res_spin_lock_off ins
- CVE-2026-92515Sep 17, 2026affected >= 6.11.0, < 6.12.110fixed 6.12.110
In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve unique-field state across nested structs btf_find_struct_field() initializes a fresh seen mask for every recursive descent. Unique special fields in different levels of the same aggregate therefor
- CVE-2026-92514Sep 17, 2026affected >= 6.0.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Fix CEQ tasklet use-after-free on removal Each CEQ interrupt handler only schedules eqc->tasklet. The tasklet calls erdma_ceq_completion_handler(), which reads the DMA-coherent EQ ring through get_n
- CVE-2026-92513Sep 17, 2026affected >= 6.15.0, < 6.18.52fixed 6.18.52
In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial table insertion mana_table_store_ud_qp() publishes a QP at its send-queue id before inserting the receive-queue id, dropping the XArray lock between the two xa_in
- CVE-2026-92512Sep 17, 2026affected >= 5.15.0, < 6.1.188fixed 6.1.188
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix use after free in ib_query_qp() When querying a QP via the netlink flow the only synchronization mechanism for the said QP is rdma_restrack_get(), meanwhile during the QP destroy path rdma_restra
Page 9 of 789