rpm package
opensuse/kernel-source&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-80847 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: clamp route advmss to TCP_MIN_MSS tcp_select_initial_window() assumes that callers never pass an MSS smaller than 1, but route-derived advmss values can violate that assumption. A too-small explicit RTAX_ | ||
| CVE-2026-80846 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: drop ESP-in-TCP packets with no ingress device ESP-in-TCP receives records through the TCP strparser. handle_esp() restores skb->dev from the saved skb_iif before passing the packet into the XFRM input pa | ||
| CVE-2026-80845 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: avoid lock inversion in nat keepalive work nat_keepalive_work() walks the state table while xfrm_state_walk() holds net->xfrm.xfrm_state_lock. Its callback then acquires x->lock, which conflicts with the | ||
| CVE-2026-80844 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of | ||
| CVE-2026-80843 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix xfrm_state_construct() auth-trunc leak attach_auth_trunc() can allocate x->aalg while leaving x->props.aalgo at zero when the selected auth algorithm has no sadb_alg_id. One real case is cmac(aes). x | ||
| CVE-2026-80842 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: fix use-after-free of a master VLAN's multicast context br_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under br->multicast_lock before stopping a VLAN's multicast context. Th | ||
| CVE-2026-80841 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/packet: defer vmalloc TX_RING free until skbs finish AF_PACKET TX_RING skbs keep a raw pointer to their ring frame. The skb page references preserve page-backed ring blocks after pg_vec is freed, but they d | ||
| CVE-2026-80840 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: seg6: clear IPv4 control block on IPIP decapsulation End.DX4 and End.DT4 decapsulate an IPv4 packet through decap_and_validate() and send it directly to IPv4 routing. The inner packet therefore bypasses i | ||
| CVE-2026-80839 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject unrepresentable multicast TVLV offsets The network and transport header fields in struct sk_buff are 16-bit offsets from skb->head, and U16_MAX is reserved as the unset transport header value | ||
| CVE-2026-80838 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: vxlan: keep the last remote linked during FDB flush A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this inv | ||
| CVE-2026-80837 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't queue packet path object notifications All file:line references below are against v7.2-rc4 (ac5b0e5651b1). The trace was captured on 7.2.0-rc6-kasan72rc6 (075b74841bd0), where the sa | ||
| CVE-2026-80836 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: virtio - bound the akcipher result length virtio_crypto_dataq_akcipher_callback() sets the result length from the device-reported response length without bounding it to the destination buffer, which was | ||
| CVE-2026-80835 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Remove crypto_rng interface qcom-rng.c exposes the same hardware through two completely separate interfaces, crypto_rng and hwrng. However, the implementation of this is buggy because it per | ||
| CVE-2026-80834 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ce - Remove crypto_rng interface Since the crypto_rng interface for hardware PRNGs is unused and is redundant with hwrng and the actual Linux RNG, it's being phased out. Most drivers for it were a | ||
| CVE-2026-80833 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Remove crypto_rng interface Since the crypto_rng interface for hardware PRNGs is unused and is redundant with hwrng and the actual Linux RNG, it's being phased out. Most drivers for it were a | ||
| CVE-2026-80832 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix CCM AAD buffer underallocation The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen() can be smaller than the length later programmed into the DMA scatterlist. The allocation size is | ||
| CVE-2026-80831 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - fix source scatterlist length access mxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source scatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid and could re | ||
| CVE-2026-80830 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: core: Add lock to usb_wakeup_notification() Add a spin lock to usb_wakeup notification to prevent a race condition with dereferencing freed memory. This could be hit by the xHCI driver as it calls this fun | ||
| CVE-2026-80829 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() snd_usbmidi_novation_output() lays out a two-byte header at transfer_buffer[0..1] and passes &transfer_buffer[2] together with a length of ep->max | ||
| CVE-2026-80828 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Complete cleanup after system-resume errors A failed system resume can leave the card unusable until reboot. usb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or snd_usb_mixer_resum |
- CVE-2026-80847Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: tcp: clamp route advmss to TCP_MIN_MSS tcp_select_initial_window() assumes that callers never pass an MSS smaller than 1, but route-derived advmss values can violate that assumption. A too-small explicit RTAX_
- CVE-2026-80846Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: xfrm: drop ESP-in-TCP packets with no ingress device ESP-in-TCP receives records through the TCP strparser. handle_esp() restores skb->dev from the saved skb_iif before passing the packet into the XFRM input pa
- CVE-2026-80845Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: xfrm: avoid lock inversion in nat keepalive work nat_keepalive_work() walks the state table while xfrm_state_walk() holds net->xfrm.xfrm_state_lock. Its callback then acquires x->lock, which conflicts with the
- CVE-2026-80844Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of
- CVE-2026-80843Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix xfrm_state_construct() auth-trunc leak attach_auth_trunc() can allocate x->aalg while leaving x->props.aalgo at zero when the selected auth algorithm has no sadb_alg_id. One real case is cmac(aes). x
- CVE-2026-80842Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: fix use-after-free of a master VLAN's multicast context br_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under br->multicast_lock before stopping a VLAN's multicast context. Th
- CVE-2026-80841Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: net/packet: defer vmalloc TX_RING free until skbs finish AF_PACKET TX_RING skbs keep a raw pointer to their ring frame. The skb page references preserve page-backed ring blocks after pg_vec is freed, but they d
- CVE-2026-80840Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ipv6: seg6: clear IPv4 control block on IPIP decapsulation End.DX4 and End.DT4 decapsulate an IPv4 packet through decap_and_validate() and send it directly to IPv4 routing. The inner packet therefore bypasses i
- CVE-2026-80839Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject unrepresentable multicast TVLV offsets The network and transport header fields in struct sk_buff are 16-bit offsets from skb->head, and U16_MAX is reserved as the unset transport header value
- CVE-2026-80838Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: vxlan: keep the last remote linked during FDB flush A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this inv
- CVE-2026-80837Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't queue packet path object notifications All file:line references below are against v7.2-rc4 (ac5b0e5651b1). The trace was captured on 7.2.0-rc6-kasan72rc6 (075b74841bd0), where the sa
- CVE-2026-80836Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: virtio - bound the akcipher result length virtio_crypto_dataq_akcipher_callback() sets the result length from the device-reported response length without bounding it to the destination buffer, which was
- CVE-2026-80835Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Remove crypto_rng interface qcom-rng.c exposes the same hardware through two completely separate interfaces, crypto_rng and hwrng. However, the implementation of this is buggy because it per
- CVE-2026-80834Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ce - Remove crypto_rng interface Since the crypto_rng interface for hardware PRNGs is unused and is redundant with hwrng and the actual Linux RNG, it's being phased out. Most drivers for it were a
- CVE-2026-80833Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Remove crypto_rng interface Since the crypto_rng interface for hardware PRNGs is unused and is redundant with hwrng and the actual Linux RNG, it's being phased out. Most drivers for it were a
- CVE-2026-80832Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix CCM AAD buffer underallocation The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen() can be smaller than the length later programmed into the DMA scatterlist. The allocation size is
- CVE-2026-80831Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - fix source scatterlist length access mxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source scatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid and could re
- CVE-2026-80830Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: usb: core: Add lock to usb_wakeup_notification() Add a spin lock to usb_wakeup notification to prevent a race condition with dereferencing freed memory. This could be hit by the xHCI driver as it calls this fun
- CVE-2026-80829Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() snd_usbmidi_novation_output() lays out a two-byte header at transfer_buffer[0..1] and passes &transfer_buffer[2] together with a length of ep->max
- CVE-2026-80828Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Complete cleanup after system-resume errors A failed system resume can leave the card unusable until reboot. usb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or snd_usb_mixer_resum
Page 10 of 107