rpm package
opensuse/kernel-source&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-80827 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: USB: serial: option: fix slab OOB read in interrupt URB callback The interrupt URB buffer is allocated in setup_port_interrupt_in() based on the endpoint's wMaxPacketSize: buffer_size = usb_endpoint_maxp(e | ||
| CVE-2026-80826 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: USB: c67x00: fix use-after-free in c67x00_add_iso_urb() When TD creation fails for the last packet of an isochronous URB, c67x00_add_iso_urb() gives the URB back before updating the endpoint scheduling state. | ||
| CVE-2026-80825 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb mt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB header onto every skb and assumes the headroom for them is already there. That | ||
| CVE-2026-80824 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: usbfs: fix use-after-free of usb_device in usbdev_release() usbdev_release() drops its reference to the struct usb_device before draining the list of completed async URBs, but that drain path reads back th | ||
| CVE-2026-80823 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: st21nfca: validate ATR_REQ length against the received frame st21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at least ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->leng | ||
| CVE-2026-80822 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() Add a check to see if devm_kasprintf() is not NULL in mchp_ipc_get_cluster_aggr_irq(), returning -ENOMEM if the function failed. | ||
| CVE-2026-80821 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: put CQ ref on create_cq mapping failure nvmet_pci_epf_create_cq() calls nvmet_cq_create(), which takes a reference on the controller and installs the completion queue. If the subsequent PCI addr | ||
| CVE-2026-80819 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept rfcomm_sock_recvmsg() completes a deferred setup by calling rfcomm_dlc_accept() without holding any RFCOMM lock: if (test_and_clear_bit(RFCOM | ||
| CVE-2026-80818 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown arm_smmu_impl_remove() is registered as a devres action in arm_smmu_impl_probe(), before arm_smmu_init_queues() allocates smmu->cmdq.q.base. On a de | ||
| CVE-2026-80817 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages iommufd_ioas_change_process() iterates every IOAS area while only holding every IOAS iova_rwsem, so it a | ||
| CVE-2026-80816 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: Use a private URB for the notification endpoint fcp_init_notify() used mixer->urb, which snd_usb_mixer_status_create() allocates for the optional UAC2 status interrupt endpoint and mixer.c kills, res | ||
| CVE-2026-80815 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Use a private URB for the notification endpoint scarlett2_init_notify() used mixer->urb, which snd_usb_mixer_status_create() allocates for the UAC2 status interrupt endpoint and mixer.c manages | ||
| CVE-2026-80814 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: rndis_host: add overflow check in rndis_rx_fixup() Add an overflow check to ensure that data_offset + data_len + 8 does not wrap, which would enable an OOB read of the USB data buffer. | ||
| CVE-2026-80813 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() When a host issues an Identify command with CNS 07h (Active Namespace ID List for a specific I/O Command Set), nvmet_execute_identify_nslis | ||
| CVE-2026-80812 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: dummy: Check card index validity at probe snd_dummy_probe() blindly trusts that the given devptr->id value is within the proper card index range. It's OK for the devices the driver itself creates at the | ||
| CVE-2026-80811 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/cmd: fix iovec leak when the async cmd is not recycled An io_async_cmd carries an iovec array in ->vec.iovec, allocated when the vec has to grow and kept across recycling through ctx->cmd_cache. On tw | ||
| CVE-2026-80810 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() io_vec_fill_bvec() computes the folio size with a plain int 1: unsigned long folio_size = 1 << imu->folio_shift; imu->folio_shift is unsigned int | ||
| CVE-2026-80809 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix missing metadata reservation for large xattrs [BUG] lsetxattr() panics the kernel when setting a large xattr value on a fragmented filesystem where the file already has an external xattr block. [CAU | ||
| CVE-2026-80808 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: stop retrying saturated xattr cache entries ext4_xattr_block_set() retries when a cache entry selected for reuse has a saturated reference count after taking the buffer lock. The retry returns to the mbca | ||
| CVE-2026-80807 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject invalid block index in GC ioctl Syzbot reported list corruption caused by a double list_add_tail() call on bh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers(). Analysis revealed that th |
- CVE-2026-80827Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: USB: serial: option: fix slab OOB read in interrupt URB callback The interrupt URB buffer is allocated in setup_port_interrupt_in() based on the endpoint's wMaxPacketSize: buffer_size = usb_endpoint_maxp(e
- CVE-2026-80826Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: USB: c67x00: fix use-after-free in c67x00_add_iso_urb() When TD creation fails for the last packet of an isochronous URB, c67x00_add_iso_urb() gives the URB back before updating the endpoint scheduling state.
- CVE-2026-80825Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb mt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB header onto every skb and assumes the headroom for them is already there. That
- CVE-2026-80824Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: usb: usbfs: fix use-after-free of usb_device in usbdev_release() usbdev_release() drops its reference to the struct usb_device before draining the list of completed async URBs, but that drain path reads back th
- CVE-2026-80823Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: st21nfca: validate ATR_REQ length against the received frame st21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at least ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->leng
- CVE-2026-80822Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() Add a check to see if devm_kasprintf() is not NULL in mchp_ipc_get_cluster_aggr_irq(), returning -ENOMEM if the function failed.
- CVE-2026-80821Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: put CQ ref on create_cq mapping failure nvmet_pci_epf_create_cq() calls nvmet_cq_create(), which takes a reference on the controller and installs the completion queue. If the subsequent PCI addr
- CVE-2026-80819Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept rfcomm_sock_recvmsg() completes a deferred setup by calling rfcomm_dlc_accept() without holding any RFCOMM lock: if (test_and_clear_bit(RFCOM
- CVE-2026-80818Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown arm_smmu_impl_remove() is registered as a devres action in arm_smmu_impl_probe(), before arm_smmu_init_queues() allocates smmu->cmdq.q.base. On a de
- CVE-2026-80817Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages iommufd_ioas_change_process() iterates every IOAS area while only holding every IOAS iova_rwsem, so it a
- CVE-2026-80816Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: Use a private URB for the notification endpoint fcp_init_notify() used mixer->urb, which snd_usb_mixer_status_create() allocates for the optional UAC2 status interrupt endpoint and mixer.c kills, res
- CVE-2026-80815Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Use a private URB for the notification endpoint scarlett2_init_notify() used mixer->urb, which snd_usb_mixer_status_create() allocates for the UAC2 status interrupt endpoint and mixer.c manages
- CVE-2026-80814Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: rndis_host: add overflow check in rndis_rx_fixup() Add an overflow check to ensure that data_offset + data_len + 8 does not wrap, which would enable an OOB read of the USB data buffer.
- CVE-2026-80813Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() When a host issues an Identify command with CNS 07h (Active Namespace ID List for a specific I/O Command Set), nvmet_execute_identify_nslis
- CVE-2026-80812Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: dummy: Check card index validity at probe snd_dummy_probe() blindly trusts that the given devptr->id value is within the proper card index range. It's OK for the devices the driver itself creates at the
- CVE-2026-80811Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: io_uring/cmd: fix iovec leak when the async cmd is not recycled An io_async_cmd carries an iovec array in ->vec.iovec, allocated when the vec has to grow and kept across recycling through ctx->cmd_cache. On tw
- CVE-2026-80810Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() io_vec_fill_bvec() computes the folio size with a plain int 1: unsigned long folio_size = 1 << imu->folio_shift; imu->folio_shift is unsigned int
- CVE-2026-80809Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix missing metadata reservation for large xattrs [BUG] lsetxattr() panics the kernel when setting a large xattr value on a fragmented filesystem where the file already has an external xattr block. [CAU
- CVE-2026-80808Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ext4: stop retrying saturated xattr cache entries ext4_xattr_block_set() retries when a cache entry selected for reuse has a saturated reference count after taking the buffer lock. The retry returns to the mbca
- CVE-2026-80807Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject invalid block index in GC ioctl Syzbot reported list corruption caused by a double list_add_tail() call on bh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers(). Analysis revealed that th
Page 11 of 107