rpm package
opensuse/kernel-source&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-80806 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: don't enable DAX on new encrypted files Currently, when a new encrypted regular file is created, the call to ext4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made before EXT4_INODE_ENCRYPT | ||
| CVE-2026-80805 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: validate attr entry pointer before field access xfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen, valuelen) before checking if the entry pointer itself is within bounds. If nameidx is c | ||
| CVE-2026-80804 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: restore nofs context unconditionally in xfs_trans_roll When __xfs_trans_commit() fails in xfs_trans_roll(), the NOFS context is cleared but only restored in the success path. This leaves the error path wi | ||
| CVE-2026-80803 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: digital: clamp SENSF_RES length to the destination buffer digital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote NFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res fiel | ||
| CVE-2026-80802 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: bound the device-reported read length and fix an skb leak fdp_nci_i2c_read() takes the next packet length from two device-supplied bytes and never validates it. The value is a u16 used as the i2c_mast | ||
| CVE-2026-80801 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: microread: validate target discovery payload lengths microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were che | ||
| CVE-2026-80800 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound the connect_sn TLV walk to the skb Commit 27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and add length checks") fixed the unbounded TLV walk in nfc_llcp_recv_snl(), and commit d8bd | ||
| CVE-2026-80799 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain three related bugs in their TLV parsing loops: 1. 'offset' is declared u8 but tlv_a | ||
| CVE-2026-80798 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: reject PDUs shorter than the LLCP header Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the receive path never checked that a frame is at least LLCP_HEADER_SIZE bytes before pa | ||
| CVE-2026-80797 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: purge fragmented skbs during cleanup pn53x_common_clean() purges resp_q before freeing the common PN533 state, but it leaves fragment_skb untouched. The fragmentation helpers queue transmit fragmen | ||
| CVE-2026-80796 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: add data_len bound checks to activation parameter extractors nci_extract_activation_params_iso_dep() and nci_extract_activation_params_nfc_dep() read an inner length byte from the NCI RF_INTF_ACTIVATE | ||
| CVE-2026-80795 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix out-of-bounds write in nci_target_auto_activated() nci_target_auto_activated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets wit | ||
| CVE-2026-80794 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a notification into an on-stack struct (nci_rf_discover_ntf / | ||
| CVE-2026-80793 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: reject undersized MTUs in ip_do_fragment() ip_do_fragment() subtracts the IPv4 header length from the effective MTU and passes the resulting payload MTU to ip_frag_next(). If the effective MTU is smaller | ||
| CVE-2026-80792 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix use-after-free in ip6_finish_output2() ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmit path or other encapsulation | ||
| CVE-2026-80791 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builde | ||
| CVE-2026-80790 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: fix invalid free in LS IOD error path nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD array. If an rqstbuf allocation or response buffer DMA mapping fails, the unwind loop decre | ||
| CVE-2026-80789 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: bound SGL data length before allocating command buffers nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length and, for the in-capsule offset descriptor (type 0x01), checks it against port | ||
| CVE-2026-80788 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations When fuzzing the nvme target code, I tripped a kernel warning in nvmet_tcp_map_data() because the length passed into the allocator is cont | ||
| CVE-2026-80787 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() nvmet_pci_epf_exec_iod_work() submits an I/O command with req->execute() and then waits for the command to complete and transfers the data bac |
- CVE-2026-80806Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ext4: don't enable DAX on new encrypted files Currently, when a new encrypted regular file is created, the call to ext4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made before EXT4_INODE_ENCRYPT
- CVE-2026-80805Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: xfs: validate attr entry pointer before field access xfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen, valuelen) before checking if the entry pointer itself is within bounds. If nameidx is c
- CVE-2026-80804Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: xfs: restore nofs context unconditionally in xfs_trans_roll When __xfs_trans_commit() fails in xfs_trans_roll(), the NOFS context is cleared but only restored in the success path. This leaves the error path wi
- CVE-2026-80803Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: digital: clamp SENSF_RES length to the destination buffer digital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote NFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res fiel
- CVE-2026-80802Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: bound the device-reported read length and fix an skb leak fdp_nci_i2c_read() takes the next packet length from two device-supplied bytes and never validates it. The value is a u16 used as the i2c_mast
- CVE-2026-80801Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: microread: validate target discovery payload lengths microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were che
- CVE-2026-80800Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound the connect_sn TLV walk to the skb Commit 27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and add length checks") fixed the unbounded TLV walk in nfc_llcp_recv_snl(), and commit d8bd
- CVE-2026-80799Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain three related bugs in their TLV parsing loops: 1. 'offset' is declared u8 but tlv_a
- CVE-2026-80798Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: reject PDUs shorter than the LLCP header Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the receive path never checked that a frame is at least LLCP_HEADER_SIZE bytes before pa
- CVE-2026-80797Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: purge fragmented skbs during cleanup pn53x_common_clean() purges resp_q before freeing the common PN533 state, but it leaves fragment_skb untouched. The fragmentation helpers queue transmit fragmen
- CVE-2026-80796Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: add data_len bound checks to activation parameter extractors nci_extract_activation_params_iso_dep() and nci_extract_activation_params_nfc_dep() read an inner length byte from the NCI RF_INTF_ACTIVATE
- CVE-2026-80795Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix out-of-bounds write in nci_target_auto_activated() nci_target_auto_activated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets wit
- CVE-2026-80794Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a notification into an on-stack struct (nci_rf_discover_ntf /
- CVE-2026-80793Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ipv4: reject undersized MTUs in ip_do_fragment() ip_do_fragment() subtracts the IPv4 header length from the effective MTU and passes the resulting payload MTU to ip_frag_next(). If the effective MTU is smaller
- CVE-2026-80792Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix use-after-free in ip6_finish_output2() ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmit path or other encapsulation
- CVE-2026-80791Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builde
- CVE-2026-80790Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: fix invalid free in LS IOD error path nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD array. If an rqstbuf allocation or response buffer DMA mapping fails, the unwind loop decre
- CVE-2026-80789Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: bound SGL data length before allocating command buffers nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length and, for the in-capsule offset descriptor (type 0x01), checks it against port
- CVE-2026-80788Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations When fuzzing the nvme target code, I tripped a kernel warning in nvmet_tcp_map_data() because the length passed into the allocator is cont
- CVE-2026-80787Sep 4, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() nvmet_pci_epf_exec_iod_work() submits an I/O command with req->execute() and then waits for the command to complete and transfers the data bac
Page 12 of 107