rpm package
opensuse/kernel-source&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-89573 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm array: reject an array block whose value size is not the caller's array_block_check() can only compare the header against itself, so a block with value_size 4 and max_entries 1018 is internally consistent an | |
| CVE-2026-89503 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() ring_buffer_alloc_read_page() is racy with ring_buffer_subbuf_order_set, it can allocate a reader page with an outdated order. This isn't a | |
| CVE-2026-89502 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbuf_order When sub-buffers use an order greater than 0, cpu_buffer->free_page is allocated with subbuf_order. Use the correct order for cpu_buffer->free_page. | ||
| CVE-2026-89501 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf Because, ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page, hold cpu_buffer->lock to prevent races with ring_buffer_alloc_read_page() and r | |
| CVE-2026-89500 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page Discarding a cached reader page after a concurrent ring buffer resize uses the new global subbuf_order for the free_pages() call. This mismatched | |
| CVE-2026-89484 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocation failure nlmclnt_locks_init_private() installs NLM file lock operations even when nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc() then r | ||
| CVE-2026-89483 | Hig | 7.5 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: zero the discard fallback page nvme_setup_discard() always maps sizeof(struct nvme_dsm_range) * NVME_DSM_MAX_RANGES = 4096 bytes as the DSM payload however many ranges the command declares, because some d | |
| CVE-2026-89482 | Cri | 9.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone Commit 25e5cb780e62 ("nvme-tcp: fix possible crash in write_zeroes processing") established that blk_rq_payload_bytes() must not be read wit | |
| CVE-2026-89477 | Hig | 7.5 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix NULL deref on untransmitted RECONF completion sctp_process_strreset_outreq(), sctp_process_strreset_addstrm_out() and sctp_process_strreset_resp() complete a pending stream reconfiguration request by | |
| CVE-2026-89476 | Hig | 7.5 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix stream->outcnt underflow on duplicate RECONF responses A cached RECONF chunk may contain more than one request parameter. A duplicate response can therefore find and process the same ADD_OUT request | |
| CVE-2026-89460 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks The command 'perf stat -e cycles -- ' crashes the kernel when CPUs are hotplug added during that run. Root cause is the allocation of struct | ||
| CVE-2026-89459 | Hig | 7.0 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils Commit a737737cdb9c ("s390/percpu: Infrastructure for more efficient this_cpu operations") introduced MVIY_PERCPU(), which stringifies arguments that are alrea | |
| CVE-2026-89458 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Do not complete a failed ESE read as successful dasd_int_handler() completes an NRF read of an unallocated ESE track by calling ese_read() and unconditionally marking the request DASD_CQR_SUCCESS. da | ||
| CVE-2026-89457 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Guard sysfs discipline callbacks against unallocated private data Several sysfs show/store handlers call a discipline callback that dereferences device->private, either directly or through the DASD_D | ||
| CVE-2026-89456 | Hig | 7.0 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length across ERP recovery dasd_default_erp_postaction() copies the timing and device state from the finished ERP request back to the original request but drops proc_byte | |
| CVE-2026-89447 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invoke. However, the current test calls iommuf | ||
| CVE-2026-89446 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Release current IOAS on xa_store() failure iommufd_take_all_iova_rwsem() takes an object reference and the iova_rwsem write lock before storing the IOAS in the temporary ioas_list xarray. If xa_store( | ||
| CVE-2026-89445 | Hig | 8.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUFD selftest TRIGGER_IOPF borrows an attach handle from group->pasid_array without synchronizing against PASID detach, then a concurrent iommu_report_device_fault | |
| CVE-2026-89443 | Hig | 7.1 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask ioctls isst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the user-provided level as an index into perf_levels[] via _read_pp_level_info() and _re | |
| CVE-2026-89442 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_assoc ioctl isst_if_clos_assoc() validates the user-supplied socket_id with 'socket_id > topology_max_packages()', but isst_common.sst_inst[] is allocated with top |
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm array: reject an array block whose value size is not the caller's array_block_check() can only compare the header against itself, so a block with value_size 4 and max_entries 1018 is internally consistent an
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() ring_buffer_alloc_read_page() is racy with ring_buffer_subbuf_order_set, it can allocate a reader page with an outdated order. This isn't a
- CVE-2026-89502Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbuf_order When sub-buffers use an order greater than 0, cpu_buffer->free_page is allocated with subbuf_order. Use the correct order for cpu_buffer->free_page.
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf Because, ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page, hold cpu_buffer->lock to prevent races with ring_buffer_alloc_read_page() and r
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page Discarding a cached reader page after a concurrent ring buffer resize uses the new global subbuf_order for the free_pages() call. This mismatched
- CVE-2026-89484Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocation failure nlmclnt_locks_init_private() installs NLM file lock operations even when nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc() then r
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: nvme: zero the discard fallback page nvme_setup_discard() always maps sizeof(struct nvme_dsm_range) * NVME_DSM_MAX_RANGES = 4096 bytes as the DSM payload however many ranges the command declares, because some d
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone Commit 25e5cb780e62 ("nvme-tcp: fix possible crash in write_zeroes processing") established that blk_rq_payload_bytes() must not be read wit
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: sctp: fix NULL deref on untransmitted RECONF completion sctp_process_strreset_outreq(), sctp_process_strreset_addstrm_out() and sctp_process_strreset_resp() complete a pending stream reconfiguration request by
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: sctp: fix stream->outcnt underflow on duplicate RECONF responses A cached RECONF chunk may contain more than one request parameter. A duplicate response can therefore find and process the same ADD_OUT request
- CVE-2026-89460Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks The command 'perf stat -e cycles -- ' crashes the kernel when CPUs are hotplug added during that run. Root cause is the allocation of struct
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils Commit a737737cdb9c ("s390/percpu: Infrastructure for more efficient this_cpu operations") introduced MVIY_PERCPU(), which stringifies arguments that are alrea
- CVE-2026-89458Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Do not complete a failed ESE read as successful dasd_int_handler() completes an NRF read of an unallocated ESE track by calling ese_read() and unconditionally marking the request DASD_CQR_SUCCESS. da
- CVE-2026-89457Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Guard sysfs discipline callbacks against unallocated private data Several sysfs show/store handlers call a discipline callback that dereferences device->private, either directly or through the DASD_D
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length across ERP recovery dasd_default_erp_postaction() copies the timing and device state from the finished ERP request back to the original request but drops proc_byte
- CVE-2026-89447Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invoke. However, the current test calls iommuf
- CVE-2026-89446Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: iommufd: Release current IOAS on xa_store() failure iommufd_take_all_iova_rwsem() takes an object reference and the iova_rwsem write lock before storing the IOAS in the temporary ioas_list xarray. If xa_store(
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUFD selftest TRIGGER_IOPF borrows an attach handle from group->pasid_array without synchronizing against PASID detach, then a concurrent iommu_report_device_fault
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask ioctls isst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the user-provided level as an index into perf_levels[] via _read_pp_level_info() and _re
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_assoc ioctl isst_if_clos_assoc() validates the user-supplied socket_id with 'socket_id > topology_max_packages()', but isst_common.sst_inst[] is allocated with top
Page 3 of 107