rpm package
opensuse/kernel-source&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-89441 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: cancel card-detect work on remove Disabling the device interrupt and freeing the IRQ prevents new card-detect work from being queued, but carddet_work already queued by the handler can still run | |
| CVE-2026-89440 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe failure request_irq() registers the SD card-detect interrupt and the probe enables it before mmc_add_host() runs. If mmc_add_host() fails, the error path only | |
| CVE-2026-89439 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Add a NULL check for sst_inst[] To be consistent with other places, add a NULL check for failed socket loading by checking isst_common.sst_inst[]. | ||
| CVE-2026-89438 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate logical CPU id and clos id Validate max CLOS ID and logical CPU ID for core power feature. Reject any clos level or logical CPU number greater than the supported maximum. These are | ||
| CVE-2026-89437 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: int1092: Fix potential memory leak in sar_probe() The memory allocated for device_mode_info in parse_package() called by sar_get_data() is not freed in some of the error paths in sar_probe(). Fix | ||
| CVE-2026-89436 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] acpi_pcc_retrieve_biosdata() rejects SINF packages only when pcc->num_sifr is strictly less than hkey->package.count, then unconditionally wri | |
| CVE-2026-81018 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Free system certificate signatures Multi-certificate support also allows the system authentication object to store ->signature and ->save_signature, which leak when the driver is remove | ||
| CVE-2026-81017 | Hig | 8.4 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Bound the EC-reported sensor number Each EC FIFO event carries an 8-bit sensor number (in->sensor_num). cros_ec_sensorhub_ring_handler() validates the FIFO event count, the per-read | |
| CVE-2026-81016 | Hig | 7.7 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") th | |
| CVE-2026-81015 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails amd_pmc_probe() registers the LPS0 s2idle handler with acpi_register_lps0_dev() and creates the driver's debugfs directory before calling amd | |
| CVE-2026-81014 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() sk_store() and kek_store() strip a trailing newline from the sysfs write before allocating the key buffer: length = count; if (buf[le | ||
| CVE-2026-81013 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on empty password write validate_password_input() computes length = strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that len | ||
| CVE-2026-81012 | Hig | 8.4 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() hp_get_string_from_buffer() clamps the converted string length against the destination buffer size with "size > dst_size", so when t | |
| CVE-2026-81011 | Hig | 7.1 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element count to package parsers The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and then | |
| CVE-2026-81010 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originating task. The fallback runs from a kworker a | |
| CVE-2026-81009 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value as usize. copy_struct_to_user() uses that u | ||
| CVE-2026-81008 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() In of_icc_get_by_index() and icc_get(), if the dynamic allocation for path->name fails via kasprintf(), the error handling path directly c | |
| CVE-2026-81007 | Hig | 7.1 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes. A length smaller than the SMBus header u | |
| CVE-2026-81006 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failure ipmi_add_smi() creates the nr_users and nr_msgs files before trying to create the maintenance_mode file. If that last creation fails, the error path removes | |
| CVE-2026-81005 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipmi: si: Fix NULL pointer dereference after failed registration try_smi_init() allocates new_smi->si_sm and later calls ipmi_register_smi_mod(), which maps to ipmi_add_smi(). During ipmi_add_smi(), the upper |
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: cancel card-detect work on remove Disabling the device interrupt and freeing the IRQ prevents new card-detect work from being queued, but carddet_work already queued by the handler can still run
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe failure request_irq() registers the SD card-detect interrupt and the probe enables it before mmc_add_host() runs. If mmc_add_host() fails, the error path only
- CVE-2026-89439Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Add a NULL check for sst_inst[] To be consistent with other places, add a NULL check for failed socket loading by checking isst_common.sst_inst[].
- CVE-2026-89438Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate logical CPU id and clos id Validate max CLOS ID and logical CPU ID for core power feature. Reject any clos level or logical CPU number greater than the supported maximum. These are
- CVE-2026-89437Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: int1092: Fix potential memory leak in sar_probe() The memory allocated for device_mode_info in parse_package() called by sar_get_data() is not freed in some of the error paths in sar_probe(). Fix
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] acpi_pcc_retrieve_biosdata() rejects SINF packages only when pcc->num_sifr is strictly less than hkey->package.count, then unconditionally wri
- CVE-2026-81018Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Free system certificate signatures Multi-certificate support also allows the system authentication object to store ->signature and ->save_signature, which leak when the driver is remove
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Bound the EC-reported sensor number Each EC FIFO event carries an 8-bit sensor number (in->sensor_num). cros_ec_sensorhub_ring_handler() validates the FIFO event count, the per-read
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") th
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails amd_pmc_probe() registers the LPS0 s2idle handler with acpi_register_lps0_dev() and creates the driver's debugfs directory before calling amd
- CVE-2026-81014Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() sk_store() and kek_store() strip a trailing newline from the sysfs write before allocating the key buffer: length = count; if (buf[le
- CVE-2026-81013Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on empty password write validate_password_input() computes length = strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that len
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() hp_get_string_from_buffer() clamps the converted string length against the destination buffer size with "size > dst_size", so when t
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element count to package parsers The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and then
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originating task. The fallback runs from a kworker a
- CVE-2026-81009Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value as usize. copy_struct_to_user() uses that u
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() In of_icc_get_by_index() and icc_get(), if the dynamic allocation for path->name fails via kasprintf(), the error handling path directly c
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes. A length smaller than the SMBus header u
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failure ipmi_add_smi() creates the nr_users and nr_msgs files before trying to create the maintenance_mode file. If that last creation fails, the error path removes
- CVE-2026-81005Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ipmi: si: Fix NULL pointer dereference after failed registration try_smi_init() allocates new_smi->si_sm and later calls ipmi_register_smi_mod(), which maps to ipmi_add_smi(). During ipmi_add_smi(), the upper
Page 4 of 107