VYPR

rpm package

opensuse/kernel-source&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed

Vulnerabilities (2,129)

  • CVE-2026-81003HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingress device afiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte name fields in the transport header alone. No check is made against the ne

  • CVE-2026-81000HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to T

  • CVE-2026-80999Sep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO rtl83xx_reset_assert() and rtl83xx_reset_deassert() are only called from the probe path, which may sleep and is not timing-critical. When the rese

  • CVE-2026-80998HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: bnxt: ring the doorbell when SW USO exits early When a burst of packets is handed down to the driver, the driver defers the doorbell to the end by setting txr->kick_pending = 1. The normal TX path handles

  • CVE-2026-80997HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix stalled modem TX queue after runtime resume ipa_start_xmit() unconditionally stops the TX queue before calling pm_runtime_get(), relying on the wake scheduled by runtime resume (ipa_modem_wake_que

  • CVE-2026-80996Sep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: l2tp: do not propagate multicast notification errors The tunnel create, tunnel modify, session create, and session modify netlink handlers send multicast notifications through helpers that can fail while a

  • CVE-2026-80995HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in mctp_route_lookup() mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the rou

  • CVE-2026-80994HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix flow mask use-after-free on flow deletion The commit in the Fixes tag below made so flow->mask free is scheduled via RCU right after it is removed from the flow table. The pointer stays i

  • CVE-2026-80993Sep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: phylink: correctly validate returned PCS in phylink_inband_caps In phylink_inband_caps(), the PCS returned by mac_select_pcs is only checked if NULL but mac_select_pcs can also return an error pointer. Th

  • CVE-2026-80992HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: ravb: avoid dereferencing an invalid PTP clock The PTP clock is unavailable before the first open, so querying its index can dereference a NULL pointer. Registration failures can also leave an error pointe

  • CVE-2026-80991HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: ravb: serialize PTP clock teardown ravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to ptp_clock_event() while ptp_clock_unregister() is freeing it. This can lead to a use-after-free.

  • CVE-2026-80990Sep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range() as the lower bound, so a taken id is not an error there: the alloc

  • CVE-2026-80989HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Mark the connection down when bringing it up fails Every failure path in tbnet_connected_work() undoes its own work and returns without clearing login_sent, so the connection still looks estab

  • CVE-2026-80988Sep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Fail TX enqueue when the QP link is down Commit f195a1a6fe41 ("ntb: Drop packets when qp link is down") meant to make ntb_transport_tx_enqueue() drop packets submitted while the QP link is d

  • CVE-2026-80987HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntb_process_tx() handles an oversized buffer by calling tx_handler() with a NULL data pointer and returning success. ntb_netdev therefore neither frees the skb in

  • CVE-2026-80986CriSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages On a link whose device has max_recv_sge == 1 there is no shared v2 receive buffer, and smc_llc_save_add_link_rkeys() takes the v2 extension from 44 by

  • CVE-2026-80985HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part of a v2 message that does not fit into the 44-byte union smc_llc_msg, a

  • CVE-2026-80984Sep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that co

  • CVE-2026-80983Sep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket refcount leak in smc_switch_conns() smc_switch_conns() takes a reference on the SMC socket before dropping lgr->conns_lock, so the connection stays alive while the CDC slot is fetched:

  • CVE-2026-80982HigSep 11, 2026
    affected < 7.2.6-1.1fixed 7.2.6-1.1

    In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free in smc_rx_pipe_buf_release() smc_rx_splice() hands RMB pages to a pipe and takes a socket reference per entry so the smc_sock stays alive until the reader finishes. The connection do

Page 5 of 107