rpm package
opensuse/kernel-source&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-80981 | Cri | 9.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link; smc_llc.c:1482 ... smc_llc_s | |
| CVE-2026-80980 | Cri | 9.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-wri | |
| CVE-2026-80979 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining the rx tasklet smc_conn_free() calls smc_ism_unset_conn() only while the link group is still on its device list, and never sets conn->killed. smc_lgr_terminate | |
| CVE-2026-80978 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel devices derive their advertised needed_headroom from lower output devices. A stack of user-created devices can make the derived value larger than the 16-bit skb | |
| CVE-2026-80977 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't touch shared zerocopy state in skb_tx_error() skb_tx_error() completes the zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears SKBFL_MANAGED_FRAG_REFS. Both | |
| CVE-2026-80976 | Cri | 9.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_and_validate() pulls the outer SRv6 headers and makes the inner packet the skb network header. The IPv6 control block still contains values collected while parsi | |
| CVE-2026-80975 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: mfd: qnap-mcu: keep the reply buffer alive past a command timeout qnap_mcu_exec() publishes an on-stack buffer to the receive path: unsigned char rx[QNAP_MCU_RX_BUFFER_SIZE]; ... reply->data = rx; reply->l | |
| CVE-2026-80974 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: Fix potential memory leaks during remove The memory allocated for struct sm501_devdata in sm501_pci_probe() and sm501_plat_probe() is not freed by the corresponding remove functions sm501_pci_remove | ||
| CVE-2026-80970 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: do not copy out an uninitialised init response fcp_ioctl_init() allocates its response buffer with kmalloc() and copies the whole buffer back to userspace: buf_size = init.step0_resp_size + init.st | ||
| CVE-2026-80969 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: mpu401: Check card index validity at probe mpu401 driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates a | ||
| CVE-2026-80968 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe Although mts64 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via s | ||
| CVE-2026-80967 | Hig | 8.4 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ pcxhr_probe() requests pcxhr_threaded_irq() before initializing mgr->lock, even though the threaded handler takes that mutex. Initialize the manag | |
| CVE-2026-80966 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: portman2x4: Check card index validity at probe Although portman2x4 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when b | ||
| CVE-2026-80965 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: serial-u16550: Check card index validity at probe serial-u16550 driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver it | ||
| CVE-2026-80964 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe virmidi driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates | ||
| CVE-2026-80963 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu data fails If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code jumps to the "out" label and calls dm_stat_free. dm_stat_free does "for_each_possi | ||
| CVE-2026-80962 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate geometry fields from on-disk cache_info cache_segs_init() iterates cache_info->n_segs times indexing cache->segments[], which is sized to the cache device geometry, and get_seg_id() takes ea | |
| CVE-2026-80961 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment bounds Two more fields decoded from the cache device go unbounded. The kset key_num drives cache_kset_crc() and the replay loop in cache_replay(), the writebac | |
| CVE-2026-80960 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate on-media seg_num against the cache device size seg_num is read from the crc32c-only superblock, so whoever supplies the cache device on a table load (CAP_SYS_ADMIN) controls it. It sizes cac | ||
| CVE-2026-80959 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: bound the persisted tail-position offset cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from the cache device and addresses within the segment with it. A seg_off at or past th |
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link; smc_llc.c:1482 ... smc_llc_s
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-wri
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining the rx tasklet smc_conn_free() calls smc_ism_unset_conn() only while the link group is still on its device list, and never sets conn->killed. smc_lgr_terminate
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel devices derive their advertised needed_headroom from lower output devices. A stack of user-created devices can make the derived value larger than the 16-bit skb
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't touch shared zerocopy state in skb_tx_error() skb_tx_error() completes the zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears SKBFL_MANAGED_FRAG_REFS. Both
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_and_validate() pulls the outer SRv6 headers and makes the inner packet the skb network header. The IPv6 control block still contains values collected while parsi
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: mfd: qnap-mcu: keep the reply buffer alive past a command timeout qnap_mcu_exec() publishes an on-stack buffer to the receive path: unsigned char rx[QNAP_MCU_RX_BUFFER_SIZE]; ... reply->data = rx; reply->l
- CVE-2026-80974Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: Fix potential memory leaks during remove The memory allocated for struct sm501_devdata in sm501_pci_probe() and sm501_plat_probe() is not freed by the corresponding remove functions sm501_pci_remove
- CVE-2026-80970Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: do not copy out an uninitialised init response fcp_ioctl_init() allocates its response buffer with kmalloc() and copies the whole buffer back to userspace: buf_size = init.step0_resp_size + init.st
- CVE-2026-80969Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: mpu401: Check card index validity at probe mpu401 driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates a
- CVE-2026-80968Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe Although mts64 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via s
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ pcxhr_probe() requests pcxhr_threaded_irq() before initializing mgr->lock, even though the threaded handler takes that mutex. Initialize the manag
- CVE-2026-80966Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: portman2x4: Check card index validity at probe Although portman2x4 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when b
- CVE-2026-80965Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: serial-u16550: Check card index validity at probe serial-u16550 driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver it
- CVE-2026-80964Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe virmidi driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates
- CVE-2026-80963Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu data fails If "dm_kvzalloc(percpu_alloc_size, cpu_to_node(cpu))" fails, the code jumps to the "out" label and calls dm_stat_free. dm_stat_free does "for_each_possi
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate geometry fields from on-disk cache_info cache_segs_init() iterates cache_info->n_segs times indexing cache->segments[], which is sized to the cache device geometry, and get_seg_id() takes ea
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment bounds Two more fields decoded from the cache device go unbounded. The kset key_num drives cache_kset_crc() and the replay loop in cache_replay(), the writebac
- CVE-2026-80960Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate on-media seg_num against the cache device size seg_num is read from the crc32c-only superblock, so whoever supplies the cache device on a table load (CAP_SYS_ADMIN) controls it. It sizes cac
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: bound the persisted tail-position offset cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from the cache device and addresses within the segment with it. A seg_off at or past th
Page 6 of 107