rpm package
opensuse/kernel-source&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-80958 | Hig | 7.1 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: clamp the tail kset read to the segment data region The tail-kset read in cache_replay(), the writeback worker and the GC worker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment size r | |
| CVE-2026-80957 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: detect a cycle in the last-kset chain during replay cache_replay() follows the on-media last-kset chain by next_cache_seg_id with no cond_resched(). A forged chain that points back into a segment it | ||
| CVE-2026-80956 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: only hand out initialized cache segments get_cache_segment() scans the segment map up to cache->n_segs, the physical device segment count, but cache_segs_init() only initializes the first cache_info- | ||
| CVE-2026-80955 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() In kset_replay, when key->seg_gen is stale (key->seg_gen < key->cache_pos.cache_seg->gen), cache_key_put(key) is called but then key->ca | |
| CVE-2026-80954 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the master controller. However, dev->desc must not be dereferenc | |
| CVE-2026-80953 | Hig | 8.4 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabling interrupts adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR before the controller's IBI state, transfer queue list and transfer queu | |
| CVE-2026-80952 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before calling device_unregister(). During device_unregister(), device_del() emits a KOBJ_ | |
| CVE-2026-80951 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: bound IBI payload to the requested max_payload_len svc_i3c_master_handle_ibi() reads the IBI payload from the RX FIFO into the IBI slot. The loop is bounded by the hardware FIFO size (SVC_I3C_ | ||
| CVE-2026-80950 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid before accessing it The Renesas I3C driver uses an asynchronous model to transfer data. It prepares a struct renesas_i3c_xfer, enqueues it, and waits for completio | |
| CVE-2026-80949 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() The memory allocated for buf is not freed in some of the error paths in brcmf_sdio_read_control(). Fix that by adding vfree() calls. [arend: rework | ||
| CVE-2026-80948 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() In iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses the out_free_eeprom_blob label. Consequently, error paths triggered after | ||
| CVE-2026-80947 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop rtl8xxxu arms rx_urb_wq from the RX completion path: rtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), which queues it on rx_urb_pending_ | |
| CVE-2026-80946 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse: copy request headers via a stack buffer for io-uring The fuse-io-uring transport copies req->in.h out to the ring in fuse_uring_copy_to_ring() and req->out.h back in fuse_uring_commit(). Both headers live | ||
| CVE-2026-80945 | Cri | 9.1 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst with the CPU while it is still mapped DMA_FR | |
| CVE-2026-80944 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupted wait mwifiex synchronous commands keep the caller-provided data buffer in cmd_node->data_buf. Several callers pass stack-allocated objects there. If wait_ev | |
| CVE-2026-80943 | Hig | 7.6 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee8 | |
| CVE-2026-80942 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subsequent error paths in rtl92du_init_sw_vars(). F | ||
| CVE-2026-80941 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() The skb passed to the rtw_hci_tx_write() is expected to be freed when the function fails, but the error path in rtw_txq_push_skb() does not free the | ||
| CVE-2026-80940 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: pci: fix resource leak on failed NAPI setup rtw_pci_probe() allocates PCI resources through rtw_pci_setup_resource() before it sets up NAPI. If rtw_pci_napi_init() fails, the error path jumps strai | ||
| CVE-2026-80939 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Since the hardware rfkill polling was introduced, arm64 platforms can panic with an asynchronous SError during warm reboot: SError In |
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: clamp the tail kset read to the segment data region The tail-kset read in cache_replay(), the writeback worker and the GC worker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment size r
- CVE-2026-80957Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: detect a cycle in the last-kset chain during replay cache_replay() follows the on-media last-kset chain by next_cache_seg_id with no cond_resched(). A forged chain that points back into a segment it
- CVE-2026-80956Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: only hand out initialized cache segments get_cache_segment() scans the segment map up to cache->n_segs, the physical device segment count, but cache_segs_init() only initializes the first cache_info-
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() In kset_replay, when key->seg_gen is stale (key->seg_gen < key->cache_pos.cache_seg->gen), cache_key_put(key) is called but then key->ca
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the master controller. However, dev->desc must not be dereferenc
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabling interrupts adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR before the controller's IBI state, transfer queue list and transfer queu
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before calling device_unregister(). During device_unregister(), device_del() emits a KOBJ_
- CVE-2026-80951Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: bound IBI payload to the requested max_payload_len svc_i3c_master_handle_ibi() reads the IBI payload from the RX FIFO into the IBI slot. The loop is bounded by the hardware FIFO size (SVC_I3C_
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid before accessing it The Renesas I3C driver uses an asynchronous model to transfer data. It prepares a struct renesas_i3c_xfer, enqueues it, and waits for completio
- CVE-2026-80949Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() The memory allocated for buf is not freed in some of the error paths in brcmf_sdio_read_control(). Fix that by adding vfree() calls. [arend: rework
- CVE-2026-80948Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() In iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses the out_free_eeprom_blob label. Consequently, error paths triggered after
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop rtl8xxxu arms rx_urb_wq from the RX completion path: rtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), which queues it on rx_urb_pending_
- CVE-2026-80946Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: fuse: copy request headers via a stack buffer for io-uring The fuse-io-uring transport copies req->in.h out to the ring in fuse_uring_copy_to_ring() and req->out.h back in fuse_uring_commit(). Both headers live
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst with the CPU while it is still mapped DMA_FR
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupted wait mwifiex synchronous commands keep the caller-provided data buffer in cmd_node->data_buf. Several callers pass stack-allocated objects there. If wait_ev
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee8
- CVE-2026-80942Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subsequent error paths in rtl92du_init_sw_vars(). F
- CVE-2026-80941Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() The skb passed to the rtw_hci_tx_write() is expected to be freed when the function fails, but the error path in rtw_txq_push_skb() does not free the
- CVE-2026-80940Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: pci: fix resource leak on failed NAPI setup rtw_pci_probe() allocates PCI resources through rtw_pci_setup_resource() before it sets up NAPI. If rtw_pci_napi_init() fails, the error path jumps strai
- CVE-2026-80939Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Since the hardware rfkill polling was introduced, arm64 platforms can panic with an asynchronous SError during warm reboot: SError In
Page 7 of 107