rpm package
opensuse/kernel-source&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-80938 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex mt7615_suspend() acquired the mt76 mutex and then called cancel_delayed_work_sync() on mac_work. mt7615_mac_work() acquires the same mutex vi | ||
| CVE-2026-80937 | Hig | 8.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's dev->mt76.eeprom.data buffer at the offset reported by the MCU resp | |
| CVE-2026-80936 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel mlo_pm_work on stop mt7925 queues mlo_pm_work with a 5 second delay during multi-link power-save setup and never cancels it on the stop path. If the device is torn down inside that wi | |
| CVE-2026-80935 | Hig | 8.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block copy from the address reported by the MCU response (event->addr, | |
| CVE-2026-80934 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames mt7996/mt7992 hand the firmware a HW MAC-TXP for AddBA req action frames (MT_TXD7_MAC_TXD, set in mt7996_mac_write_txwi_80211()), but are otherwi | ||
| CVE-2026-80933 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmware size The default EEPROM firmware is parsed and copied as a full EEPROM without checking its length. A truncated file can make the driver read beyond the firm | |
| CVE-2026-80932 | Hig | 8.4 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for depend | |
| CVE-2026-80931 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the device. | |
| CVE-2026-80930 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout i2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the interrupt handler to report a status change. If the wait times out, or is interrupted before | ||
| CVE-2026-80929 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is only used in the root namespace. However, due to pid_table_root_permissions(), a non-root user | |
| CVE-2026-80928 | Hig | 7.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a n | |
| CVE-2026-80927 | — | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() If the auxiliary clock is disabled during tk_get_aux_ts64() but is enabled before tks->clock_valid is checked, then uninitialized stackd | ||
| CVE-2026-80926 | Cri | 9.8 | < 7.2.6-1.1 | 7.2.6-1.1 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning the | |
| CVE-2026-80925 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling HW VLAN offload Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX) on a lower device invokes vlan_transfer_features(), which | ||
| CVE-2026-80924 | Hig | 7.5 | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buffers crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the | |
| CVE-2026-80923 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: xhci: dbgtty: Fix unregister on tty_register_driver() failure If tty_register_driver() fails, it drops the reference, but fails to set the global dbc_tty_driver to NULL, causing the unregister to be called agai | ||
| CVE-2026-80922 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Allow zero as a random number Zero is a valid random number and needs to be allowed. Otherwise the output is distinguishable from random. | ||
| CVE-2026-80921 | Hig | 8.8 | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. | |
| CVE-2026-80920 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring: defer eventfd signaling when queued from a wakeup handler io_req_local_work_add() signals the CQ ring eventfd inline when it is the one to push the first entry onto ->work_list. For DEFER_TASKRUN ring | ||
| CVE-2026-80918 | — | < 7.2.5-1.1 | 7.2.5-1.1 | Sep 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: core: fix number/pointer type confusion on long items When fetch_item() is called by hid_scan_report() on an item with HID_ITEM_TAG_LONG, it stores a pointer to the item data in item->data.longdata instead |
- CVE-2026-80938Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex mt7615_suspend() acquired the mt76 mutex and then called cancel_delayed_work_sync() on mac_work. mt7615_mac_work() acquires the same mutex vi
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's dev->mt76.eeprom.data buffer at the offset reported by the MCU resp
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel mlo_pm_work on stop mt7925 queues mlo_pm_work with a 5 second delay during multi-link power-save setup and never cancels it on the stop path. If the device is torn down inside that wi
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block copy from the address reported by the MCU response (event->addr,
- CVE-2026-80934Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames mt7996/mt7992 hand the firmware a HW MAC-TXP for AddBA req action frames (MT_TXD7_MAC_TXD, set in mt7996_mac_write_txwi_80211()), but are otherwi
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmware size The default EEPROM firmware is parsed and copied as a full EEPROM without checking its length. A truncated file can make the driver read beyond the firm
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for depend
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the device.
- CVE-2026-80930Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout i2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the interrupt handler to report a status change. If the wait times out, or is interrupted before
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is only used in the root namespace. However, due to pid_table_root_permissions(), a non-root user
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a n
- CVE-2026-80927Sep 11, 2026affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() If the auxiliary clock is disabled during tk_get_aux_ts64() but is enabled before tks->clock_valid is checked, then uninitialized stackd
- affected < 7.2.6-1.1fixed 7.2.6-1.1
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning the
- CVE-2026-80925Sep 9, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling HW VLAN offload Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX) on a lower device invokes vlan_transfer_features(), which
- affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buffers crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the
- CVE-2026-80923Sep 9, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: xhci: dbgtty: Fix unregister on tty_register_driver() failure If tty_register_driver() fails, it drops the reference, but fails to set the global dbc_tty_driver to NULL, causing the unregister to be called agai
- CVE-2026-80922Sep 9, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Allow zero as a random number Zero is a valid random number and needs to be allowed. Otherwise the output is distinguishable from random.
- affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb.
- CVE-2026-80920Sep 9, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: io_uring: defer eventfd signaling when queued from a wakeup handler io_req_local_work_add() signals the CQ ring eventfd inline when it is the one to push the first entry onto ->work_list. For DEFER_TASKRUN ring
- CVE-2026-80918Sep 9, 2026affected < 7.2.5-1.1fixed 7.2.5-1.1
In the Linux kernel, the following vulnerability has been resolved: HID: core: fix number/pointer type confusion on long items When fetch_item() is called by hid_scan_report() on an item with HID_ITEM_TAG_LONG, it stores a pointer to the item data in item->data.longdata instead
Page 8 of 107