VYPR

rpm package

opensuse/kernel-source&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed

Vulnerabilities (2,129)

  • CVE-2026-80917Sep 9, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems On 32-bit systems the config space is too large to ioremap in one go, so pci_ecam_create() maps each bus segment separately and relies on th

  • CVE-2026-80916Sep 9, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: kcov: fix data corruption and race conditions on PREEMPT_RT syzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the temporary storage used for saving/restoring remote KCOV state is currently al

  • CVE-2026-80914HigSep 9, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready iso_conn_ready() looks up the BIS listener socket with iso_get_sock(), which takes a reference, and then, without re-checking its state, c

  • CVE-2026-80864Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp rxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the IB_QP_STATE path, so it holds no state_lock and runs while the responder task rx

  • CVE-2026-80863Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix OOB in free_rd_atomic_resources() free_rd_atomic_resources() iterates using qp->attr.max_dest_rd_atomic. Updating max_dest_rd_atomic before freeing the old array can make the free path walk past t

  • CVE-2026-80862Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix usage of page_frag_cache nvme uses page_frag_cache to preallocate PDU for each preallocated request of block device. Block devices are created in parallel threads, consequently page_frag_cache is

  • CVE-2026-80861Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: usb: xhci: bail out of setup if the controller is inaccessible xhci_gen_setup() locates the operational registers using the capability length read from the very first register: xhci->op_regs = hcd->regs + H

  • CVE-2026-80860Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: fuse: fix race between interrupt and resend After commit f8fce75fedf7 ("fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req") the WARN_ON(!list_empty(&req->intr_entry)) in fuse_request_free() stil

  • CVE-2026-80859Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: fuse: fix missing barrier when checking io-uring readiness fuse_block_alloc() reads fch->initialized and then fch->io_uring. fch->io_uring is set before fch->initialized, ordered by the smp_wmb() in fuse_chan_s

  • CVE-2026-80858Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: fuse: publish io-uring queues with release semantics fuse_uring_create_queue() initializes a fuse_ring_queue and then publishes the pointer into ring->queues[qid] with WRITE_ONCE() under the fch->lock. There ar

  • CVE-2026-80857Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free The abort_on_kill path in request_wait_answer() calls fuse_abort_conn() and returns without waiting for FR_FINISHED. If fuse_dev_do_write()

  • CVE-2026-80856Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on setattr writeback failure fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate (fault_blocked = true) and releases it at the out:/error: labels. But when a wri

  • CVE-2026-80855Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on open O_TRUNC DAX failure fuse_open() takes filemap_invalidate_lock() for a DAX truncate (dax_truncate = true) and releases it before the out_inode_unlock label. But when fuse_

  • CVE-2026-80854Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: keep port count until LUN teardown completes tcm_usbg_drop_nexus() permits session removal once tpg_port_count reaches zero. However, usbg_port_unlink() currently decrements that count from

  • CVE-2026-80853Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts When {de,en}crypting memory of an SEV or SEV-ES guest on an SNP-enabled host via a temporary buffer, allocate a full 4KiB page for the buf

  • CVE-2026-80852Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: tls: device: fix out-of-bounds write in tls_append_frag() Found with syzkaller and a local syzbot instance running on top of a netdevsim TLS offload emulation; tls_device.c is otherwise only reachable on a mach

  • CVE-2026-80851Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: gtp: serialize PDP context updates PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP network device is being unregistered. The latter is serialized by RTNL, but the generic-netlink delete path

  • CVE-2026-80850Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: tcp: fix AO info use-after-free in tcp_ao_connect_init() tcp_v4_connect() adds a SYN-SENT socket to the ehash before calling tcp_connect(). If TCP-AO is configured, tcp_connect() first verifies that a key matc

  • CVE-2026-80849Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free of current_key on reconnect to another peer tcp_inbound_ao_hash() is called before bh_lock_sock_nested() is taken, with only rcu_read_lock() held. On the fast path for established

  • CVE-2026-80848Sep 4, 2026
    affected < 7.2.5-1.1fixed 7.2.5-1.1

    In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: fix UAF during close ZDI reported and analyzed a race condition during close for espintcp sockets: espintcp_close() frees emsg->skb via kfree_skb() without holding any socket lock. Conc

Page 9 of 107