VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-80985High· 7.0⚖ disputed
2w ago

kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)

A flaw was found in the Linux kernel's Server Message Block over Remote Direct Memory Access (SMC-Rv2) protocol implementation. The `smc_llc_rmt_delete_rkey()` and `smc_llc_save_add_link_rkeys()` functions incorrectly handle oversized LLC …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.54%via CSAF
CVE-2026-80962Medium· 5.5
2w ago

kernel: dm-pcache: validate geometry fields from on-disk cache_info (CVE-2026-80962)

A flaw was found in the Linux kernel's dm-pcache component. A local attacker with administrative privileges (CAP_SYS_ADMIN) could manipulate on-disk cache metadata to provide invalid geometry fields. This manipulation could lead to an out-…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-80961Medium· 5.5⚖ disputed
2w ago

kernel: dm-pcache: validate kset key_num and intra-segment bounds (CVE-2026-80961)

A flaw was found in the `dm-pcache` component of the Linux kernel. A local attacker with `CAP_SYS_ADMIN` capabilities could exploit unbounded fields decoded from the cache device. This could lead to an out-of-bounds read, potentially discl…

▾ SunlitRed Hat · LinuxEPSS 0.17%via CSAF
CVE-2026-80959Medium· 5.5⚖ disputed
2w ago

kernel: dm-pcache: bound the persisted tail-position offset (CVE-2026-80959)

A flaw was found in the Linux kernel's device-mapper persistent cache (dm-pcache) component. A local attacker with administrative privileges (CAP_SYS_ADMIN) could provide a specially crafted cache device, leading to an out-of-bounds read. …

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-80958Medium· 5.5⚖ disputed
2w ago

kernel: dm-pcache: clamp the tail kset read to the segment data region (CVE-2026-80958)

A flaw was found in the dm-pcache component of the Linux kernel. The tail-kset read operations, used by cache_replay(), the writeback worker, and the garbage collection (GC) worker, incorrectly calculate the length of the data region. This…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.16%via CSAF
CVE-2026-89526High· 7.0
2w ago

kernel: svcrdma: Validate Read chunk positions before reconstruction (CVE-2026-89526)

A flaw was found in the `svcrdma` component of the Linux kernel. A remote attacker can exploit this vulnerability by supplying a crafted `RPC/RDMA Read chunk position` field that is not properly validated against the received inline body l…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.67%via CSAF
CVE-2026-89492Critical· 9.8⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and signature of an indexed-dire…

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and signature of an indexed-dire…

▾ MidnightLinux · LinuxEPSS 0.67%via NVD
CVE-2026-89633High· 7.0⚖ disputed
2w ago

kernel: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() (CVE-2026-89633)

A flaw was found in the Linux kernel's Server Message Block (SMB) client. The `coalesce_t2()` function processes server-supplied `DataOffset` fields without proper validation against buffer boundaries. A remote attacker could exploit this …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.65%via CSAF
CVE-2026-89631High· 8.1⚖ disputed
2w ago

kernel: smb: client: reject a tree connect response whose byte count is too small (CVE-2026-89631)

A flaw was found in the Linux kernel's Server Message Block (SMB) client. A remote malicious SMB server could send a specially crafted tree connect response with a byte count that is too small. This incorrect handling can lead to an intege…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.63%via CSAF
CVE-2026-89630High· 7.0⚖ disputed
2w ago

kernel: smb: client: restore the data_offset bound in is_valid_oplock_break() (CVE-2026-89630)

A flaw was found in the Linux kernel's Server Message Block (SMB) client. An incorrect calculation of the `data_offset` bound in the `is_valid_oplock_break()` function can lead to a read overflow. This vulnerability allows a malicious SMB …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.54%via CSAF
CVE-2026-89614Medium· 5.5⚖ disputed
2w ago

kernel: ntfs: bound the free-cluster bitmap scan to the volume (CVE-2026-89614)

A flaw was found in the Linux kernel's NTFS file system driver. This vulnerability occurs because the free-cluster bitmap scan is not properly bounded to the volume size. A specially crafted NTFS image, where the bitmap covers more cluster…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2026-89588Medium· 5.5⚖ disputed
2w ago

kernel: ACPI: APEI: GHES: fix ARM section length accounting after header (CVE-2026-89588)

A flaw was found in the Linux kernel's Advanced Configuration and Power Interface (ACPI) APEI Generic Hardware Error Source (GHES) component. Incorrect length accounting in the `ghes_handle_arm_hw_error()` function can lead to the parser r…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.20%via CSAF
CVE-2026-89574Medium· 5.5⚖ disputed
2w ago

kernel: dm array: validate array block headers on read (CVE-2026-89574)

A flaw was found in the Linux kernel's device mapper (dm) array component. Insufficient validation of array block headers during read operations allows a local attacker to craft a malicious on-disk `nr_entries` value. This can lead to an o…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89571Medium· 5.5⚖ disputed
2w ago

kernel: cxl/features: bound fwctl command payload to the input buffer (CVE-2026-89571)

A flaw was found in the Linux kernel's CXL (Compute Express Link) features. A local attacker could exploit an out-of-bounds read vulnerability in the `fwctl_cmd_rpc()` and `cxlctl_set_feature()` functions. This occurs when the system attem…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.16%via CSAF
CVE-2026-89537High· 7.0⚖ disputed
2w ago

kernel: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 (CVE-2026-89537)

A flaw was found in the Linux kernel's SUNRPC implementation, specifically within the `gss_krb5_verify_mic_v2` function. A remote malicious Network File System (NFS) server could provide a specially crafted, short Kerberos Message Integrit…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.54%via CSAF
CVE-2026-89691High· 7.0
2w ago

kernel: nfsd: clear opcnt on compound arg release to prevent OOB read (CVE-2026-89691)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd) component. The nfsd4_release_compoundargs() function does not properly clear an internal counter (opcnt) when releasing a buffer. This oversight can lead to an out-of…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89651High· 7.0⚖ disputed
2w ago

kernel: ceph: bound MDSCapAuth path and fs_name decode in handle_session() (CVE-2026-89651)

A flaw was found in the Linux kernel's Ceph client. An out-of-bounds read vulnerability exists in the `handle_session()` function when decoding `MDSCapAuth` records. A malicious or compromised Metadata Server (MDS) can trigger this during …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.67%via CSAF
CVE-2026-89632High· 7.0
2w ago

kernel: smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr() (CVE-2026-89632)

A flaw was found in the Linux kernel's Server Message Block (SMB) client. A malicious server could exploit this vulnerability by sending specially crafted data, leading to an out-of-bounds read. This occurs because the `reparse_buf_ptr()` …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.45%via CSAF
CVE-2026-89743Medium· 5.5
2w ago

kernel: misc: nsm: bound the device-reported response length (CVE-2026-89743)

A flaw was found in the Linux kernel's Network Shared Memory (NSM) component. A malicious or buggy backend can report a response length larger than the allocated buffer. This can lead to an out-of-bounds read, disclosing adjacent kernel me…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.19%via CSAF
CVE-2026-89731High· 7.1
2w ago

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using…

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89705High· 7.0
2w ago

kernel: nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths (CVE-2026-89705)

A flaw was found in the Linux kernel's Network File System (NFS) daemon, nfsd. This vulnerability occurs due to a synchronization issue where a status counter (rq_status_counter) is not correctly reset on all exit paths within the nfsd_dis…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.16%via CSAF
CVE-2026-80976High· 7.0⚖ disputed
2w ago

kernel: seg6: reset IP6CB after IPv6 decapsulation (CVE-2026-80976)

A flaw was found in the Linux kernel's IPv6 Segment Routing (seg6) implementation. An unprivileged user can exploit this vulnerability by injecting a specially crafted IPv6 packet. This can lead to an out-of-bounds read, potentially causin…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-80973High· 7.0
2w ago

kernel: ALSA: 6fire: bound the MIDI event length from the device (CVE-2026-80973)

A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the 6fire driver. This vulnerability allows a malicious USB device to trigger an out-of-bounds read by sending a specially craft…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-80972Medium· 5.5
2w ago

kernel: ALSA: aloop: Check card index validity at probe (CVE-2026-80972)

A flaw was found in the ALSA (Advanced Linux Sound Architecture) aloop driver within the Linux kernel. This vulnerability arises from insufficient validation of the card index during device setup, specifically when a device is manually con…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80969Medium· 5.5
2w ago

kernel: ALSA: mpu401: Check card index validity at probe (CVE-2026-80969)

A flaw was found in the Linux kernel's ALSA mpu401 driver. The driver fails to validate the card index when a device is manually bound through the sysfs interface. This oversight can lead to an out-of-bounds memory access. A local attacker…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-80966Medium· 5.5
2w ago

kernel: ALSA: portman2x4: Check card index validity at probe (CVE-2026-80966)

A flaw was found in the ALSA portman2x4 driver of the Linux kernel. This vulnerability occurs because the driver does not properly validate the card index, specifically failing to check for negative ID values. A local attacker could exploi…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-80933Medium· 5.5⚖ disputed
2w ago

kernel: wifi: mt76: mt7996: validate default EEPROM firmware size (CVE-2026-80933)

A flaw was found in the Linux kernel's mt76: mt7996 Wi-Fi driver. This vulnerability occurs because the driver does not properly validate the size of the default EEPROM (Electrically Erasable Programmable Read-Only Memory) firmware. A spec…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-80931Medium· 5.5⚖ disputed
2w ago

kernel: w1: ds28e17: reject an oversize length on an I2C block read (CVE-2026-80931)

A flaw was found in the Linux kernel's w1: ds28e17 1-Wire to I2C bridge driver. A malicious I2C slave device can provide an oversized length during an I2C block read operation. This causes the driver to read beyond the allocated buffer, le…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-81014Medium· 5.5
2w ago

kernel: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (CVE-2026-81014)

A flaw was found in the Linux kernel's `hp-bioscfg` module. A local attacker with write access to the `sysfs` entry for `hp-bioscfg` could exploit a heap out-of-bounds read vulnerability. This occurs because the `sk_store()` and `kek_store…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-81013Medium· 5.5
2w ago

kernel: platform/x86: hp-bioscfg: fix heap OOB read on empty password write (CVE-2026-81013)

A flaw was found in the hp-bioscfg component of the Linux kernel. A local user could trigger a heap out-of-bounds read by writing an empty string to the current_password or new_password fields. This occurs because the validate_password_inp…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CWE-125 vulnerabilities (CVEs) — page 6 · VulnSea