VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2026-80937Medium· 5.5⚖ disputed
2w ago

kernel: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy (CVE-2026-80937)

A flaw was found in the Linux kernel's Wi-Fi driver for mt7915 chipsets. This vulnerability allows a malicious or malfunctioning Wi-Fi device to provide an invalid memory address. This can cause the driver to write data beyond its allocate…

▾ SunlitRed Hat · LinuxEPSS 0.38%via CSAF
CVE-2026-89513Medium· 5.5
2w ago

kernel: RISC-V: KVM: Fix PMU event info array size overflow (CVE-2026-89513)

A flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) component for RISC-V architectures. A malicious guest operating system could exploit an integer overflow vulnerability by providing a crafted number of Performance M…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-89436Medium· 5.5⚖ disputed
2w ago

kernel: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] (CVE-2026-89436)

A flaw was found in the Linux kernel's `panasonic-laptop` driver. This vulnerability involves an out-of-bounds write when processing ACPI SINF packages, where a small amount of data is written beyond the intended memory buffer. This can le…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.18%via CSAF
CVE-2026-89612Medium· 5.5⚖ disputed
2w ago

kernel: ntfs: reject invalid MFT LCNs from boot sector (CVE-2026-89612)

A flaw was found in the Linux kernel's NTFS filesystem driver. A local attacker could provide a specially crafted NTFS boot sector containing an invalid Master File Table (MFT) Logical Cluster Number (LCN). Due to an integer overflow durin…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2026-89611Medium· 5.5⚖ disputed
2w ago

kernel: ntfs: validate non-resident attribute offsets (CVE-2026-89611)

A flaw was found in the Linux kernel. The NTFS file system driver does not properly validate non-resident attribute offsets when converting between sparse and non-sparse attributes. A local attacker could craft a malicious Master File Tabl…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2026-89610Medium· 5.5⚖ disputed
2w ago

kernel: ntfs: verify run length exceeding volume boundary (CVE-2026-89610)

A flaw was found in the Linux kernel's NTFS component. The mapping pairs decoder fails to verify if a run length extends beyond the volume boundary. A local attacker could exploit this by providing a malformed NTFS image with a crafted map…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2026-89602High· 7.8
2w ago

In the Linux kernel, the following vulnerability has been resolved: erofs: skip sufficiently large global buffers when resizing z_erofs_gbuf_nrpages is advanced only after every global buffer has been grown

In the Linux kernel, the following vulnerability has been resolved: erofs: skip sufficiently large global buffers when resizing z_erofs_gbuf_nrpages is advanced only after every global buffer has been grown. If a resize fails after som…

▾ TwilightLinux · LinuxEPSS 0.19%via NVD
CVE-2026-89580High· 7.0
2w ago

kernel: bpf: Disable preemption in __bpf_get_stack (CVE-2026-89580)

A flaw was found in the Linux kernel's BPF (Berkeley Packet Filter) subsystem. A local attacker could exploit a timing issue in the `__bpf_get_stack` function. This occurs when a preemptible BPF program is scheduled out, allowing another t…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89530High· 7.0⚖ disputed
2w ago

kernel: svcrdma: Reject inline replies that overflow the pull-up buffer (CVE-2026-89530)

A flaw was found in the Linux kernel's svcrdma component, which handles network communication using Remote Direct Memory Access (RDMA). A remote attacker can send a specially crafted network reply that is larger than expected. This can cau…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.67%via CSAF
CVE-2026-89761Medium· 5.5⚖ disputed
2w ago

kernel: apparmor: fix out-of-bounds write when null terminating a label vec (CVE-2026-89761)

A flaw was found in the Linux kernel's AppArmor security module. An out-of-bounds write vulnerability exists when null terminating a label vector due to improper memory allocation. An unprivileged local attacker can exploit this by writing…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89754High· 7.0
2w ago

kernel: mm/pagewalk: fix stale walk->action escaping walk_pmd_range() (CVE-2026-89754)

A flaw was found in the Linux kernel's memory management (mm/pagewalk) component. An issue in the `walk_pmd_range()` function, where a stale `walk->action` state is not properly reset, can lead to duplicate walk callbacks. A local attacker…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.17%via CSAF
CVE-2026-89748Medium· 5.5
2w ago

kernel: tracing: Fix retry exhaustion in simple ring buffer reader swap (CVE-2026-89748)

A flaw was found in the Linux kernel's tracing subsystem. An issue in the `simple_ring_buffer_swap_reader_page()` function, related to retry exhaustion during ring buffer reader page swaps, can lead to incorrect handling of successful or f…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-89702High· 7.0⚖ disputed
2w ago

kernel: nfsd: size fh_verify server sockaddr slot by xpt_locallen (CVE-2026-89702)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When processing NFSv2/v3-over-UDP requests, the `nfsd_fh_verify` and `nfsd_fh_verify_err` tracepoints incorrectly size a memory buffer. This can lead to an out-of-bo…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.67%via CSAF
CVE-2026-80968Medium· 5.5
2w ago

kernel: ALSA: mts64: Check card index validity at probe (CVE-2026-80968)

A flaw was found in the ALSA mts64 driver within the Linux kernel. This driver does not properly validate the card index, specifically failing to check for negative ID values when bound via sysfs. A local attacker could exploit this vulner…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-80951High· 7.0
2w ago

kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len (CVE-2026-80951)

A flaw was found in the Linux kernel's I3C master driver. A malicious I3C device could exploit this by sending an In-Band Interrupt (IBI) payload that exceeds the allocated slot size. This can lead to an out-of-bounds write into the IBI po…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80944High· 7.0
2w ago

kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait (CVE-2026-80944)

A flaw was found in the Linux kernel's mwifiex Wi-Fi driver. When a synchronous command's wait operation is interrupted, the driver can attempt to write data to a memory location that has already been released. This memory corruption can l…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-80935Medium· 5.5⚖ disputed
2w ago

kernel: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy (CVE-2026-80935)

A flaw was found in the Linux kernel's Wi-Fi driver for MediaTek MT7996 devices. A malicious or malfunctioning Wi-Fi device can exploit improper validation of an EEPROM (Electrically Erasable Programmable Read-Only Memory) address during a…

▾ SunlitRed Hat · LinuxEPSS 0.38%via CSAF
CVE-2026-89438Medium· 5.5
2w ago

kernel: platform/x86: ISST: Validate logical CPU id and clos id (CVE-2026-89438)

A flaw was found in the Linux kernel, specifically within the Intel Speed Select Technology (ISST) component. This vulnerability arises from insufficient validation of input values, such as logical CPU ID and CLOS ID, used in the core powe…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-81017Medium· 5.5⚖ disputed
2w ago

kernel: platform/chrome: sensorhub: Bound the EC-reported sensor number (CVE-2026-81017)

A flaw was found in the Linux kernel's `sensorhub` component. A local attacker could provide a maliciously crafted sensor number in an EC FIFO event. This unchecked sensor number could lead to an out-of-bounds read and write in the `batch_…

▾ SunlitRed Hat · LinuxEPSS 0.20%via CSAF
CVE-2026-81002High· 7.0⚖ disputed
2w ago

kernel: xdp: fix zero-copy frame layout (CVE-2026-81002)

A flaw was found in the Linux kernel's XDP (eXpress Data Path) component. Incorrect handling of zero-copy frame layout in the `xdp_convert_zc_to_xdp_frame()` function can allow an AF_XDP zero-copy packet, when redirected through `cpumap`, …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-81000High· 7.8PoC
2w ago

kernel: net: tun: bound receive headroom (CVE-2026-81000)

A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively lar…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.4)EPSS 0.36%via CSAF
CVE-2026-89482High· 7.0⚖ disputed
2w ago

kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone (CVE-2026-89482)

A flaw was found in the nvme-tcp module of the Linux kernel. This vulnerability arises from improper handling of C2HData for REQ_OP_WRITE_ZEROES commands, where the system fails to adequately validate the data length. A remote attacker cou…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89471Medium· 5.5⚖ disputed
2w ago

kernel: power: supply: cros_usbpd-charger: bound the EC-reported port count (CVE-2026-89471)

A flaw was found in the Linux kernel's `cros_usbpd-charger` driver. A malicious or compromised embedded controller (EC) can report an excessive number of USB Power Delivery (PD) ports. This causes the driver to write beyond the allocated m…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89470Medium· 5.5⚖ disputed
2w ago

kernel: power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (CVE-2026-89470)

A flaw was found in the Linux kernel's `cros_usbpd-charger` driver. This driver, which manages USB power delivery, incorrectly processes port count information from an embedded controller. A malicious embedded controller could provide an e…

▾ SunlitRed Hat · LinuxEPSS 0.20%via CSAF
CVE-2026-89493Medium· 5.5⚖ disputed
2w ago

kernel: ocfs2: validate rl_used against rl_count in refcount block validator (CVE-2026-89493)

A flaw was found in the Linux kernel's ocfs2 component. A local attacker with CAP_SYS_ADMIN privileges could exploit this by mounting a crafted or corrupted ocfs2 image, or by performing a raw write to the block device backing an already-m…

▾ SunlitRed Hat · LinuxEPSS 0.68%via CSAF
CVE-2026-89607High· 7.0
2w ago

kernel: ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet (CVE-2026-89607)

A flaw was found in ecryptfs in the Linux kernel. The parse_tag_3_packet() function does not properly validate the size of the encrypted key, allowing an oversized key to be processed. This improper validation leads to out-of-bounds writes…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.18%via CSAF
CVE-2026-89579High· 7.0
2w ago

kernel: bpf: Harden bloom filter sizing and indexing on 32-bit kernels (CVE-2026-89579)

A flaw was found in the Linux kernel's Berkeley Packet Filter (BPF) component, specifically impacting 32-bit systems. This vulnerability stems from incorrect sizing and indexing of bloom filters, which can lead to out-of-bounds memory acce…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89559High· 7.0
2w ago

kernel: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() (CVE-2026-89559)

A flaw was found in the Linux kernel's `libnvdimm/labels` component. An integer overflow vulnerability exists in the `__nd_label_validate()` function, where a 32-bit calculation of a namespace index field (`nslot`) can wrap around. This al…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89656High· 7.0⚖ disputed
2w ago

kernel: libceph: reject buckets with mismatched CRUSH ids (CVE-2026-89656)

A flaw was found in libceph within the Linux kernel. This vulnerability allows a local attacker to craft a malformed CRUSH map, which is used for data placement. By doing so, one data bucket can be made to reuse another bucket's memory wor…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89653High· 8.1⚖ disputed
2w ago

kernel: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode (CVE-2026-89653)

A flaw was found in the Linux kernel's Ceph filesystem. This vulnerability occurs when a malicious or malformed MDSMap export_targets entry, controlled by a monitor, contains a rank value that exceeds the maximum allowed (CEPH_MAX_MDS) dur…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.74%via CSAF
CWE-787 vulnerabilities (CVEs) — page 7 · VulnSea