VulnSea

Daily digest

Saturday 14 February 2026

A quiet day: only 8 new CVEs against a recent average of about 16. Severity skewed high: 4 high, 50% of the total. Linux was the most-affected vendor with 8.

8
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2026-23191High· 7.8
7mo ago

ALSA: aloop: Fix racy access at PCM trigger

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix racy access at PCM trigger The PCM trigger callback of aloop driver tries to check the PCM state and stop the stream of the tied substream in the corr…

▾ TwilightLinux · LinuxEPSS 0.12%via CVEORG
CVE-2026-23185High· 7.8
7mo ago

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, wh…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2025-71221High· 7.8
7mo ago

dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()

In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() Add proper locking in mmp_pdma_residue() to prevent use-after-free when accessing descriptor list and des…

▾ TwilightLinux · LinuxEPSS 0.10%via CVEORG
CVE-2026-23204High· 7.1
7mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: use skb_header_pointer_careful() skb_header_pointer() does not fully validate negative @offset values. Use skb_header_pointer_careful() instead. …

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: use skb_header_pointer_careful() skb_header_pointer() does not fully validate negative @offset values. Use skb_header_pointer_careful() instead. …

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-23201None
7mo ago

ceph: fix oops due to invalid pointer for kfree() in parse_longname()

In the Linux kernel, the following vulnerability has been resolved: ceph: fix oops due to invalid pointer for kfree() in parse_longname() This fixes a kernel oops when reading ceph snapshot directories (.snap), for example by simply ru…

▾ SunlitLinux · LinuxEPSS 0.12%via CVEORG
CVE-2026-23154None
7mo ago

net: fix segmentation of forwarding fraglist GRO

In the Linux kernel, the following vulnerability has been resolved: net: fix segmentation of forwarding fraglist GRO This patch enhances GSO segment handling by properly checking the SKB_GSO_DODGY flag for frag_list GSO packets, addres…

▾ SunlitLinux · LinuxEPSS 0.12%via CVEORG
CVE-2026-23137None
7mo ago

of: unittest: Fix memory leak in unittest_data_add()

In the Linux kernel, the following vulnerability has been resolved: of: unittest: Fix memory leak in unittest_data_add() In unittest_data_add(), if of_resolve_phandles() fails, the allocated unittest_data is not freed, leading to a mem…

▾ SunlitLinux · LinuxEPSS 0.13%via CVEORG
CVE-2026-23113None
7mo ago

io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop

In the Linux kernel, the following vulnerability has been resolved: io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop Currently this is checked before running the pending work. Normally this is quite fine, as work items either …

▾ SunlitLinux · LinuxEPSS 0.12%via CVEORG

Most-affected vendors

By CVEs published in the period.