VulnSea

linux vulnerabilities

CVEs whose affected-version data names the linux package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

1965 CVEsRSS

CVE-2026-89535High· 8.1
2w ago

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id svc_rdma_free() caches rdma->sc_cm_id->device before teardown, then calls rdma_destroy_id(sc_cm_id) which…

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id svc_rdma_free() caches rdma->sc_cm_id->device before teardown, then calls rdma_destroy_id(sc_cm_id) which…

▾ TwilightLinux · LinuxEPSS 0.57%via NVD
CVE-2026-89685High· 7.5
2w ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but comp…

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but comp…

▾ TwilightLinux · LinuxEPSS 0.63%via NVD
CVE-2026-89676Critical· 9.8⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before dup_copy_fields(), so the s2s_cp_stateids…

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before dup_copy_fields(), so the s2s_cp_stateids…

▾ MidnightLinux · LinuxEPSS 0.67%via NVD
CVE-2026-89667High· 8.1⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtabl…

In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtabl…

▾ TwilightLinux · LinuxEPSS 0.57%via NVD
CVE-2026-89660Critical· 9.8⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it. The cli…

▾ MidnightLinux · LinuxEPSS 0.65%via NVD
CVE-2026-89659Critical· 9.8⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegation revoke A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegation revoke A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive. The …

▾ MidnightLinux · LinuxEPSS 0.65%via NVD
CVE-2026-89763High· 7.8⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM teardown ordering trusted_tpm_exit() drops the TPM chip reference and frees the digest array before unregistering the trusted key type

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM teardown ordering trusted_tpm_exit() drops the TPM chip reference and frees the digest array before unregistering the trusted key type. key_type…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89761Medium· 5.5⚖ disputed
2w ago

kernel: apparmor: fix out-of-bounds write when null terminating a label vec (CVE-2026-89761)

A flaw was found in the Linux kernel's AppArmor security module. An out-of-bounds write vulnerability exists when null terminating a label vector due to improper memory allocation. An unprivileged local attacker can exploit this by writing…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89755High· 7.8
2w ago

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeing swapcache __migrate_device_pages() reads the folio mapping before calling folio_free_swap()

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeing swapcache __migrate_device_pages() reads the folio mapping before calling folio_free_swap(). When folio_free_swap…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89731High· 7.1
2w ago

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using…

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89708Critical· 9.8⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still h…

In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still h…

▾ MidnightLinux · LinuxEPSS 0.65%via NVD
CVE-2026-80968Medium· 5.5
2w ago

kernel: ALSA: mts64: Check card index validity at probe (CVE-2026-80968)

A flaw was found in the ALSA mts64 driver within the Linux kernel. This driver does not properly validate the card index, specifically failing to check for negative ID values when bound via sysfs. A local attacker could exploit this vulner…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-80966Medium· 5.5
2w ago

kernel: ALSA: portman2x4: Check card index validity at probe (CVE-2026-80966)

A flaw was found in the ALSA portman2x4 driver of the Linux kernel. This vulnerability occurs because the driver does not properly validate the card index, specifically failing to check for negative ID values. A local attacker could exploi…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-80965Medium· 5.5
2w ago

kernel: ALSA: serial-u16550: Check card index validity at probe (CVE-2026-80965)

A flaw was found in the Linux kernel's ALSA serial-u16550 driver. This vulnerability occurs because the driver does not properly validate the card index when a device is manually bound via the sysfs interface. A local user could exploit th…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-80938Medium· 5.5
2w ago

kernel: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (CVE-2026-80938)

A flaw was found in the Linux kernel, specifically within the `mt7615` Wi-Fi driver. A deadlock can occur during system suspend operations when the suspend process attempts to acquire a mutex (a locking mechanism) while simultaneously wait…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-80935Medium· 5.5⚖ disputed
2w ago

kernel: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy (CVE-2026-80935)

A flaw was found in the Linux kernel's Wi-Fi driver for MediaTek MT7996 devices. A malicious or malfunctioning Wi-Fi device can exploit improper validation of an EEPROM (Electrically Erasable Programmable Read-Only Memory) address during a…

▾ SunlitRed Hat · LinuxEPSS 0.38%via CSAF
CVE-2026-80933Medium· 5.5⚖ disputed
2w ago

kernel: wifi: mt76: mt7996: validate default EEPROM firmware size (CVE-2026-80933)

A flaw was found in the Linux kernel's mt76: mt7996 Wi-Fi driver. This vulnerability occurs because the driver does not properly validate the size of the default EEPROM (Electrically Erasable Programmable Read-Only Memory) firmware. A spec…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-80931Medium· 5.5⚖ disputed
2w ago

kernel: w1: ds28e17: reject an oversize length on an I2C block read (CVE-2026-80931)

A flaw was found in the Linux kernel's w1: ds28e17 1-Wire to I2C bridge driver. A malicious I2C slave device can provide an oversized length during an I2C block read operation. This causes the driver to read beyond the allocated buffer, le…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-80928Medium· 5.5⚖ disputed
2w ago

kernel: smack: fix cred UAF in smack_file_send_sigiotask() (CVE-2026-80928)

A flaw was found in the Linux kernel's SMACK (Simplified Mandatory Access Control Kernel) security module. Incorrect handling of task credentials within the smack_file_send_sigiotask() function can lead to a Use-After-Free (UAF) vulnerabil…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89437Medium· 5.5
2w ago

kernel: platform/x86: int1092: Fix potential memory leak in sar_probe() (CVE-2026-89437)

A flaw was found in the Linux kernel. The `sar_probe()` function, specifically in its error handling paths, fails to free memory allocated for `device_mode_info` by the `parse_package()` function, which is called by `sar_get_data()`. This …

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-81017Medium· 5.5⚖ disputed
2w ago

kernel: platform/chrome: sensorhub: Bound the EC-reported sensor number (CVE-2026-81017)

A flaw was found in the Linux kernel's `sensorhub` component. A local attacker could provide a maliciously crafted sensor number in an EC FIFO event. This unchecked sensor number could lead to an out-of-bounds read and write in the `batch_…

▾ SunlitRed Hat · LinuxEPSS 0.20%via CSAF
CVE-2026-81014Medium· 5.5
2w ago

kernel: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (CVE-2026-81014)

A flaw was found in the Linux kernel's `hp-bioscfg` module. A local attacker with write access to the `sysfs` entry for `hp-bioscfg` could exploit a heap out-of-bounds read vulnerability. This occurs because the `sk_store()` and `kek_store…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-81013Medium· 5.5
2w ago

kernel: platform/x86: hp-bioscfg: fix heap OOB read on empty password write (CVE-2026-81013)

A flaw was found in the hp-bioscfg component of the Linux kernel. A local user could trigger a heap out-of-bounds read by writing an empty string to the current_password or new_password fields. This occurs because the validate_password_inp…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-81011Medium· 5.5
2w ago

kernel: platform/x86: hp-bioscfg: pass validated element count to package parsers (CVE-2026-81011)

A flaw was found in the Linux kernel's hp-bioscfg module. The module's package parsers incorrectly determine the number of elements in a package, using a value derived from a name string rather than the true package size. While currently p…

▾ SunlitRed Hat · LinuxEPSS 0.17%via CSAF
CVE-2026-81007High· 7.1
2w ago

ipmi: ipmb: validate write message length

In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes…

▾ TwilightLinux · LinuxEPSS 0.17%via CVEORG
CVE-2026-81005Medium· 4.1
2w ago

kernel: ipmi: si: Fix NULL pointer dereference after failed registration (CVE-2026-81005)

A flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) subsystem. During the registration of an IPMI message handler, if the Baseboard Management Controller (BMC) device information cannot be fetched, a NUL…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-81003High· 8.1
2w ago

net/iucv: filter frames in afiucv_hs_rcv() by ingress device

In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingress device afiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte name fields in the transport he…

▾ TwilightLinux · LinuxEPSS 0.50%via CVEORG
CVE-2026-80992Medium· 5.5⚖ disputed
2w ago

kernel: net: ravb: avoid dereferencing an invalid PTP clock (CVE-2026-80992)

A flaw was found in the `net: ravb` component of the Linux kernel. This vulnerability allows for a NULL pointer dereference when the Precision Time Protocol (PTP) clock's index is queried before it is properly initialized or if its registr…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89490None
2w ago

ocfs2: fix readdir position truncation on 32-bit kernels

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix readdir position truncation on 32-bit kernels In ocfs2_dir_foreach_blk_el(), the directory cookie position is rebuilt with ctx->pos = (ctx->pos & ~(sb->s_…

▾ SunlitLinux · LinuxEPSS 0.22%via CVEORG
CVE-2026-89470Medium· 5.5⚖ disputed
2w ago

kernel: power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (CVE-2026-89470)

A flaw was found in the Linux kernel's `cros_usbpd-charger` driver. This driver, which manages USB power delivery, incorrectly processes port count information from an embedded controller. A malicious embedded controller could provide an e…

▾ SunlitRed Hat · LinuxEPSS 0.20%via CSAF
linux vulnerabilities (CVEs) — page 51 · VulnSea