openshift_container_platform vulnerabilities
CVEs whose affected-version data names the openshift_container_platform package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
470 CVEsRSS
CVE-2026-89687Medium· 5.5kernel: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file (CVE-2026-89687)
A flaw was found in the Linux kernel's Network File System Daemon (nfsd). The `nfsd_file_do_acquire()` function might attempt to use a file that has not been fully opened, as the `->atomic_open` operation could return success prematurely. …
CVE-2026-80932Medium· 5.5⚖ disputedkernel: vsock/virtio: flush works in dependency order (CVE-2026-80932)
A flaw was found in the Linux kernel, specifically within the `vsock/virtio` component. An incorrect order of flushing work items during the removal of a `virtio_vsock` object can lead to a use-after-free condition. This vulnerability allo…
CVE-2026-80979High· 7.0kernel: net/smc: unregister the connection before draining the rx tasklet (CVE-2026-80979)
A flaw was found in the Linux kernel's Shared Memory Communications (SMC) component. During connection termination, the SMC component may fail to properly unregister a connection before draining its receive tasklet. This can lead to a use-…
CVE-2026-80977High· 7.0kernel: net: skbuff: don't touch shared zerocopy state in skb_tx_error() (CVE-2026-80977)
A flaw was found in the Linux kernel's networking subsystem. The `skb_tx_error()` function improperly handles shared zerocopy state in socket buffers (skbs). When a cloned skb is processed, it can prematurely signal that its pages are free…
CVE-2026-80976High· 7.0⚖ disputedkernel: seg6: reset IP6CB after IPv6 decapsulation (CVE-2026-80976)
A flaw was found in the Linux kernel's IPv6 Segment Routing (seg6) implementation. An unprivileged user can exploit this vulnerability by injecting a specially crafted IPv6 packet. This can lead to an out-of-bounds read, potentially causin…
CVE-2026-80973High· 7.0kernel: ALSA: 6fire: bound the MIDI event length from the device (CVE-2026-80973)
A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the 6fire driver. This vulnerability allows a malicious USB device to trigger an out-of-bounds read by sending a specially craft…
CVE-2026-80972Medium· 5.5kernel: ALSA: aloop: Check card index validity at probe (CVE-2026-80972)
A flaw was found in the ALSA (Advanced Linux Sound Architecture) aloop driver within the Linux kernel. This vulnerability arises from insufficient validation of the card index during device setup, specifically when a device is manually con…
CVE-2026-80971High· 7.0kernel: ALSA: bcd2000: clear the URB pointers on disconnect (CVE-2026-80971)
A flaw was found in the ALSA bcd2000 driver of the Linux kernel. When a USB device using this driver is disconnected while a rawmidi substream is still active, the driver fails to clear the Universal Serial Bus Request Block (URB) pointers…
CVE-2026-80970High· 7.0kernel: ALSA: FCP: do not copy out an uninitialised init response (CVE-2026-80970)
A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) FireWire Control Protocol (FCP) subsystem. This vulnerability allows a local attacker to trigger the copying of uninitialized kernel memory to userspace. By se…
CVE-2026-80969Medium· 5.5kernel: ALSA: mpu401: Check card index validity at probe (CVE-2026-80969)
A flaw was found in the Linux kernel's ALSA mpu401 driver. The driver fails to validate the card index when a device is manually bound through the sysfs interface. This oversight can lead to an out-of-bounds memory access. A local attacker…
CVE-2026-80967Medium· 5.5⚖ disputedkernel: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (CVE-2026-80967)
A flaw was found in the ALSA pcxhr driver within the Linux kernel. The `pcxhr_probe()` function requests a threaded interrupt before properly initializing a critical mutex (`mgr->lock`). This oversight could allow an early interrupt to ope…
CVE-2026-80963Medium· 5.5kernel: dm-stats: fix a crash if allocation of per-cpu data fails (CVE-2026-80963)
A flaw was found in the Linux kernel's `dm-stats` module. This vulnerability occurs when the allocation of per-CPU data fails, which can lead to a null pointer dereference during the subsequent cleanup operation. This issue can cause the s…
CVE-2026-80952High· 7.0kernel: i3c: master: Fix info leak and UAF in device unregister path (CVE-2026-80952)
A flaw was found in the Linux kernel's i3c master component. During device unregistration, a race condition can occur where the device descriptor is prematurely cleared. This can lead to an information leak, exposing kernel stack contents …
CVE-2026-80951High· 7.0kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len (CVE-2026-80951)
A flaw was found in the Linux kernel's I3C master driver. A malicious I3C device could exploit this by sending an In-Band Interrupt (IBI) payload that exceeds the allocated slot size. This can lead to an out-of-bounds write into the IBI po…
CVE-2026-80949Medium· 5.5kernel: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (CVE-2026-80949)
A flaw was found in the Linux kernel's brcmfmac Wi-Fi driver. The memory allocated for a buffer is not properly released in certain error handling paths within the `brcmf_sdio_read_control()` function. This improper memory management can l…
CVE-2026-80944High· 7.0kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait (CVE-2026-80944)
A flaw was found in the Linux kernel's mwifiex Wi-Fi driver. When a synchronous command's wait operation is interrupted, the driver can attempt to write data to a memory location that has already been released. This memory corruption can l…
CVE-2026-80941Medium· 5.5kernel: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (CVE-2026-80941)
A flaw was found in the rtw88 Wi-Fi driver of the Linux kernel. This issue occurs because the rtw_txq_push_skb() function fails to free a socket buffer (skb) when an error occurs during transmission. This oversight can lead to a memory lea…
CVE-2026-80939Medium· 5.5kernel: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot (CVE-2026-80939)
A flaw was found in the Linux kernel's rtw89 PCI driver. During a warm reboot on ARM64 platforms, the driver's missing shutdown callback fails to stop radio frequency kill (rfkill) polling. This leads to attempts to read from a non-respond…
CVE-2026-80930Medium· 5.5kernel: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (CVE-2026-80930)
A flaw was found in the Linux kernel's TPM I2C Nuvoton driver. The `i2c_nuvoton_wait_for_stat()` function enables an interrupt (IRQ) but fails to disable it if the wait operation times out or is interrupted. This oversight can lead to an u…
CVE-2026-89440High· 7.0kernel: mmc: via-sdmmc: stop card-detect handling on probe failure (CVE-2026-89440)
A flaw was found in the Linux kernel's mmc: via-sdmmc component. During the probe process, if the `mmc_add_host()` function fails, the SD card-detect interrupt handler continues to operate on memory that has already been released. This can…
CVE-2026-89438Medium· 5.5kernel: platform/x86: ISST: Validate logical CPU id and clos id (CVE-2026-89438)
A flaw was found in the Linux kernel, specifically within the Intel Speed Select Technology (ISST) component. This vulnerability arises from insufficient validation of input values, such as logical CPU ID and CLOS ID, used in the core powe…
CVE-2026-81008High· 7.0kernel: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (CVE-2026-81008)
A flaw was found in the Linux kernel's interconnect subsystem. When a dynamic memory allocation fails during path initialization, an object is prematurely freed while still being referenced in internal lists. This creates dangling pointers…
CVE-2026-81002High· 7.0⚖ disputedkernel: xdp: fix zero-copy frame layout (CVE-2026-81002)
A flaw was found in the Linux kernel's XDP (eXpress Data Path) component. Incorrect handling of zero-copy frame layout in the `xdp_convert_zc_to_xdp_frame()` function can allow an AF_XDP zero-copy packet, when redirected through `cpumap`, …
CVE-2026-81001High· 7.0kernel: slip: fix use-after-free in sl_sync() (CVE-2026-81001)
A flaw was found in the Linux kernel's Serial Line Internet Protocol (SLIP) driver. A race condition in the `sl_sync()` function allows for a use-after-free vulnerability, where the driver attempts to access a network device pointer after …
CVE-2026-81000High· 7.8PoCkernel: net: tun: bound receive headroom (CVE-2026-81000)
A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively lar…
CVE-2026-80994High· 7.0kernel: net: openvswitch: fix flow mask use-after-free on flow deletion (CVE-2026-80994)
A flaw was found in the Open vSwitch component of the Linux kernel. A local attacker could exploit a use-after-free vulnerability during flow deletion. This occurs due to a race condition where the flow mask is freed prematurely, allowing …
CVE-2026-80990Medium· 5.5kernel: net: thunderbolt: Release the Rx HopID that was handed out on mismatch (CVE-2026-80990)
A flaw was found in the Linux kernel's Thunderbolt networking driver. An issue in the `tbnet_connected_work()` function can lead to a resource leak. When an unexpected HopID is allocated during an XDomain connection, the ID is not properly…
CVE-2026-80989High· 7.0kernel: net: thunderbolt: Mark the connection down when bringing it up fails (CVE-2026-80989)
A flaw was found in the Linux kernel's Thunderbolt networking subsystem. When a Thunderbolt connection fails to establish, the system may not correctly update its state, leading to repeated attempts to tear down an already inactive connect…
CVE-2026-80987Medium· 5.5⚖ disputedkernel: NTB: ntb_transport: Reject oversized TX buffers (CVE-2026-80987)
A flaw was found in the Linux kernel's Non-Transparent Bridge (NTB) transport module. When processing oversized transmit (TX) buffers, the system fails to properly free the allocated memory, leading to a memory leak. This continuous leakag…
CVE-2026-80984Medium· 5.5kernel: net/smc: do not dereference an unset send buffer on the SMC-D teardown path (CVE-2026-80984)
A flaw was found in the `net/smc` component of the Linux kernel. When a link group terminates while a socket is waiting in `smc_close_stream_wait()`, a NULL pointer dereference can occur during the SMC-D teardown path. This can lead to a s…