Tagged “csaf”
CVEs tagged csaf, newest first.
3093 CVEsRSS
CVE-2026-89595Medium· 5.5kernel: fsnotify: Fix stale object mask after concurrent mark updates (CVE-2026-89595)
A flaw was found in the Linux kernel's fsnotify subsystem, affecting fanotify and inotify. A race condition can occur during concurrent updates to event marks, where the object mask becomes stale. This can lead to a denial of service or in…
CVE-2026-89594Medium· 5.5⚖ disputedkernel: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device (CVE-2026-89594)
A flaw was found in the Linux kernel's OMAP SSI driver. The driver uses a synthetic HSI controller device that does not properly initialize its Direct Memory Access (DMA) mask. This oversight can lead to the driver crashing or triggering w…
CVE-2026-89587High· 7.0kernel: ACPI: pfr_update: fix stack buffer overflow in query_capability() (CVE-2026-89587)
A flaw was found in the Linux kernel's ACPI Platform Firmware Runtime Update (pfr_update) component. The `query_capability()` function, responsible for handling ACPI buffer objects from firmware, performs an unchecked memory copy operation…
CVE-2026-89586Medium· 5.5⚖ disputedkernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes (CVE-2026-89586)
A flaw was found in the Linux kernel's `libata-scsi` component. This vulnerability occurs when the system attempts to perform Data Set Management (DSM) TRIM operations on storage devices with logical sector sizes exceeding 2048 bytes. Due …
CVE-2026-89585Medium· 5.5⚖ disputedkernel: auxdisplay: charlcd: cancel backlight work on registration failure (CVE-2026-89585)
A flaw was found in the `auxdisplay: charlcd` component of the Linux kernel. This use-after-free vulnerability occurs when the `charlcd_register()` function fails, leading to the `charlcd` object being freed while a delayed work item still…
CVE-2026-89583High· 7.0kernel: Bluetooth: eir: Fix OOB read in eir_get_service_data() (CVE-2026-89583)
A flaw was found in the Linux kernel's Bluetooth subsystem. An out-of-bounds (OOB) read vulnerability exists in the `eir_get_service_data()` function due to incorrect length calculation when parsing Extended Inquiry Response (EIR) advertis…
CVE-2026-89582High· 7.0kernel: bnx2x: fix double free in bnx2x_init_firmware() error path (CVE-2026-89582)
A flaw was found in the `bnx2x` component of the Linux kernel. This flaw occurs due to a double free vulnerability within the `bnx2x_init_firmware()` function's error handling path. Memory pointers are freed without being set to NULL, allo…
CVE-2026-89579High· 7.0kernel: bpf: Harden bloom filter sizing and indexing on 32-bit kernels (CVE-2026-89579)
A flaw was found in the Linux kernel's Berkeley Packet Filter (BPF) component, specifically impacting 32-bit systems. This vulnerability stems from incorrect sizing and indexing of bloom filters, which can lead to out-of-bounds memory acce…
CVE-2026-89576Medium· 5.5kernel: dm-era: fix shadowed superblock leak on take-snap failure (CVE-2026-89576)
A flaw was found in the Linux kernel's device-mapper era (dm-era) component. When a snapshot operation fails, a block of metadata is allocated but not properly freed. This leads to a permanent leak of system resources with each failed atte…
CVE-2026-89575High· 7.0kernel: dm raid1: reserve space for NUL-terminator in build_constructor_string() (CVE-2026-89575)
A flaw was found in the Linux kernel's device mapper (dm-raid1) component. This vulnerability occurs in the `build_constructor_string()` function, where insufficient space is reserved for a NUL-terminator when formatting a string with `spr…
CVE-2026-89569High· 7.0kernel: Bluetooth: RFCOMM: serialize security confirmation handling (CVE-2026-89569)
A flaw was found in the Linux kernel's Bluetooth RFCOMM subsystem. This vulnerability arises because the system does not properly manage memory when handling Bluetooth security confirmations. A race condition allows a part of the system to…
CVE-2026-89565Medium· 5.5kernel: ipip: fix skb leak in collect_md mode when metadata_dst allocation fails (CVE-2026-89565)
A flaw was found in the Linux kernel's IP over IP (ipip) tunnel driver. When operating in collect_md mode, the ipip_tunnel_rcv() function fails to free a network packet buffer (skb) if the metadata_dst allocation fails. This oversight lead…
CVE-2026-89563High· 7.0kernel: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() (CVE-2026-89563)
A flaw was found in the `ip6_tunnel` module of the Linux kernel. Incorrect handling of socket buffers (skb) during headroom reallocation in the `ip6_tnl_xmit()` function can lead to a double-free vulnerability. This occurs when an error pa…
CVE-2026-89559High· 7.0kernel: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() (CVE-2026-89559)
A flaw was found in the Linux kernel's `libnvdimm/labels` component. An integer overflow vulnerability exists in the `__nd_label_validate()` function, where a 32-bit calculation of a namespace index field (`nslot`) can wrap around. This al…
CVE-2026-89554Medium· 5.5⚖ disputedkernel: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction (CVE-2026-89554)
A flaw was found in the Linux kernel's Multipath TCP (MPTCP) implementation. When reconstructing a Multipath TCP (MPTCP) join request under SYN cookies, the `local_id` field is not properly initialized. An off-path attacker can influence t…
CVE-2026-89553High· 7.0kernel: nouveau/gem: reserve the bo in the info ioctl around the vma lookup (CVE-2026-89553)
A flaw was found in the Linux kernel's nouveau/gem component. A race condition exists where the graphics execution manager (GEM) close path can close a virtual memory area (VMA) while an information lookup is still trying to access it. Thi…
CVE-2026-89684High· 7.0kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state (CVE-2026-89684)
A flaw was found in the Linux kernel's nfsd component. A remote attacker, by sending a specially crafted OFFLOAD_CANCEL request, could exploit a race condition during the initialization of copy state notifications. This could lead to a den…
CVE-2026-89674Medium· 5.5⚖ disputedkernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget (CVE-2026-89674)
A flaw was found in the `nfsd` component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An attacker could…
CVE-2026-89673Medium· 5.5kernel: nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo (CVE-2026-89673)
A flaw was found in the Linux kernel's NFS daemon (nfsd). A remote attacker could exploit an error in the XDR (External Data Representation) padding calculation within the `ff_encode_getdeviceinfo` function. This mismatch between reserved …
CVE-2026-89672High· 7.0⚖ disputedkernel: nfsd: gate nfs2 setacl by argp->mask (CVE-2026-89672)
A flaw was found in the Linux kernel's Network File System (NFS) server daemon (`nfsd`). When processing NFSACL version 2 SETACL requests, the system could unintentionally remove a directory's default Access Control List (ACL) or both acce…
CVE-2026-89671High· 7.0⚖ disputedkernel: nfsd: gate nfs3 setacl by argp->mask (CVE-2026-89671)
A flaw was found in the Linux kernel's Network File System version 3 (NFSv3) server daemon (`nfsd`). The `nfsd3_proc_setacl()` function unconditionally processes Access Control List (ACL) update requests, even when the client's request doe…
CVE-2026-89669High· 7.0⚖ disputedkernel: nfsd: initialize copy-notify stateid before publishing it (CVE-2026-89669)
A flaw was found in the `nfsd` component of the Linux kernel. A use-after-free vulnerability exists due to improper initialization of the copy-notify state ID before its publication. A remote attacker could exploit this by sending a crafte…
CVE-2026-89665High· 7.0kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE (CVE-2026-89665)
A flaw was found in the Linux kernel's nfsd component. A remote attacker could exploit this vulnerability by sending a specially crafted NFSv2 SETATTR or CREATE request with an out-of-range 'useconds' value. This could lead to incorrect ti…
CVE-2026-89663High· 7.0kernel: nfsd: revoke copy-notify stateids before dropping their reference (CVE-2026-89663)
A flaw was found in the Linux kernel's Network File System Daemon (nfsd). This vulnerability arises from improper handling of "copy-notify stateids" during their revocation. When a stateid's reference is dropped without unlinking it, the m…
CVE-2026-89662High· 7.0⚖ disputedkernel: NFSD: Prevent lock owner use-after-free during client teardown (CVE-2026-89662)
A flaw was found in the Linux kernel's Network File System Daemon (NFSD). During client teardown, a race condition can occur where a lock owner is freed while still being referenced, leading to a use-after-free vulnerability. This can resu…
CVE-2026-89657High· 7.0kernel: libceph: validate OSD extent maps before cursor advance (CVE-2026-89657)
A flaw was found in libceph in the Linux kernel. A malicious or compromised authenticated Ceph Object Storage Device (OSD) peer could send a specially crafted sparse-read reply that lacks proper validation of extent maps. This could cause …
CVE-2026-89656High· 7.0⚖ disputedkernel: libceph: reject buckets with mismatched CRUSH ids (CVE-2026-89656)
A flaw was found in libceph within the Linux kernel. This vulnerability allows a local attacker to craft a malformed CRUSH map, which is used for data placement. By doing so, one data bucket can be made to reuse another bucket's memory wor…
CVE-2026-89655High· 7.0⚖ disputedkernel: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock (CVE-2026-89655)
A flaw was found in the Linux kernel's Ceph file system component. A race condition exists in the `__kick_flushing_caps()` function during the handling of capability messages. This allows a separate process to free a data structure (`cf en…
CVE-2026-89653High· 8.1⚖ disputedkernel: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode (CVE-2026-89653)
A flaw was found in the Linux kernel's Ceph filesystem. This vulnerability occurs when a malicious or malformed MDSMap export_targets entry, controlled by a monitor, contains a rank value that exceeds the maximum allowed (CEPH_MAX_MDS) dur…
CVE-2026-89652High· 7.0⚖ disputedkernel: ceph: bound copied dentry name length in NFS export get_name (CVE-2026-89652)
A flaw was found in the Linux kernel's Ceph file system. A malicious or compromised Ceph Metadata Server (MDS) can send a specially crafted `LOOKUPNAME` reply that causes a buffer overflow when copying dentry names during an NFS export ope…