VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-89595Medium· 5.5
2w ago

kernel: fsnotify: Fix stale object mask after concurrent mark updates (CVE-2026-89595)

A flaw was found in the Linux kernel's fsnotify subsystem, affecting fanotify and inotify. A race condition can occur during concurrent updates to event marks, where the object mask becomes stale. This can lead to a denial of service or in…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.22%via CSAF
CVE-2026-89594Medium· 5.5⚖ disputed
2w ago

kernel: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device (CVE-2026-89594)

A flaw was found in the Linux kernel's OMAP SSI driver. The driver uses a synthetic HSI controller device that does not properly initialize its Direct Memory Access (DMA) mask. This oversight can lead to the driver crashing or triggering w…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89587High· 7.0
2w ago

kernel: ACPI: pfr_update: fix stack buffer overflow in query_capability() (CVE-2026-89587)

A flaw was found in the Linux kernel's ACPI Platform Firmware Runtime Update (pfr_update) component. The `query_capability()` function, responsible for handling ACPI buffer objects from firmware, performs an unchecked memory copy operation…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.19%via CSAF
CVE-2026-89586Medium· 5.5⚖ disputed
2w ago

kernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes (CVE-2026-89586)

A flaw was found in the Linux kernel's `libata-scsi` component. This vulnerability occurs when the system attempts to perform Data Set Management (DSM) TRIM operations on storage devices with logical sector sizes exceeding 2048 bytes. Due …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.63%via CSAF
CVE-2026-89585Medium· 5.5⚖ disputed
2w ago

kernel: auxdisplay: charlcd: cancel backlight work on registration failure (CVE-2026-89585)

A flaw was found in the `auxdisplay: charlcd` component of the Linux kernel. This use-after-free vulnerability occurs when the `charlcd_register()` function fails, leading to the `charlcd` object being freed while a delayed work item still…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89583High· 7.0
2w ago

kernel: Bluetooth: eir: Fix OOB read in eir_get_service_data() (CVE-2026-89583)

A flaw was found in the Linux kernel's Bluetooth subsystem. An out-of-bounds (OOB) read vulnerability exists in the `eir_get_service_data()` function due to incorrect length calculation when parsing Extended Inquiry Response (EIR) advertis…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.41%via CSAF
CVE-2026-89582High· 7.0
2w ago

kernel: bnx2x: fix double free in bnx2x_init_firmware() error path (CVE-2026-89582)

A flaw was found in the `bnx2x` component of the Linux kernel. This flaw occurs due to a double free vulnerability within the `bnx2x_init_firmware()` function's error handling path. Memory pointers are freed without being set to NULL, allo…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89579High· 7.0
2w ago

kernel: bpf: Harden bloom filter sizing and indexing on 32-bit kernels (CVE-2026-89579)

A flaw was found in the Linux kernel's Berkeley Packet Filter (BPF) component, specifically impacting 32-bit systems. This vulnerability stems from incorrect sizing and indexing of bloom filters, which can lead to out-of-bounds memory acce…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89576Medium· 5.5
2w ago

kernel: dm-era: fix shadowed superblock leak on take-snap failure (CVE-2026-89576)

A flaw was found in the Linux kernel's device-mapper era (dm-era) component. When a snapshot operation fails, a block of metadata is allocated but not properly freed. This leads to a permanent leak of system resources with each failed atte…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89575High· 7.0
2w ago

kernel: dm raid1: reserve space for NUL-terminator in build_constructor_string() (CVE-2026-89575)

A flaw was found in the Linux kernel's device mapper (dm-raid1) component. This vulnerability occurs in the `build_constructor_string()` function, where insufficient space is reserved for a NUL-terminator when formatting a string with `spr…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.24%via CSAF
CVE-2026-89569High· 7.0
2w ago

kernel: Bluetooth: RFCOMM: serialize security confirmation handling (CVE-2026-89569)

A flaw was found in the Linux kernel's Bluetooth RFCOMM subsystem. This vulnerability arises because the system does not properly manage memory when handling Bluetooth security confirmations. A race condition allows a part of the system to…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.40%via CSAF
CVE-2026-89565Medium· 5.5
2w ago

kernel: ipip: fix skb leak in collect_md mode when metadata_dst allocation fails (CVE-2026-89565)

A flaw was found in the Linux kernel's IP over IP (ipip) tunnel driver. When operating in collect_md mode, the ipip_tunnel_rcv() function fails to free a network packet buffer (skb) if the metadata_dst allocation fails. This oversight lead…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89563High· 7.0
2w ago

kernel: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() (CVE-2026-89563)

A flaw was found in the `ip6_tunnel` module of the Linux kernel. Incorrect handling of socket buffers (skb) during headroom reallocation in the `ip6_tnl_xmit()` function can lead to a double-free vulnerability. This occurs when an error pa…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89559High· 7.0
2w ago

kernel: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() (CVE-2026-89559)

A flaw was found in the Linux kernel's `libnvdimm/labels` component. An integer overflow vulnerability exists in the `__nd_label_validate()` function, where a 32-bit calculation of a namespace index field (`nslot`) can wrap around. This al…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89554Medium· 5.5⚖ disputed
2w ago

kernel: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction (CVE-2026-89554)

A flaw was found in the Linux kernel's Multipath TCP (MPTCP) implementation. When reconstructing a Multipath TCP (MPTCP) join request under SYN cookies, the `local_id` field is not properly initialized. An off-path attacker can influence t…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.61%via CSAF
CVE-2026-89553High· 7.0
2w ago

kernel: nouveau/gem: reserve the bo in the info ioctl around the vma lookup (CVE-2026-89553)

A flaw was found in the Linux kernel's nouveau/gem component. A race condition exists where the graphics execution manager (GEM) close path can close a virtual memory area (VMA) while an information lookup is still trying to access it. Thi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89684High· 7.0
2w ago

kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state (CVE-2026-89684)

A flaw was found in the Linux kernel's nfsd component. A remote attacker, by sending a specially crafted OFFLOAD_CANCEL request, could exploit a race condition during the initialization of copy state notifications. This could lead to a den…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.72%via CSAF
CVE-2026-89674Medium· 5.5⚖ disputed
2w ago

kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget (CVE-2026-89674)

A flaw was found in the `nfsd` component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An attacker could…

▾ SunlitRed Hat · LinuxEPSS 0.76%via CSAF
CVE-2026-89673Medium· 5.5
2w ago

kernel: nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo (CVE-2026-89673)

A flaw was found in the Linux kernel's NFS daemon (nfsd). A remote attacker could exploit an error in the XDR (External Data Representation) padding calculation within the `ff_encode_getdeviceinfo` function. This mismatch between reserved …

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89672High· 7.0⚖ disputed
2w ago

kernel: nfsd: gate nfs2 setacl by argp->mask (CVE-2026-89672)

A flaw was found in the Linux kernel's Network File System (NFS) server daemon (`nfsd`). When processing NFSACL version 2 SETACL requests, the system could unintentionally remove a directory's default Access Control List (ACL) or both acce…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.52%via CSAF
CVE-2026-89671High· 7.0⚖ disputed
2w ago

kernel: nfsd: gate nfs3 setacl by argp->mask (CVE-2026-89671)

A flaw was found in the Linux kernel's Network File System version 3 (NFSv3) server daemon (`nfsd`). The `nfsd3_proc_setacl()` function unconditionally processes Access Control List (ACL) update requests, even when the client's request doe…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.52%via CSAF
CVE-2026-89669High· 7.0⚖ disputed
2w ago

kernel: nfsd: initialize copy-notify stateid before publishing it (CVE-2026-89669)

A flaw was found in the `nfsd` component of the Linux kernel. A use-after-free vulnerability exists due to improper initialization of the copy-notify state ID before its publication. A remote attacker could exploit this by sending a crafte…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.73%via CSAF
CVE-2026-89665High· 7.0
2w ago

kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE (CVE-2026-89665)

A flaw was found in the Linux kernel's nfsd component. A remote attacker could exploit this vulnerability by sending a specially crafted NFSv2 SETATTR or CREATE request with an out-of-range 'useconds' value. This could lead to incorrect ti…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.62%via CSAF
CVE-2026-89663High· 7.0
2w ago

kernel: nfsd: revoke copy-notify stateids before dropping their reference (CVE-2026-89663)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). This vulnerability arises from improper handling of "copy-notify stateids" during their revocation. When a stateid's reference is dropped without unlinking it, the m…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.66%via CSAF
CVE-2026-89662High· 7.0⚖ disputed
2w ago

kernel: NFSD: Prevent lock owner use-after-free during client teardown (CVE-2026-89662)

A flaw was found in the Linux kernel's Network File System Daemon (NFSD). During client teardown, a race condition can occur where a lock owner is freed while still being referenced, leading to a use-after-free vulnerability. This can resu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.73%via CSAF
CVE-2026-89657High· 7.0
2w ago

kernel: libceph: validate OSD extent maps before cursor advance (CVE-2026-89657)

A flaw was found in libceph in the Linux kernel. A malicious or compromised authenticated Ceph Object Storage Device (OSD) peer could send a specially crafted sparse-read reply that lacks proper validation of extent maps. This could cause …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.63%via CSAF
CVE-2026-89656High· 7.0⚖ disputed
2w ago

kernel: libceph: reject buckets with mismatched CRUSH ids (CVE-2026-89656)

A flaw was found in libceph within the Linux kernel. This vulnerability allows a local attacker to craft a malformed CRUSH map, which is used for data placement. By doing so, one data bucket can be made to reuse another bucket's memory wor…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89655High· 7.0⚖ disputed
2w ago

kernel: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock (CVE-2026-89655)

A flaw was found in the Linux kernel's Ceph file system component. A race condition exists in the `__kick_flushing_caps()` function during the handling of capability messages. This allows a separate process to free a data structure (`cf en…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89653High· 8.1⚖ disputed
2w ago

kernel: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode (CVE-2026-89653)

A flaw was found in the Linux kernel's Ceph filesystem. This vulnerability occurs when a malicious or malformed MDSMap export_targets entry, controlled by a monitor, contains a rank value that exceeds the maximum allowed (CEPH_MAX_MDS) dur…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.74%via CSAF
CVE-2026-89652High· 7.0⚖ disputed
2w ago

kernel: ceph: bound copied dentry name length in NFS export get_name (CVE-2026-89652)

A flaw was found in the Linux kernel's Ceph file system. A malicious or compromised Ceph Metadata Server (MDS) can send a specially crafted `LOOKUPNAME` reply that causes a buffer overflow when copying dentry names during an NFS export ope…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.67%via CSAF
CVEs tagged “csaf” — page 37 · VulnSea