VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-89720Medium· 5.5⚖ disputed
2w ago

kernel: ubifs: fix out-of-bounds read in signature length check (CVE-2026-89720)

A flaw was found in the Linux kernel's Unsorted Block Image File System (UBIFS). An incorrect bounds check in the ubifs_sb_verify_signature() function allows a crafted signed UBIFS image to declare a signature length larger than its actual…

▾ SunlitRed Hat · LinuxEPSS 0.19%via CSAF
CVE-2026-89712High· 7.0⚖ disputed
2w ago

kernel: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock (CVE-2026-89712)

A flaw was found in the Linux kernel's Network File System Daemon (NFSD) component. A race condition exists where, during the processing of unmounted source-server mounts, a thread may temporarily release a lock. During this window, anothe…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89710High· 7.0
2w ago

kernel: NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path (CVE-2026-89710)

A flaw was found in the Linux kernel's NFSv4.1 implementation. When a server returns a new layout state identifier while an existing one is still active, the pnfs_layout_process() function fails to properly release memory associated with l…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89707High· 7.0
2w ago

kernel: nfsd: release path refs on follow_down() error (CVE-2026-89707)

A flaw was found in the Linux kernel's nfsd component. An authenticated Network File System (NFS) client can exploit this vulnerability by triggering a failed cross-mount operation through `nfsd_lookup_dentry` or the NFSv4 READDIR encode p…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.63%via CSAF
CVE-2026-89706High· 7.0
2w ago

kernel: nfsd: Reset write verifier when async COPY writeback fails (CVE-2026-89706)

A flaw was found in the Linux kernel's nfsd component. When an asynchronous (async) copy writeback operation fails, the server's write verifier is not properly reset. This can lead to a client incorrectly assuming that data has been made d…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.55%via CSAF
CVE-2026-89704High· 7.0
2w ago

kernel: nfsd: sample writeback error cursor before async COPY loop (CVE-2026-89704)

A flaw was found in the Linux kernel's nfsd component. The _nfsd_copy_file_range() function incorrectly samples the writeback error cursor after the copy loop. This allows a concurrent write operation to advance the error cursor prematurel…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.55%via CSAF
CVE-2026-89699Medium· 5.5⚖ disputed
2w ago

kernel: nfsd: validate symlink target length in NFSv4 CREATE (CVE-2026-89699)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd) when handling NFSv4 CREATE operations. A remote attacker can exploit this by sending a crafted request with an oversized symbolic link (symlink) target length. This u…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.72%via CSAF
CVE-2026-89697High· 7.0⚖ disputed
2w ago

kernel: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() (CVE-2026-89697)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When setting file attributes using `nfsd_proc_setattr()`, a specific code path (`BOTH_TIME_SET` branch) prematurely verifies file handles. This bypasses a critical w…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.74%via CSAF
CVE-2026-89696Medium· 5.5⚖ disputed
2w ago

kernel: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref (CVE-2026-89696)

A flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd). A remote client can exploit this by sending a specially crafted NFS COMPOUND request. This request, when processed, can lead to a NULL pointer dereference in t…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89694High· 7.0
2w ago

kernel: nfsd: check client ownership when cancelling a copy-notify stateid (CVE-2026-89694)

A flaw was found in the Linux kernel's NFSv4.2 server (nfsd). An authenticated NFSv4.2 client could exploit a vulnerability in the `manage_cpntf_state()` function by guessing a state identifier. This improper ownership check allows the cli…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89765Medium· 5.5
2w ago

kernel: timers/itimer: Zero-init old itimerval before copy to userspace (CVE-2026-89765)

A flaw was found in the Linux kernel's `timers/itimer` component. On native sparc64 systems, the `struct __kernel_old_timeval` contains uninitialized padding bytes. When `put_itimerval()` copies this structure to userspace, these padding b…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89756Medium· 5.5
2w ago

kernel: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() (CVE-2026-89756)

A flaw was found in the Linux kernel. When performing memory migration on KVM (Kernel-based Virtual Machine) hosts, the `migrate_pages_batch()` function fails to report RCU (Read-Copy Update) tasks quiescent states during large batch unmap…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.19%via CSAF
CVE-2026-89753Medium· 5.5
2w ago

kernel: mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() (CVE-2026-89753)

A flaw was found in the Linux kernel's memory management subsystem. The `shrink_lruvec()` function, responsible for memory reclaim, fails to properly report Read-Copy-Update (RCU) task quiescent states on systems with preemption enabled. T…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89752Medium· 5.5
2w ago

kernel: mm: memcg: stop reclaim when a limit update is superseded (CVE-2026-89752)

A flaw was found in the Linux kernel's memory cgroup (memcg) component. When multiple file operations concurrently update `memory.high` or `memory.max` files in `kernfs`, a writer can continue reclaiming memory towards an outdated target. …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89751Medium· 5.5
2w ago

kernel: x86/tdx: Fix off-by-one in port I/O handling (CVE-2026-89751)

A flaw was found in the Linux kernel's x86/tdx component. An off-by-one error in the `handle_in()` and `handle_out()` functions, specifically in the `GENMASK` calculation for port I/O operations, causes the mask to be one bit too wide. Thi…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89750Medium· 5.5⚖ disputed
2w ago

kernel: tracing/user_events: Clear copied tracing state before fork duplication (CVE-2026-89750)

A flaw was found in the Linux kernel's tracing/user_events component. This vulnerability arises when a child process, created via `fork`, exits and frees memory that the parent process still references. This creates a Use-After-Free (UAF) …

▾ SunlitRed Hat · LinuxEPSS 0.17%via CSAF
CVE-2026-89749Medium· 5.5
2w ago

kernel: tracing: Fix crash passing ERR_PTR to kthread_stop() (CVE-2026-89749)

A flaw was found in the Linux kernel. Specifically, within the tracing subsystem, the `event_test_stuff()` function can pass an invalid error pointer to `kthread_stop()` if `kthread_run()` fails to create a kernel thread. This improper han…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-81010High· 7.8⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originati…

In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originati…

▾ TwilightLinux · LinuxEPSS 0.18%via NVD
CVE-2026-80964Medium· 5.5
2w ago

In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe virmidi driver blindly trusts that the given devptr->id value is within the proper card index range at probe

In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe virmidi driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's O…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89566Medium· 5.5
2w ago

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. Th…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89506Medium· 4.7
2w ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that ca…

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that ca…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89715Medium· 5.5
2w ago

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing …

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing …

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89447Medium· 4.4
2w ago

In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invo…

In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invo…

▾ SunlitLinux · LinuxEPSS 0.22%via NVD
CVE-2026-89518Medium· 5.5
2w ago

kernel: sched_ext: Fix this_rq() assumptions in dispatch kfuncs (CVE-2026-89518)

A flaw was found in the Linux kernel's `sched_ext` component. Under core scheduling, incorrect assumptions in dispatch kfuncs regarding `this_rq()` can lead to a deadlock. This occurs when an `rq` lock is acquired on a CPU different from t…

▾ SunlitRed Hat · LinuxEPSS 0.20%via CSAF
CVE-2026-89517Medium· 5.5
2w ago

kernel: sched_ext: Fix rq->core_pick corruption under core scheduling (CVE-2026-89517)

A flaw was found in the Linux kernel's `sched_ext` component, which handles core scheduling. When multiple selections on the same core interleave due to a dropped lock, they can corrupt the scheduling state. This corruption can lead to a N…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89516Medium· 5.5
2w ago

kernel: sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users (CVE-2026-89516)

A flaw was found in the Linux kernel's `sched_ext` component. When a Deferred Scheduling Queue (DSQ) is destroyed, a pending deferred re-enqueue (DRU) operation might still attempt to access the destroyed DSQ. This can lead to a `BUG_ON` c…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89514Medium· 5.5
2w ago

kernel: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock (CVE-2026-89514)

A flaw was found in the Linux kernel's Fibre Channel over Ethernet Network Interface Card (fnic) driver. The `fnic_fcoe_process_vlan_resp()` function attempts to allocate memory in a way that can cause the system to sleep while holding a s…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89509Medium· 5.5
2w ago

kernel: RDMA/ionic: Embed counter driver data in rdma_counter allocation (CVE-2026-89509)

A flaw was found in the Linux kernel's RDMA/ionic driver. This vulnerability arises from the driver's incorrect handling of `rdma_counter` allocations, specifically by not embedding counter driver data as required. This oversight can lead …

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89505Medium· 5.5
2w ago

kernel: RDMA/uverbs: Guard legacy bundles without method_elm (CVE-2026-89505)

A flaw was found in the Linux kernel's RDMA/uverbs component. Malformed input from a provider in the legacy write path can cause the `uverbs_get_handler_fn()` function to dereference an uninitialized pointer. This can lead to a system cras…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.20%via CSAF
CVE-2026-89502Medium· 5.5
2w ago

kernel: ring-buffer: Free cpu_buffer::free_page with subbuf_order (CVE-2026-89502)

A flaw was found in the Linux kernel's ring-buffer component. When sub-buffers are configured with a specific memory allocation order greater than zero, the system attempts to free a memory page using an incorrect size. This memory managem…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via CSAF
CVEs tagged “csaf” — page 39 · VulnSea