Tagged “cve.org”
CVEs tagged cve.org, newest first.
18494 CVEsRSS
CVE-2026-80944High· 7.0kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait (CVE-2026-80944)
A flaw was found in the Linux kernel's mwifiex Wi-Fi driver. When a synchronous command's wait operation is interrupted, the driver can attempt to write data to a memory location that has already been released. This memory corruption can l…
CVE-2026-80941Medium· 5.5kernel: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (CVE-2026-80941)
A flaw was found in the rtw88 Wi-Fi driver of the Linux kernel. This issue occurs because the rtw_txq_push_skb() function fails to free a socket buffer (skb) when an error occurs during transmission. This oversight can lead to a memory lea…
CVE-2026-80939Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Since the hardware rfkill polling was introduced, arm64 platforms can panic with an asynchron…
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Since the hardware rfkill polling was introduced, arm64 platforms can panic with an asynchron…
CVE-2026-80938Medium· 5.5kernel: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (CVE-2026-80938)
A flaw was found in the Linux kernel, specifically within the `mt7615` Wi-Fi driver. A deadlock can occur during system suspend operations when the suspend process attempts to acquire a mutex (a locking mechanism) while simultaneously wait…
CVE-2026-80935High· 8.8⚖ disputedIn the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block copy from the address …
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block copy from the address …
CVE-2026-80933Medium· 5.5⚖ disputedkernel: wifi: mt76: mt7996: validate default EEPROM firmware size (CVE-2026-80933)
A flaw was found in the Linux kernel's mt76: mt7996 Wi-Fi driver. This vulnerability occurs because the driver does not properly validate the size of the default EEPROM (Electrically Erasable Programmable Read-Only Memory) firmware. A spec…
CVE-2026-80931Medium· 5.5⚖ disputedkernel: w1: ds28e17: reject an oversize length on an I2C block read (CVE-2026-80931)
A flaw was found in the Linux kernel's w1: ds28e17 1-Wire to I2C bridge driver. A malicious I2C slave device can provide an oversized length during an I2C block read operation. This causes the driver to read beyond the allocated buffer, le…
CVE-2026-80930Medium· 5.5kernel: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (CVE-2026-80930)
A flaw was found in the Linux kernel's TPM I2C Nuvoton driver. The `i2c_nuvoton_wait_for_stat()` function enables an interrupt (IRQ) but fails to disable it if the wait operation times out or is interrupted. This oversight can lead to an u…
CVE-2026-80928Medium· 5.5⚖ disputedkernel: smack: fix cred UAF in smack_file_send_sigiotask() (CVE-2026-80928)
A flaw was found in the Linux kernel's SMACK (Simplified Mandatory Access Control Kernel) security module. Incorrect handling of task credentials within the smack_file_send_sigiotask() function can lead to a Use-After-Free (UAF) vulnerabil…
CVE-2026-89440High· 7.0kernel: mmc: via-sdmmc: stop card-detect handling on probe failure (CVE-2026-89440)
A flaw was found in the Linux kernel's mmc: via-sdmmc component. During the probe process, if the `mmc_add_host()` function fails, the SD card-detect interrupt handler continues to operate on memory that has already been released. This can…
CVE-2026-89438Medium· 5.5kernel: platform/x86: ISST: Validate logical CPU id and clos id (CVE-2026-89438)
A flaw was found in the Linux kernel, specifically within the Intel Speed Select Technology (ISST) component. This vulnerability arises from insufficient validation of input values, such as logical CPU ID and CLOS ID, used in the core powe…
CVE-2026-89437Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: platform/x86: int1092: Fix potential memory leak in sar_probe() The memory allocated for device_mode_info in parse_package() called by sar_get_data() is not freed in s…
In the Linux kernel, the following vulnerability has been resolved: platform/x86: int1092: Fix potential memory leak in sar_probe() The memory allocated for device_mode_info in parse_package() called by sar_get_data() is not freed in s…
CVE-2026-81017Medium· 5.5⚖ disputedkernel: platform/chrome: sensorhub: Bound the EC-reported sensor number (CVE-2026-81017)
A flaw was found in the Linux kernel's `sensorhub` component. A local attacker could provide a maliciously crafted sensor number in an EC FIFO event. This unchecked sensor number could lead to an out-of-bounds read and write in the `batch_…
CVE-2026-81014Medium· 5.5kernel: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (CVE-2026-81014)
A flaw was found in the Linux kernel's `hp-bioscfg` module. A local attacker with write access to the `sysfs` entry for `hp-bioscfg` could exploit a heap out-of-bounds read vulnerability. This occurs because the `sk_store()` and `kek_store…
CVE-2026-81013Medium· 5.5kernel: platform/x86: hp-bioscfg: fix heap OOB read on empty password write (CVE-2026-81013)
A flaw was found in the hp-bioscfg component of the Linux kernel. A local user could trigger a heap out-of-bounds read by writing an empty string to the current_password or new_password fields. This occurs because the validate_password_inp…
CVE-2026-81011Medium· 5.5kernel: platform/x86: hp-bioscfg: pass validated element count to package parsers (CVE-2026-81011)
A flaw was found in the Linux kernel's hp-bioscfg module. The module's package parsers incorrectly determine the number of elements in a package, using a value derived from a name string rather than the true package size. While currently p…
CVE-2026-81008High· 7.0kernel: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (CVE-2026-81008)
A flaw was found in the Linux kernel's interconnect subsystem. When a dynamic memory allocation fails during path initialization, an object is prematurely freed while still being referenced in internal lists. This creates dangling pointers…
CVE-2026-81007High· 7.1ipmi: ipmb: validate write message length
In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes…
CVE-2026-81005Medium· 4.1kernel: ipmi: si: Fix NULL pointer dereference after failed registration (CVE-2026-81005)
A flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) subsystem. During the registration of an IPMI message handler, if the Baseboard Management Controller (BMC) device information cannot be fetched, a NUL…
CVE-2026-81003High· 8.1net/iucv: filter frames in afiucv_hs_rcv() by ingress device
In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingress device afiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte name fields in the transport he…
CVE-2026-81002High· 7.0⚖ disputedkernel: xdp: fix zero-copy frame layout (CVE-2026-81002)
A flaw was found in the Linux kernel's XDP (eXpress Data Path) component. Incorrect handling of zero-copy frame layout in the `xdp_convert_zc_to_xdp_frame()` function can allow an AF_XDP zero-copy packet, when redirected through `cpumap`, …
CVE-2026-81001High· 7.0kernel: slip: fix use-after-free in sl_sync() (CVE-2026-81001)
A flaw was found in the Linux kernel's Serial Line Internet Protocol (SLIP) driver. A race condition in the `sl_sync()` function allows for a use-after-free vulnerability, where the driver attempts to access a network device pointer after …
CVE-2026-81000High· 7.8PoCkernel: net: tun: bound receive headroom (CVE-2026-81000)
A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests. This can occur if Open vSwitch (OVS) propagates an excessively lar…
CVE-2026-80994High· 7.0kernel: net: openvswitch: fix flow mask use-after-free on flow deletion (CVE-2026-80994)
A flaw was found in the Open vSwitch component of the Linux kernel. A local attacker could exploit a use-after-free vulnerability during flow deletion. This occurs due to a race condition where the flow mask is freed prematurely, allowing …
CVE-2026-80992Medium· 5.5⚖ disputedkernel: net: ravb: avoid dereferencing an invalid PTP clock (CVE-2026-80992)
A flaw was found in the `net: ravb` component of the Linux kernel. This vulnerability allows for a NULL pointer dereference when the Precision Time Protocol (PTP) clock's index is queried before it is properly initialized or if its registr…
CVE-2026-80990Medium· 5.5kernel: net: thunderbolt: Release the Rx HopID that was handed out on mismatch (CVE-2026-80990)
A flaw was found in the Linux kernel's Thunderbolt networking driver. An issue in the `tbnet_connected_work()` function can lead to a resource leak. When an unexpected HopID is allocated during an XDomain connection, the ID is not properly…
CVE-2026-80989High· 7.0kernel: net: thunderbolt: Mark the connection down when bringing it up fails (CVE-2026-80989)
A flaw was found in the Linux kernel's Thunderbolt networking subsystem. When a Thunderbolt connection fails to establish, the system may not correctly update its state, leading to repeated attempts to tear down an already inactive connect…
CVE-2026-80988Medium· 5.5kernel: NTB: ntb_transport: Fail TX enqueue when the QP link is down (CVE-2026-80988)
A flaw was found in the Linux kernel's Non-Transparent Bridge (NTB) transport module. When the NTB transport attempts to transmit packets while the Queue Pair (QP) link is down, the system incorrectly reports a successful transmission with…
CVE-2026-80987Medium· 5.5⚖ disputedkernel: NTB: ntb_transport: Reject oversized TX buffers (CVE-2026-80987)
A flaw was found in the Linux kernel's Non-Transparent Bridge (NTB) transport module. When processing oversized transmit (TX) buffers, the system fails to properly free the allocated memory, leading to a memory leak. This continuous leakag…
CVE-2026-80984Medium· 5.5kernel: net/smc: do not dereference an unset send buffer on the SMC-D teardown path (CVE-2026-80984)
A flaw was found in the `net/smc` component of the Linux kernel. When a link group terminates while a socket is waiting in `smc_close_stream_wait()`, a NULL pointer dereference can occur during the SMC-D teardown path. This can lead to a s…