VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18494 CVEsRSS

CVE-2026-89617Medium· 5.5⚖ disputed
3w ago

kernel: fs/ntfs3: validate dirty page table on log replay (CVE-2026-89617)

A flaw was found in the Linux kernel's NTFS3 filesystem driver. An attacker with local access could craft a malicious NTFS log file. During log replay, insufficient validation of the `lcns_follow` field in a `DIR_PAGE_ENTRY` could lead to …

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89616Medium· 5.5⚖ disputed
3w ago

kernel: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() (CVE-2026-89616)

A flaw was found in the Linux kernel's NTFS3 filesystem driver. When decompressing LZNT data, the `ni_read_frame()` function may not fully zero out memory after a partial decompression. This can lead to the disclosure of previously used ke…

▾ SunlitRed Hat · LinuxEPSS 0.57%via CSAF
CVE-2026-89615Medium· 5.5⚖ disputed
3w ago

kernel: fs/ntfs3: bound page_lcns[] index by the log record (CVE-2026-89615)

A flaw was found in the Linux kernel's NTFS3 file system driver. A local attacker could exploit this by providing a specially crafted log record. This crafted record causes a buffer overflow in the page_lcns[] array, leading to memory corr…

▾ SunlitRed Hat · LinuxEPSS 0.20%via CSAF
CVE-2026-89609High· 7.0
3w ago

kernel: ecryptfs: hold msg ctx list lock when cleaning daemon queue (CVE-2026-89609)

A flaw was found in the eCryptfs component of the Linux kernel. A race condition occurs during the cleanup of the daemon message queue because a required lock is not held. This can lead to unpredictable system behavior or instability due t…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.18%via CSAF
CVE-2026-89608Medium· 5.5
3w ago

kernel: ecryptfs: pass packet set buffer size to parser (CVE-2026-89608)

A flaw was found in the `ecryptfs` component of the Linux kernel. The `ecryptfs_parse_packet_set()` function incorrectly calculates the available buffer size when processing version 1 headers, leading to an overstatement of the buffer's ac…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.17%via CSAF
CVE-2026-89746High· 7.0
3w ago

kernel: tracing: Fix use-after-free with same-name named triggers (CVE-2026-89746)

A flaw was found in the Linux kernel's tracing component. A local user can exploit a use-after-free vulnerability by registering multiple histogram triggers with the same name. This action causes the kernel to attempt to access freed memor…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89744Medium· 5.5⚖ disputed
3w ago

kernel: device property: fix infinite loop in fwnode_for_each_child_node() (CVE-2026-89744)

A flaw was found in the Linux kernel's device property handling. When the kernel iterates over child nodes of a firmware node (fwnode) that also has a secondary fwnode, the `fwnode_get_next_child_node()` function can enter an endless loop.…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-89742Medium· 5.5⚖ disputed
3w ago

kernel: rapidio: mport_cdev: fix use-after-free in dma_req_free() (CVE-2026-89742)

A flaw was found in the Linux kernel. A local user could exploit a use-after-free vulnerability in the `dma_req_free()` function within the RapidIO mport character device interface. This flaw occurs when the `dma_req_free()` function attem…

▾ SunlitRed Hat · LinuxEPSS 0.17%via CSAF
CVE-2026-89741High· 7.0
3w ago

kernel: Revert "media: v4l2-dev: fix error handling in __video_register_device()" (CVE-2026-89741)

A flaw was found in the Linux kernel's media subsystem, specifically within the v4l2-dev component. This vulnerability arises from incorrect error handling in the `__video_register_device()` function. If a device registration fails, the sy…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89736Medium· 5.5⚖ disputed
3w ago

kernel: usb: gadget: u_audio: Fix use-after-free on sound card disconnect (CVE-2026-89736)

A flaw was found in the Linux kernel's USB audio gadget driver (u_audio). This vulnerability occurs during sound card disconnection when Asynchronous Linux Sound Architecture (ALSA) control elements (kctls) remain open in userspace. A loca…

▾ SunlitRed Hat · LinuxEPSS 0.17%via CSAF
CVE-2026-89735Medium· 5.5
3w ago

kernel: usb: gadget: midi2: remove default configfs groups on teardown (CVE-2026-89735)

A flaw was found in the Linux kernel's USB gadget MIDI2 driver. The driver fails to properly remove default configuration file system (configfs) groups during teardown, leading to a resource leak. A local attacker could exploit this vulner…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89733Medium· 5.5⚖ disputed
3w ago

kernel: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (CVE-2026-89733)

A flaw was found in the Linux kernel's USB Video Class (UVC) gadget driver. This vulnerability occurs in the `uvc_function_bind()` and `uvc_function_unbind()` functions, where pointers to freed memory are not properly cleared. This can lea…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89732Medium· 5.5
3w ago

kernel: usb: gadget: f_fs: Prevent deadlock during ep0 read loop (CVE-2026-89732)

A flaw was found in the Linux kernel's USB FunctionFS (f_fs) module. A local attacker could exploit a deadlock vulnerability in the ffs_ep0_read() function. This occurs when a userspace daemon polls ep0 and the USB gadget is simultaneously…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.24%via CSAF
CVE-2026-89730Medium· 5.5
3w ago

kernel: fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (CVE-2026-89730)

A flaw was found in the `altera-cvp` FPGA driver within the Linux kernel. The `altera_cvp_send_block()` function can perform an out-of-bounds read when processing the trailing bytes of an input buffer. This occurs if the buffer ends at a p…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.22%via CSAF
CVE-2026-89729High· 7.0
3w ago

kernel: HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (CVE-2026-89729)

A flaw was found in the Linux kernel's Human Interface Device (HID) sensor-hub driver. A local attacker could exploit this vulnerability by providing a specially crafted HID descriptor. This malicious descriptor could cause the `sensor_hub…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.41%via CSAF
CVE-2026-89726Medium· 5.5
3w ago

kernel: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (CVE-2026-89726)

A flaw was found in the Linux kernel's `ucs2_strnlen()` function. This vulnerability occurs because the function checks the current character before verifying if the maximum allowed length has been reached. If the input string is not prope…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89725Medium· 5.5⚖ disputed
3w ago

kernel: media: cec: stm32: prevent out-of-bounds write on RX overflow (CVE-2026-89725)

A flaw was found in the Linux kernel's `media: cec: stm32` driver. A remote attacker can exploit an out-of-bounds write vulnerability by sending an overlong Consumer Electronics Control (CEC) message without an end-of-message signal. This …

▾ SunlitRed Hat · LinuxEPSS 0.41%via CSAF
CVE-2026-89724Medium· 5.5⚖ disputed
3w ago

kernel: media: vicodec: fix out-of-bounds write in FWHT encoder (CVE-2026-89724)

A flaw was found in the Linux kernel's `media: vicodec` component. An out-of-bounds write vulnerability exists in the FWHT encoder due to incorrect buffer sizing during video output format handling. This issue allows an attacker to cause c…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89723Medium· 5.5⚖ disputed
3w ago

kernel: nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation (CVE-2026-89723)

A flaw was found in the nilfs2 file system component of the Linux kernel. When a file is truncated, an intermediate node block is not properly deleted and remains in the B-tree node cache. This can lead to the log writer incorrectly proces…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-89720Medium· 5.5⚖ disputed
3w ago

kernel: ubifs: fix out-of-bounds read in signature length check (CVE-2026-89720)

A flaw was found in the Linux kernel's Unsorted Block Image File System (UBIFS). An incorrect bounds check in the ubifs_sb_verify_signature() function allows a crafted signed UBIFS image to declare a signature length larger than its actual…

▾ SunlitRed Hat · LinuxEPSS 0.19%via CSAF
CVE-2026-89712High· 7.0⚖ disputed
3w ago

kernel: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock (CVE-2026-89712)

A flaw was found in the Linux kernel's Network File System Daemon (NFSD) component. A race condition exists where, during the processing of unmounted source-server mounts, a thread may temporarily release a lock. During this window, anothe…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89711High· 8.2
3w ago

NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check

In the Linux kernel, the following vulnerability has been resolved: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in fh_verify of directories") details the assumptio…

▾ TwilightLinux · LinuxEPSS 0.63%via CVEORG
CVE-2026-89710High· 7.0
3w ago

kernel: NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path (CVE-2026-89710)

A flaw was found in the Linux kernel's NFSv4.1 implementation. When a server returns a new layout state identifier while an existing one is still active, the pnfs_layout_process() function fails to properly release memory associated with l…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89707High· 7.0
3w ago

kernel: nfsd: release path refs on follow_down() error (CVE-2026-89707)

A flaw was found in the Linux kernel's nfsd component. An authenticated Network File System (NFS) client can exploit this vulnerability by triggering a failed cross-mount operation through `nfsd_lookup_dentry` or the NFSv4 READDIR encode p…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.63%via CSAF
CVE-2026-89706High· 7.0
3w ago

kernel: nfsd: Reset write verifier when async COPY writeback fails (CVE-2026-89706)

A flaw was found in the Linux kernel's nfsd component. When an asynchronous (async) copy writeback operation fails, the server's write verifier is not properly reset. This can lead to a client incorrectly assuming that data has been made d…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.55%via CSAF
CVE-2026-89704High· 7.0
3w ago

kernel: nfsd: sample writeback error cursor before async COPY loop (CVE-2026-89704)

A flaw was found in the Linux kernel's nfsd component. The _nfsd_copy_file_range() function incorrectly samples the writeback error cursor after the copy loop. This allows a concurrent write operation to advance the error cursor prematurel…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.55%via CSAF
CVE-2026-89699Medium· 5.5⚖ disputed
3w ago

kernel: nfsd: validate symlink target length in NFSv4 CREATE (CVE-2026-89699)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd) when handling NFSv4 CREATE operations. A remote attacker can exploit this by sending a crafted request with an oversized symbolic link (symlink) target length. This u…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.72%via CSAF
CVE-2026-89697High· 7.0⚖ disputed
3w ago

kernel: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() (CVE-2026-89697)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When setting file attributes using `nfsd_proc_setattr()`, a specific code path (`BOTH_TIME_SET` branch) prematurely verifies file handles. This bypasses a critical w…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.74%via CSAF
CVE-2026-89696Medium· 5.5⚖ disputed
3w ago

kernel: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref (CVE-2026-89696)

A flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd). A remote client can exploit this by sending a specially crafted NFS COMPOUND request. This request, when processed, can lead to a NULL pointer dereference in t…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89694High· 7.0
3w ago

kernel: nfsd: check client ownership when cancelling a copy-notify stateid (CVE-2026-89694)

A flaw was found in the Linux kernel's NFSv4.2 server (nfsd). An authenticated NFSv4.2 client could exploit a vulnerability in the `manage_cpntf_state()` function by guessing a state identifier. This improper ownership check allows the cli…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVEs tagged “cve.org” — page 357 · VulnSea