VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20135 CVEsRSS

CVE-2026-89570High· 7.0⚖ disputed
3w ago

kernel: cxl/mce: Make the MCE notifier per-region (CVE-2026-89570)

A flaw was found in the Linux kernel's Compute Express Link (CXL) subsystem. Lifetime issues with the CXL Machine Check Exception (MCE) notifier can lead to NULL dereferences and use-after-free vulnerabilities in the MCE handler. This coul…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.17%via CSAF
CVE-2026-89564High· 7.8
3w ago

In the Linux kernel, the following vulnerability has been resolved: ip: orphan prefetched skbs before multicast forwarding IPv4 and IPv6 input preserve an skb->sk association installed by bpf_sk_assign() so that local delivery can use …

In the Linux kernel, the following vulnerability has been resolved: ip: orphan prefetched skbs before multicast forwarding IPv4 and IPv6 input preserve an skb->sk association installed by bpf_sk_assign() so that local delivery can use …

▾ TwilightLinux · LinuxEPSS 0.14%via NVD
CVE-2026-89561High· 7.5⚖ disputed
3w ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL check when reading idev->cnf.rpl…

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL check when reading idev->cnf.rpl…

▾ TwilightLinux · LinuxEPSS 0.44%via NVD
CVE-2026-89558High· 7.0⚖ disputed
3w ago

kernel: md/raid10: fix still_degraded being inverted in raid10_sync_request() (CVE-2026-89558)

A flaw was found in the Linux kernel's md/raid10 (RAID10) driver. This vulnerability occurs when a RAID10 array is in a degraded state and a device is being recovered while another mirror is still missing. Due to an inverted boolean value,…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.64%via CSAF
CVE-2026-89546Medium· 5.3⚖ disputed
3w ago

kernel: Linux Kernel: Resource management flaw in SUNRPC NFS callback service (CVE-2026-89546)

A flaw was found in the Linux kernel's SUNRPC (Sun Remote Procedure Call) Network File System (NFS) callback service. A race condition during the service teardown can lead to system resources not being properly released, causing a resource…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2026-89545High· 7.8
3w ago

In the Linux kernel, the following vulnerability has been resolved: sunrpc: defer rq_argp and rq_resp free until after RCU grace period svc_rqst_free() frees rqstp->rq_argp and rqstp->rq_resp synchronously via kfree(), but defers the r…

In the Linux kernel, the following vulnerability has been resolved: sunrpc: defer rq_argp and rq_resp free until after RCU grace period svc_rqst_free() frees rqstp->rq_argp and rqstp->rq_resp synchronously via kfree(), but defers the r…

▾ TwilightLinux · LinuxEPSS 0.16%via NVD
CVE-2026-89544High· 7.5⚖ disputed
3w ago

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gssx_dec_option_array error path bugs Four coupled defects in the gssx XDR option-array decoder make the error paths unsafe: a NULL deref in the caller, a …

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gssx_dec_option_array error path bugs Four coupled defects in the gssx XDR option-array decoder make the error paths unsafe: a NULL deref in the caller, a …

▾ TwilightLinux · LinuxEPSS 0.59%via NVD
CVE-2026-89537High· 7.0⚖ disputed
3w ago

kernel: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 (CVE-2026-89537)

A flaw was found in the Linux kernel's SUNRPC implementation, specifically within the `gss_krb5_verify_mic_v2` function. A remote malicious Network File System (NFS) server could provide a specially crafted, short Kerberos Message Integrit…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.54%via CSAF
CVE-2026-89535High· 8.1
3w ago

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id svc_rdma_free() caches rdma->sc_cm_id->device before teardown, then calls rdma_destroy_id(sc_cm_id) which…

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id svc_rdma_free() caches rdma->sc_cm_id->device before teardown, then calls rdma_destroy_id(sc_cm_id) which…

▾ TwilightLinux · LinuxEPSS 0.54%via NVD
CVE-2026-89530High· 7.0⚖ disputed
3w ago

kernel: svcrdma: Reject inline replies that overflow the pull-up buffer (CVE-2026-89530)

A flaw was found in the Linux kernel's svcrdma component, which handles network communication using Remote Direct Memory Access (RDMA). A remote attacker can send a specially crafted network reply that is larger than expected. This can cau…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.46%via CSAF
CVE-2026-89692Medium· 5.5⚖ disputed
3w ago

kernel: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue (CVE-2026-89692)

A flaw was found in the Linux kernel's Network File System (NFS) daemon, `nfsd`. This vulnerability occurs when a delegation recall operation fails, leaving a critical internal flag uncleared. This prevents subsequent attempts to break the…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.61%via CSAF
CVE-2026-89691High· 7.0
3w ago

kernel: nfsd: clear opcnt on compound arg release to prevent OOB read (CVE-2026-89691)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd) component. The nfsd4_release_compoundargs() function does not properly clear an internal counter (opcnt) when releasing a buffer. This oversight can lead to an out-of…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89690High· 7.0
3w ago

kernel: nfsd: defer vfree of compound ops to fix rpc_status UAF (CVE-2026-89690)

A flaw was found in the `nfsd` component of the Linux kernel. This vulnerability, a use-after-free, occurs when a specific memory buffer is prematurely released while another process is still trying to access it. This timing issue can lead…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.16%via CSAF
CVE-2026-89689High· 7.0⚖ disputed
3w ago

kernel: nfsd: don't free session slots that are still in use (CVE-2026-89689)

A flaw was found in the Linux kernel's Network File System (NFS) daemon, `nfsd`. A remote attacker could exploit a use-after-free vulnerability in the `nfsd4_sequence()` function. This occurs when the system attempts to reduce the number o…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.65%via CSAF
CVE-2026-89688High· 7.0⚖ disputed
3w ago

kernel: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry (CVE-2026-89688)

A flaw was found in the Linux kernel's nfsd component. During a `seqid_op` replay retry, the system incorrectly handles reference counts for stateowners, leading to a reference count underflow and a use-after-free vulnerability. This issue…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.74%via CSAF
CVE-2026-89686High· 7.0⚖ disputed
3w ago

kernel: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke (CVE-2026-89686)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd) for NFSv4 layouts. A race condition allows a remote attacker to trigger a kernel panic, leading to a Denial of Service (DoS). This occurs when the `nfsd4_alloc_layout…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.66%via CSAF
CVE-2026-89685High· 7.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but comp…

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but comp…

▾ TwilightLinux · LinuxEPSS 0.44%via NVD
CVE-2026-89682High· 7.0
3w ago

kernel: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net (CVE-2026-89682)

A flaw was found in the Linux kernel's NFS daemon (nfsd) component. The nfsd_file_dispose_list_delayed() function, responsible for deferring file disposal, uses a separately allocated structure for its freeme queue. During network namespac…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.53%via CSAF
CVE-2026-89681Medium· 5.5⚖ disputed
3w ago

kernel: nfsd: fix layout fence worker double-reference race (CVE-2026-89681)

A flaw was found in the Linux kernel's nfsd component. A race condition in the layout fence worker can cause a double-reference to a layout stateid. This occurs because the workqueue core clears a pending flag prematurely, allowing a new w…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.55%via CSAF
CVE-2026-89680High· 7.0⚖ disputed
3w ago

kernel: nfsd: fix nfsd_file leak on inter-server COPY setup failure (CVE-2026-89680)

A flaw was found in the Linux kernel's nfsd component. This vulnerability occurs when an inter-server COPY operation fails during its setup phase, leading to improper resource cleanup. Consequently, each failed operation results in a memor…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.65%via CSAF
CVE-2026-89679Medium· 5.5
3w ago

kernel: nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs (CVE-2026-89679)

A flaw was found in the Linux kernel's nfsd component. A remote attacker can exploit this by sending a specially crafted SETATTR request that includes specific delegation timestamp attributes and a special NFSv4 state ID. This triggers a n…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.72%via CSAF
CVE-2026-89678High· 7.0
3w ago

kernel: nfsd: fix partial-write detection in nfsd_direct_write (CVE-2026-89678)

A flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd) component. The `nfsd_direct_write()` function, responsible for handling direct writes, incorrectly detects partial writes. This issue occurs because the logic f…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.38%via CSAF
CVE-2026-89677High· 7.0⚖ disputed
3w ago

kernel: nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() (CVE-2026-89677)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When creating files, the `dentry_create()` function could return an unexpected directory entry (dentry). This could lead to a previously stored dentry being prematur…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.55%via CSAF
CVE-2026-89676Critical· 9.8⚖ disputed
3w ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before dup_copy_fields(), so the s2s_cp_stateids…

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before dup_copy_fields(), so the s2s_cp_stateids…

▾ MidnightLinux · LinuxEPSS 0.46%via NVD
CVE-2026-89675High· 7.0⚖ disputed
3w ago

kernel: nfsd: fix UAF in async copy cancel and shutdown (CVE-2026-89675)

A flaw was found in the Linux kernel's nfsd component. A race condition exists during asynchronous copy cancellation and shutdown operations, which can lead to a Use-After-Free (UAF) vulnerability. This allows an async copy object to be fr…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.65%via CSAF
CVE-2026-89670High· 7.0
3w ago

kernel: nfsd: hold rcu across localio cmpxchg retry (CVE-2026-89670)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd) component. A race condition exists in the `nfsd_open_local_fh()` function where an `nfsd_file` object can be freed and its memory recycled while another process attem…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.17%via CSAF
CVE-2026-89668High· 7.0⚖ disputed
3w ago

kernel: nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() (CVE-2026-89668)

A flaw was found in the `nfsd` component of the Linux kernel. The `nfsd_debugfs_init()` function is called before `nfsd4_init_slabs()`. If the slab allocation fails, the `nfsd_debugfs_exit()` cleanup function is bypassed, leaving orphaned …

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.18%via CSAF
CVE-2026-89667High· 8.1⚖ disputed
3w ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtabl…

In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtabl…

▾ TwilightLinux · LinuxEPSS 0.54%via NVD
CVE-2026-89664High· 7.0
3w ago

kernel: nfsd: release OPEN-decoded posix ACLs via op_release (CVE-2026-89664)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When processing malformed NFSv4 OPEN compound operations that include valid Portable Operating System Interface (POSIX) Access Control List (ACL) attributes, the ker…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
CVE-2026-89660Critical· 9.8⚖ disputed
3w ago

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it. The cli…

▾ MidnightLinux · LinuxEPSS 0.62%via NVD
CVEs tagged “cve.org” — page 402 · VulnSea