VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20152 CVEsRSS

CVE-2026-89461Medium· 5.5
3w ago

kernel: power: supply: max17040: synchronize work cancellation on suspend (CVE-2026-89461)

A flaw was found in the Linux kernel's `max17040` power supply driver. A timing issue, known as a race condition, can occur during system suspend. This allows a background process (polling callback) to continue accessing the fuel gauge and…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89460Medium· 4.4
3w ago

kernel: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks (CVE-2026-89460)

A flaw was found in the Linux kernel. A local user can trigger a kernel panic by running the `perf stat` command while CPUs are being hotplugged. This occurs because the system fails to properly allocate CPU event structures for newly onli…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89458High· 7.0
3w ago

kernel: s390/dasd: Do not complete a failed ESE read as successful (CVE-2026-89458)

A flaw was found in the Linux kernel's s390/dasd component. The `dasd_int_handler()` function incorrectly marks failed Extended Sense Data (ESE) read operations as successful when processing unallocated ESE tracks. This leads to the block …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89457Medium· 5.5
3w ago

kernel: s390/dasd: Guard sysfs discipline callbacks against unallocated private data (CVE-2026-89457)

A flaw was found in the s390/dasd component of the Linux kernel. An unprivileged local user can trigger a null pointer dereference by reading specific world-readable sysfs attributes while the device is being brought online. This can lead …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89456High· 7.0
3w ago

kernel: s390/dasd: Propagate partial completion length across ERP recovery (CVE-2026-89456)

A flaw was found in the Linux kernel. Specifically, within the s390/dasd component, an issue exists during error recovery for disk read operations. When a request is partially completed and then recovered, the system fails to correctly pro…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.15%via CSAF
CVE-2026-89448High· 7.0⚖ disputed
3w ago

kernel: iommu/vt-d: Force requesting ACS when tboot is enabled (CVE-2026-89448)

A flaw was found in the Linux kernel's IOMMU (Input/Output Memory Management Unit) component. When tboot (Trusted Boot) is enabled, the system may fail to correctly request Access Control Services (ACS). This misconfiguration could potenti…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVE-2026-89444High· 7.0
3w ago

kernel: platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (CVE-2026-89444)

A flaw was found in the Linux kernel. The `dell-wmi-sysman` driver, responsible for managing Dell WMI (Windows Management Instrumentation) system attributes, incorrectly logs sensitive information. Specifically, when setting a BIOS attribu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89443Medium· 5.5
3w ago

kernel: platform/x86: ISST: Validate level in perf mask ioctls (CVE-2026-89443)

A flaw was found in the Linux kernel's platform/x86 ISST module. The `isst_if_get_perf_level_mask()` and `isst_if_get_base_freq_mask()` functions fail to validate a user-provided 'level' parameter. A local attacker could exploit this by pr…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.16%via CSAF
CVE-2026-89442Medium· 5.5⚖ disputed
3w ago

kernel: platform/x86: ISST: Validate socket ID in clos_assoc ioctl (CVE-2026-89442)

A flaw was found in the Linux kernel. The isst_if_clos_assoc ioctl function in the platform/x86: ISST module contains an improper validation of the socket_id. This allows a local attacker to cause an out-of-bounds access or a NULL pointer …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-81012Medium· 5.5⚖ disputed
3w ago

kernel: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (CVE-2026-81012)

A flaw was found in the Linux kernel's hp-bioscfg component. The `hp_get_string_from_buffer()` function contains an off-by-one write vulnerability. This occurs because the NUL terminator can be written one byte beyond the allocated buffer,…

▾ SunlitRed Hat · LinuxEPSS 0.14%via CSAF
CVE-2026-89551High· 7.0⚖ disputed
3w ago

kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow (CVE-2026-89551)

A flaw was found in the Linux kernel's SUNRPC subsystem, specifically within the `xdr_buf_trim()` function. This vulnerability occurs when `xdr_buf_trim()` attempts to reduce the size of an XDR buffer. If the buffer's length is smaller tha…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.51%via CSAF
CVE-2026-89550Critical· 9.8
3w ago

SUNRPC: svcauth_gss: enforce krb5 token minimum length

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: enforce krb5 token minimum length svcauth_gss_unwrap_priv() validates only an upper bound on the wire-supplied opaque length before handing the bu…

▾ MidnightLinux · LinuxEPSS 0.46%via CVEORG
CVE-2026-89549High· 7.5
3w ago

sunrpc: route to a populated pool in svc_pool_for_cpu()

In the Linux kernel, the following vulnerability has been resolved: sunrpc: route to a populated pool in svc_pool_for_cpu() svc_set_num_threads() spreads the requested threads evenly across the service's pools (base = nrservs / sv_nrpo…

▾ TwilightLinux · LinuxEPSS 0.71%via CVEORG
CVE-2026-89548High· 7.0
3w ago

kernel: SUNRPC: always drain cache_cleaner before destroying a cache_detail (CVE-2026-89548)

A flaw was found in the Linux kernel's SUNRPC component. When `sunrpc_destroy_cache_detail()` is called, it may not properly drain the `cache_cleaner` before freeing a `cache_detail` object. This oversight can lead to a use-after-free vuln…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89547High· 7.0
3w ago

kernel: SUNRPC: Check svc pool percpu counter allocation (CVE-2026-89547)

A flaw was found in the Linux kernel's SUNRPC component. A local administrator, under specific conditions of memory pressure or fault injection during RPC server startup, can trigger a failure in per-CPU counter allocation. This failure le…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.56%via CSAF
CVE-2026-89542Critical· 9.8
3w ago

SUNRPC: harden gss_krb5_unwrap_v2 against short tokens

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_krb5_unwrap_v2 against short tokens gss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and ptr+6 before validating that the token is a…

▾ MidnightLinux · LinuxEPSS 0.51%via CVEORG
CVE-2026-89541High· 7.0⚖ disputed
3w ago

kernel: SUNRPC: harden gss_unwrap_resp_priv length checks (CVE-2026-89541)

A flaw was found in the Linux kernel. Specifically, an integer overflow vulnerability exists in the `gss_unwrap_resp_priv()` function within the SUNRPC component. This flaw occurs when validating the length of RPCSEC_GSS opaque data. A mal…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.51%via CSAF
CVE-2026-89540High· 7.0
3w ago

kernel: sunrpc: init gssp_lock before publishing proc entry (CVE-2026-89540)

A flaw was found in the Linux kernel's sunrpc component. A race condition exists where the `gssp_lock` mutex is not initialized before its associated `/proc/net/rpc/use-gss-proxy` entry is published. This allows a local attacker to trigger…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89538High· 7.0⚖ disputed
3w ago

kernel: SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field (CVE-2026-89538)

A flaw was found in the Linux kernel's Server Unix Remote Procedure Call (SUNRPC) component. A remote attacker, with a valid Generic Security Service (GSS) context, could send a specially crafted Kerberos v2 wrap token with an oversized "e…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.71%via CSAF
CVE-2026-89536Critical· 9.8
3w ago

SUNRPC: wait for in-flight client TLS handshake callback

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake callback xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the lower transport before submitting the…

▾ MidnightLinux · LinuxEPSS 0.64%via CVEORG
CVE-2026-89533High· 7.0⚖ disputed
3w ago

kernel: svcrdma: Fix offset arithmetic in read_chunk_range (CVE-2026-89533)

A flaw was found in the `svcrdma` component of the Linux kernel. Incorrect offset arithmetic in the `svc_rdma_read_chunk_range()` function can lead to a `u32` underflow. This underflow can cause the system to attempt to allocate a large am…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.50%via CSAF
CVE-2026-89532High· 7.0⚖ disputed
3w ago

kernel: svcrdma: Fix pcl_for_each_segment for empty chunks (CVE-2026-89532)

A flaw was found in the Linux kernel's svcrdma component. A remote attacker could send a specially crafted network packet that causes an integer underflow in the `pcl_for_each_segment` function when processing a chunk with zero segments. T…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.50%via CSAF
CVE-2026-89525Medium· 5.5
3w ago

kernel: udf: reject VAT indexes equal to the entry count (CVE-2026-89525)

A flaw was found in the Linux kernel. A local attacker could craft a malicious Universal Disk Format (UDF) image to trigger an out-of-bounds read vulnerability in the `udf_get_pblock_virt15()` function. This occurs when the system attempts…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89524Medium· 5.5⚖ disputed
3w ago

kernel: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (CVE-2026-89524)

A flaw was found in the ath6kl Wi-Fi driver of the Linux kernel. An integer underflow vulnerability occurs when processing Wi-Fi association requests or responses that are shorter than expected. This can cause the system to read beyond the…

▾ SunlitRed Hat · LinuxEPSS 0.27%via CSAF
CVE-2026-89515Medium· 5.5
3w ago

kernel: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() (CVE-2026-89515)

A flaw was found in the Linux kernel's SCSI core component. When processing data transfers using scatter-gather lists, the system does not properly initialize padding bytes for unaligned data elements. This can result in the exposure of un…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89512Medium· 5.5
3w ago

kernel: remoteproc: scp: Fix device reference leak on failed lookup (CVE-2026-89512)

A flaw was found in the Linux kernel's remoteproc SCP component. This vulnerability involves a device reference leak, where the system fails to properly release a reference to a device during a driver data lookup. This occurs specifically …

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-89511Medium· 5.5⚖ disputed
3w ago

kernel: qede: Fix NULL pointer dereference in TPA fragment processing (CVE-2026-89511)

A flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragm…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.71%via CSAF
CVE-2026-89510High· 7.0
3w ago

kernel: RDMA/cxgb4: Cancel reg_work before freeing device on remove (CVE-2026-89510)

A flaw was found in the Linux kernel's RDMA/cxgb4 component. This vulnerability occurs when the `c4iw_remove()` function frees a device while its registration work (`reg_work`) is still pending or actively running. This timing issue can le…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89508Medium· 5.5⚖ disputed
3w ago

kernel: RDMA/ucma: Lock the handler in ucma_set_ib_path() (CVE-2026-89508)

A flaw was found in the Linux kernel's RDMA/ucma component. A race condition exists in the `ucma_set_ib_path()` function when handling events concurrently with `ucma_migrate_id()`. This can allow a local attacker with access to an RDMA dev…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89504Medium· 5.5⚖ disputed
3w ago

kernel: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (CVE-2026-89504)

A flaw was found in the Linux kernel's regulator subsystem. This vulnerability arises from a programming error where a device tree node pointer is released too early, creating a "dangling pointer"—a reference to memory that is no longer va…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVEs tagged “cve.org” — page 407 · VulnSea