VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20154 CVEsRSS

CVE-2026-89576Medium· 5.5
3w ago

kernel: dm-era: fix shadowed superblock leak on take-snap failure (CVE-2026-89576)

A flaw was found in the Linux kernel's device-mapper era (dm-era) component. When a snapshot operation fails, a block of metadata is allocated but not properly freed. This leads to a permanent leak of system resources with each failed atte…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89575High· 7.0
3w ago

kernel: dm raid1: reserve space for NUL-terminator in build_constructor_string() (CVE-2026-89575)

A flaw was found in the Linux kernel's device mapper (dm-raid1) component. This vulnerability occurs in the `build_constructor_string()` function, where insufficient space is reserved for a NUL-terminator when formatting a string with `spr…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.23%via CSAF
CVE-2026-89573High· 7.8
3w ago

dm array: reject an array block whose value size is not the caller's

In the Linux kernel, the following vulnerability has been resolved: dm array: reject an array block whose value size is not the caller's array_block_check() can only compare the header against itself, so a block with value_size 4 and m…

▾ TwilightLinux · LinuxEPSS 0.13%via CVEORG
CVE-2026-89569High· 7.0
3w ago

kernel: Bluetooth: RFCOMM: serialize security confirmation handling (CVE-2026-89569)

A flaw was found in the Linux kernel's Bluetooth RFCOMM subsystem. This vulnerability arises because the system does not properly manage memory when handling Bluetooth security confirmations. A race condition allows a part of the system to…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.34%via CSAF
CVE-2026-89565Medium· 5.5
3w ago

kernel: ipip: fix skb leak in collect_md mode when metadata_dst allocation fails (CVE-2026-89565)

A flaw was found in the Linux kernel's IP over IP (ipip) tunnel driver. When operating in collect_md mode, the ipip_tunnel_rcv() function fails to free a network packet buffer (skb) if the metadata_dst allocation fails. This oversight lead…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89563High· 7.0
3w ago

kernel: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() (CVE-2026-89563)

A flaw was found in the `ip6_tunnel` module of the Linux kernel. Incorrect handling of socket buffers (skb) during headroom reallocation in the `ip6_tnl_xmit()` function can lead to a double-free vulnerability. This occurs when an error pa…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVE-2026-89562High· 7.8
3w ago

ip6_gre: fix hardware header length for NBMA tunnels

In the Linux kernel, the following vulnerability has been resolved: ip6_gre: fix hardware header length for NBMA tunnels ip6gre_tnl_link_config_route() accumulates the lower device's hardware header length into dev->hard_header_len whe…

▾ TwilightLinux · LinuxEPSS 0.13%via CVEORG
CVE-2026-89560High· 8.4
3w ago

In the Linux kernel, the following vulnerability has been resolved: landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation Whiteout objects are used in the upper layer of an OverlayFS to indicate that the file with this na…

In the Linux kernel, the following vulnerability has been resolved: landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation Whiteout objects are used in the upper layer of an OverlayFS to indicate that the file with this na…

▾ TwilightLinux · LinuxEPSS 0.13%via NVD
CVE-2026-89559High· 7.0
3w ago

kernel: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() (CVE-2026-89559)

A flaw was found in the Linux kernel's `libnvdimm/labels` component. An integer overflow vulnerability exists in the `__nd_label_validate()` function, where a 32-bit calculation of a namespace index field (`nslot`) can wrap around. This al…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89557High· 7.8
3w ago

md: do overflow check for sb->bblog_shift in super_1_load()

In the Linux kernel, the following vulnerability has been resolved: md: do overflow check for sb->bblog_shift in super_1_load() In super_1_load(), sb->bblog_shift is an __u8 type value loaded from on- disk superblock. It is used for ba…

▾ TwilightLinux · LinuxEPSS 0.17%via CVEORG
CVE-2026-89555Critical· 9.8
3w ago

mpls: reload header after pskb_may_pull()

In the Linux kernel, the following vulnerability has been resolved: mpls: reload header after pskb_may_pull() mpls_select_multipath() calls mpls_multipath_hash() to choose a nexthop when an MPLS route has multiple nexthops. While walk…

▾ MidnightLinux · LinuxEPSS 0.69%via CVEORG
CVE-2026-89554Medium· 5.5⚖ disputed
3w ago

kernel: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction (CVE-2026-89554)

A flaw was found in the Linux kernel's Multipath TCP (MPTCP) implementation. When reconstructing a Multipath TCP (MPTCP) join request under SYN cookies, the `local_id` field is not properly initialized. An off-path attacker can influence t…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.60%via CSAF
CVE-2026-89553High· 7.0
3w ago

kernel: nouveau/gem: reserve the bo in the info ioctl around the vma lookup (CVE-2026-89553)

A flaw was found in the Linux kernel's nouveau/gem component. A race condition exists where the graphics execution manager (GEM) close path can close a virtual memory area (VMA) while an information lookup is still trying to access it. Thi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89684High· 7.0
3w ago

kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state (CVE-2026-89684)

A flaw was found in the Linux kernel's nfsd component. A remote attacker, by sending a specially crafted OFFLOAD_CANCEL request, could exploit a race condition during the initialization of copy state notifications. This could lead to a den…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.50%via CSAF
CVE-2026-89674Medium· 5.5⚖ disputed
3w ago

kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget (CVE-2026-89674)

A flaw was found in the `nfsd` component of the Linux kernel. Incorrect calculations in the XDR (External Data Representation) buffer size within the `nfsd4_ff_encode_layoutget()` function can lead to two critical issues. An attacker could…

▾ SunlitRed Hat · LinuxEPSS 0.51%via CSAF
CVE-2026-89673Medium· 5.5
3w ago

kernel: nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo (CVE-2026-89673)

A flaw was found in the Linux kernel's NFS daemon (nfsd). A remote attacker could exploit an error in the XDR (External Data Representation) padding calculation within the `ff_encode_getdeviceinfo` function. This mismatch between reserved …

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89672High· 7.0⚖ disputed
3w ago

kernel: nfsd: gate nfs2 setacl by argp->mask (CVE-2026-89672)

A flaw was found in the Linux kernel's Network File System (NFS) server daemon (`nfsd`). When processing NFSACL version 2 SETACL requests, the system could unintentionally remove a directory's default Access Control List (ACL) or both acce…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.52%via CSAF
CVE-2026-89671High· 7.0⚖ disputed
3w ago

kernel: nfsd: gate nfs3 setacl by argp->mask (CVE-2026-89671)

A flaw was found in the Linux kernel's Network File System version 3 (NFSv3) server daemon (`nfsd`). The `nfsd3_proc_setacl()` function unconditionally processes Access Control List (ACL) update requests, even when the client's request doe…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.50%via CSAF
CVE-2026-89669High· 7.0⚖ disputed
3w ago

kernel: nfsd: initialize copy-notify stateid before publishing it (CVE-2026-89669)

A flaw was found in the `nfsd` component of the Linux kernel. A use-after-free vulnerability exists due to improper initialization of the copy-notify state ID before its publication. A remote attacker could exploit this by sending a crafte…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.69%via CSAF
CVE-2026-89665High· 7.0
3w ago

kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE (CVE-2026-89665)

A flaw was found in the Linux kernel's nfsd component. A remote attacker could exploit this vulnerability by sending a specially crafted NFSv2 SETATTR or CREATE request with an out-of-range 'useconds' value. This could lead to incorrect ti…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.62%via CSAF
CVE-2026-89663High· 7.0
3w ago

kernel: nfsd: revoke copy-notify stateids before dropping their reference (CVE-2026-89663)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). This vulnerability arises from improper handling of "copy-notify stateids" during their revocation. When a stateid's reference is dropped without unlinking it, the m…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.46%via CSAF
CVE-2026-89662High· 7.0⚖ disputed
3w ago

kernel: NFSD: Prevent lock owner use-after-free during client teardown (CVE-2026-89662)

A flaw was found in the Linux kernel's Network File System Daemon (NFSD). During client teardown, a race condition can occur where a lock owner is freed while still being referenced, leading to a use-after-free vulnerability. This can resu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.69%via CSAF
CVE-2026-89657High· 7.0
3w ago

kernel: libceph: validate OSD extent maps before cursor advance (CVE-2026-89657)

A flaw was found in libceph in the Linux kernel. A malicious or compromised authenticated Ceph Object Storage Device (OSD) peer could send a specially crafted sparse-read reply that lacks proper validation of extent maps. This could cause …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.61%via CSAF
CVE-2026-89656High· 8.8⚖ disputed
3w ago

kernel: libceph: reject buckets with mismatched CRUSH ids (CVE-2026-89656)

A flaw was found in libceph within the Linux kernel. This vulnerability allows a local attacker to craft a malformed CRUSH map, which is used for data placement. By doing so, one data bucket can be made to reuse another bucket's memory wor…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.51%via CSAF
CVE-2026-89655High· 7.0⚖ disputed
3w ago

kernel: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock (CVE-2026-89655)

A flaw was found in the Linux kernel's Ceph file system component. A race condition exists in the `__kick_flushing_caps()` function during the handling of capability messages. This allows a separate process to free a data structure (`cf en…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.71%via CSAF
CVE-2026-89653High· 8.1
3w ago

kernel: kernel: Memory corruption via out-of-bounds write in Ceph client (CVE-2026-89653)

A flaw was found in the Linux kernel's Ceph file system client. When decoding metadata server maps (MDSMap), the client fails to properly validate rank identifiers within export targets against protocol limits. A malicious or compromised C…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.50%via CSAF
CVE-2026-89652High· 7.0⚖ disputed
3w ago

kernel: ceph: bound copied dentry name length in NFS export get_name (CVE-2026-89652)

A flaw was found in the Linux kernel's Ceph file system. A malicious or compromised Ceph Metadata Server (MDS) can send a specially crafted `LOOKUPNAME` reply that causes a buffer overflow when copying dentry names during an NFS export ope…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.46%via CSAF
CVE-2026-89650High· 7.0⚖ disputed
3w ago

kernel: ceph: bound num_export_targets array for mds info v2/v3 (CVE-2026-89650)

A flaw was found in the Linux kernel's Ceph client. A malicious or compromised Ceph monitor, or an on-path attacker, can send a specially crafted Metadata Server (MDS) map. This map, with an oversized num_export_targets field and a per-MDS…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.50%via CSAF
CVE-2026-89649High· 7.0⚖ disputed
3w ago

kernel: ceph: bound xattr value length in __build_xattrs() (CVE-2026-89649)

A flaw was found in the Linux kernel's Ceph file system (CephFS) component. A malicious or compromised metadata server can manipulate the length of an extended attribute (xattr) value, causing the system to read beyond the intended memory …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.68%via CSAF
CVE-2026-89643Critical· 9.8
3w ago

audit: avoid dropping live tree ref on fsnotify rule autoremove

In the Linux kernel, the following vulnerability has been resolved: audit: avoid dropping live tree ref on fsnotify rule autoremove audit_del_rule() is used for both netlink deletion templates and internal fsnotify autoremove. The for…

▾ MidnightLinux · LinuxEPSS 0.71%via CVEORG
CVEs tagged “cve.org” — page 409 · VulnSea