VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-89755High· 7.8
2w ago

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeing swapcache __migrate_device_pages() reads the folio mapping before calling folio_free_swap()

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeing swapcache __migrate_device_pages() reads the folio mapping before calling folio_free_swap(). When folio_free_swap…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89754High· 7.0
2w ago

kernel: mm/pagewalk: fix stale walk->action escaping walk_pmd_range() (CVE-2026-89754)

A flaw was found in the Linux kernel's memory management (mm/pagewalk) component. An issue in the `walk_pmd_range()` function, where a stale `walk->action` state is not properly reset, can lead to duplicate walk callbacks. A local attacker…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.17%via CSAF
CVE-2026-89748Medium· 5.5
2w ago

kernel: tracing: Fix retry exhaustion in simple ring buffer reader swap (CVE-2026-89748)

A flaw was found in the Linux kernel's tracing subsystem. An issue in the `simple_ring_buffer_swap_reader_page()` function, related to retry exhaustion during ring buffer reader page swaps, can lead to incorrect handling of successful or f…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-89747High· 7.0⚖ disputed
2w ago

kernel: tracing: Fix use-after-free in trace_pipe read on sub-buffer order change (CVE-2026-89747)

A flaw was found in the Linux kernel's tracing component. A local attacker could exploit a use-after-free vulnerability, a type of memory corruption, by manipulating the `trace_pipe` functionality. This occurs when the system attempts to r…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.17%via CSAF
CVE-2026-89743Medium· 5.5
2w ago

kernel: misc: nsm: bound the device-reported response length (CVE-2026-89743)

A flaw was found in the Linux kernel's Network Shared Memory (NSM) component. A malicious or buggy backend can report a response length larger than the allocated buffer. This can lead to an out-of-bounds read, disclosing adjacent kernel me…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.19%via CSAF
CVE-2026-89738Medium· 5.5⚖ disputed
2w ago

kernel: usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed (CVE-2026-89738)

A flaw was found in the Linux kernel's `at91_udc` USB gadget driver. In polled-VBUS mode, a timing issue during driver unbinding or probe failure can lead to a use-after-free vulnerability. A local attacker could exploit this by triggering…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.18%via CSAF
CVE-2026-89731High· 7.1
2w ago

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using…

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89713High· 7.0⚖ disputed
2w ago

kernel: NFSD: check truncate permission under inode lock (CVE-2026-89713)

A flaw was found in the Linux kernel's Network File System Daemon (NFSD). A remote attacker, by sending a crafted file attribute modification request (SETATTR) while a file is being concurrently appended, could exploit a time-of-check to t…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.65%via CSAF
CVE-2026-89709High· 7.0⚖ disputed
2w ago

kernel: lockd, nfsd: RCU-protect nlmsvc_ops dispatch (CVE-2026-89709)

A flaw was found in the Linux kernel's lockd and nfsd components. An unguarded dereference of nlmsvc_ops after the nfsd module is removed can lead to a NULL pointer dereference or a use-after-free condition. This vulnerability could allow …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.45%via CSAF
CVE-2026-89708Critical· 9.8⚖ disputed
2w ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still h…

In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still h…

▾ MidnightLinux · LinuxEPSS 0.65%via NVD
CVE-2026-89705High· 7.0
2w ago

kernel: nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths (CVE-2026-89705)

A flaw was found in the Linux kernel's Network File System (NFS) daemon, nfsd. This vulnerability occurs due to a synchronization issue where a status counter (rq_status_counter) is not correctly reset on all exit paths within the nfsd_dis…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.16%via CSAF
CVE-2026-89703High· 7.0⚖ disputed
2w ago

kernel: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations (CVE-2026-89703)

A flaw was found in the `nfsd` component of the Linux kernel. The `nfsd4_drop_revoked_stid()` function, which handles admin-revoked delegations, fails to correctly set a status flag before releasing a lock. This oversight can lead to a use…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.65%via CSAF
CVE-2026-89702High· 7.0⚖ disputed
2w ago

kernel: nfsd: size fh_verify server sockaddr slot by xpt_locallen (CVE-2026-89702)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). When processing NFSv2/v3-over-UDP requests, the `nfsd_fh_verify` and `nfsd_fh_verify_err` tracepoints incorrectly size a memory buffer. This can lead to an out-of-bo…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.67%via CSAF
CVE-2026-89695High· 7.0⚖ disputed
2w ago

kernel: nfsd: cap decoded POSIX ACL count to bound sort cost (CVE-2026-89695)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). The `nfsd4_decode_posixacl()` function, responsible for decoding POSIX Access Control Lists (ACLs), does not properly cap the entry count received from a client. A r…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-89687Medium· 5.5
2w ago

kernel: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file (CVE-2026-89687)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). The `nfsd_file_do_acquire()` function might attempt to use a file that has not been fully opened, as the `->atomic_open` operation could return success prematurely. …

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
CVE-2026-80932Medium· 5.5⚖ disputed
2w ago

kernel: vsock/virtio: flush works in dependency order (CVE-2026-80932)

A flaw was found in the Linux kernel, specifically within the `vsock/virtio` component. An incorrect order of flushing work items during the removal of a `virtio_vsock` object can lead to a use-after-free condition. This vulnerability allo…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.19%via CSAF
CVE-2026-80979High· 7.0
2w ago

kernel: net/smc: unregister the connection before draining the rx tasklet (CVE-2026-80979)

A flaw was found in the Linux kernel's Shared Memory Communications (SMC) component. During connection termination, the SMC component may fail to properly unregister a connection before draining its receive tasklet. This can lead to a use-…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-80977High· 7.0
2w ago

kernel: net: skbuff: don't touch shared zerocopy state in skb_tx_error() (CVE-2026-80977)

A flaw was found in the Linux kernel's networking subsystem. The `skb_tx_error()` function improperly handles shared zerocopy state in socket buffers (skbs). When a cloned skb is processed, it can prematurely signal that its pages are free…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-80976High· 7.0⚖ disputed
2w ago

kernel: seg6: reset IP6CB after IPv6 decapsulation (CVE-2026-80976)

A flaw was found in the Linux kernel's IPv6 Segment Routing (seg6) implementation. An unprivileged user can exploit this vulnerability by injecting a specially crafted IPv6 packet. This can lead to an out-of-bounds read, potentially causin…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-80973High· 7.0
2w ago

kernel: ALSA: 6fire: bound the MIDI event length from the device (CVE-2026-80973)

A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the 6fire driver. This vulnerability allows a malicious USB device to trigger an out-of-bounds read by sending a specially craft…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-80972Medium· 5.5
2w ago

kernel: ALSA: aloop: Check card index validity at probe (CVE-2026-80972)

A flaw was found in the ALSA (Advanced Linux Sound Architecture) aloop driver within the Linux kernel. This vulnerability arises from insufficient validation of the card index during device setup, specifically when a device is manually con…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80971High· 7.0
2w ago

kernel: ALSA: bcd2000: clear the URB pointers on disconnect (CVE-2026-80971)

A flaw was found in the ALSA bcd2000 driver of the Linux kernel. When a USB device using this driver is disconnected while a rawmidi substream is still active, the driver fails to clear the Universal Serial Bus Request Block (URB) pointers…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-80970High· 7.0
2w ago

kernel: ALSA: FCP: do not copy out an uninitialised init response (CVE-2026-80970)

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) FireWire Control Protocol (FCP) subsystem. This vulnerability allows a local attacker to trigger the copying of uninitialized kernel memory to userspace. By se…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80969Medium· 5.5
2w ago

kernel: ALSA: mpu401: Check card index validity at probe (CVE-2026-80969)

A flaw was found in the Linux kernel's ALSA mpu401 driver. The driver fails to validate the card index when a device is manually bound through the sysfs interface. This oversight can lead to an out-of-bounds memory access. A local attacker…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-80968Medium· 5.5
2w ago

kernel: ALSA: mts64: Check card index validity at probe (CVE-2026-80968)

A flaw was found in the ALSA mts64 driver within the Linux kernel. This driver does not properly validate the card index, specifically failing to check for negative ID values when bound via sysfs. A local attacker could exploit this vulner…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-80967Medium· 5.5⚖ disputed
2w ago

kernel: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (CVE-2026-80967)

A flaw was found in the ALSA pcxhr driver within the Linux kernel. The `pcxhr_probe()` function requests a threaded interrupt before properly initializing a critical mutex (`mgr->lock`). This oversight could allow an early interrupt to ope…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-80966Medium· 5.5
2w ago

kernel: ALSA: portman2x4: Check card index validity at probe (CVE-2026-80966)

A flaw was found in the ALSA portman2x4 driver of the Linux kernel. This vulnerability occurs because the driver does not properly validate the card index, specifically failing to check for negative ID values. A local attacker could exploi…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-80965Medium· 5.5
2w ago

kernel: ALSA: serial-u16550: Check card index validity at probe (CVE-2026-80965)

A flaw was found in the Linux kernel's ALSA serial-u16550 driver. This vulnerability occurs because the driver does not properly validate the card index when a device is manually bound via the sysfs interface. A local user could exploit th…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-80963Medium· 5.5
2w ago

kernel: dm-stats: fix a crash if allocation of per-cpu data fails (CVE-2026-80963)

A flaw was found in the Linux kernel's `dm-stats` module. This vulnerability occurs when the allocation of per-CPU data fails, which can lead to a null pointer dereference during the subsequent cleanup operation. This issue can cause the s…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-80952High· 7.0
2w ago

kernel: i3c: master: Fix info leak and UAF in device unregister path (CVE-2026-80952)

A flaw was found in the Linux kernel's i3c master component. During device unregistration, a race condition can occur where the device descriptor is prematurely cleared. This can lead to an information leak, exposing kernel stack contents …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVEs tagged “red-hat” — page 30 · VulnSea