Tagged “vex”
CVEs tagged vex, newest first.
2956 CVEsRSS
CVE-2026-89540High· 7.0kernel: sunrpc: init gssp_lock before publishing proc entry (CVE-2026-89540)
A flaw was found in the Linux kernel's sunrpc component. A race condition exists where the `gssp_lock` mutex is not initialized before its associated `/proc/net/rpc/use-gss-proxy` entry is published. This allows a local attacker to trigger…
CVE-2026-89538High· 7.0⚖ disputedkernel: SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field (CVE-2026-89538)
A flaw was found in the Linux kernel's Server Unix Remote Procedure Call (SUNRPC) component. A remote attacker, with a valid Generic Security Service (GSS) context, could send a specially crafted Kerberos v2 wrap token with an oversized "e…
CVE-2026-89533High· 7.0⚖ disputedkernel: svcrdma: Fix offset arithmetic in read_chunk_range (CVE-2026-89533)
A flaw was found in the `svcrdma` component of the Linux kernel. Incorrect offset arithmetic in the `svc_rdma_read_chunk_range()` function can lead to a `u32` underflow. This underflow can cause the system to attempt to allocate a large am…
CVE-2026-89532High· 7.0⚖ disputedkernel: svcrdma: Fix pcl_for_each_segment for empty chunks (CVE-2026-89532)
A flaw was found in the Linux kernel's svcrdma component. A remote attacker could send a specially crafted network packet that causes an integer underflow in the `pcl_for_each_segment` function when processing a chunk with zero segments. T…
CVE-2026-89525Medium· 5.5kernel: udf: reject VAT indexes equal to the entry count (CVE-2026-89525)
A flaw was found in the Linux kernel. A local attacker could craft a malicious Universal Disk Format (UDF) image to trigger an out-of-bounds read vulnerability in the `udf_get_pblock_virt15()` function. This occurs when the system attempts…
CVE-2026-89524Medium· 5.5⚖ disputedkernel: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (CVE-2026-89524)
A flaw was found in the ath6kl Wi-Fi driver of the Linux kernel. An integer underflow vulnerability occurs when processing Wi-Fi association requests or responses that are shorter than expected. This can cause the system to read beyond the…
CVE-2026-89515Medium· 5.5kernel: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() (CVE-2026-89515)
A flaw was found in the Linux kernel's SCSI core component. When processing data transfers using scatter-gather lists, the system does not properly initialize padding bytes for unaligned data elements. This can result in the exposure of un…
CVE-2026-89512Medium· 5.5kernel: remoteproc: scp: Fix device reference leak on failed lookup (CVE-2026-89512)
A flaw was found in the Linux kernel's remoteproc SCP component. This vulnerability involves a device reference leak, where the system fails to properly release a reference to a device during a driver data lookup. This occurs specifically …
CVE-2026-89511Medium· 5.5⚖ disputedkernel: qede: Fix NULL pointer dereference in TPA fragment processing (CVE-2026-89511)
A flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragm…
CVE-2026-89510High· 7.0kernel: RDMA/cxgb4: Cancel reg_work before freeing device on remove (CVE-2026-89510)
A flaw was found in the Linux kernel's RDMA/cxgb4 component. This vulnerability occurs when the `c4iw_remove()` function frees a device while its registration work (`reg_work`) is still pending or actively running. This timing issue can le…
CVE-2026-89508Medium· 5.5⚖ disputedkernel: RDMA/ucma: Lock the handler in ucma_set_ib_path() (CVE-2026-89508)
A flaw was found in the Linux kernel's RDMA/ucma component. A race condition exists in the `ucma_set_ib_path()` function when handling events concurrently with `ucma_migrate_id()`. This can allow a local attacker with access to an RDMA dev…
CVE-2026-89504Medium· 5.5⚖ disputedkernel: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (CVE-2026-89504)
A flaw was found in the Linux kernel's regulator subsystem. This vulnerability arises from a programming error where a device tree node pointer is released too early, creating a "dangling pointer"—a reference to memory that is no longer va…
CVE-2026-89498Medium· 5.5kernel: orangefs: fix double-free of trailer_buf on readdir copy failure (CVE-2026-89498)
A flaw was found in OrangeFS within the Linux kernel. A local client, by sending a specially crafted readdir downcall with a declared trailer_size exceeding the actual supplied bytes, can trigger a double-free vulnerability. This memory co…
CVE-2026-89496Medium· 5.5kernel: ocfs2: always run deallocs on copy-on-write completion (CVE-2026-89496)
A flaw was found in ocfs2, the Oracle Cluster File System, within the Linux kernel. A local user could exploit this vulnerability by performing a `copy_file_range()` operation within the same filesystem. This can lead to a memory leak, pot…
CVE-2026-89495Medium· 5.5⚖ disputedkernel: ocfs2: bound namelen in dlm_migrate_request_handler (CVE-2026-89495)
A flaw was found in ocfs2 in the Linux kernel. A malicious or compromised node within a Distributed Lock Manager (DLM) cluster can send specially crafted messages with unchecked length fields. This can lead to a heap out-of-bounds write, p…
CVE-2026-89493Medium· 5.5⚖ disputedkernel: ocfs2: validate rl_used against rl_count in refcount block validator (CVE-2026-89493)
A flaw was found in the Linux kernel's ocfs2 component. A local attacker with CAP_SYS_ADMIN privileges could exploit this by mounting a crafted or corrupted ocfs2 image, or by performing a raw write to the block device backing an already-m…
CVE-2026-89491Medium· 5.5kernel: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() (CVE-2026-89491)
A flaw was found in the Linux kernel's ocfs2 cluster module. This vulnerability allows a local attacker to trigger a denial of service. The issue arises when a sleeping function is called while a spinlock is held within the o2hb_region_pin…
CVE-2026-89489Medium· 5.5⚖ disputedkernel: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall (CVE-2026-89489)
A flaw was found in the Linux kernel. The `sys_or1k_atomic()` syscall, specific to the openrisc architecture, does not adequately validate user-provided pointers. An unprivileged process can exploit this by supplying kernel addresses to th…
CVE-2026-89488High· 7.0kernel: openvswitch: Fix CT limit teardown use-after-free (CVE-2026-89488)
A flaw was found in the Linux kernel's Open vSwitch (OVS) component. An unprivileged user, operating from a user and network namespace, can trigger a use-after-free vulnerability during network namespace teardown. This occurs because packe…
CVE-2026-89487High· 7.0kernel: openvswitch: only skb_tx_error() a packet we are about to drop (CVE-2026-89487)
A flaw was found in openvswitch in the Linux kernel. This vulnerability occurs when the `queue_userspace_packet()` function incorrectly modifies a shared network packet buffer by stripping a critical flag. This action can lead to an unpriv…
CVE-2026-89485High· 7.0⚖ disputedkernel: lockd: pin next file across nlm_inspect_file lock-drop (CVE-2026-89485)
A flaw was found in the `lockd` component of the Linux kernel. This use-after-free vulnerability occurs in the `nlm_traverse_files()` function when a file's memory is prematurely released while an iterator still holds a pointer to it. A re…
CVE-2026-89483Medium· 5.5⚖ disputedkernel: nvme: zero the discard fallback page (CVE-2026-89483)
A flaw was found in the Linux kernel's Non-Volatile Memory Express (NVMe) subsystem. Under specific memory pressure conditions, a local user could trigger a scenario where uninitialized kernel memory is used and potentially exposed. This c…
CVE-2026-89607High· 7.0kernel: ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet (CVE-2026-89607)
A flaw was found in ecryptfs in the Linux kernel. The parse_tag_3_packet() function does not properly validate the size of the encrypted key, allowing an oversized key to be processed. This improper validation leads to out-of-bounds writes…
CVE-2026-89606High· 7.0kernel: ecryptfs: reject too-small tag 70 packets (CVE-2026-89606)
A flaw was found in ecryptfs, a component of the Linux kernel. This vulnerability allows a remote attacker to send a specially crafted tag 70 packet with a body smaller than expected. This can lead to an integer underflow during size calcu…
CVE-2026-89605Medium· 5.5⚖ disputedkernel: ecryptfs: release message context on send failure (CVE-2026-89605)
A flaw was found in the `ecryptfs` component of the Linux kernel. When the `ecryptfs_send_miscdev()` function fails to send a message to the userspace daemon, the associated message context is not properly released. This oversight leaves t…
CVE-2026-89604Medium· 5.5kernel: efivarfs: Rate limit statfs() handler (CVE-2026-89604)
A flaw was found in the Linux kernel's efivarfs component. An unprivileged local user can exploit this by repeatedly calling the `statfs()` handler on the `efivarfs` mount point. This action triggers a flood of calls to the `QueryVariableI…
CVE-2026-89603High· 7.8kernel: entry: Fix seccomp bypass after ptrace with TSYNC (CVE-2026-89603)
A flaw was found in the Linux kernel. A race condition exists where a seccomp filter, intended to restrict system calls, can be bypassed by an unprivileged process. This occurs when a thread is stopped for tracing (ptrace) and another thre…
CVE-2026-89599Medium· 5.5⚖ disputedkernel: fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (CVE-2026-89599)
A flaw was found in the Linux kernel's `fbdev: omapfb: panel-dsi-cm` component. The `dsicm_probe()` function registers a display before its associated lock (mutex) is properly initialized. This timing issue allows another process to attemp…
CVE-2026-89598Medium· 5.5kernel: fbdev: ssd1307fb: defer I2C transfers from damage callbacks (CVE-2026-89598)
A flaw was found in the Linux kernel's fbdev (framebuffer device) subsystem, specifically within the ssd1307fb driver. This vulnerability occurs when display damage callbacks, which handle updates to the display, perform synchronous I2C (I…
CVE-2026-89597Medium· 5.5⚖ disputedkernel: fbdev: uvesafb: unregister connector callback on init failure (CVE-2026-89597)
A flaw was found in the `uvesafb` component of the Linux kernel. During the initialization process, if the platform driver fails to register, a connector callback is not properly unregistered. This oversight can lead to a resource leak, wh…