Tagged “vex”
CVEs tagged vex, newest first.
2956 CVEsRSS
CVE-2026-89652High· 7.0⚖ disputedkernel: ceph: bound copied dentry name length in NFS export get_name (CVE-2026-89652)
A flaw was found in the Linux kernel's Ceph file system. A malicious or compromised Ceph Metadata Server (MDS) can send a specially crafted `LOOKUPNAME` reply that causes a buffer overflow when copying dentry names during an NFS export ope…
CVE-2026-89650High· 7.0⚖ disputedkernel: ceph: bound num_export_targets array for mds info v2/v3 (CVE-2026-89650)
A flaw was found in the Linux kernel's Ceph client. A malicious or compromised Ceph monitor, or an on-path attacker, can send a specially crafted Metadata Server (MDS) map. This map, with an oversized num_export_targets field and a per-MDS…
CVE-2026-89649High· 7.0⚖ disputedkernel: ceph: bound xattr value length in __build_xattrs() (CVE-2026-89649)
A flaw was found in the Linux kernel's Ceph file system (CephFS) component. A malicious or compromised metadata server can manipulate the length of an extended attribute (xattr) value, causing the system to read beyond the intended memory …
CVE-2026-89640Medium· 5.5kernel: cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 (CVE-2026-89640)
A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When performing a file range remapping operation with a zero length, an integer underflow can occur if the offset exceeds the file size. This can lea…
CVE-2026-89636High· 7.0⚖ disputedkernel: smb: client: clear ce->tgthint in free_tgts() (CVE-2026-89636)
A flaw was found in the Linux kernel's Server Message Block (SMB) client. When the `free_tgts()` function frees data structures, a pointer (`ce->tgthint`) is not properly reset, leaving it pointing to a memory location that has already bee…
CVE-2026-89634High· 7.0⚖ disputedkernel: smb: client: fix ALIGN() overflow in symlink_data() error context loop (CVE-2026-89634)
A flaw was found in the Server Message Block (SMB) client within the Linux kernel. An integer overflow in the ALIGN() function, specifically within the symlink_data() error context loop, can lead to an out-of-bounds read. This issue allows…
CVE-2026-89628Medium· 5.5kernel: HID: picolcd: clamp eeprom debugfs read to bytes actually received (CVE-2026-89628)
A flaw was found in the Human Interface Device (HID) picolcd driver in the Linux kernel. A local attacker with root privileges, by using a specially crafted or spoofed picoLCD device, could exploit an out-of-bounds read vulnerability in th…
CVE-2026-89627Medium· 5.5kernel: HID: roccat: free buffered reports when destroying device (CVE-2026-89627)
A flaw was found in the Linux kernel's HID (Human Interface Device) roccat driver. When a roccat device is destroyed, the driver fails to properly free buffered reports, leading to a memory leak. A local attacker could potentially exploit …
CVE-2026-89626High· 7.0kernel: HID: sensor: custom: Fix field sysfs group cleanup on failure (CVE-2026-89626)
A flaw was found in the Linux kernel's Human Interface Device (HID) sensor custom driver. When creating sysfs groups for custom sensor fields, the `hid_sensor_custom_add_attributes()` function fails to properly clean up previously created …
CVE-2026-89623Medium· 5.5kernel: HID: mcp2221: stop device IO before hid_hw_stop (CVE-2026-89623)
A flaw was found in the Linux kernel's HID (Human Interface Device) mcp2221 driver. This vulnerability occurs when the device's input/output (IO) operations are not properly stopped before hardware teardown during device removal or probe f…
CVE-2026-89621Medium· 5.5kernel: HID: mcp2221: validate report size in mcp2221_raw_event() (CVE-2026-89621)
A flaw was found in the Linux kernel's HID (Human Interface Device) mcp2221 driver. A malicious USB device can exploit this vulnerability by sending a specially crafted, short HID report with an invalid size. This can cause the system to r…
CVE-2026-89618Medium· 5.5kernel: eventfs: Initialize ei->children and ei->list in init_ei() (CVE-2026-89618)
A flaw was found in the Linux kernel's eventfs component. When the `eventfs_create_dir()` function fails due to memory pressure, an uninitialized internal data structure can cause the system to issue a misleading warning during the cleanup…
CVE-2026-89617Medium· 5.5⚖ disputedkernel: fs/ntfs3: validate dirty page table on log replay (CVE-2026-89617)
A flaw was found in the Linux kernel's NTFS3 filesystem driver. An attacker with local access could craft a malicious NTFS log file. During log replay, insufficient validation of the `lcns_follow` field in a `DIR_PAGE_ENTRY` could lead to …
CVE-2026-89616Medium· 5.5⚖ disputedkernel: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() (CVE-2026-89616)
A flaw was found in the Linux kernel's NTFS3 filesystem driver. When decompressing LZNT data, the `ni_read_frame()` function may not fully zero out memory after a partial decompression. This can lead to the disclosure of previously used ke…
CVE-2026-89615Medium· 5.5⚖ disputedkernel: fs/ntfs3: bound page_lcns[] index by the log record (CVE-2026-89615)
A flaw was found in the Linux kernel's NTFS3 file system driver. A local attacker could exploit this by providing a specially crafted log record. This crafted record causes a buffer overflow in the page_lcns[] array, leading to memory corr…
CVE-2026-89609High· 7.0kernel: ecryptfs: hold msg ctx list lock when cleaning daemon queue (CVE-2026-89609)
A flaw was found in the eCryptfs component of the Linux kernel. A race condition occurs during the cleanup of the daemon message queue because a required lock is not held. This can lead to unpredictable system behavior or instability due t…
CVE-2026-89608Medium· 5.5kernel: ecryptfs: pass packet set buffer size to parser (CVE-2026-89608)
A flaw was found in the `ecryptfs` component of the Linux kernel. The `ecryptfs_parse_packet_set()` function incorrectly calculates the available buffer size when processing version 1 headers, leading to an overstatement of the buffer's ac…
CVE-2026-89746High· 7.0kernel: tracing: Fix use-after-free with same-name named triggers (CVE-2026-89746)
A flaw was found in the Linux kernel's tracing component. A local user can exploit a use-after-free vulnerability by registering multiple histogram triggers with the same name. This action causes the kernel to attempt to access freed memor…
CVE-2026-89744Medium· 5.5⚖ disputedkernel: device property: fix infinite loop in fwnode_for_each_child_node() (CVE-2026-89744)
A flaw was found in the Linux kernel's device property handling. When the kernel iterates over child nodes of a firmware node (fwnode) that also has a secondary fwnode, the `fwnode_get_next_child_node()` function can enter an endless loop.…
CVE-2026-89742Medium· 5.5⚖ disputedkernel: rapidio: mport_cdev: fix use-after-free in dma_req_free() (CVE-2026-89742)
A flaw was found in the Linux kernel. A local user could exploit a use-after-free vulnerability in the `dma_req_free()` function within the RapidIO mport character device interface. This flaw occurs when the `dma_req_free()` function attem…
CVE-2026-89741High· 7.0kernel: Revert "media: v4l2-dev: fix error handling in __video_register_device()" (CVE-2026-89741)
A flaw was found in the Linux kernel's media subsystem, specifically within the v4l2-dev component. This vulnerability arises from incorrect error handling in the `__video_register_device()` function. If a device registration fails, the sy…
CVE-2026-89736Medium· 5.5⚖ disputedkernel: usb: gadget: u_audio: Fix use-after-free on sound card disconnect (CVE-2026-89736)
A flaw was found in the Linux kernel's USB audio gadget driver (u_audio). This vulnerability occurs during sound card disconnection when Asynchronous Linux Sound Architecture (ALSA) control elements (kctls) remain open in userspace. A loca…
CVE-2026-89735Medium· 5.5kernel: usb: gadget: midi2: remove default configfs groups on teardown (CVE-2026-89735)
A flaw was found in the Linux kernel's USB gadget MIDI2 driver. The driver fails to properly remove default configuration file system (configfs) groups during teardown, leading to a resource leak. A local attacker could exploit this vulner…
CVE-2026-89733Medium· 5.5⚖ disputedkernel: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (CVE-2026-89733)
A flaw was found in the Linux kernel's USB Video Class (UVC) gadget driver. This vulnerability occurs in the `uvc_function_bind()` and `uvc_function_unbind()` functions, where pointers to freed memory are not properly cleared. This can lea…
CVE-2026-89732Medium· 5.5kernel: usb: gadget: f_fs: Prevent deadlock during ep0 read loop (CVE-2026-89732)
A flaw was found in the Linux kernel's USB FunctionFS (f_fs) module. A local attacker could exploit a deadlock vulnerability in the ffs_ep0_read() function. This occurs when a userspace daemon polls ep0 and the USB gadget is simultaneously…
CVE-2026-89730Medium· 5.5kernel: fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (CVE-2026-89730)
A flaw was found in the `altera-cvp` FPGA driver within the Linux kernel. The `altera_cvp_send_block()` function can perform an out-of-bounds read when processing the trailing bytes of an input buffer. This occurs if the buffer ends at a p…
CVE-2026-89729High· 7.0kernel: HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (CVE-2026-89729)
A flaw was found in the Linux kernel's Human Interface Device (HID) sensor-hub driver. A local attacker could exploit this vulnerability by providing a specially crafted HID descriptor. This malicious descriptor could cause the `sensor_hub…
CVE-2026-89726Medium· 5.5kernel: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (CVE-2026-89726)
A flaw was found in the Linux kernel's `ucs2_strnlen()` function. This vulnerability occurs because the function checks the current character before verifying if the maximum allowed length has been reached. If the input string is not prope…
CVE-2026-89725Medium· 5.5⚖ disputedkernel: media: cec: stm32: prevent out-of-bounds write on RX overflow (CVE-2026-89725)
A flaw was found in the Linux kernel's `media: cec: stm32` driver. A remote attacker can exploit an out-of-bounds write vulnerability by sending an overlong Consumer Electronics Control (CEC) message without an end-of-message signal. This …
CVE-2026-89724Medium· 5.5⚖ disputedkernel: media: vicodec: fix out-of-bounds write in FWHT encoder (CVE-2026-89724)
A flaw was found in the Linux kernel's `media: vicodec` component. An out-of-bounds write vulnerability exists in the FWHT encoder due to incorrect buffer sizing during video output format handling. This issue allows an attacker to cause c…